getpgid: UB when the kernel returns process group 0 (kernel threads / other PID namespace)
Maintainers usually reply within 4 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 30/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- rust
- Domain
- api, backend, operating-systems
Research direction
Read src/backend/linux_raw/process/syscalls.rs and src/backend/libc/process/syscalls.rs, starting at getpgid and comparing how each handles the kernel result. Then check the public Pid API and related wrappers such as getsid to understand the impact of the proposed choices. Done means a safe, consistent way to represent or handle a returned 0 is agreed on and applied; the issue does not specify which fix to choose.
Written by the indexing model from the issue text.
Description
getpgid can return a process group ID of 0 on Linux. rustix then builds a Pid from that value with Pid::from_raw_unchecked, which calls NonZeroI32::new_unchecked(0). That is undefined behavior in release builds. Debug builds hit the debug_assert!(pgid > 0) instead.
Where: src/backend/linux_raw/process/syscalls.rs, getpgid, unchanged in 1.1.4 and on main. The libc backend (src/backend/libc/process/syscalls.rs) does the same without the debug assertion.
When the kernel returns 0: getpgid(2) reports the group ID as seen from the caller's PID namespace. Two cases give 0:
- kernel threads, for example PID 2 (
kthreadd) and its children; - any process whose process group is not visible in the caller's namespace.
A process that scans /proc and calls getpgid on every PID will meet both cases.
Reproduction (Linux, debug build):
let pgid = rustix::process::getpgid(rustix::process::Pid::from_raw(2));
// panics on the debug_assert; in release it creates a Pid holding 0 (UB)
Possible fixes:
- return
Result<Option<Pid>>, withNonefor 0; - map 0 to an error;
- document it and return a type that may hold 0.
Other wrappers that hand a kernel-provided ID to from_raw_unchecked (for example getsid) may have the same issue.
We found this while running a test suite natively on Ubuntu 26.04. As a workaround we now call libc::getpgid directly and treat 0 as "no visible group".
- Dominant language
- Rust
- Stars
- 2.1k
- Forks
- 301
- Avg merge
- 10d 1h
- Merged PRs (30d)
- 1
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from bytecodealliance/rustix
-
net feature alone fails to compile in 1.1.5: sockopt uses crate::timespec, which net does not gate inMay be free again A pull request for this issue was closed without being merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
bytecodealliance/rustix#1689 · 2 comments ·
Maintainers usually reply within 4 days
-
Wrong flag used for (set_)ipv6_multicast_hopsPossibly taken @RajaBabu15 claimed this 53 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
bytecodealliance/rustix#1660 ·
Maintainers usually reply within 4 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
bytecodealliance/rustix#1635 ·
Maintainers usually reply within 4 days
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
bytecodealliance/rustix#1068 ·
Maintainers usually reply within 4 days
-
Difficulty 3/5 1-2 days Newbie friendliness 66/100
bytecodealliance/rustix#1694 ·
Maintainers usually reply within 4 days
All issues in bytecodealliance/rustix
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
bug llm translation
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
skillfs: one malformed chat-log line aborts the entire skill-usage analysis (skill_usage_from_chat_logs.py)Possibly taken @zjncs claimed this today. Opencomponent:skillfs
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
agentic-os-org/ANOLISA#6116 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
indygreg/cryptography-rs#99 ·