Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

getpgid: UB when the kernel returns process group 0 (kernel threads / other PID namespace)

Open
#1,696 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 4 days

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
30/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
rust

Research direction

Read src/backend/linux_raw/process/syscalls.rs and src/backend/libc/process/syscalls.rs, starting at getpgid and comparing how each handles the kernel result. Then check the public Pid API and related wrappers such as getsid to understand the impact of the proposed choices. Done means a safe, consistent way to represent or handle a returned 0 is agreed on and applied; the issue does not specify which fix to choose.

Written by the indexing model from the issue text.

Description

getpgid can return a process group ID of 0 on Linux. rustix then builds a Pid from that value with Pid::from_raw_unchecked, which calls NonZeroI32::new_unchecked(0). That is undefined behavior in release builds. Debug builds hit the debug_assert!(pgid > 0) instead.

Where: src/backend/linux_raw/process/syscalls.rs, getpgid, unchanged in 1.1.4 and on main. The libc backend (src/backend/libc/process/syscalls.rs) does the same without the debug assertion.

When the kernel returns 0: getpgid(2) reports the group ID as seen from the caller's PID namespace. Two cases give 0:

  • kernel threads, for example PID 2 (kthreadd) and its children;
  • any process whose process group is not visible in the caller's namespace.

A process that scans /proc and calls getpgid on every PID will meet both cases.

Reproduction (Linux, debug build):

let pgid = rustix::process::getpgid(rustix::process::Pid::from_raw(2));
// panics on the debug_assert; in release it creates a Pid holding 0 (UB)

Possible fixes:

  • return Result<Option<Pid>>, with None for 0;
  • map 0 to an error;
  • document it and return a type that may hold 0.

Other wrappers that hand a kernel-provided ID to from_raw_unchecked (for example getsid) may have the same issue.

We found this while running a test suite natively on Ubuntu 26.04. As a workaround we now call libc::getpgid directly and treat 0 as "no visible group".

Dominant language
Rust
Stars
2.1k
Forks
301
Avg merge
10d 1h
Merged PRs (30d)
1

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from bytecodealliance/rustix

All issues in bytecodealliance/rustix

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.