Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

bwrap has impact on the shell when finished

Open
#744 6 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
45/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
bash, c, docker, linux

Research direction

Start by running the reproduction script with and without bwrap's --unshare-pid flag, comparing the interactive-shell behavior and the subsequent docker exec command. Trace the --unshare-pid path and terminal/job-control handling in bubblewrap; done means the command after the interactive shell runs directly without requiring fg.

Written by the indexing model from the issue text.

Description

It’s a bit difficult to explain the issue, so I’m giving a script below to reproduce it. It arises with docker but also "other container tools" (my first occurence occured with machinectl, but docker allows a more minimal example)

#!/usr/bin/env bash

if ! command -v bwrap || ! command -v docker; then
  echo "bubblewrap and docker are needed for this example"
  exit 1
fi

# Make sure we don't leave some running containers behind
container_id=$(docker run -d -it alpine)
trap "docker stop $container_id" EXIT

# This command works
echo "This docker command works"
docker exec -it "$container_id" ls -a

echo "Please exit the shell below to continue"
bwrap --unshare-pid --ro-bind-try /bin /bin --ro-bind-try /lib64 /lib64 --ro-bind-try /lib /lib --ro-bind-try /usr /usr --ro-bind-try /nix /nix -- /bin/sh

echo "This docker command doesn't work"
# Bash "backgrounds" the command instead of running docker. We are
# obliged to run "fg" to let it continue
docker exec -it "$container_id" ls -a

When I run this script, I get the following output:

host $ ./example.sh 
This docker command works
(some ls output)
Please exit the shell below to continue
$ 
This docker command doesn't work

[1]+  Stopped                 ./example.sh
host $ fg
./example.sh
(some ls output)
7e75ced3ecdf227d1eaad68d6dfc3e44587ae483ec124e09937628238a4d6560

The issue only happens when the "--unshare-pid" flag is present on bwrap (the rest of the flags is just to get a MVE). I could reproduce the issue on two different kinds of systems (debian and nixos). "Normal" (non-container related) commands work just fine. Also, we need to get an interactive shell with bwrap, otherwise the issue doesn’t arise either.

I searched for some information regarding that kind of behavior in vain, any pointer to an explanation / solution would be appreciated

Dominant language
C
Stars
8.9k
Forks
391
Avg merge
17h 45m
Merged PRs (30d)
10

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from containers/bubblewrap

All issues in containers/bubblewrap

Similar issues

More C issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.