Relative lookups into `/proc`, `/sys` and `/dev/shm` from a descriptor on `/` reach the intercepts through `openat` only
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 48/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- c, linux, macos
- Domain
- operating-systems
Research direction
Start with path_translate_at in src/syscall/path.c, then trace path_rebase_hostdirfd and the lookup entry points in src/syscall/fs.c and src/syscall/fs-stat.c. Use the supplied C reproducer on macOS and the qemu reference lane to compare relative lookups. Done means relative descriptor lookups consistently reach the intercepts, including when the sysroot contains an empty directory, without leaving stat, access, or readlink behind.
Written by the indexing model from the issue text.
Description
Symptom
Measured on 2c4a8f4, macOS 15.6.1, Apple M1. Three runs of each, identical.
A name relative to a directory that no intercept serves, such as /, reaches the intercepts only through openat. When it lands in /proc, /sys or /dev/shm, the other lookups in the table answer ENOENT for a file openat has just opened. No sysroot:
relative to a descriptor on / openat O_PATH fstatat nofollow statx faccess readlnk cwd-stat
proc/self/status ok ok ENOENT ENOENT ENOENT ENOENT ENOENT ENOENT
proc/self/exe ok ok ENOENT ENOENT ENOENT ENOENT ENOENT ENOENT
sys/devices/system/cpu/online ok ok ENOENT ENOENT ENOENT ENOENT ENOENT ENOENT
dev/shm ok ok ENOENT ENOENT ENOENT ENOENT ENOENT ENOENT
On Linux 6.18.54-0-virt, through the qemu reference lane, every column answers. EINVAL there is readlinkat on a name that is not a link:
relative to a descriptor on / openat O_PATH fstatat nofollow statx faccess readlnk cwd-stat
proc/self/status ok ok ok ok ok ok EINVAL ok
proc/self/exe ok ok ok ok ok ok ok ok
sys/devices/system/cpu/online ok ok ok ok ok ok EINVAL ok
dev/shm ok ok ok ok ok ok EINVAL ok
With a sysroot whose /proc is an empty directory, which is how the Alpine rootfs ships it, openat of the directory itself stops reaching the intercept too. The host finds the empty directory first, so a listing taken through openat(root, "proc") has 2 entries where /proc has 5:
/proc lists 5 entries absolutely, 2 through openat(root, "proc")
The table reads the same with that sysroot.
Reproducer
#define _GNU_SOURCE
#include <dirent.h>
#include <errno.h>
#include <fcntl.h>
#include <stdio.h>
#include <sys/stat.h>
#include <unistd.h>
static const char *rc(long r) {
static char buf[16][16];
static int i;
i = (i + 1) % 16;
if (r >= 0)
return "ok";
snprintf(buf[i], sizeof(buf[i]),
errno == ENOENT ? "ENOENT"
: errno == EINVAL ? "EINVAL"
: "E%d",
errno);
return buf[i];
}
static const char *opened(int fd) {
const char *r = rc(fd);
if (fd >= 0)
close(fd);
return r;
}
static int entries(int fd) {
DIR *d = fdopendir(fd);
int n = 0;
while (d && readdir(d))
n++;
if (d)
closedir(d);
return n;
}
int main(void) {
static const char *names[] = {"proc/self/status", "proc/self/exe",
"sys/devices/system/cpu/online", "dev/shm"};
int root = open("/", O_RDONLY | O_DIRECTORY);
struct stat st;
struct statx sx;
char link[256];
printf("relative to a descriptor on / openat O_PATH fstatat "
"nofollow statx faccess readlnk cwd-stat\n");
for (int i = 0; i < 4; i++) {
const char *n = names[i];
const char *o = opened(openat(root, n, O_RDONLY | O_NONBLOCK));
const char *p = opened(openat(root, n, O_PATH | O_NOFOLLOW));
const char *f = rc(fstatat(root, n, &st, 0));
const char *nf = rc(fstatat(root, n, &st, AT_SYMLINK_NOFOLLOW));
const char *x = rc(statx(root, n, 0, STATX_BASIC_STATS, &sx));
const char *a = rc(faccessat(root, n, F_OK, 0));
const char *l = rc(readlinkat(root, n, link, sizeof(link)));
fchdir(root);
const char *c = rc(stat(n, &st));
printf("%-31s %-6s %-6s %-7s %-8s %-6s %-7s %-7s %s\n", n, o, p, f, nf, x,
a, l, c);
}
printf(
"/proc lists %d entries absolutely, %d through openat(root, \"proc\")\n",
entries(open("/proc", O_RDONLY | O_DIRECTORY)),
entries(openat(root, "proc", O_RDONLY | O_DIRECTORY)));
return 0;
}
Mechanism
- The gates that send a name to the intercepts answer false for any name that does not start with
/(path_might_use_open_intercept,src/syscall/path.c:84;path_might_use_stat_intercept,src/syscall/path.c:222). The intercepts themselves match absolute names, sosys_readlinkat, which callsproc_intercept_readlinkwith no gate (src/syscall/fs.c:2974), finds nothing either. - A relative name is rebuilt into an absolute guest path for three kinds of base: a descriptor carrying a stamp (
resolve_proc_dirfd_path,src/syscall/path.c:1355), a cwd on/proc,/dev/pts,/sysor/dev/bus(src/syscall/path.c:1421), and a FUSE mount (fuse_resolve_at_path,src/syscall/fuse.c:2990). A descriptor on/is none of them, and neither is a cwd of/, so the name reaches the host as written. sys_openat_pathgives the host answer a second chance. After a hostENOENTit rebases the name through the descriptor's host path and retries the absolute spelling (src/syscall/fs.c:1016-1035,path_rebase_hostdirfdatsrc/syscall/path.c:1469; the comment there names systemd'schase()as the walker it is for). Nothing else calls the rebase, sostat_at_path(src/syscall/fs-stat.c:289), which servesnewfstatatandstatx,sys_faccessat(src/syscall/fs.c:3512) andsys_readlinkat(src/syscall/fs.c:2958) report the host'sENOENT.- The second chance runs only after
ENOENT. A sysroot that holds an empty directory under the same name answers the host open, so the intercept is never asked.
Direction
The rebase belongs where a relative name is first translated, in path_translate_at, so every entry point gets it. It also cannot wait for the host to fail, since a sysroot may hold an empty directory under the same name.
What that costs has to be weighed. path_rebase_hostdirfd asks the host for the base's path with F_GETPATH, which is one more host call on every relative lookup if it runs unconditionally.
Found while measuring #398, and listed there under "Not in this change".
- Dominant language
- C
- Stars
- 271
- Forks
- 28
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 27
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from sysprog21/elfuse
-
Difficulty 3/5 1-2 days Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
bug
Difficulty 4/5 3-5 days Newbie friendliness 64/100
Maintainers usually reply within 1 day
-
bug
Difficulty 4/5 3-5 days Newbie friendliness 48/100
Maintainers usually reply within 1 day
-
bug
Difficulty 4/5 3-5 days Newbie friendliness 45/100
Maintainers usually reply within 1 day
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 78/100
Maintainers usually reply within 1 day
All issues in sysprog21/elfuse
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
containers/bubblewrap#813 · 1 reaction ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
tree-sitter/tree-sitter#6005 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
kubernetes-sigs/security-profiles-operator#3537 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
darktable-org/darktable#22502 · 2 comments ·
Maintainers usually reply within 1 day