Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Relative lookups into `/proc`, `/sys` and `/dev/shm` from a descriptor on `/` reach the intercepts through `openat` only

Open
#404 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
48/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
c, linux, macos

Research direction

Start with path_translate_at in src/syscall/path.c, then trace path_rebase_hostdirfd and the lookup entry points in src/syscall/fs.c and src/syscall/fs-stat.c. Use the supplied C reproducer on macOS and the qemu reference lane to compare relative lookups. Done means relative descriptor lookups consistently reach the intercepts, including when the sysroot contains an empty directory, without leaving stat, access, or readlink behind.

Written by the indexing model from the issue text.

Description

Symptom

Measured on 2c4a8f4, macOS 15.6.1, Apple M1. Three runs of each, identical.

A name relative to a directory that no intercept serves, such as /, reaches the intercepts only through openat. When it lands in /proc, /sys or /dev/shm, the other lookups in the table answer ENOENT for a file openat has just opened. No sysroot:

relative to a descriptor on /   openat O_PATH  fstatat nofollow statx  faccess readlnk cwd-stat
proc/self/status                ok     ok     ENOENT  ENOENT   ENOENT ENOENT  ENOENT  ENOENT
proc/self/exe                   ok     ok     ENOENT  ENOENT   ENOENT ENOENT  ENOENT  ENOENT
sys/devices/system/cpu/online   ok     ok     ENOENT  ENOENT   ENOENT ENOENT  ENOENT  ENOENT
dev/shm                         ok     ok     ENOENT  ENOENT   ENOENT ENOENT  ENOENT  ENOENT

On Linux 6.18.54-0-virt, through the qemu reference lane, every column answers. EINVAL there is readlinkat on a name that is not a link:

relative to a descriptor on /   openat O_PATH  fstatat nofollow statx  faccess readlnk cwd-stat
proc/self/status                ok     ok     ok      ok       ok     ok      EINVAL  ok
proc/self/exe                   ok     ok     ok      ok       ok     ok      ok      ok
sys/devices/system/cpu/online   ok     ok     ok      ok       ok     ok      EINVAL  ok
dev/shm                         ok     ok     ok      ok       ok     ok      EINVAL  ok

With a sysroot whose /proc is an empty directory, which is how the Alpine rootfs ships it, openat of the directory itself stops reaching the intercept too. The host finds the empty directory first, so a listing taken through openat(root, "proc") has 2 entries where /proc has 5:

/proc lists 5 entries absolutely, 2 through openat(root, "proc")

The table reads the same with that sysroot.

Reproducer

#define _GNU_SOURCE
#include <dirent.h>
#include <errno.h>
#include <fcntl.h>
#include <stdio.h>
#include <sys/stat.h>
#include <unistd.h>

static const char *rc(long r) {
  static char buf[16][16];
  static int i;
  i = (i + 1) % 16;
  if (r >= 0)
    return "ok";
  snprintf(buf[i], sizeof(buf[i]),
           errno == ENOENT   ? "ENOENT"
           : errno == EINVAL ? "EINVAL"
                             : "E%d",
           errno);
  return buf[i];
}

static const char *opened(int fd) {
  const char *r = rc(fd);
  if (fd >= 0)
    close(fd);
  return r;
}

static int entries(int fd) {
  DIR *d = fdopendir(fd);
  int n = 0;
  while (d && readdir(d))
    n++;
  if (d)
    closedir(d);
  return n;
}

int main(void) {
  static const char *names[] = {"proc/self/status", "proc/self/exe",
                                "sys/devices/system/cpu/online", "dev/shm"};
  int root = open("/", O_RDONLY | O_DIRECTORY);
  struct stat st;
  struct statx sx;
  char link[256];

  printf("relative to a descriptor on /   openat O_PATH  fstatat "
         "nofollow statx  faccess readlnk cwd-stat\n");
  for (int i = 0; i < 4; i++) {
    const char *n = names[i];
    const char *o = opened(openat(root, n, O_RDONLY | O_NONBLOCK));
    const char *p = opened(openat(root, n, O_PATH | O_NOFOLLOW));
    const char *f = rc(fstatat(root, n, &st, 0));
    const char *nf = rc(fstatat(root, n, &st, AT_SYMLINK_NOFOLLOW));
    const char *x = rc(statx(root, n, 0, STATX_BASIC_STATS, &sx));
    const char *a = rc(faccessat(root, n, F_OK, 0));
    const char *l = rc(readlinkat(root, n, link, sizeof(link)));
    fchdir(root);
    const char *c = rc(stat(n, &st));
    printf("%-31s %-6s %-6s %-7s %-8s %-6s %-7s %-7s %s\n", n, o, p, f, nf, x,
           a, l, c);
  }
  printf(
      "/proc lists %d entries absolutely, %d through openat(root, \"proc\")\n",
      entries(open("/proc", O_RDONLY | O_DIRECTORY)),
      entries(openat(root, "proc", O_RDONLY | O_DIRECTORY)));
  return 0;
}

Mechanism

  1. The gates that send a name to the intercepts answer false for any name that does not start with / (path_might_use_open_intercept, src/syscall/path.c:84; path_might_use_stat_intercept, src/syscall/path.c:222). The intercepts themselves match absolute names, so sys_readlinkat, which calls proc_intercept_readlink with no gate (src/syscall/fs.c:2974), finds nothing either.
  2. A relative name is rebuilt into an absolute guest path for three kinds of base: a descriptor carrying a stamp (resolve_proc_dirfd_path, src/syscall/path.c:1355), a cwd on /proc, /dev/pts, /sys or /dev/bus (src/syscall/path.c:1421), and a FUSE mount (fuse_resolve_at_path, src/syscall/fuse.c:2990). A descriptor on / is none of them, and neither is a cwd of /, so the name reaches the host as written.
  3. sys_openat_path gives the host answer a second chance. After a host ENOENT it rebases the name through the descriptor's host path and retries the absolute spelling (src/syscall/fs.c:1016-1035, path_rebase_hostdirfd at src/syscall/path.c:1469; the comment there names systemd's chase() as the walker it is for). Nothing else calls the rebase, so stat_at_path (src/syscall/fs-stat.c:289), which serves newfstatat and statx, sys_faccessat (src/syscall/fs.c:3512) and sys_readlinkat (src/syscall/fs.c:2958) report the host's ENOENT.
  4. The second chance runs only after ENOENT. A sysroot that holds an empty directory under the same name answers the host open, so the intercept is never asked.

Direction

The rebase belongs where a relative name is first translated, in path_translate_at, so every entry point gets it. It also cannot wait for the host to fail, since a sysroot may hold an empty directory under the same name.

What that costs has to be weighed. path_rebase_hostdirfd asks the host for the base's path with F_GETPATH, which is one more host call on every relative lookup if it runs unconditionally.

Found while measuring #398, and listed there under "Not in this change".

Dominant language
C
Stars
271
Forks
28
Avg merge
1d 20h
Merged PRs (30d)
27

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from sysprog21/elfuse

All issues in sysprog21/elfuse

Similar issues

More C issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.