Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Cached tasks cannot spawn child processes inside a rootless bubblewrap sandbox (EPERM)

Đang mở
#700 2 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

@lifeiscontent đang làm issue này rồi.

Từ ngày 30/8/2026.

  • #701 của @lifeiscontent — đang mở

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
48/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
linux, rust

Hướng nghiên cứu

Tái hiện lỗi bằng lệnh rootless bubblewrap được cung cấp và so sánh các task đã được cache với các task bị tắt cache bằng vp run -r test. Bắt đầu bằng cách truy vết đường dẫn fspy_preload_unix và quá trình thiết lập tiến trình con; hoàn thành khi các task đã được cache có thể spawn trong sandbox này, hoặc việc tracking suy giảm mà không chặn exec.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Summary

Inside a rootless bubblewrap sandbox, a cache-enabled task cannot spawn child processes. Every spawn/spawnSync/execFile fails with EPERM before the child runs. Setting cache: false on the same task, with nothing else changed, makes it work.

The path is absolute and executable in both cases, so this is not PATH resolution.

Reproduction

Sandbox is entered as:

bwrap --die-with-parent --new-session \
  --unshare-user --unshare-pid --unshare-ipc --unshare-uts --unshare-cgroup --unshare-net \
  --cap-drop ALL \
  --clearenv --setenv PATH /runtime/bin \
  --ro-bind <toolchain-image> /runtime \
  --tmpfs /tmp --dev /dev --proc /proc \
  --bind <checkout> /workspace \
  -- /runtime/bin/sh -c 'cd /workspace && vp run -r test'

There is no /usr/bin, /bin or /usr/lib in the sandbox; everything is under /runtime.

Any cached task whose command spawns a child reproduces it:

execFileSync("/tmp/shell/sh", ["-n"], { input: script });
task config spawn
{ command: 'vp test' } EPERM
{ command: 'vp test', cache: false } works

In one vp run -r test over a workspace, the packages I had flipped to cache: false spawned fine while the packages still cached failed in the same run, same sandbox, same commit. Flipping two packages took the spawn failures from 74 to 0.

Observed

Error: spawnSync /tmp/shell/sh EPERM
Error: spawn EPERM

Nothing is printed by the child. git subprocesses fail the same way one level down:

fatal: cannot exec 'git-receive-pack': Operation not permitted

Environment

  • vite-plus 0.3.0
  • Linux x86_64, glibc
  • rootless bubblewrap, seccomp, unprivileged user namespaces

Notes

Not #569/#576 — 0.3.0 has both. LD_PRELOAD is unset going in, so not #340.

Guess: fspy_preload_unix has to inject into each child, and this sandbox is --cap-drop ALL with /usr/lib unmounted, so either the preload object is unreachable in the child's mount namespace or something it does on init is denied — and the exec is refused instead of tracking degrading.

Falling back to caching without file tracking would be better than failing the spawn. Today the only workaround is disabling the cache for the whole package.

Happy to run patches or a debug build against the sandbox.

Ngôn ngữ chính
Rust
Star
471
Fork
42
Merge trung bình
1 ngày 4 giờ
Pull request đã merge (30 ngày)
45

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của voidzero-dev/vite-task

Tất cả issue của voidzero-dev/vite-task

Issue tương tự

Thêm issue về Rust

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.