Skip to content

fix(sandbox): report the real seccomp probe launcher error - #4061

Closed
fede-kamel wants to merge 1 commit into
NVIDIA:mainfrom
fede-kamel:fix/seccomp-probe-error
Closed

fede-kamel wants to merge 1 commit into
NVIDIA:mainfrom
fede-kamel:fix/seccomp-probe-error

Conversation

@fede-kamel

Copy link
Copy Markdown
Contributor

Summary

The seccomp notification probes hide the kernel error that caused them
to fail. When install_listener fails on the launcher thread, the broker
only observes a closed channel and reports notification launcher disappeared, discarding the errno. This makes several unrelated
failures indistinguishable from the pre-5.19 WAIT_KILLABLE_RECV
rejection fixed in #3420, which is why #3842 looks like a regression
of that fix. This PR joins the launcher thread and propagates its
real error.

Related Issue

Refs #3842

Changes

  • Add launcher_failure() which joins the launcher thread on handover
    failure and returns its real error with the original ErrorKind
    preserved, so the errno reaches the qualification report.
  • Use it on the recv() failure path of all three probes:
    probe_scalar_round_trip, probe_addfd_send, and
    probe_connected_sendto_fast_path.
  • Distinguish the remaining non-error cases: a launcher that exited
    without sending, and a launcher that panicked.

Testing

  • New test notification_probe_reports_rejected_listener_install. It
    spawns a disposable child process, installs a filter that refuses
    SECCOMP_SET_MODE_FILTER with EPERM while leaving the notification
    size query working, and asserts the probe surfaces PermissionDenied
    with os error 1. This models a restrictive host which the EINVAL
    fallback cannot retry — distinct from a pre-5.19 kernel.
  • Watched it fail before the fix with left: Other, right: PermissionDenied, confirming it catches the swallowed error
    rather than passing vacuously.
  • cargo test -p openshell-isolation-interface: 29 lib + 25
    integration tests pass.
  • cargo clippy: clean.
  • cargo check on dependent crates: clean.

The seccomp notification probes hide the kernel error that caused them
to fail. When install_listener fails on the launcher thread, the broker
only observes a closed channel and reports
notification launcher disappeared, discarding the errno.

This PR joins the launcher thread on handover failure and propagates
its real error for all three probes: probe_scalar_round_trip,
probe_addfd_send, and probe_connected_sendto_fast_path.

A new test spawns a disposable child with a seccomp filter that blocks
SYS_seccomp and verifies the probe surfaces PermissionDenied with os
error 1 (EPERM) instead of a generic message.

Signed-off-by: fede-kamel <fkamelhar@gmail.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@johntmyers

Copy link
Copy Markdown
Collaborator

is this needed with #4051?

@purp

purp commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Closing in favor of #4051 with the noted recommendation to pick up the raw OS err number handling from this PR.

Thanks for the contribution, Fede!

@purp purp closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants