fix(sandbox): report the real seccomp probe launcher error - #4061
Closed
fede-kamel wants to merge 1 commit into
Closed
fede-kamel wants to merge 1 commit into
fede-kamel wants to merge 1 commit into
Conversation
The seccomp notification probes hide the kernel error that caused them to fail. When install_listener fails on the launcher thread, the broker only observes a closed channel and reports notification launcher disappeared, discarding the errno. This PR joins the launcher thread on handover failure and propagates its real error for all three probes: probe_scalar_round_trip, probe_addfd_send, and probe_connected_sendto_fast_path. A new test spawns a disposable child with a seccomp filter that blocks SYS_seccomp and verifies the probe surfaces PermissionDenied with os error 1 (EPERM) instead of a generic message. Signed-off-by: fede-kamel <fkamelhar@gmail.com>
fede-kamel
requested review from
a team,
derekwaynecarr,
mrunalp and
sjenning
as code owners
October 1, 2026 16:38
Collaborator
|
is this needed with #4051? |
4 of 6 tasks
Collaborator
|
Closing in favor of #4051 with the noted recommendation to pick up the raw OS err number handling from this PR. Thanks for the contribution, Fede! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The seccomp notification probes hide the kernel error that caused them
to fail. When install_listener fails on the launcher thread, the broker
only observes a closed channel and reports
notification launcher disappeared, discarding the errno. This makes several unrelatedfailures indistinguishable from the pre-5.19 WAIT_KILLABLE_RECV
rejection fixed in #3420, which is why #3842 looks like a regression
of that fix. This PR joins the launcher thread and propagates its
real error.
Related Issue
Refs #3842
Changes
launcher_failure()which joins the launcher thread on handoverfailure and returns its real error with the original ErrorKind
preserved, so the errno reaches the qualification report.
probe_scalar_round_trip, probe_addfd_send, and
probe_connected_sendto_fast_path.
without sending, and a launcher that panicked.
Testing
notification_probe_reports_rejected_listener_install. Itspawns a disposable child process, installs a filter that refuses
SECCOMP_SET_MODE_FILTER with EPERM while leaving the notification
size query working, and asserts the probe surfaces PermissionDenied
with os error 1. This models a restrictive host which the EINVAL
fallback cannot retry — distinct from a pre-5.19 kernel.
left: Other, right: PermissionDenied, confirming it catches the swallowed errorrather than passing vacuously.
cargo test -p openshell-isolation-interface: 29 lib + 25integration tests pass.
cargo clippy: clean.cargo checkon dependent crates: clean.