pidfd_monitor_thread checks the target with kill(hpid, 0) and then registers EVFILT_PROC on hpid, the host pid recorded when the pidfd was created. If the target exits and macOS reuses that host pid before the monitor registers, the monitor ends up watching an unrelated process. The pidfd then reports the exit of that process, or waits on it, and not on the guest's target.
The window is between pidfd_create recording the host pid and the kevent() registration succeeding, so it needs fast pid reuse and is unlikely in practice. It is not specific to the pidfd table: anything in elfuse that holds a host pid across a gap has the same exposure, so the fix may belong with however the rest of the process layer tracks host pids.
Found while reviewing #399.
pidfd_monitor_threadchecks the target withkill(hpid, 0)and then registersEVFILT_PROConhpid, the host pid recorded when the pidfd was created. If the target exits and macOS reuses that host pid before the monitor registers, the monitor ends up watching an unrelated process. The pidfd then reports the exit of that process, or waits on it, and not on the guest's target.The window is between
pidfd_createrecording the host pid and thekevent()registration succeeding, so it needs fast pid reuse and is unlikely in practice. It is not specific to the pidfd table: anything in elfuse that holds a host pid across a gap has the same exposure, so the fix may belong with however the rest of the process layer tracks host pids.Found while reviewing #399.