Symptom
Measured on 2c4a8f4, macOS 15.6.1, Apple M1. Three runs of each, identical.
A name relative to a directory that no intercept serves, such as /, reaches the intercepts only through openat. When it lands in /proc, /sys or /dev/shm, the other lookups in the table answer ENOENT for a file openat has just opened. No sysroot:
relative to a descriptor on / openat O_PATH fstatat nofollow statx faccess readlnk cwd-stat
proc/self/status ok ok ENOENT ENOENT ENOENT ENOENT ENOENT ENOENT
proc/self/exe ok ok ENOENT ENOENT ENOENT ENOENT ENOENT ENOENT
sys/devices/system/cpu/online ok ok ENOENT ENOENT ENOENT ENOENT ENOENT ENOENT
dev/shm ok ok ENOENT ENOENT ENOENT ENOENT ENOENT ENOENT
On Linux 6.18.54-0-virt, through the qemu reference lane, every column answers. EINVAL there is readlinkat on a name that is not a link:
relative to a descriptor on / openat O_PATH fstatat nofollow statx faccess readlnk cwd-stat
proc/self/status ok ok ok ok ok ok EINVAL ok
proc/self/exe ok ok ok ok ok ok ok ok
sys/devices/system/cpu/online ok ok ok ok ok ok EINVAL ok
dev/shm ok ok ok ok ok ok EINVAL ok
With a sysroot whose /proc is an empty directory, which is how the Alpine rootfs ships it, openat of the directory itself stops reaching the intercept too. The host finds the empty directory first, so a listing taken through openat(root, "proc") has 2 entries where /proc has 5:
/proc lists 5 entries absolutely, 2 through openat(root, "proc")
The table reads the same with that sysroot.
Reproducer
#define _GNU_SOURCE
#include <dirent.h>
#include <errno.h>
#include <fcntl.h>
#include <stdio.h>
#include <sys/stat.h>
#include <unistd.h>
static const char *rc(long r) {
static char buf[16][16];
static int i;
i = (i + 1) % 16;
if (r >= 0)
return "ok";
snprintf(buf[i], sizeof(buf[i]),
errno == ENOENT ? "ENOENT"
: errno == EINVAL ? "EINVAL"
: "E%d",
errno);
return buf[i];
}
static const char *opened(int fd) {
const char *r = rc(fd);
if (fd >= 0)
close(fd);
return r;
}
static int entries(int fd) {
DIR *d = fdopendir(fd);
int n = 0;
while (d && readdir(d))
n++;
if (d)
closedir(d);
return n;
}
int main(void) {
static const char *names[] = {"proc/self/status", "proc/self/exe",
"sys/devices/system/cpu/online", "dev/shm"};
int root = open("/", O_RDONLY | O_DIRECTORY);
struct stat st;
struct statx sx;
char link[256];
printf("relative to a descriptor on / openat O_PATH fstatat "
"nofollow statx faccess readlnk cwd-stat\n");
for (int i = 0; i < 4; i++) {
const char *n = names[i];
const char *o = opened(openat(root, n, O_RDONLY | O_NONBLOCK));
const char *p = opened(openat(root, n, O_PATH | O_NOFOLLOW));
const char *f = rc(fstatat(root, n, &st, 0));
const char *nf = rc(fstatat(root, n, &st, AT_SYMLINK_NOFOLLOW));
const char *x = rc(statx(root, n, 0, STATX_BASIC_STATS, &sx));
const char *a = rc(faccessat(root, n, F_OK, 0));
const char *l = rc(readlinkat(root, n, link, sizeof(link)));
fchdir(root);
const char *c = rc(stat(n, &st));
printf("%-31s %-6s %-6s %-7s %-8s %-6s %-7s %-7s %s\n", n, o, p, f, nf, x,
a, l, c);
}
printf(
"/proc lists %d entries absolutely, %d through openat(root, \"proc\")\n",
entries(open("/proc", O_RDONLY | O_DIRECTORY)),
entries(openat(root, "proc", O_RDONLY | O_DIRECTORY)));
return 0;
}
Mechanism
- The gates that send a name to the intercepts answer false for any name that does not start with
/ (path_might_use_open_intercept, src/syscall/path.c:84; path_might_use_stat_intercept, src/syscall/path.c:222). The intercepts themselves match absolute names, so sys_readlinkat, which calls proc_intercept_readlink with no gate (src/syscall/fs.c:2974), finds nothing either.
- A relative name is rebuilt into an absolute guest path for three kinds of base: a descriptor carrying a stamp (
resolve_proc_dirfd_path, src/syscall/path.c:1355), a cwd on /proc, /dev/pts, /sys or /dev/bus (src/syscall/path.c:1421), and a FUSE mount (fuse_resolve_at_path, src/syscall/fuse.c:2990). A descriptor on / is none of them, and neither is a cwd of /, so the name reaches the host as written.
sys_openat_path gives the host answer a second chance. After a host ENOENT it rebases the name through the descriptor's host path and retries the absolute spelling (src/syscall/fs.c:1016-1035, path_rebase_hostdirfd at src/syscall/path.c:1469; the comment there names systemd's chase() as the walker it is for). Nothing else calls the rebase, so stat_at_path (src/syscall/fs-stat.c:289), which serves newfstatat and statx, sys_faccessat (src/syscall/fs.c:3512) and sys_readlinkat (src/syscall/fs.c:2958) report the host's ENOENT.
- The second chance runs only after
ENOENT. A sysroot that holds an empty directory under the same name answers the host open, so the intercept is never asked.
Direction
The rebase belongs where a relative name is first translated, in path_translate_at, so every entry point gets it. It also cannot wait for the host to fail, since a sysroot may hold an empty directory under the same name.
What that costs has to be weighed. path_rebase_hostdirfd asks the host for the base's path with F_GETPATH, which is one more host call on every relative lookup if it runs unconditionally.
Found while measuring #398, and listed there under "Not in this change".
Symptom
Measured on
2c4a8f4, macOS 15.6.1, Apple M1. Three runs of each, identical.A name relative to a directory that no intercept serves, such as
/, reaches the intercepts only throughopenat. When it lands in/proc,/sysor/dev/shm, the other lookups in the table answerENOENTfor a fileopenathas just opened. No sysroot:On Linux 6.18.54-0-virt, through the qemu reference lane, every column answers.
EINVALthere isreadlinkaton a name that is not a link:With a sysroot whose
/procis an empty directory, which is how the Alpine rootfs ships it,openatof the directory itself stops reaching the intercept too. The host finds the empty directory first, so a listing taken throughopenat(root, "proc")has 2 entries where/prochas 5:The table reads the same with that sysroot.
Reproducer
Mechanism
/(path_might_use_open_intercept,src/syscall/path.c:84;path_might_use_stat_intercept,src/syscall/path.c:222). The intercepts themselves match absolute names, sosys_readlinkat, which callsproc_intercept_readlinkwith no gate (src/syscall/fs.c:2974), finds nothing either.resolve_proc_dirfd_path,src/syscall/path.c:1355), a cwd on/proc,/dev/pts,/sysor/dev/bus(src/syscall/path.c:1421), and a FUSE mount (fuse_resolve_at_path,src/syscall/fuse.c:2990). A descriptor on/is none of them, and neither is a cwd of/, so the name reaches the host as written.sys_openat_pathgives the host answer a second chance. After a hostENOENTit rebases the name through the descriptor's host path and retries the absolute spelling (src/syscall/fs.c:1016-1035,path_rebase_hostdirfdatsrc/syscall/path.c:1469; the comment there names systemd'schase()as the walker it is for). Nothing else calls the rebase, sostat_at_path(src/syscall/fs-stat.c:289), which servesnewfstatatandstatx,sys_faccessat(src/syscall/fs.c:3512) andsys_readlinkat(src/syscall/fs.c:2958) report the host'sENOENT.ENOENT. A sysroot that holds an empty directory under the same name answers the host open, so the intercept is never asked.Direction
The rebase belongs where a relative name is first translated, in
path_translate_at, so every entry point gets it. It also cannot wait for the host to fail, since a sysroot may hold an empty directory under the same name.What that costs has to be weighed.
path_rebase_hostdirfdasks the host for the base's path withF_GETPATH, which is one more host call on every relative lookup if it runs unconditionally.Found while measuring #398, and listed there under "Not in this change".