Skip to content

Relative lookups into /proc, /sys and /dev/shm from a descriptor on / reach the intercepts through openat only #404

Description

@jotpalch

Symptom

Measured on 2c4a8f4, macOS 15.6.1, Apple M1. Three runs of each, identical.

A name relative to a directory that no intercept serves, such as /, reaches the intercepts only through openat. When it lands in /proc, /sys or /dev/shm, the other lookups in the table answer ENOENT for a file openat has just opened. No sysroot:

relative to a descriptor on /   openat O_PATH  fstatat nofollow statx  faccess readlnk cwd-stat
proc/self/status                ok     ok     ENOENT  ENOENT   ENOENT ENOENT  ENOENT  ENOENT
proc/self/exe                   ok     ok     ENOENT  ENOENT   ENOENT ENOENT  ENOENT  ENOENT
sys/devices/system/cpu/online   ok     ok     ENOENT  ENOENT   ENOENT ENOENT  ENOENT  ENOENT
dev/shm                         ok     ok     ENOENT  ENOENT   ENOENT ENOENT  ENOENT  ENOENT

On Linux 6.18.54-0-virt, through the qemu reference lane, every column answers. EINVAL there is readlinkat on a name that is not a link:

relative to a descriptor on /   openat O_PATH  fstatat nofollow statx  faccess readlnk cwd-stat
proc/self/status                ok     ok     ok      ok       ok     ok      EINVAL  ok
proc/self/exe                   ok     ok     ok      ok       ok     ok      ok      ok
sys/devices/system/cpu/online   ok     ok     ok      ok       ok     ok      EINVAL  ok
dev/shm                         ok     ok     ok      ok       ok     ok      EINVAL  ok

With a sysroot whose /proc is an empty directory, which is how the Alpine rootfs ships it, openat of the directory itself stops reaching the intercept too. The host finds the empty directory first, so a listing taken through openat(root, "proc") has 2 entries where /proc has 5:

/proc lists 5 entries absolutely, 2 through openat(root, "proc")

The table reads the same with that sysroot.

Reproducer

#define _GNU_SOURCE
#include <dirent.h>
#include <errno.h>
#include <fcntl.h>
#include <stdio.h>
#include <sys/stat.h>
#include <unistd.h>

static const char *rc(long r) {
  static char buf[16][16];
  static int i;
  i = (i + 1) % 16;
  if (r >= 0)
    return "ok";
  snprintf(buf[i], sizeof(buf[i]),
           errno == ENOENT   ? "ENOENT"
           : errno == EINVAL ? "EINVAL"
                             : "E%d",
           errno);
  return buf[i];
}

static const char *opened(int fd) {
  const char *r = rc(fd);
  if (fd >= 0)
    close(fd);
  return r;
}

static int entries(int fd) {
  DIR *d = fdopendir(fd);
  int n = 0;
  while (d && readdir(d))
    n++;
  if (d)
    closedir(d);
  return n;
}

int main(void) {
  static const char *names[] = {"proc/self/status", "proc/self/exe",
                                "sys/devices/system/cpu/online", "dev/shm"};
  int root = open("/", O_RDONLY | O_DIRECTORY);
  struct stat st;
  struct statx sx;
  char link[256];

  printf("relative to a descriptor on /   openat O_PATH  fstatat "
         "nofollow statx  faccess readlnk cwd-stat\n");
  for (int i = 0; i < 4; i++) {
    const char *n = names[i];
    const char *o = opened(openat(root, n, O_RDONLY | O_NONBLOCK));
    const char *p = opened(openat(root, n, O_PATH | O_NOFOLLOW));
    const char *f = rc(fstatat(root, n, &st, 0));
    const char *nf = rc(fstatat(root, n, &st, AT_SYMLINK_NOFOLLOW));
    const char *x = rc(statx(root, n, 0, STATX_BASIC_STATS, &sx));
    const char *a = rc(faccessat(root, n, F_OK, 0));
    const char *l = rc(readlinkat(root, n, link, sizeof(link)));
    fchdir(root);
    const char *c = rc(stat(n, &st));
    printf("%-31s %-6s %-6s %-7s %-8s %-6s %-7s %-7s %s\n", n, o, p, f, nf, x,
           a, l, c);
  }
  printf(
      "/proc lists %d entries absolutely, %d through openat(root, \"proc\")\n",
      entries(open("/proc", O_RDONLY | O_DIRECTORY)),
      entries(openat(root, "proc", O_RDONLY | O_DIRECTORY)));
  return 0;
}

Mechanism

  1. The gates that send a name to the intercepts answer false for any name that does not start with / (path_might_use_open_intercept, src/syscall/path.c:84; path_might_use_stat_intercept, src/syscall/path.c:222). The intercepts themselves match absolute names, so sys_readlinkat, which calls proc_intercept_readlink with no gate (src/syscall/fs.c:2974), finds nothing either.
  2. A relative name is rebuilt into an absolute guest path for three kinds of base: a descriptor carrying a stamp (resolve_proc_dirfd_path, src/syscall/path.c:1355), a cwd on /proc, /dev/pts, /sys or /dev/bus (src/syscall/path.c:1421), and a FUSE mount (fuse_resolve_at_path, src/syscall/fuse.c:2990). A descriptor on / is none of them, and neither is a cwd of /, so the name reaches the host as written.
  3. sys_openat_path gives the host answer a second chance. After a host ENOENT it rebases the name through the descriptor's host path and retries the absolute spelling (src/syscall/fs.c:1016-1035, path_rebase_hostdirfd at src/syscall/path.c:1469; the comment there names systemd's chase() as the walker it is for). Nothing else calls the rebase, so stat_at_path (src/syscall/fs-stat.c:289), which serves newfstatat and statx, sys_faccessat (src/syscall/fs.c:3512) and sys_readlinkat (src/syscall/fs.c:2958) report the host's ENOENT.
  4. The second chance runs only after ENOENT. A sysroot that holds an empty directory under the same name answers the host open, so the intercept is never asked.

Direction

The rebase belongs where a relative name is first translated, in path_translate_at, so every entry point gets it. It also cannot wait for the host to fail, since a sysroot may hold an empty directory under the same name.

What that costs has to be weighed. path_rebase_hostdirfd asks the host for the base's path with F_GETPATH, which is one more host call on every relative lookup if it runs unconditionally.

Found while measuring #398, and listed there under "Not in this change".

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions