Repository navigation
kryptikd gc takes --rootfs, volume passwd names the zone, and wlproxy's refusals carry the right error kinds - #221
Merged
Merged
Conversation
…'s refusals carry the right error kinds - gc built a volume's mountpoint from the default rootfs base only, so a zone launched with --rootfs left its volume open; gc takes --rootfs as stop does. - volume passwd's wrong-passphrase error named the container path as the zone; is_mountpoint escapes backslash, tab and newline as /proc/self/mounts does, not only space; both memfds are owned, so a failed second one closes the first. - seccomp's widening reports a denied syscall as denied, not as a bad number. - wlproxy: a table without set_app_id, a forbidden null and a second new_id are logged as what they are.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Small verified fixes from the repository cleanup's bug list, in kryptikd and kryptik-wlproxy:
gc --rootfs, the zone name involume passwd's error, mountpoint escaping, an fd leak on a failed memfd, a denied-syscall error variant, and three wlproxy error kinds. Written by a subagent that ran out of session before opening this PR; I committed its finished edits unreviewed, so CI and a non-author read decide. Read since by the session that owns the update chain: gc now closes volumes under the same zone-data base thatkryptikpasses to launch, the passphrase error names the zone rather than the volume's path, mount paths are escaped as /proc/self/mounts writes them (backslash first), both memfds close on every path, and the error kinds are renamed or added with nothing matching on the old ones. No findings. The branch merges into main b69b728 without conflict.Distro run 37347957140 at 53a1bcb: every acceptance part green. CI green.