Skip to content

kryptikd gc takes --rootfs, volume passwd names the zone, and wlproxy's refusals carry the right error kinds - #221

Merged
DevomB merged 1 commit into
mainfrom
kryptikd-fixes
Oct 7, 2026
Merged

DevomB merged 1 commit into
mainfrom
kryptikd-fixes

Conversation

@DevomB

@DevomB DevomB commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Small verified fixes from the repository cleanup's bug list, in kryptikd and kryptik-wlproxy: gc --rootfs, the zone name in volume passwd's error, mountpoint escaping, an fd leak on a failed memfd, a denied-syscall error variant, and three wlproxy error kinds. Written by a subagent that ran out of session before opening this PR; I committed its finished edits unreviewed, so CI and a non-author read decide. Read since by the session that owns the update chain: gc now closes volumes under the same zone-data base that kryptik passes to launch, the passphrase error names the zone rather than the volume's path, mount paths are escaped as /proc/self/mounts writes them (backslash first), both memfds close on every path, and the error kinds are renamed or added with nothing matching on the old ones. No findings. The branch merges into main b69b728 without conflict.

Distro run 37347957140 at 53a1bcb: every acceptance part green. CI green.

…'s refusals carry the right error kinds

- gc built a volume's mountpoint from the default rootfs base only, so a
  zone launched with --rootfs left its volume open; gc takes --rootfs as
  stop does.
- volume passwd's wrong-passphrase error named the container path as the
  zone; is_mountpoint escapes backslash, tab and newline as /proc/self/mounts
  does, not only space; both memfds are owned, so a failed second one closes
  the first.
- seccomp's widening reports a denied syscall as denied, not as a bad number.
- wlproxy: a table without set_app_id, a forbidden null and a second new_id
  are logged as what they are.
@DevomB
DevomB marked this pull request as ready for review October 7, 2026 04:11
@DevomB
DevomB merged commit 127af64 into main Oct 7, 2026
27 of 29 checks passed
@DevomB
DevomB deleted the kryptikd-fixes branch October 7, 2026 04:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant