fix(fspy): don't abort traced processes when the preload has no payload - #753
Open
lifeiscontent wants to merge 2 commits into
Open
lifeiscontent wants to merge 2 commits into
lifeiscontent wants to merge 2 commits into
Conversation
lifeiscontent
force-pushed
the
fix/fspy-preload-no-payload
branch
from
September 23, 2026 23:50
10d79bd to
e76c256
Compare
lifeiscontent
force-pushed
the
fix/fspy-preload-no-payload
branch
from
September 23, 2026 23:55
e76c256 to
f1fb005
Compare
lifeiscontent
force-pushed
the
fix/fspy-preload-no-payload
branch
from
September 23, 2026 23:56
f1fb005 to
6f63d39
Compare
If the preload can't set up tracking for an exec (for example, the seccomp filter for a static binary can't be installed because the sandbox denies the syscall), mark the trace incomplete and run the original call untracked instead of failing it. Resolution errors such as ENOENT or EACCES are still returned as-is. Each exec variant falls back to its own libc original with its original arguments, so execvp and execlp still search PATH, execveat keeps its dirfd and flags, and fexecve keeps its fd. Refs voidzero-dev#700
The preload constructor panicked when FSPY_PAYLOAD was missing or invalid, or when the shared-memory channel couldn't be opened, which aborts the host process. This happens with a leaked LD_PRELOAD in a sandbox that clears the environment. Leave the client unset in that case and forward every exec and posix_spawn call to its original.
lifeiscontent
force-pushed
the
fix/fspy-preload-no-payload
branch
from
September 24, 2026 10:38
6f63d39 to
f3f2a54
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Part of #700, split out of #701. The preload constructor panicked when
FSPY_PAYLOADwas missing or invalid, or when its shared-memory channel couldn't be opened, and a panic there aborts the host process. A leakedLD_PRELOADin a sandbox that clears the environment is enough to trigger it.Changes
Client::from_envreturnsOption. The constructor leaves the client unset instead of panicking, andhandle_openno longer unwraps.ChannelConf::senderreturnsNoneinstead of panicking when the channel exists but can't be opened.posix_spawn(p)calls its original directly, using the per-variant fallback from fix(fspy): run exec untracked when injection fails #701.This branch is based on #701. A PR from a fork can't target another fork branch, so only the top commit belongs to this PR until #701 merges.