Skip to content

fix(fspy): don't abort traced processes when the preload has no payload - #753

Open
lifeiscontent wants to merge 2 commits into
voidzero-dev:mainfrom
lifeiscontent:fix/fspy-preload-no-payload
Open

lifeiscontent wants to merge 2 commits into
voidzero-dev:mainfrom
lifeiscontent:fix/fspy-preload-no-payload

Conversation

@lifeiscontent

@lifeiscontent lifeiscontent commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Motivation

Part of #700, split out of #701. The preload constructor panicked when FSPY_PAYLOAD was missing or invalid, or when its shared-memory channel couldn't be opened, and a panic there aborts the host process. A leaked LD_PRELOAD in a sandbox that clears the environment is enough to trigger it.

Changes

  • Client::from_env returns Option. The constructor leaves the client unset instead of panicking, and handle_open no longer unwraps.
  • ChannelConf::sender returns None instead of panicking when the channel exists but can't be opened.
  • With no client, every exec variant and posix_spawn(p) calls its original directly, using the per-variant fallback from fix(fspy): run exec untracked when injection fails #701.

This branch is based on #701. A PR from a fork can't target another fork branch, so only the top commit belongs to this PR until #701 merges.

If the preload can't set up tracking for an exec (for example, the
seccomp filter for a static binary can't be installed because the
sandbox denies the syscall), mark the trace incomplete and run the
original call untracked instead of failing it. Resolution errors such
as ENOENT or EACCES are still returned as-is.

Each exec variant falls back to its own libc original with its original
arguments, so execvp and execlp still search PATH, execveat keeps its
dirfd and flags, and fexecve keeps its fd.

Refs voidzero-dev#700
The preload constructor panicked when FSPY_PAYLOAD was missing or
invalid, or when the shared-memory channel couldn't be opened, which
aborts the host process. This happens with a leaked LD_PRELOAD in a
sandbox that clears the environment. Leave the client unset in that
case and forward every exec and posix_spawn call to its original.
@lifeiscontent
lifeiscontent force-pushed the fix/fspy-preload-no-payload branch from 6f63d39 to f3f2a54 Compare September 24, 2026 10:38

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant