feat: add linkat - #1334
feat: add linkat#1334
Conversation
End-to-End Test ReportTest Previewgrate harnessGrate Test Report
Cases
static harnessTest ReportDeterministic TestsSummary
Test Results by Category
Fail TestsSummary
wasm harnessTest ReportDeterministic TestsSummary
Test Results by Category
Fail TestsSummary
Test Results by Category
C++ harnessSummary
Cases
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
End-to-End Test ReportTest Previewgrate harnessGrate Test Report
Cases
static harnessTest ReportDeterministic TestsSummary
Test Results by Category
Fail TestsSummary
wasm harnessTest ReportDeterministic TestsSummary
Test Results by Category
Fail TestsSummary
Test Results by Category
C++ harnessSummary
Cases
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
qianxichen233
left a comment
There was a problem hiding this comment.
it probably makes sense to have the original link syscall directly calls the new linkat syscall for two reasons:
- it reduces the number of trusted code
- I think linux kernel also have an internal function that's called by both
linkandlinkat
DanielZ224
left a comment
There was a problem hiding this comment.
Thanks for implementing the missing linkat syscall path and adding regression tests. The syscall-number plumbing, glibc wrapper, syscall-table registration, and the basic success/error cases look reasonable. The tests also verify the resulting filesystem state rather than only checking the return value, which is important for the original issue.
However, I have two blocking concerns about the non-AT_FDCWD path handling.
1. Raw guest paths are passed directly to the host kernel
For a non-AT_FDCWD dirfd, the implementation translates the virtual fd to an underlying host fd, but then passes the raw guest pathname directly to libc::linkat().
This appears to bypass Lind's sandbox-aware path translation and confinement logic. In particular:
- An absolute guest path would be resolved from the host root because the host kernel ignores
dirfdfor absolute paths. - A relative path containing
..may escape above the directory represented by the underlying fd. - The
oldpath_cageid/newpath_cageidvalues do not appear to be used in these branches.
Could this reuse an existing sandbox-aware *at path-resolution helper, or introduce a shared helper that resolves a guest path relative to a virtual dirfd without exposing the raw host path?
The same concern applies to both oldpath and newpath.
2. Absolute paths should ignore the corresponding dirfd
linkat() should only validate and use a dirfd when the associated pathname is relative. When the pathname is absolute, the corresponding dirfd must be ignored.
The current implementation appears to translate and validate the dirfd before determining whether the pathname is absolute. As a result, a call such as:
linkat(-1, "/absolute/source", -1, "/absolute/destination", 0);may incorrectly return EBADF, even though both dirfds should be ignored.
Could the implementation first determine whether each path is absolute, and only translate the corresponding dirfd for relative paths?
Suggested regression coverage
Please consider adding tests for:
- A real
olddirfdwith a relativeoldpath. - Both
olddirfdandnewdirfdbeing real directory descriptors. - Absolute paths combined with intentionally invalid dirfds.
..traversal and other sandbox-confinement cases.- The default
flags == 0symlink behavior in addition toAT_SYMLINK_FOLLOW.
I also agree with the existing suggestion to share the trusted implementation between link and linkat, for example by implementing link through the equivalent linkat(AT_FDCWD, ..., AT_FDCWD, ..., 0) path. This would reduce duplicated security-sensitive path-resolution and hard-link logic.
End-to-End Test ReportTest Previewgrate harnessGrate Test Report
Cases
static harnessTest ReportDeterministic TestsSummary
Test Results by Category
Fail TestsSummary
wasm-math harnessTest ReportDeterministic TestsSummary
Test Results by Category
Fail TestsSummary
wasm-filesystem harnessTest ReportDeterministic TestsSummary
Test Results by Category
Fail TestsSummary
wasm-memory harnessTest ReportDeterministic TestsSummary
Test Results by Category
Fail TestsSummary
Test Results by Category
wasm-process harnessTest ReportDeterministic TestsSummary
Test Results by Category
Fail TestsSummary
wasm-signals harnessTest ReportDeterministic TestsSummary
Test Results by Category
Fail TestsSummary
Test Results by Category
wasm-networking harnessTest ReportDeterministic TestsSummary
Test Results by Category
Fail TestsSummary
wasm-dynamic-linking harnessTest ReportDeterministic TestsSummary
Test Results by Category
Fail TestsSummary
Test Results by Category
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Summary
linkat in glibc is not using make_legacy_syscall which will always return success.
Update linkat in glibc to use make_legacy_syscall
Related issues
Resolves #1332
Testing
New test case added in this PR
Checklist