Skip to content

Assert that --app-fd, --env-fd, etc. don't pass into the sandbox - #6599

Draft
smcv wants to merge 6 commits into
flatpak:mainfrom
smcv:closed-all-fds
Draft

smcv wants to merge 6 commits into
flatpak:mainfrom
smcv:closed-all-fds

Conversation

@smcv

@smcv smcv commented Apr 10, 2026

Copy link
Copy Markdown
Collaborator

Based on #6598 to avoid conflicts.

  • utils: Add flatpak_unset_cloexec()

  • tests: Add a helper to close all inherited fds, with exceptions

    We don't know what fds our tests are going to inherit from the user or
    the test framework, but we can use this wrapper to enforce that none
    of them are passed to Flatpak, allowing us to make assertions about
    what fds remain open.

  • tests: Add a helper to assert that a specified set of fds are open

  • tests: Assert that extraneous fds aren't inherited into the sandbox

smcv added 6 commits April 10, 2026 15:11
These fds are stdin, stdout and stderr respectively, and are expected
to remain open at all times (if they are not needed then they can point
to /dev/null, but they should always be open). If the user gives us
`--env-fd=2` or similar, we don't want to close fd 2 before exiting
unsuccessfully: that would give us nowhere to display the error message.

Signed-off-by: Simon McVittie <[email protected]>
We don't know what fds our tests are going to inherit from the user or
the test framework, but we can use this wrapper to enforce that none
of them are passed to Flatpak, allowing us to make assertions about
what fds remain open.

Signed-off-by: Simon McVittie <[email protected]>
@smcv smcv changed the title Closed all fds Assert that --app-fd, --env-fd, etc. don't pass into the sandbox Apr 10, 2026
@smcv
smcv requested a review from swick April 10, 2026 14:42
Comment thread tests/test-run-custom.sh Dismissed

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants