Skip to content

Update libglnx to fix EAGAIN from openat2 - #6787

Merged
swick merged 9 commits into
flatpak:mainfrom
swick:wip/update-libglnx-again
Aug 19, 2026
Merged

swick merged 9 commits into
flatpak:mainfrom
swick:wip/update-libglnx-again

Conversation

@swick

@swick swick commented Aug 18, 2026

Copy link
Copy Markdown
Collaborator
Update subtree: libglnx 2026-08-18

* glnx_file_copy_at: Use O_PATH fd for xattr and ownership operations
* xattrs: Drop fd-based code paths from get_xattrs_impl
* xattrs: Use /proc/self/fd path in glnx_fd_set_all_xattrs
* xattrs: Use /proc/self/fd path in glnx_fd_get_all_xattrs
* chase: Handle EAGAIN from openat2

The EAGAIN handling in openat2 fixes a bug which would prevent
extensions from being populated in the sandbox:

Closes: #6783
Signed-off-by: Sebastian Wick <[email protected]>

swick and others added 9 commits August 18, 2026 17:15
From openat2(2):

  EAGAIN how.resolve contains either RESOLVE_IN_ROOT or
    RESOLVE_BENEATH, and the kernel could not ensure that a
    ".." component didn't escape (due to a race condition or
    potential attack).  The caller may choose to retry the
    openat2() call.

We should handle this by simply retrying the syscall.
chase: Handle EAGAIN from openat2

See merge request GNOME/libglnx!79
This allows it to work on O_PATH file descriptors, which is needed for
operating on symlinks.
This allows it to work on O_PATH file descriptors, which is needed for
operating on symlinks.
All callers now go through /proc/self/fd paths, so the flistxattr,
fgetxattr branches and the fd parameter are dead code.
After creating the symlink, open it with O_PATH to pin the inode and
verify the target matches. All subsequent operations (xattrs, chown) go
through the pinned fd instead of path-based operations.
glnx_file_copy_at: Use O_PATH fd for xattr and ownership operations

See merge request GNOME/libglnx!78
* glnx_file_copy_at: Use O_PATH fd for xattr and ownership operations
* xattrs: Drop fd-based code paths from get_xattrs_impl
* xattrs: Use /proc/self/fd path in glnx_fd_set_all_xattrs
* xattrs: Use /proc/self/fd path in glnx_fd_get_all_xattrs
* chase: Handle EAGAIN from openat2

The EAGAIN handling in openat2 fixes a bug which would prevent
extensions from being populated in the sandbox:

Closes: flatpak#6783
Signed-off-by: Sebastian Wick <[email protected]>
@swick
swick added this pull request to the merge queue Aug 19, 2026
Merged via the queue into flatpak:main with commit 06f43a5 Aug 19, 2026
11 checks passed
@swick
swick deleted the wip/update-libglnx-again branch August 19, 2026 15:08
@swick

swick commented Aug 19, 2026

Copy link
Copy Markdown
Collaborator Author

Fun, github has dropped fd0df8d.

@smcv

smcv commented Aug 19, 2026

Copy link
Copy Markdown
Collaborator

Did the merge queue do a rebase?

@swick

swick commented Aug 19, 2026

Copy link
Copy Markdown
Collaborator Author

I am very much not sure what it did. A rebase would not have changed the order of the subtree commits, but it seems to have done that as well.

@swick

swick commented Aug 19, 2026

Copy link
Copy Markdown
Collaborator Author

At this point I'm annoyed enough to just convert the libglnx subtree to a meson wrap like I did with portals.

@swick swick mentioned this pull request Aug 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants