Skip to content

bug: fcntl(F_DUPFD) reports EBADF instead of EMFILE #1372

Description

@Shounak-Ghosh

Component: src/rawposix/src/fs_calls.rs (fcntl_syscall, F_DUPFD and F_DUPFD_CLOEXEC arms)
Severity: POSIX conformance
Found by: CONC-005a (#1304), conc_005_fd_exhaustion_isolation.c

Symptom

A cage at its virtual fd table limit cannot be distinguished from one that was handed
an invalid descriptor: both return EBADF. POSIX requires EMFILE for the former.
Well-behaved applications that retry after closing something instead treat the fd as
bad and give up.

Root cause

// src/rawposix/src/fs_calls.rs, F_DUPFD arm (~1451) and F_DUPFD_CLOEXEC arm (~1470)
Err(_) => return syscall_error(Errno::EBADF, "fcntl", "Bad File Descriptor"),

vfd_arg has already been validated by _fcntl_helper before this point, so the only
way the allocation can fail is a full table, which is EMFILE by definition.

Proposed fix

-                Err(_) => return syscall_error(Errno::EBADF, "fcntl", "Bad File Descriptor"),
+                // `vfd_arg` was already validated by `_fcntl_helper` above, so the only
+                // way this allocation fails is a full virtual fd table: that is EMFILE,
+                // not EBADF. Reporting EBADF here made an exhausted cage look like it
+                // had been handed a bad descriptor.
+                Err(_) => return syscall_error(Errno::EMFILE, "fcntl", "Too many open files"),

Apply to both the F_DUPFD and F_DUPFD_CLOEXEC arms.

Guest-visible change: fcntl(fd, F_DUPFD) on a full table returns EMFILE, was
EBADF. This is a correction toward Linux.

Un-skip on merge

Remove conc_005_fd_exhaustion_isolation.c from skip_test_cases.txt.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions