Skip to content

Fix illumos script exec - #640

Open
keragez wants to merge 3 commits into
ppp-project:masterfrom
keragez:fix-illumos-script-exec
Open

keragez wants to merge 3 commits into
ppp-project:masterfrom
keragez:fix-illumos-script-exec

Conversation

@keragez

@keragez keragez commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #639.

On illumos, hook scripts (ip-up, ip-down, auth-up, ...) don't run in 2.5.4: none of the fd-based exec methods work for #! scripts there (fexecve() → EFAULT, /dev/fd/N → EACCES, /proc/self/fd/N hangs). On SOL2, this restores exec by path as in 2.5.3, but only if stat() of the path still matches fstat() of the checked descriptor. That leaves a small check-to-exec window on Solaris/illumos, documented in pppd.8. Linux is unchanged.

Also fixes the "Can't execute" message reporting a wrong errno, which made this hard to diagnose.

Testing: OmniOS script-run passes with this PR, with all five hooks running and labelled correctly. On master it reports XFAIL (hooks exit 99).

When the exec of a hook script fails, the child reopens syslog and logs
"Can't execute <script>: %m". reopen_log() can change errno, so the
message may show the error from reopening the log instead of the one
from the exec. On OmniOS this reported "Bad file number" where the exec
had actually failed with EFAULT.

Save errno before reopen_log() and restore it before logging.

Signed-off-by: Adam Zegarek <keragez@gmail.com>
Since 6a4944f, with strict-script-checks (the default), run_program()
executes hook scripts through the descriptor it checked, using
fexecve() or /dev/fd/N. On illumos neither works for #! scripts, so
ip-up, ip-down, auth-up and the other hooks never run; the child exits
with status 99 and logs "Can't execute ...". Tested on OmniOS r151058:

 - fexecve(fd, ...) fails with EFAULT
 - execve("/dev/fd/N", ...) fails with EACCES (not a regular file)
 - execve("/proc/self/fd/N", ...) hangs the child

On SOL2, exec the script by path as 2.5.3 did, but only if stat() of
the path still gives the same device and inode as fstat() of the
checked descriptor. This leaves a small window between the stat() and
the execve() instead of none, which pppd.8 now mentions.

Linux is unchanged.

Fixes: 6a4944f ("pppd: relax and simplify permission check")
Signed-off-by: Adam Zegarek <keragez@gmail.com>
With "pppd: Exec hook scripts by path on Solaris/illumos" the hooks run
on OmniOS, so drop the XFAIL for hooks that fail to exec there. Such a
failure is now a plain FAIL on every platform; the pppd log line with
the exit status is still included in the message.

Signed-off-by: Adam Zegarek <keragez@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

OmniOS: cannot run scripts in v2.5.4

1 participant