Skip to content

Conversation

alpeng-jump
Copy link
Contributor

@alpeng-jump alpeng-jump commented Jul 16, 2025

No description provided.

@mmcgee-jump
Copy link
Contributor

Why is this needed? IIRC we haven't had issues with making core dumps without these changes?

@alpeng-jump alpeng-jump force-pushed the alpeng/sandbox-rlimit branch from f007352 to 6bb8ec1 Compare July 17, 2025 14:01
@alpeng-jump alpeng-jump changed the title sandbox: do not reset RLIMIT_CORE and clone pid ns when dumpable sandbox: do not reset RLIMIT_CORE when dumpable Jul 17, 2025
@alpeng-jump
Copy link
Contributor Author

Reverting CLONE_NEWPID for tiles since having them run as init is fine for core dumps - https://elixir.bootlin.com/linux/v6.11/source/kernel/signal.c#L1351. We do need to leave the rlimit though. More observations explained in slack.

@alpeng-jump alpeng-jump force-pushed the alpeng/sandbox-rlimit branch from 6bb8ec1 to f9336b7 Compare July 17, 2025 14:13
@alpeng-jump alpeng-jump enabled auto-merge July 17, 2025 16:21
@alpeng-jump alpeng-jump requested a review from mmcgee-jump July 18, 2025 04:17
Copy link
Contributor

@mmcgee-jump mmcgee-jump left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

just some nits, but strict about sandbox code

@alpeng-jump alpeng-jump force-pushed the alpeng/sandbox-rlimit branch from f9336b7 to dbd042d Compare July 21, 2025 18:44
@alpeng-jump alpeng-jump requested a review from mmcgee-jump July 21, 2025 18:52
@alpeng-jump alpeng-jump added this pull request to the merge queue Jul 21, 2025
Merged via the queue into main with commit 4095b13 Jul 21, 2025
9 checks passed
@alpeng-jump alpeng-jump deleted the alpeng/sandbox-rlimit branch July 21, 2025 19:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants