Skip to content

NaCl process creation improvements - #2001

Open
slipher wants to merge 6 commits into
DaemonEngine:masterfrom
slipher:nacl-creation
Open

slipher wants to merge 6 commits into
DaemonEngine:masterfrom
slipher:nacl-creation

Conversation

@slipher

@slipher slipher commented Sep 7, 2026

Copy link
Copy Markdown
Member

Stacked on #1998. Additional changes to NaCl process creation:

  • Never use nacl_helper_bootstrap with the 64-bit loader. This lets us remove a nice chunk of cruft.
  • Clear the environment variables on Windows like we do on *nix.

@slipher slipher changed the title Nacl creation NaCl process creation improvements Sep 7, 2026
@illwieckz

Copy link
Copy Markdown
Member

I'm in the process of rebasing this over #1986:

And this commit was already implemented:

  • Make the box64 inherit environment thing less confusing

Set up the chdir and environment variable in posix_spawn.
Fixes DaemonEngine#1336.
When box64 is used for the NaCl loader, environment variables are
allowed to pass through. Make it clearer that this is the bool
argument being passed and avoid unnecessary ifdef.
Remove cvars controlling whether the Linux bootstrap loader is used.
Never use bootstrap with the amd64 loader.
Always use bootstrap with 32-bit loaders.
Remove amd64 bootstrap usage from deps.

Closes DaemonEngine#1327.
When creating a NaCl (or native exe) VM on Windows, block
evironment variables from being passed through to the 
subprocess as is done on *nix. Probably we do this since
there are NACL* variables that can disable secure sandboxing.

inheritEnvironment is always false on Windows, but I implemented
the true case anyway since it's less code than having the Q_UNUSED
and asserting it's false.
@slipher

slipher commented Oct 5, 2026

Copy link
Copy Markdown
Member Author

Fixed merge conflict and compiler warning.

Check the Linux sysctl vm.mmap_min_addr only when using the NaCl
bootstrap (rather than always when using NaCl). Or equivalently, check
it only with 32-bit NaCl runtimes. The bootstrap fails to start when the
value is too high to due low fixed address mappings. On ARM at least,
sel_ldr proper would also fail with a too-high min address since that
disturbs the address space layout. On 64-bit there is neither the
bootstrap nor 0-based address space layout so it always works.
@illwieckz

Copy link
Copy Markdown
Member

By the way yesterday I rebased both this and #1998 over:

Because it's the least effort to do it this way than the other way, a lot of things in #1998 and #2001 were based on things that were already reworked in #1986.

It also means that some intermediary work from #1986 is made useless (like the bootstrap being reworked, just for being completely removed later), but doing the rebase that way really was the least effort.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants