From 3f5cc41f917ab380ef498ae3186fd59acc42bf7b Mon Sep 17 00:00:00 2001 From: can1357 Date: Sun, 14 Jun 2026 23:07:53 +0200 Subject: [PATCH] test(pi-natives): tolerate PID-namespaced getsid(0) in session test MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Inside a container PID namespace (the Kata microVM CI runner), the host process's session leader lives outside the namespace, so getsid(0) returns 0 via task_session_vnr — not an error. The assert host_sid > 0 was too strict and panicked with 'getsid(0) failed: Success (os error 0)'. Relax to host_sid >= 0 (only -1 is a real failure); the meaningful invariant (child detaches into its own session: child_sid == child_pid, distinct from host) is unchanged. --- crates/pi-natives/src/shell.rs | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/crates/pi-natives/src/shell.rs b/crates/pi-natives/src/shell.rs index ca41f1be9..3861a486b 100644 --- a/crates/pi-natives/src/shell.rs +++ b/crates/pi-natives/src/shell.rs @@ -424,9 +424,13 @@ mod tests { .parse::() .expect("child pid parses"); // SAFETY: `getsid(0)` only queries the current process session; the - // return value is checked below. + // return value is checked below. Inside a PID namespace (e.g. the + // containerized CI runner) the host's session leader can live outside + // the namespace, so `getsid(0)` legitimately reports 0 — only -1 is a + // real failure. The meaningful invariant is that the child detached + // into its own session (`child_sid == child_pid`, distinct from host). let host_sid = unsafe { libc::getsid(0) }; - assert!(host_sid > 0, "getsid(0) failed: {}", std::io::Error::last_os_error()); + assert!(host_sid >= 0, "getsid(0) failed: {}", std::io::Error::last_os_error()); // SAFETY: `child_pid` is a live positive PID reported by the child; the // return value is checked below. let child_sid = unsafe { libc::getsid(child_pid) };