Summary
When fspy tracks a Unix child process that calls execl, execlp, or execle with at least 32 non-NULL argv entries (including arg0), the preload interposer aborts the child process.
In with_argv, the heap branch creates a slice with exactly argc elements, then writes the required NULL terminator at out[argc]:
let ptr = libc::malloc(argc * size_of::<*const c_char>());
let out = slice::from_raw_parts_mut(ptr.cast(), argc);
// ...
out[argc].write(core::ptr::null());
The valid indices are 0..argc, so this deterministically panics. Because the panic occurs inside an extern "C" interposer, it cannot unwind and the process aborts.
Reproduction
Reproduced against 44186c8 on macOS through the real fspy preload path. A temporary fspy integration test called libc::execl("/usr/bin/true", ...) from inside track_fn! and was run with:
cargo test --offline -p fspy --test execl_many_args -- --nocapture
Non-NULL argv entries, including arg0 |
Result |
| 31 |
Passes; uses the fixed 32-slot stack storage |
| 32 |
Aborts; heap slice has length 32 and writes index 32 |
Observed failure:
with_argv.rs:52:5:
index out of bounds: the len is 32 but the index is 32
panic in a function that cannot unwind
thread caused non-unwinding panic. aborting.
Trigger flow
cached/auto-tracked task
-> fspy preload is injected into a child process
-> the tracked native process calls execl/execlp/execle
-> with_argv rebuilds argv
-> argc >= 32 selects heap storage
-> out[argc] writes past the slice boundary
-> non-unwinding panic aborts the child
This is not triggered merely because a command has 32 arguments: the tracked program must use one of the variadic execl* APIs. Calls through execv/execve, posix_spawn, and most common high-level process APIs do not use this path. That makes the scenario uncommon, but deterministic for native tools that invoke execl* with sufficiently many arguments.
Suggested coverage
Allocate space for argc + 1 entries and add real preload regression cases at the 31/32/33 boundary for execl, execlp, and execle.
Summary
When fspy tracks a Unix child process that calls
execl,execlp, orexeclewith at least 32 non-NULL argv entries (includingarg0), the preload interposer aborts the child process.In
with_argv, the heap branch creates a slice with exactlyargcelements, then writes the required NULL terminator atout[argc]:The valid indices are
0..argc, so this deterministically panics. Because the panic occurs inside anextern "C"interposer, it cannot unwind and the process aborts.Reproduction
Reproduced against
44186c8on macOS through the real fspy preload path. A temporaryfspyintegration test calledlibc::execl("/usr/bin/true", ...)from insidetrack_fn!and was run with:cargo test --offline -p fspy --test execl_many_args -- --nocapturearg0Observed failure:
Trigger flow
This is not triggered merely because a command has 32 arguments: the tracked program must use one of the variadic
execl*APIs. Calls throughexecv/execve,posix_spawn, and most common high-level process APIs do not use this path. That makes the scenario uncommon, but deterministic for native tools that invokeexecl*with sufficiently many arguments.Suggested coverage
Allocate space for
argc + 1entries and add real preload regression cases at the 31/32/33 boundary forexecl,execlp, andexecle.