Skip to content

fix(response): validate and terminate through one process handle - #680

Merged
Karib0u merged 1 commit into
mainfrom
fix/response-process-handle
Oct 1, 2026
Merged

Karib0u merged 1 commit into
mainfrom
fix/response-process-handle

Conversation

@Karib0u

@Karib0u Karib0u commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Summary

Active response could validate one process and then kill an unrelated replacement if the PID was reused before termination. Keep the process reference alive through validation and termination.

  • Linux opens a pidfd before reading identity, confirms it is still live after the /proc reads, and sends SIGKILL through that same pidfd. Unsupported or denied pidfd operations fail safely without a bare-PID fallback.
  • Windows opens one handle with query and terminate rights, queries identity through it, and terminates through that same handle.
  • Add normal-CI child-process and injected-swap tests, and document each platform's guarantee, including the remaining macOS PID-reuse window.

Fixes #601.

Type of change

  • bug - bug fix

Test plan

  • Native Windows tests: not run locally. Windows GNU cross-check and all-targets Clippy passed.
  • Linux: 902 tests passed, 16 normally ignored, with the embedded eBPF ABI check excluded because the local build uses RUSTINEL_EBPF_STUB=1.
  • macOS: full suite passed (836 tests), plus all 7 active-response integration tests including the previously ignored live tests.
  • New tests run without an example build or elevated privileges. The focused Linux run passed as UID 1000.
  • Regression verification: a temporary bare-PID termination mutation killed the replacement and failed the swap test; the retained-handle implementation was restored and the focused suite passed.
  • Clippy passed on macOS, Linux, and the Windows GNU cross target. Formatting, documentation lint/reflow, and diff checks passed.

Checklist

  • Labels added: bug, security, linux, windows.
  • Active-response documentation updated with platform guarantees and failure behavior.
  • Generated documentation and release preparation checks are not applicable.

@Karib0u Karib0u added bug Something isn't working security Security-related maintenance linux Linux support windows Windows support labels Oct 1, 2026
@Karib0u
Karib0u merged commit d4a8990 into main Oct 1, 2026
17 checks passed
@Karib0u
Karib0u deleted the fix/response-process-handle branch October 1, 2026 15:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working linux Linux support security Security-related maintenance windows Windows support

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(response): validate and terminate through one process handle

1 participant