Repository navigation
Conversation
69a1cda to
a4ec63f
Compare
|
This comment has been minimized.
This comment has been minimized.
a4ec63f to
700eb1e
Compare
Merging this PR will not alter performance
Comparing Footnotes
|
Valgrind loads the client executable itself, so the kernel never grants it its file capabilities, and Valgrind refuses to run such executables (EACCES, exit code 126 from a shell) rather than run them without the capabilities they expect. Some executables carry capabilities that only part of their code needs, and run fine without them. --allow-file-caps=patt1,patt2,... takes patterns in the --trace-children-skip syntax. An executable whose name matches is run despite its file capabilities, without them. It applies to the client executable and to traced children, so the option is parsed in the early pass, before the client is loaded. Setuid and setgid executables are still refused. The tests create a capped executable with setcap, sudo -n setcap, or an unprivileged user namespace, and are skipped when none is available. CI installs setcap so that they run there. Refs COD-3722 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
700eb1e to
c1a37ef
Compare
No description provided.