From nobody Sat Jul 25 22:03:16 2026 Received: from mail-pj1-f53.google.com (mail-pj1-f53.google.com [209.85.216.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1BFE9375F82 for ; Mon, 13 Jul 2026 09:28:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783934909; cv=none; b=gLWSvpnAsZLUfGRK93+RslGEseOwzzbgeOSv4ygFycd3lRtelfhNSlXDmPbDd8BUfJqGJp+ck7acbEWECPv3mpl+Nr+SBErgHjhy7SDkOPLzRJ/RRZuKVRTpShUHz2AI3BbGNtFxGbqerVlK3EwxbeNHHZgoqJ0354BAAWzEOyg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783934909; c=relaxed/simple; bh=sDWk28xBuFZTTizpUURrHrIa51+ATw6mlf2LRdxFbyg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=pR1gFNUfwAiUBHnRKBSE6rAtT+D6JodzTf/pFckCQEgA35tIRgFi+I8zVeWmMMxGs5qwBmleodFAtIt5yV1uJ2A7aJYyLgw7gwIjExJ5utVhfRGoB8nNhQPG/9yXvHQ0qBzTPccZHY9GurrXQeUW+H0iztv5Z89oFHu73yzr4DU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=H4Z76j5D; arc=none smtp.client-ip=209.85.216.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="H4Z76j5D" Received: by mail-pj1-f53.google.com with SMTP id 98e67ed59e1d1-38dc69c74b8so1381440a91.0 for ; Mon, 13 Jul 2026 02:28:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783934907; x=1784539707; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=4623BPbRgjIujmWqWQj6M4QygEbpjJiFDAO4rapy8N4=; b=H4Z76j5DdsoiZc+sWXEadhMw8YRmgzEHculdvPcoN4TjsemeLPTrFzcxF9utO+ByFw 79VAWsrjth+iJUw3kQ0D8wVQjon8QsMCFWmEApk7h2ySROjoQQ2ACwb2dDcbNZJ1BIs2 Pi7cv5SCK5gqTWheJ4WnlKKVnQX32PSuvR9N/+hlOXPlkwUClKQwafwXptjhj2XNhCUu Z1bvewx57aFY+7ow4KIVJV6skRCrLA54OZRwuBOy202xZaqEC2y5HtfaAYK5TaYySsZd qtAO+xxqLK3RNcvfZGh/oXrU1t6uij18EKVQPod4HbZlqfTpxJD7jmBtfTRN6v8Mjnqv Md0w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783934907; x=1784539707; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=4623BPbRgjIujmWqWQj6M4QygEbpjJiFDAO4rapy8N4=; b=Hy5dprAsNN3fGrkF4IH8W4+sxu3d/uRl3xYLIoooXg0ku8kKzCdvfoLJ1keOB+ZoZn XrfRcE92Ps2K0MkSi/QNA8CnkARCc7tncE7Q+qJZfCRsOCc2TGJ0EbmQlnDEwgXiPKoQ mkiXBmRSpSFrEzjX+v5JviXhCSggVQp1Kanl6R8NhlNaotyLi55G2V2zuqAVR7UrxpNO p2uz7cZtPRp4cP4IsnbVKsm+i+Osd19seG41G8SG/RnmtieV0OJvpkmv6suVcq1xX2B8 p4AzFHFLrenxm3tOzN6n9P8AcfgBmyBwH60Q2JsyHU4hPqE0D428znAaeyiddtUVQdkM zbkQ== X-Forwarded-Encrypted: i=1; AHgh+Rr/CnfOHn4TuBCmrkLpszAHnbxkEwEL8iPhwnETiJYyYyi59UTsi17gU6H/DOW2ePLyqd71oRoPl2zgFTE=@vger.kernel.org X-Gm-Message-State: AOJu0YwuG8YQt8tO0FYTbTk/7i4CGrcH846YJbp9B8BadiQNpLaeTJLQ c+9Wknv9X+p0uvPzTYBk8yexRQVZoCAkt4FMSCTagxMZqorgAT8QfnOS X-Gm-Gg: AfdE7cnS95wERavqpPkPZckDLtq3vp49i6cSApFfJRxJWRlE4mTfMIcEZdTiJ1ogvXq SNapgcKTxNGc/gvGpHR3ItuNPI6esNL+uAzR5bhe6kU1NtBQkmf1bbI0ElHodT+mCl+v7OzxH5f EcGTE/DFfEVB7zkgJgwMZ0WLTVJs6xXIyyX/iwZ6Ypa0hqeZR2f/hkgZNCbrCY1P9s7+yRx373d K2AbgqhksAnUmUogkpTTJsYd2LZfXCSsdQTlaXIr6e7qvjsmRVDFxdT6uMdDqM17UmXH/KU5j7a CBH+TtimlgPDV2L5bjOS79bVGy7SFlFvT3EpLBhFYOpOEvXIOxJAJhgVn35B87VkIRzrOUQADzM JrKzkZ1DtFXjkqZK0tg0NRbixEhAVyQ05ZIgBQy1f25OZHjrV4MSB0wQ3f7fzWWd0WHc1qd1zXM OZ3afjISXjuRU= X-Received: by 2002:a17:90b:1c91:b0:380:534f:58c2 with SMTP id 98e67ed59e1d1-38dc7b81c27mr7444738a91.30.1783934907345; Mon, 13 Jul 2026 02:28:27 -0700 (PDT) Received: from lima-kernel ([104.28.160.216]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-38a5564f58csm6293039a91.8.2026.07.13.02.28.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 13 Jul 2026 02:28:27 -0700 (PDT) From: Injae Ryou To: Andrew Morton Cc: David Hildenbrand , Lorenzo Stoakes , linux-mm@kvack.org, linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org, Injae Ryou , Brendan Jackman Subject: [PATCH] selftests/mm: fix on-fault-limit false failure under sudo-rs Date: Mon, 13 Jul 2026 18:27:00 +0900 Message-ID: <20260713092700.464376-1-injaeryou@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" run_vmtests.sh runs on-fault-limit as the nobody user via "sudo -u nobody ./on-fault-limit", guarded by a check that nobody can access the binary ("sudo -u nobody ls ./on-fault-limit"). The guard resolves the relative path from the inherited working directory, which only requires search permission on the test directory itself. Classic sudo passes the relative path through to execve() the same way, so the two agree. However, sudo-rs (the default sudo implementation since Ubuntu 25.10) canonicalizes the command to an absolute path before executing it, which requires search permission on every ancestor directory. When the kernel tree lives under a private home directory (mode 0750, the Ubuntu default for new users since 21.04), the guard passes but the execution fails with "command not found", and the test is reported as a false FAIL: # running sudo -u nobody ./on-fault-limit sudo: './on-fault-limit': command not found # [FAIL] Wrap the command in "sh -c" so that sudo only resolves the shell binary, and the relative path is resolved by nobody's shell from the inherited working directory, matching what the guard checks. This is the only "sudo -u nobody" invocation in the script; uid, cwd, rlimits (including RLIMIT_MEMLOCK, which this test exercises) and the exit status are unchanged through sh. Verified on Ubuntu 26.04 (sudo-rs 0.2.13): the test now runs and passes instead of failing. Verified on Ubuntu 24.04 (sudo 1.9.15p5): behavior is unchanged. Fixes: 5d2146a3354f ("selftests/mm: skip mlock tests if nobody user can't r= ead it") Cc: Brendan Jackman Signed-off-by: Injae Ryou --- tools/testing/selftests/mm/run_vmtests.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tools/testing/selftests/mm/run_vmtests.sh b/tools/testing/self= tests/mm/run_vmtests.sh index a60b9f9f16e..687d115e3bd 100755 --- a/tools/testing/selftests/mm/run_vmtests.sh +++ b/tools/testing/selftests/mm/run_vmtests.sh @@ -302,7 +302,7 @@ CATEGORY=3D"compaction" run_test ./compaction_test =20 if command -v sudo &> /dev/null && sudo -u nobody ls ./on-fault-limit >/de= v/null; then - CATEGORY=3D"mlock" run_test sudo -u nobody ./on-fault-limit + CATEGORY=3D"mlock" run_test sudo -u nobody sh -c ./on-fault-limit else echo "# SKIP ./on-fault-limit" fi --=20 2.53.0