Repository navigation
Conversation
Author
|
The lint failure here is the pinned golangci-lint v2.11 being unable to type-check Go 1.27, which |
Author
|
The bullseye failures here are apt returning 404 for every package from the bullseye security pool, which left the mirror after Debian 11 reached end of life on 2026-08-31; the job exits before any Go is built. #530 moves the matrix to bookworm and ubuntu 22.04. |
GetHandle returned the bare ErrSoNotFound sentinel after every dlopen attempt failed, discarding what dlerror() had to say. A missing library and a transient loader failure produced the same message, and callers such as podman's journald log reader surfaced it to users with no way to tell which it was. GetSymbolPointer and Close in the same file already capture dlerror(); GetHandle now does the same, for each name tried, and wraps the sentinel so errors.Is still holds. Assisted-by: Claude:claude-fable-5-1 [claude-code] Signed-off-by: Andrew McCabe <amccabe@users.noreply.github.com>
amccabe
force-pushed
the
dlopen-report-dlerror
branch
from
September 18, 2026 15:21
611a973 to
51dfb20
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
GetHandlereturns the bareErrSoNotFoundsentinel when every dlopen attempt fails, discarding whatdlerror()reported.GetSymbolPointerandClosein the same file already capture it. This makesGetHandledo the same for each name tried, and wraps the sentinel soerrors.Is(err, ErrSoNotFound)still holds for existing callers.History. The omission dates from the original
dlopenpackage in coreos/pkg (5ec8ba6, 2016-02-02) and came across unchanged when it moved here as an internal package (3344f03, 2019-11-01). Every v22 tag, v22.0.0 through v22.7.0, carries it.Why it matters. The sentinel makes a missing library indistinguishable from a transient loader failure, and the string has been reported downstream for years without the cause ever being named:
Impact on k3d on podman.
podman machineruns with the journald log driver, so podman's container-logs endpoint opens the journal throughsdjournal.NewJournal, which reachesGetHandleon the first request in each API service process. I hit a case where that first request, made by k3d seconds after starting a k3s node, was answered with a 500 carrying only this sentinel. k3d treats a failed log-stream open as a dead node and rolls the whole cluster back, so one unexplained dlopen failure cost a cluster create. The retry succeeded a minute later, and the reason for the first failure is unrecoverable becausedlerror()was never read. With this change the journal would have said why.Before, with libsystemd absent:
After:
The error is wrapped with
%w, soerrors.Is(err, ErrSoNotFound)would still pass. A caller comparing with==would fail after this change; none can:internal/dlopenis an internal package, so nothing outside this module can reference the sentinel, and the in-tree users pass the error through unchanged. The success path is unchanged apart from a thread lock for the duration of the call, matching the other two functions indlopen.go. The new test asserts the sentinel is preserved and that each name tried appears in the message - it fails on main and passes here.