Skip to content

fix(daemon): add native FreeBSD process-image identity and /home log-path alias - #1467

Open
PR9000 wants to merge 3 commits into
DeusData:mainfrom
PR9000:fix/freebsd-platform-support
Open

fix(daemon): add native FreeBSD process-image identity and /home log-path alias#1467
PR9000 wants to merge 3 commits into
DeusData:mainfrom
PR9000:fix/freebsd-platform-support

Conversation

@PR9000

@PR9000 PR9000 commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

What does this PR do?

Adds native FreeBSD support to the daemon's process-image identity logic in src/daemon/runtime.c and scopes a security-sensitive /home log-path alias to FreeBSD only in src/daemon/ipc.c.

  • runtime_process_image_reference_acquire/_matches_process were guarded only for _WIN32/__APPLE__/__linux__, with FreeBSD falling through to a stub that always returned false. This broke the daemon's build-fingerprint capture and made install refuse to proceed on FreeBSD ("active CBM sessions and operations could not be stopped safely"). Adds a sysctl(CTL_KERN, KERN_PROC, KERN_PROC_PATHNAME, pid)-based FreeBSD branch, mirroring the existing macOS/Linux pattern, and renames runtime_linux_stat_same_image to runtime_posix_stat_same_image now that the comparison logic serves all three platforms.

  • private_log_directory_path_copy previously shared the /home root-owned alias between __APPLE__ and __FreeBSD__. macOS never needed /home resolved in this security-sensitive step; the alias list is now split so Darwin keeps {/tmp, /var} and only FreeBSD gains /home -> /usr/home.

Split out of #1138 per review feedback — this covers the daemon-side platform port; CLI self-path resolution and the activation_transaction.c guard fix are in separate PRs.

Checklist

  • Every commit is signed off (git commit -s) — required, CI rejects
    unsigned commits (DCO, see CONTRIBUTING.md)
  • Tests pass locally (make -f Makefile.cbm test)
  • Lint passes (make -f Makefile.cbm lint-ci)
  • New behavior is covered by a test (reproduce-first for bug fixes)

PR9000 added 3 commits August 6, 2026 03:19
private_log_directory_path_copy shared the /home root-owned alias
between __APPLE__ and __FreeBSD__. macOS never needed /home resolved
in this security-sensitive step; split the alias list so Darwin keeps
{/tmp, /var} and only FreeBSD gains /home -> /usr/home.

Signed-off-by: Pedro Ramos <131530838+pr9000@users.noreply.github.com>
Extends runtime_process_image_reference_* (self/peer process image
acquisition and comparison) to FreeBSD, previously guarded only for
_WIN32/__APPLE__/__linux__. Uses sysctl(KERN_PROC_PATHNAME) to resolve
a process's executable path without depending on procfs.

Renames runtime_linux_stat_same_image to runtime_posix_stat_same_image
now that the same comparison logic serves Linux, macOS, and FreeBSD.

Signed-off-by: Pedro Ramos <131530838+pr9000@users.noreply.github.com>
Signed-off-by: Pedro Ramos <131530838+pr9000@users.noreply.github.com>
@PR9000
PR9000 requested a review from DeusData as a code owner August 6, 2026 12:18
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown

Thanks for opening this — it has been seen, and it is queued.

This note is automated, but it is not a brush-off: it exists so you know where your PR stands instead of having to guess from silence.

Current review status: working through a backlog. 0.9.1-rc.1 is out, so the release freeze that held reviews is over — but it left a large queue of open pull requests behind it, and we are reading through them oldest-first. The background is in discussion #1144.

What that means for this PR, concretely:

  • It will not be closed for inactivity. No stale bot touches pull requests here.
  • It may still sit a while before a human reads it. That is on us, not on you.
  • Older PRs are read first, so a recent one is not being skipped — it is behind a queue.

Things that will genuinely speed it up whenever review does happen:

  • Keep it rebased on main — the tree is moving quickly right now, and a conflicting branch cannot be reviewed as the diff you intended.
  • Get CI green, or say which failures you believe are pre-existing.
  • Keep the change to one claim. Bundled features and refactors get split before they get merged, which costs you a round trip.
  • Every commit needs a sign-off (git commit -s) — CI enforces DCO.

If this fixes a bug, a reproduction we can run is worth more than a description of the symptom.

Thanks for contributing, and sorry in advance for the wait.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant