From 2ec62711c18cfc659b2b1945b267835ff1db8030 Mon Sep 17 00:00:00 2001 From: K J Sundeep Kumar Date: Thu, 27 Aug 2026 13:27:09 +0530 Subject: [PATCH] rootless: clear environment before spawning pause process When spawning the pause process, environment variables were inherited from the parent process before setting _PODMAN_PAUSE=1. If the parent environment exceeded 4096 bytes, _PODMAN_PAUSE=1 was placed beyond the first 4KB chunk read by is_pause_process(), causing a valid pause process to be treated as stale and its PID file unlinked. Call clearenv() prior to setting _PODMAN_PAUSE=1 so the pause process environment only contains the required pause marker. In addition, ensure is_pause_process() explicitly bounds its read buffer with a null terminator. Fixes: #29650 Signed-off-by: K J Sundeep Kumar --- pkg/rootless/rootless_linux.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkg/rootless/rootless_linux.c b/pkg/rootless/rootless_linux.c index fb7b1e529d..fa45568ba6 100644 --- a/pkg/rootless/rootless_linux.c +++ b/pkg/rootless/rootless_linux.c @@ -656,7 +656,7 @@ is_pause_process (long pid) if (asprintf (&environ_path, "/proc/%ld/environ", pid) < 0) return 0; - buf = malloc (buf_size); + buf = malloc (buf_size + 1); if (buf == NULL) return 0; @@ -668,6 +668,7 @@ is_pause_process (long pid) n = TEMP_FAILURE_RETRY (read (fd, buf, buf_size)); if (n <= 0) return 0; + buf[n] = '\0'; /* environ entries are separated by '\0'. Search for "_PODMAN_PAUSE=1". */ for (char *p = buf; p < buf + n; ) @@ -1099,6 +1100,7 @@ create_pause_process (const char *state_dir, char **argv) for (fd = 3; fd < open_files_max_fd + 16; fd++) close (fd); + clearenv (); setenv ("_PODMAN_PAUSE", "1", 1); execlp (argv[0], argv[0], NULL);