Repository navigation
Conversation
processLdsoconfFile decides which directories the container's ldcache already covers, so a line it reads differently from ldconfig costs a directory, and the libraries in it are not found. Five differences, against parse_conf and parse_conf_include in glibc's elf/ldconfig.c: - a trailing comment stayed on the line. ldconfig ends every line at the first '#', the format has no quoting; here only a line that started with one was skipped, so "/usr/local/lib # vendor libs" became a directory of that whole name, and the same comment on an include left it matching nothing - "include" followed by a tab was not a directive, since the prefix tested for was "include "; ldconfig takes any blank, so the line became a directory instead - only the first pattern of an include was used: ldconfig splits the remainder on blanks and globs each one, while the whole remainder went to one Glob call, which a pattern with a space in it cannot match - a relative include resolved against the working directory. ldconfig resolves it against the directory of the file that holds it, so after the pivot into the container root "include ld.so.conf.d/*.conf" looked for /ld.so.conf.d/*.conf rather than /etc/ld.so.conf.d/*.conf - a hwcap line became a directory; ldconfig has ignored the directive since 2.33 and only reports it Also answers the TODO on the ErrBadPattern path: ldconfig treats a malformed pattern as no match and carries on, which is what this already did. Signed-off-by: Dmitry Voropaev <dy.voropaev@gmail.com>
v0ropaev
requested review from
cdesiniotis,
henry118 and
tariq1890
as code owners
October 8, 2026 12:14
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
processLdsoconfFilebuilds the set of directories the container's ldcache already covers, which is then subtracted from the directories the hook would add. A line it reads differently fromldconfigcosts a directory, and the libraries in that directory are not found.Five differences from
parse_confandparse_conf_includein glibc'self/ldconfig.c:Trailing comments. ldconfig ends every line at the first
#, because the format has no quoting:Here only a line starting with
#was skipped, so/usr/local/lib # vendor libsbecame a directory of that whole name, and the same comment after anincludeleft the pattern matching nothing.A tab after
include. The test wasstrings.HasPrefix(line, "include "); ldconfig accepts any blank (isblank (cp[7])). With a tab the line fell through and became a directory.More than one pattern. ldconfig splits the remainder on blanks and globs each one:
The whole remainder went to a single
filepath.Glob, and a pattern with a space in it matches nothing, so all of the patterns were lost rather than just the later ones.Relative include patterns. ldconfig resolves them against the directory of the file that holds them:
filepath.Globresolved them against the working directory. This runs after the pivot into the container root, soinclude ld.so.conf.d/*.confin/etc/ld.so.conflooked for/ld.so.conf.d/*.conf.hwcaplines. They became directories. ldconfig has ignored the directive since 2.33 and only reports it.The
TODO: How does ldconfig handle this?on theErrBadPatternpath is answered in a comment: a malformed pattern is no match and parsing carries on, which is what the code already did.Tests
TestProcessLdsoconfFile, table-driven over a temporary directory, covering each of the five plus the cases that already worked, which are there as regression guards: a whole-line comment, an absolute include, a line that only looks like a directive (includealone,/includes,/hwcapsomething), and an include that matches nothing.Six of the ten subtests fail on
main, each with the wrong value from above.go test ./internal/...passes,go vetandgofmtclean.