From ec19137ed96fc2d3c922575da4ac1bc26b5f90b8 Mon Sep 17 00:00:00 2001 From: Duncan Tourolle Date: Fri, 17 Jul 2026 20:01:57 +0200 Subject: [PATCH] ci: fix TSan aborting at init on the nested-LXC runner The ThreadSanitizer job runs on Docker nested in an unprivileged LXC container, whose kernel randomizes mmap addresses beyond the range TSan's fixed shadow mapping expects. TSan aborted at init with "unexpected memory mapping" before any test ran. Disable ASLR per-process with `setarch -R`, which needs the personality(2) syscall that Docker's default seccomp profile blocks; seccomp=unconfined on the container permits it. Verified on the runner that both are required: setarch -R alone gets EPERM, seccomp alone still aborts, both together run clean. Scoped to the tsan job, which runs only our own test binaries. Co-Authored-By: Claude Opus 4.8 --- .gitea/workflows/tsan.yaml | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/.gitea/workflows/tsan.yaml b/.gitea/workflows/tsan.yaml index 53f81ad..7911d7d 100644 --- a/.gitea/workflows/tsan.yaml +++ b/.gitea/workflows/tsan.yaml @@ -18,6 +18,15 @@ jobs: runs-on: linux/amd64 container: image: gitea.tourolle.paris/dtourolle/kpnpp-builder:latest + # This runner is Docker nested in an unprivileged LXC container, whose + # kernel randomizes mmap addresses beyond the range TSan's fixed shadow + # mapping expects, so TSan aborts at init with "unexpected memory + # mapping". The fix is to disable ASLR per-process with `setarch -R` + # (below), which needs the personality(2) syscall that Docker's default + # seccomp profile blocks. seccomp=unconfined permits it. Verified on the + # runner: setarch -R alone gets EPERM, seccomp alone still aborts, both + # together run clean. Scoped to this job, which runs only our own tests. + options: --security-opt seccomp=unconfined steps: - name: Checkout repository uses: actions/checkout@v4 @@ -54,13 +63,14 @@ jobs: # the full picture for lock-order issues. env: TSAN_OPTIONS: "halt_on_error=1 second_deadlock_stack=1" - run: ./build/tests/kpn_tests_stress + # setarch -R disables ASLR for this process; see the container comment. + run: setarch -R ./build/tests/kpn_tests_stress - name: Run unit tests under TSan working-directory: tsan-${{ github.run_id }} env: TSAN_OPTIONS: "halt_on_error=1 second_deadlock_stack=1" - run: ./build/tests/kpn_tests + run: setarch -R ./build/tests/kpn_tests - name: Cleanup if: always()