Skip to content

fix: Apply restrictive permissions to shared memory - #460

Merged
whoisj merged 1 commit into
mainfrom
whoisj/world-readable-shared-memory-segment-in-triton
Oct 7, 2026
Merged

whoisj merged 1 commit into
mainfrom
whoisj/world-readable-shared-memory-segment-in-triton

Conversation

@whoisj

@whoisj whoisj commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

What does the PR do?

Changes the permissions applied to the shared memory used by stub processes for communication purposes from the default 664 to 640 removing world read/write and restricting group to read-only.

Root Cause

The bi::shared_memory_object defaults to 664 permissions at creation when no permissions are specified.

Fix

Specify the desired permissions when creating the bi::shared_memory_object object.

Signed-off-by: J Wyman <jwyman@nvidia.com>
@whoisj
whoisj requested a review from Vinya567 October 7, 2026 19:54
@greptile-apps

greptile-apps Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Critical risk] Changes shared memory access permissions at creation.

The PR appears safe to merge; no actionable issues were found.

What we checked:

  • Stub keeps write access: The launcher starts the stub as a child with the same user identity. Owner read/write permissions remain enabled.
  • Permissions survive growth and restart: Growth resizes the existing object. Restart uses the creation path that applies the explicit permissions.

Summary

Changes shared-memory creation to request owner read/write and group read-only permissions (0640).

  • Passes explicit permissions to bi::shared_memory_object.
  • Keeps owner access needed by the Python stub.
  • Preserves the restriction during growth and reapplies it on restart.
  • No actionable issues found. No build or runtime tests were run.

Reviews (1) · Last reviewed commit: "fix: Apply restrictive permissions to sh..." · Reviewed by Greptile

@whoisj
whoisj merged commit 6ef21b3 into main Oct 7, 2026
4 checks passed
@whoisj
whoisj deleted the whoisj/world-readable-shared-memory-segment-in-triton branch October 7, 2026 20:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants