Skip to content

Fix jail permission setup for non-root runners - #106

Merged
jiashuoz merged 2 commits into
mainfrom
ops/phase-a-runtime
Sep 28, 2026
Merged

jiashuoz merged 2 commits into
mainfrom
ops/phase-a-runtime

Conversation

@jiashuoz

@jiashuoz jiashuoz commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

A non-root microVM runner with the documented capability set could not prepare its jail: ownership moved to the VM uid before chmod, which then failed with EPERM. Reclaim the inode with CAP_CHOWN, set its mode while owned by the runner, and transfer it to the VM. The same sequence handles an inode retained across resume without adding CAP_FOWNER. An engine ownership mutex keeps concurrent launches from interleaving the sequence through hard links to the same home inode.

A real Linux regression launches a non-root child with only CAP_CHOWN and checks initial setup, repeated ownership transfer, and concurrent shared-inode transfers. It failed before the fix and passes after it; Linux CI now runs it explicitly. Focused jail tests pass, the Linux concurrency regression passed ten repetitions, and full CI passed for commit 2983175 (make verify, restricted-capability regression, and CLI/client race checks). Both independent reviews pass after fixing the adversarial concurrency finding.

The privileges document records a separate unresolved limitation: jailer 1.17.0 writes ancestor cgroup controls outside a delegated subtree. This PR fixes inode ownership; it does not qualify the complete non-root launch path or change the capability set.

@jiashuoz
jiashuoz merged commit ff45eab into main Sep 28, 2026
1 check passed
@jiashuoz
jiashuoz deleted the ops/phase-a-runtime branch September 28, 2026 03:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant