Skip to content

Require signaling privileges for non-root microVM teardown - #108

Merged
jiashuoz merged 3 commits into
mainfrom
fix/phase-a-nonroot-lifecycle
Sep 28, 2026
Merged

jiashuoz merged 3 commits into
mainfrom
fix/phase-a-nonroot-lifecycle

Conversation

@jiashuoz

@jiashuoz jiashuoz commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

A non-root runner manages VMMs under distinct UIDs and needs CAP_KILL to signal and tear them down. Startup now refuses hosts missing that capability; tests and the documented privilege contract include it. The opt-in KVM harness can target an existing delegated service cgroup for real non-root qualification.

Validation: Linux capability checks and missing-capability cases pass; the full real KVM contract passes as the non-root runner (12 cases, zero skips). Six real shared-workspace cold cycles and normal CLI teardown also pass with the final patched jailer. Five supplemental lifecycle probes ran the entire driver-level harness as root and are explicitly separated from non-root evidence. Portable tests and vet pass with Docker unavailable; code CI verify passes. Independent and adversarial code reviews passed, with documentation corrections included; all final-head CI checks pass.

Companion cloud PR: https://github.com/tokencanopy/rainier-cloud/pull/141. Phase A feasibility is complete and disposable infrastructure is removed. Runner-restart recovery and production/load/economic qualification remain later gates.

@jiashuoz
jiashuoz marked this pull request as ready for review September 28, 2026 14:29
@jiashuoz
jiashuoz merged commit 929fc1d into main Sep 28, 2026
1 check passed
@jiashuoz
jiashuoz deleted the fix/phase-a-nonroot-lifecycle branch September 28, 2026 15:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant