@@ -13,6 +13,7 @@ use openshell_core::proto::compute::v1::DriverSandbox;
1313use openshell_isolation_interface:: contract:: {
1414 OuterFenceGuarantee , OuterFenceGuarantees , ResolvedWorkloadIdentity ,
1515} ;
16+ use openshell_sandbox_backend:: ALLOW_EXTRA_SUPPLEMENTARY_GROUPS_RESOURCE_CLAIM ;
1617use openshell_sandbox_backend:: boundary_protocol:: {
1718 BoundaryConfig , BoundaryListener , GatewayVerificationKey , SandboxRuntimeDescriptor ,
1819 SandboxTlsClientConfig , SandboxTlsServerConfig , SandboxTransport ,
@@ -27,7 +28,6 @@ pub const BOOTSTRAP_PATH: &str = "/.openshell/channel/sandbox/bootstrap.json";
2728pub const RUNTIME_DESCRIPTOR_PATH : & str = "/.openshell/supervisor/runtime-descriptor.json" ;
2829pub const AUTH_BUNDLE_PATH : & str = "/.openshell/supervisor/auth.json" ;
2930pub const RESTART_METADATA_PATH : & str = "/.openshell/supervisor/restart-metadata.json" ;
30- pub const USERNS_RESOURCE_CLAIM : & str = "podman.userns" ;
3131const SOCKET_PATH : & str = "/.openshell/channel/sandbox/control.sock" ;
3232
3333#[ derive( Serialize ) ]
@@ -71,6 +71,12 @@ pub fn channel_volume_name(id: &str) -> String {
7171 format ! ( "openshell-channel-{id}" )
7272}
7373
74+ /// `keep-id` may retain the gateway user's supplementary groups in the
75+ /// container. Other user-namespace modes, including `auto`, do not.
76+ pub fn userns_preserves_host_groups ( userns : Option < & str > ) -> bool {
77+ userns. is_some_and ( |mode| mode. split ( ':' ) . next ( ) == Some ( "keep-id" ) )
78+ }
79+
7480fn invalid ( error : impl std:: fmt:: Display ) -> ComputeDriverError {
7581 ComputeDriverError :: Precondition ( error. to_string ( ) )
7682}
@@ -196,7 +202,7 @@ pub fn bootstrap_archives(
196202 container_id : & str ,
197203 generation : & str ,
198204 identity : & ResolvedWorkloadIdentity ,
199- userns : Option < & str > ,
205+ allow_extra_supplementary_groups : bool ,
200206 child_env : HashMap < String , String > ,
201207 launch_authentication : & openshell_core:: jwt:: SandboxLaunchAuthentication ,
202208) -> Result < BootstrapArchives , ComputeDriverError > {
@@ -210,8 +216,11 @@ pub fn bootstrap_archives(
210216 identity. resource_digest . clone ( ) ,
211217 ) ,
212218 ] ) ;
213- if userns. is_some_and ( |mode| mode. split ( ':' ) . next ( ) == Some ( "keep-id" ) ) {
214- resource_claims. insert ( USERNS_RESOURCE_CLAIM . into ( ) , "keep-id" . into ( ) ) ;
219+ if allow_extra_supplementary_groups {
220+ resource_claims. insert (
221+ ALLOW_EXTRA_SUPPLEMENTARY_GROUPS_RESOURCE_CLAIM . into ( ) ,
222+ "true" . into ( ) ,
223+ ) ;
215224 }
216225 let runtime_generation = launch_authentication
217226 . supervisor
@@ -501,7 +510,7 @@ mod tests {
501510 "container" ,
502511 "generation-1" ,
503512 & identity,
504- None ,
513+ false ,
505514 child_env. clone ( ) ,
506515 & authentication,
507516 )
@@ -547,6 +556,11 @@ mod tests {
547556 . outer_fence
548557 . validate ( & runtime_descriptor. generation )
549558 . unwrap ( ) ;
559+ assert ! (
560+ !config
561+ . resource_claims
562+ . contains_key( ALLOW_EXTRA_SUPPLEMENTARY_GROUPS_RESOURCE_CLAIM )
563+ ) ;
550564 let restart_metadata: RestartMetadata = serde_json:: from_slice (
551565 supervisor
552566 . get ( & PathBuf :: from (
@@ -564,4 +578,15 @@ mod tests {
564578 . any( |window| window == b"PRIVATE KEY" )
565579 ) ;
566580 }
581+
582+ #[ test]
583+ fn keep_id_is_the_only_userns_mode_that_preserves_host_groups ( ) {
584+ assert ! ( userns_preserves_host_groups( Some ( "keep-id" ) ) ) ;
585+ assert ! ( userns_preserves_host_groups( Some (
586+ "keep-id:uid=1000,gid=1000"
587+ ) ) ) ;
588+ assert ! ( !userns_preserves_host_groups( Some ( "auto" ) ) ) ;
589+ assert ! ( !userns_preserves_host_groups( Some ( "private" ) ) ) ;
590+ assert ! ( !userns_preserves_host_groups( None ) ) ;
591+ }
567592}
0 commit comments