@@ -1441,13 +1441,13 @@ pub fn build_isolation_specs(
14411441 . iter ( )
14421442 . filter_map ( |entry| entry. split_once ( '=' ) . map ( |( key, _) | key. to_string ( ) ) )
14431443 . collect ( ) ;
1444- if input. rootless {
1445- // Podman's archive endpoint writes named-volume contents with the
1446- // rootless gateway user's host ownership. In a remapped user namespace,
1447- // that is container root rather than the resolved workload UID. Start
1448- // the trusted runtime as namespace root only long enough to chown the
1449- // empty workspace and irreversibly drop to the resolved identity before
1450- // it reads bootstrap material or accepts a control connection.
1444+ if input. rootless || input . identity . source == "default" {
1445+ // Podman's archive endpoint leaves named-volume contents owned by
1446+ // container root for rootless services and for a rootful USER-less
1447+ // image's newly-created workspace. Start the trusted runtime as root
1448+ // only long enough to chown the workspace, then irreversibly drop to
1449+ // the resolved workload identity before reading bootstrap material or
1450+ // accepting a control connection.
14511451 workload. command = vec ! [
14521452 "launch-capability-free" . into( ) ,
14531453 input. identity. uid. to_string( ) ,
@@ -1808,6 +1808,42 @@ mod tests {
18081808 Some ( "openshell-sandbox" )
18091809 ) ;
18101810 assert_eq ! ( specs. supervisor. apparmor_profile, None ) ;
1811+
1812+ let default_identity =
1813+ openshell_isolation_interface:: contract:: ResolvedWorkloadIdentity :: new (
1814+ 1000 ,
1815+ 1000 ,
1816+ Vec :: new ( ) ,
1817+ "default" . into ( ) ,
1818+ "sha256:image" . into ( ) ,
1819+ )
1820+ . unwrap ( ) ;
1821+ let rootful_specs = build_isolation_specs ( IsolationSpecInput {
1822+ sandbox : & sandbox,
1823+ config : & config,
1824+ token_secret : Some ( "jwt" ) ,
1825+ gpu_devices : None ,
1826+ requested_image : "image:latest" ,
1827+ image_id : "sha256:image" ,
1828+ image_user : "" ,
1829+ image_env : & env,
1830+ supervisor_bin : None ,
1831+ tls_secrets : None ,
1832+ identity : & default_identity,
1833+ rootless : false ,
1834+ } )
1835+ . unwrap ( ) ;
1836+ assert_eq ! ( rootful_specs. workload. user, "0:0" ) ;
1837+ assert_eq ! (
1838+ rootful_specs. workload. command,
1839+ vec![
1840+ "launch-capability-free" ,
1841+ "1000" ,
1842+ "1000" ,
1843+ crate :: isolation:: BOOTSTRAP_PATH ,
1844+ driver_mounts:: DEFAULT_WORKSPACE_ROOT ,
1845+ ]
1846+ ) ;
18111847 let workload_json = serde_json:: to_string ( & specs. workload ) . unwrap ( ) ;
18121848 assert ! ( workload_json. contains( "\" apparmor_profile\" :\" openshell-sandbox\" " ) ) ;
18131849 assert_eq ! ( specs. supervisor. healthconfig. test, vec![ "NONE" ] ) ;
0 commit comments