Skip to content

box: look up the caller with the host's tables in relaxed mode - #278

Merged
martinpitt merged 1 commit into
amutable-systems:mainfrom
daandemeyer:push-pnlqmwwrxnks
Oct 8, 2026
Merged

martinpitt merged 1 commit into
amutable-systems:mainfrom
daandemeyer:push-pnlqmwwrxnks

Conversation

@daandemeyer

Copy link
Copy Markdown
Member

Relaxed mode takes /etc from the box. The box's passwd does not list the
caller, and ssh-keygen aborts when getpwuid() fails. The sandbox works around
that by writing extended passwd and group copies into /var/tmp on every run.
Only the caller's uid is mapped in relaxed mode, so the box's own users can
never own a file there. Bind the host's passwd, group and nsswitch.conf
instead. The caller then resolves as it does on the host, including a
systemd-homed user that only userdb serves.

Signed-off-by: Daan De Meyer daan@amutable.com

Relaxed mode takes /etc from the box. The box's passwd does not list the
caller, and ssh-keygen aborts when getpwuid() fails. The sandbox works around
that by writing extended passwd and group copies into /var/tmp on every run.
Only the caller's uid is mapped in relaxed mode, so the box's own users can
never own a file there. Bind the host's passwd, group and nsswitch.conf
instead. The caller then resolves as it does on the host, including a
systemd-homed user that only userdb serves.

Signed-off-by: Daan De Meyer <daan@amutable.com>

@martinpitt martinpitt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹

@martinpitt
martinpitt merged commit e4d8253 into amutable-systems:main Oct 8, 2026
2 checks passed
@martinpitt

Copy link
Copy Markdown
Member

This unfortunately caused a regression downstream:

  No user exists for uid 9999
  '/usr/bin/ssh-keygen' failed with exit status 255.

So we'll revert that.

We can retry this once systemd/systemd#44086 lands and becomes available.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants