Repository navigation
Give each action a private /tmp inside the mount namespace - #2757
Draft
MarcusSorealheis wants to merge 2 commits into
Draft
MarcusSorealheis wants to merge 2 commits into
MarcusSorealheis wants to merge 2 commits into
Conversation
Actions that run with use_mount_namespace still shared the host's /tmp, so concurrent actions could collide on predictable paths there and state could leak from one action to the next. Mount a fresh tmpfs over /tmp for each action, controlled by a new isolate_tmp worker option that defaults on when use_mount_namespace is on and /tmp exists. If the root action directory lives under /tmp its path is recreated inside the tmpfs and the action directory is restored from the saved file descriptor, so work directories under /tmp keep working. A worker without a /tmp falls back to the old behaviour with a warning instead of failing to start, and perform_remount now reports errors through pre_exec instead of panicking in the forked child. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KucPh5sXMeQ7WhdXDEJeTz
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Member
Author
|
This AI generated PR has problems. I'll convert to draft for now. |
MarcusSorealheis
marked this pull request as draft
September 10, 2026 08:58
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Actions running with
use_mount_namespacestill shared the host's/tmp, so concurrent actions could collide on predictable paths there and state could leak from one action to the next through it. This gives each action a private, empty tmpfs/tmpinside its mount namespace, behind a newisolate_tmpworker option that defaults on whenuse_mount_namespaceis on and/tmpexists. If the root action directory lives under/tmp, its path is recreated inside the new tmpfs and the action directory is restored from the saved file descriptor, so work directories under/tmpkeep working.perform_remountnow reports errors throughpre_execinstead of panicking in the forked child.How was this verified?
namespace_utils_test.rscheck that the host's/tmpis invisible to an action and its writes never reach the host, that a root action directory under/tmpstays usable (inputs by relative and absolute path, siblings masked, outputs land on the host), that two concurrent actions writing the same/tmppath do not see each other, thatisolate_tmp: falsekeeps the host/tmpvisible, and thatnamespaces_supported(false, true)is rejected. Each fails on the old code, where the host/tmpis visible.isolate_tmp_gives_action_a_private_tmpinrunning_actions_manager_test.rsruns a full action throughRunningActionsManagerImplwithYesAndMount { isolate_tmp: true }and checks the output file is still uploaded from the work directory.namespace_utils_test,running_actions_manager_testandlocal_worker_testtargets on Linux (aarch64, privileged Docker, both as root and as uid 65534 so user namespace setup matches an unprivileged runner), plus clippy and thenativelink-configtests on macOS. All green.Risk
use_mount_namespace: truenow gives actions an empty/tmp. An action that depended on a tool or file staged under the host's/tmpneedsisolate_tmp: false. Files an action writes to/tmpare now memory backed and vanish with the action./tmp(the flake's release image does not include one) keep the old behaviour with a startup warning rather than failing, so nothing that starts today stops starting.mkdircalls per action in thepre_exechook, only whenisolate_tmpis on. Nothing changes for workers without mount namespaces.🤖 Generated with Claude Code
https://claude.ai/code/session_01KucPh5sXMeQ7WhdXDEJeTz
This change is