Skip to content

Keep the file owners an image's layers record inside the actor - #2392

Open
Anish Ramasekar (aramase) wants to merge 8 commits into
agent-substrate:mainfrom
aramase:aramase/i/imagecache_tar_ownership
Open

Anish Ramasekar (aramase) wants to merge 8 commits into
agent-substrate:mainfrom
aramase:aramase/i/imagecache_tar_ownership

Conversation

@aramase

Copy link
Copy Markdown
Collaborator

Image layers record an owner for every file, but atelet's unpack only applied the mode, so everything showed up as 0:0 inside the actor. Once actors run as the image's USER (#1918), they can't read their own home directory.

  • atelet applies each tar entry's uid/gid on unpack, including symlinks and hardlinks, the same way containerd and moby do. That needs CAP_CHOWN, so atelet gets it.
  • Directories get their mode first and their owner after their contents, so setgid directories keep the bit.
  • The image cache layout moves to version 2, so caches built before this are rebuilt.

Breaking change

Please add the breaking-change label.

  • If atelet reports an unsupported cache layout after an upgrade or rollback, delete the node's image cache (docs/upgrade.md).
  • Root without DAC_OVERRIDE can't write image files other users own; the jupyter demo now adds it.

Tested with root unit tests on Linux (also with only atelet's capabilities), the new imagefs e2e on kind with gVisor (fails on main, passes here), and make test on Linux.

Fixes #2036

@aramase

Copy link
Copy Markdown
Collaborator Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Image-layer file ownership appears as uid 0 inside the actor

1 participant