Repository navigation
Conversation
`Executor::setup_envs` was a no-op for every container type. That is right for Wasm containers, where the shim passes the env into the WASI context, but a Linux (native) container has no such code, so it ran with the shim's own environment (including its PATH) instead of the one from its OCI spec. This breaks, for example, Knative's queue-proxy sidecar in a Wasm pod. Delegate to libcontainer's default `setup_envs` when the container type is Linux. libcontainer calls `validate` right before `setup_envs`, so the type cached by `validate` is available; if it is not, return an error instead of guessing. Wasm containers are unchanged. Adds unit tests, including one that runs busybox `env` through the same validate / setup_envs / exec sequence and checks it sees only its own env. Fixes containerd#1061 Assisted-by: Claude Code (claude-sonnet-5-5) Signed-off-by: Venkatasubramanian Srinivasan <mani.svs@gmail.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Executor::setup_envswas a no-op for every container type. That is right for Wasm containers, where the shim passes the env into the WASI context, but a Linux (native) container has no such code, so it ran with the shim's own environment (including its PATH) instead of the one from its OCI spec. This breaks, for example, Knative's queue-proxy sidecar in a Wasm pod.Delegate to libcontainer's default
setup_envswhen the container type is Linux. libcontainer callsvalidateright beforesetup_envs, so the type cached byvalidateis available; if it is not, return an error instead of guessing. Wasm containers are unchanged.Adds unit tests, including one that runs busybox
envthrough the same validate / setup_envs / exec sequence and checks it sees only its own env.Fixes #1061
Assisted-by: Claude Code (claude-sonnet-5-5)