You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 85939cf
Browse filesBrowse the repository at this point in the historyBrowse files
fix(sandbox): reject local control peers when the kernel denies the ingress filter
Binding the boundary control listener attaches a classic BPF filter that drops
loopback-interface ingress. Some kernels gate SO_ATTACH_FILTER on CAP_NET_ADMIN,
and a sandbox pod holds no capabilities at all, so the attach returns EPERM and
every sandbox dies at startup with:
bind boundary control listener: Operation not permitted (os error 1)
Granting the capability is not an option: the native Linux audit evidence
requires an empty capability set, so a sandbox that could attach the filter
would fail its own qualification instead.
Treat EPERM as "filter unavailable" and move the check to accept time. Any peer
the workload can reach the listener from arrives over `lo`, so its source
address is either loopback or the address the connection was accepted on; a
supervisor runs in a different pod and presents a different address. The serve
loop already drops PermissionDenied accepts, which is the same path the Unix
peer check uses, and the control channel still requires the per-sandbox mTLS
certificate.
Kernels that permit the filter keep the stronger standing guarantee.
Signed-off-by: divesh <dgude@nvidia.com>
0 commit comments