Skip to content

Commit ef2a235

Browse files
refactor(sandbox): remove unreachable root-side identity and workspace code
RFC 0012 moved the workload into its own capability-free container that starts as the final sandbox identity. The sandbox no longer runs a root supervisor that prepares the filesystem, rewrites account files, resolves OCI USER entries, or drops privileges before launching the workload, so that code had no production callers. Remove the unreachable paths and their tests: - prepare_filesystem / prepare_filesystem_with_identity, the /sandbox and OCI workspace chown preparation, and the root-side workspace validation (validate_oci_workspace and its privilege-dropped subprocess) - the hidden validate-workspace subcommand - drop_privileges / drop_privileges_with_identity, capability bounding set clearing, validate_sandbox_user/group, and /etc/passwd and /etc/group rewriting - the sandbox-side OCI USER resolver (identity.rs) and ResolvedProcessIdentity; the boundary now writes the driver-resolved UID/GID into the policy directly The workspace check that still runs inside the capability-free boundary (validate_oci_workspace_as_effective_identity) is unchanged. Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
1 parent 7caff12 commit ef2a235

5 files changed

Lines changed: 78 additions & 3297 deletions

File tree

‎crates/openshell-sandbox/src/boundary_server.rs‎

Lines changed: 2 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,6 @@ mod linux {
2727

2828
use crate::boundary_io::BoundaryRuntimeState;
2929
use crate::delegated::{AgentSignaler, spawn_workload};
30-
use crate::identity::{DriverIdentity, resolve_process_identity};
3130
use crate::main_session::{MainOutput, MainSession};
3231
use crate::network_broker::NetworkBroker;
3332
use crate::process::ProcessStatus;
@@ -2498,13 +2497,8 @@ mod linux {
24982497
.build()
24992498
);
25002499
}
2501-
let driver_identity = DriverIdentity::Resolved {
2502-
uid: self.config.workload_identity.uid,
2503-
gid: self.config.workload_identity.gid,
2504-
};
2505-
if let Err(error) = resolve_process_identity(&mut policy, &driver_identity) {
2506-
return guest_error(BoundaryErrorKind::Process, error.to_string());
2507-
}
2500+
policy.process.run_as_user = Some(self.config.workload_identity.uid.to_string());
2501+
policy.process.run_as_group = Some(self.config.workload_identity.gid.to_string());
25082502
let launch = ManagedProcessLaunch {
25092503
process_id: format!("{}:main:0", self.config.generation),
25102504
spec,

0 commit comments

Comments
 (0)