Skip to content

Reject conflicting VM user requests and report the identity that runs the workload #3950

Description

@shiju-nv

User Story

As an operator setting a sandbox's user and group, I want OpenShell to report the identity that actually runs my code and reject incompatible requests, so that I can reason about workspace ownership and permissions.

Problem Statement

The local v0.1.2 VM accepted a process policy requesting user/group 10000:10000 and reported that policy as effective, while canonical and exec processes ran as the driver's resolved 1000:1000. VM identity is deliberately driver-owned, but the accepted policy did not make the conflict visible.

Impact / Why This Matters

Users can investigate file-access and ownership failures using an effective-policy value that does not match execution. They may believe a user selection was applied when the runtime preserved its different driver identity.

Acceptance Criteria

  • A request for 10000:10000 against a driver resolving 1000:1000 fails before the workload starts and names both identities.
  • Matching numeric or symbolic requests reach Ready and canonical/exec processes report the displayed identity.
  • Independent user and group mismatches are detected; omitted selectors use the documented default.
  • Restarted overlays preserve their existing ownership, and a conflicting policy cannot silently change it.
  • Policy and runtime documentation describe the same driver-owned identity behavior.

Reproduction Steps

  1. Use the v0.1.2 VM driver with an image/configuration that resolves its sandbox account to 1000:1000.
  2. In the process section of an otherwise valid policy, set run_as_user and run_as_group to "10000".
  3. Inspect the stored policy and its reported effective status.
  4. Run id -u and id -g through sandbox exec and compare the result with the policy selectors. The recorded result was 1000:1000.

Environment

  • OpenShell: v0.1.2; current-source comparison at b8ffe5244cb244a1d74a4a03d69afe3da07e5f08.
  • Platform: Apple Silicon macOS 26.7; MicroVM backend.
  • Installation: released CLI, gateway and VM driver

Logs

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:computearea:policyPolicy engine and policy lifecycle workstate:acceptedA maintainer decided OpenShell should pursue this issue

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions