Skip to content

bug: sandbox from a USER root image fails with an unexplained "UID or GID zero" error #4030

Description

@mpereira

User Story

As someone creating a sandbox from an off-the-shelf image,
I want the error to say that the image runs as root and what I can do about it,
so that I can fix it without having to read OpenShell source code.

Problem Statement

OpenShell never runs a workload as root. When the policy doesn't set process.run_as_user, the Docker driver takes the identity from the image's USER, so an image that declares USER root is rejected. That's intended and documented in docs/how-it-works/policies/default-policy.mdx. The error message could be improved:

IdentityResolutionFailed: descriptor error: workload identity must not contain UID or GID zero

It doesn't say the zero came from the image's USER, it doesn't suggest a fix, and descriptor error is an internal name. The CLI also prints it twice.

From reading the code, a non-root user listed as a member of group 0 in the image's /etc/group gets the same error. Setting run_as_group alone doesn't fix it: the user still belongs to group 0 through the image's /etc/group.

Two related things I found:

  • Docker defaults to root both when the image has no USER and when it explicitly declares USER root. OpenShell instead uses 1000:1000 for the first case and rejects the second.
  • docs/how-it-works/sandboxes/runtimes.mdx says images without USER must set both policy fields. The code and default-policy.mdx say they fall back to 1000.

#3653 asks for regression tests on the same root rejection. This issue is about the error message.

Impact / Why This Matters

The error comes after the image pull, and it names neither the image nor a fix. Reading crates/openshell-driver-docker/src/lib.rs shows that the image's USER was the cause.

As an end user, the workaround is to build a derived image with a non-root USER, or to set run_as_user and run_as_group in a policy file. Neither is discoverable from the error.

For netshoot the policy route gets past identity resolution and then fails workspace validation: its WORKDIR is /root, which is drwxrwx--- root root in the image, so UID and GID 1000 can't enter it. That's a separate problem and not part of this issue.

Acceptance Criteria

  • When the Docker or Podman driver resolves an identity that contains a 0, the error says which part is zero (user, group, or a supplementary group) and where it came from (the image's USER, its /etc/passwd or /etc/group, or the policy).
  • When the zero comes from the image's USER, the error names the image and says to use a non-root image or set process.run_as_user and run_as_group.
  • descriptor error doesn't appear in the message.
  • The CLI prints the failure once.
  • runtimes.mdx matches default-policy.mdx and the code for images with no USER.
  • Root is still rejected, and an image with no USER and no policy identity still gets 1000:1000.

Reproduction Steps

  1. openshell sandbox create --name test-sandbox --detach --from nicolaka/netshoot:latest
  2. It fails with "IdentityResolutionFailed".
  3. docker image inspect nicolaka/netshoot:latest --format '{{.Config.User}}' shows root.

Environment

  • OpenShell 0.1.2 (Homebrew) on macOS 26.2 arm64, local Docker gateway. The identity code and both docs pages are the same on main at 021400be8.
  • Docker Engine 29.4.0 (linux/arm64)

Logs

$ openshell sandbox create --name test-sandbox --detach --from nicolaka/netshoot

Created sandbox: test-sandbox

✗ Error: IdentityResolutionFailed: descriptor error: workload identity must not contain UID or GID zero
✓ Sandbox allocated (0s)
✓ Image pulled (0s)                                                                                                           Error:   × sandbox entered error phase while provisioning: IdentityResolutionFailed: descriptor error: workload identity must not
  │ contain UID or GID zero

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions