feat(podman): honor OCI image working directories - #3933
matthewgrossman merged 2 commits into
Conversation
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
|
🌿 Preview your docs: https://nvidia-preview-pr-3933.docs.buildwithfern.com/openshell |
|
/ok to test b9ab37e |
|
Label |
| ) | ||
| .await | ||
| .map_err(ComputeDriverError::from)?; | ||
| if managed_workspace { |
There was a problem hiding this comment.
Custom-workdir sandboxes now skip workspace-volume creation, but the provisioning cleanup and delete paths still remove the deterministic workspace-volume name unconditionally. This can delete a volume that was never created or ownership-verified by this sandbox. Guard failure cleanup with managed_workspace, and make deletion inspect and verify the OpenShell sandbox ownership labels before removing a workspace volume; label verification also preserves cleanup for volumes created by older gateways.
b9ab37e to
82d8d1c
Compare
…ValidationFailed The RFC 0012 split dropped the supervisor exit status that drivers map to the WorkspaceValidationFailed condition. An image WORKDIR the sandbox identity cannot use then surfaced as ControlSupervisorStartFailed on Docker and as a signal kill on Podman. The supervisor now exits with the reserved status when the sandbox rejects the image working directory. Docker maps that supervisor exit during readiness and monitoring, and Podman maps the supervisor companion's exit instead of the workload's. Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
Podman sandboxes now use a custom OCI image WORKDIR as the workspace and as the working directory for agent commands, matching Docker. Empty, /, and /sandbox values keep the managed /sandbox workspace volume. A custom workspace stays in the image's container filesystem: no workspace volume, no archive upload, and no root setup step. Resolve the image ID, user, environment, and working directory from one pinned inspection, validate the workdir with the shared OCI rules, and reject Podman control-path overlaps and image volumes or driver mounts that cover it. The runtime starts from / and passes the resolved path to agent commands with --workdir. Add podman_oci_identity to the Podman CI test list. Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
82d8d1c to
6059307
Compare
|
GitHub automatically marked this PR merged when its reordered head became an ancestor of its old base during stack maintenance. The change has not landed on main. Replacement draft PR: #3982, in the new stack #3983. |
Summary
Podman sandboxes now use an image's custom
WORKDIRas the agent workspace, as Docker already does. Images without a custom working directory still use the managed/sandboxvolume. Docker behavior does not change.This is the last of three stacked PRs split out of #3801 (#3931 ← #3932 ← this PR), and it supersedes #3801.
Why this matters
An image can set
WORKDIR /home/app/projectand prepare that directory with files and permissions for its user. Today, a Podman sandbox ignores that choice and puts the agent in/sandboxinstead. Files the image placed in its working directory are not in the agent's workspace, so commands and uploads can go to the wrong place. Docker already works from the image's chosen directory.With this change, Podman keeps a custom workspace in the image's own filesystem rather than mounting a new volume over it. That preserves the image's files and ownership; OpenShell does not create the directory or grant the user new access. If the image leaves
WORKDIRunset, sets it to/, or chooses/sandbox, the existing managed-volume behavior remains, with the ownership fix from #3932.What you can now do
On a Podman gateway host, build an image with a writable custom working directory:
Previously, Podman used
/sandboxregardless of the image'sWORKDIR.Related Issue
Fixes #2526. Supersedes #3801 and the Podman approach in #2715, which needed extra directory checks because the workload and supervisor shared a container. RFC 0012 runs them in separate containers, so those checks are no longer needed.
Follow-ups kept out of this PR:
HOMEcontract.VOLUMEs, with Docker parity.Changes
ResolvedPodmanImage)./.openshell, supervisor CA runtime root). Reject imageVOLUMEs or driver mounts that cover the workspace; mounts nested below it remain valid.--workdir. Start the runtime from/so Podman neither creates a missingWORKDIRnor fails tochdirinto it before OpenShell validates it.oci-imagesuite onfedora-podman-rootfulandfedora-podman-rootlessin branch E2E and both release workflows (Docker was added by the base PR). Addpodman_oci_identityto the Podman CI test list, and give its image a customWORKDIRwith no workspace mounts.podman_oci_identityto the checks only Podman can make: the pinned image ID and the isolated workload/supervisor container pair (users, capabilities, networking, mounts). The identity seen by the main process andsandbox execis covered by the shared suite on both runtimes.TESTING.md.Testing
All checks ran against a local rootful Podman machine (macOS, libkrun). Rootless coverage comes from the
fedora-podman-rootlessCI lane that this PR adds.mise run pre-commitpassescargo test -p openshell-driver-podman --lib(230 passed), covering the workspace spec, custom vs. managed launch, and image volumes and driver mounts that cover the workdir.cargo clippy -p openshell-driver-podman --all-targets -- -D warningsis clean.oci-imagesuite passes 4/4 throughe2e/with-podman-gateway.sh, including theWorkspaceValidationFailedreason for an unwritableWORKDIR.podman_oci_identitypasses.Checklist