feat(podman): honor OCI image working directories - #3982
Draft
matthewgrossman wants to merge 2 commits into
Draft
matthewgrossman wants to merge 2 commits into
matthewgrossman wants to merge 2 commits into
Conversation
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
matthewgrossman
added this pull request to stack #3983
September 30, 2026 18:53
|
🌿 Preview your docs: https://nvidia-preview-pr-3982.docs.buildwithfern.com/openshell |
This was referenced Sep 30, 2026
matthewgrossman
force-pushed
the
podman-workdir/c-oci-workdir
branch
2 times, most recently
from
September 30, 2026 23:15
454f188 to
d4ffa52
Compare
6 tasks
…ValidationFailed The RFC 0012 split dropped the supervisor exit status that drivers map to the WorkspaceValidationFailed condition. An image WORKDIR the sandbox identity cannot use then surfaced as ControlSupervisorStartFailed on Docker and as a signal kill on Podman. The supervisor now exits with the reserved status when the sandbox rejects the image working directory. Docker maps that supervisor exit during readiness and monitoring, and Podman maps the supervisor companion's exit instead of the workload's. Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
Podman sandboxes now use a custom OCI image WORKDIR as the workspace and as the working directory for agent commands, matching Docker. Empty, /, and /sandbox values keep the managed /sandbox workspace volume. A custom workspace stays in the image's container filesystem: no workspace volume, no archive upload, and no root setup step. Resolve the image ID, user, environment, and working directory from one pinned inspection, validate the workdir with the shared OCI rules, and reject Podman control-path overlaps and image volumes or driver mounts that cover it. The runtime starts from / and passes the resolved path to agent commands with --workdir. Add podman_oci_identity to the Podman CI test list. Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
matthewgrossman
force-pushed
the
podman-workdir/c-oci-workdir
branch
from
October 1, 2026 19:15
d4ffa52 to
f192442
Compare
Contributor
Author
|
/ok to test f192442 |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Podman sandboxes now use an image's custom
WORKDIRas the agent workspace, as Docker already does. Images without a custom working directory still use the managed/sandboxvolume. Docker behavior does not change.When the image user can't use the image's
WORKDIR, sandbox creation now fails withWorkspaceValidationFailedon both Docker and Podman, instead of a generic startup failure.This is the third of four stacked PRs split out of #3801: #3979 (remove unreachable sandbox code) ← #3981 (Podman workspace volume ownership) ← this PR ← #3931 (shared OCI image tests). Together, the four supersede #3801.
Why this matters
Custom
WORKDIRon Podman. An image can setWORKDIR /home/app/projectand prepare that directory with files and permissions for its user. Today, a Podman sandbox ignores that choice and puts the agent in/sandboxinstead. Files the image placed in its working directory are not in the agent's workspace, so commands and uploads can go to the wrong place. Docker already works from the image's chosen directory.With this change, Podman keeps a custom workspace in the image's own filesystem rather than mounting a new volume over it. That preserves the image's files and ownership; OpenShell does not create the directory or grant the user new access. If the image leaves
WORKDIRunset, sets it to/, or chooses/sandbox, the existing managed-volume behavior remains, with the ownership fix from #3981.A clear error for an unusable
WORKDIR. When someone points OpenShell at an image whoseWORKDIRthe image user cannot write, sandbox creation should say so. The RFC 0012 runtime split dropped the supervisor exit status that drivers used to report this:ControlSupervisorStartFailed, with the real cause buried in a log tail.Users got no hint that the image was the problem.
What you can now do
On a Podman gateway host, build an image with a writable custom working directory:
Previously, Podman used
/sandboxregardless of the image'sWORKDIR.Related Issue
Replaces #3933, which GitHub automatically marked merged during stack reordering.
Fixes #2526. Supersedes #3801 and the Podman approach in #2715, which needed extra directory checks because the workload and supervisor shared a container. RFC 0012 runs them in separate containers, so those checks are no longer needed.
Follow-ups kept out of this PR:
HOMEcontract.VOLUMEs, with Docker parity.Changes
WorkspaceValidationFailedreportingopenshell-core: shared constants for the error context and the fixed condition message, next to the existing reserved exit status 78.openshell-sandbox: tags the rejection with the shared error context.openshell-supervisor: exits with status 78 when an agent start fails with that context.openshell-driver-docker: maps a supervisor exit of 78 toWorkspaceValidationFailed, both while waiting for readiness and while monitoring.openshell-driver-podman: reads the supervisor companion's exit status, not the workload's (the watcher stops the workload with SIGKILL), and maps 78 toWorkspaceValidationFailed.Podman OCI
WORKDIRResolvedPodmanImage)./.openshell, supervisor CA runtime root). Reject imageVOLUMEs or driver mounts that cover the workspace; mounts nested below it remain valid.--workdir. Start the runtime from/so Podman neither creates a missingWORKDIRnor fails tochdirinto it before OpenShell validates it.podman_oci_identityto the Podman CI test list, and give its image a customWORKDIRwith no workspace mounts.#3931 adds the shared
oci-imagesuite on top of this PR and runs it on Docker and both Podman lanes in CI.Testing
All checks ran against a local rootful Podman machine (macOS, libkrun). Rootless coverage comes from the
fedora-podman-rootlessoci-imagelane added in #3931.mise run pre-commitpassescargo testpasses foropenshell-core,openshell-driver-docker, andopenshell-driver-podman. That includes the supervisor exit mapping, Docker readiness and monitor reasons, the Podman supervisor-exit condition, the workspace spec, custom vs. managed launch, and image volumes and driver mounts that cover the workdir. Clippy is clean for those crates, and foropenshell-sandboxandopenshell-supervisoronaarch64-unknown-linux-gnu.podman_oci_identitypasses.oci-imagesuite from test(oci): share OCI USER and WORKDIR checks across Docker and Podman #3931 passes 4/4, including theWorkspaceValidationFailedreason for an unwritableWORKDIR.ubuntu-docker-rootful/oci-imagelane in test(oci): share OCI USER and WORKDIR checks across Docker and Podman #3931 is the end-to-end check for the Docker side ofWorkspaceValidationFailed.Checklist