Skip to content

Expose strict VirtioFS ownership preparation - #127

Merged
JAORMX merged 3 commits into
mainfrom
feat/virtiofs-ownership-preparation
Sep 22, 2026
Merged

JAORMX merged 3 commits into
mainfrom
feat/virtiofs-ownership-preparation

Conversation

@JAORMX

@JAORMX JAORMX commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Expose virtiofs.PrepareOwnership(ctx, root, relativePath, uid, gid) for strict full-tree or targeted preparation using the existing override_stat mechanism. Startup and explicit calls share one descriptor-relative, symlink-confined implementation.

Startup policy and compatibility

  • Startup remains best-effort by default: recoverable entry failures are reported in a bounded warning per incomplete mount, while safe descendants, siblings, and subsequent mounts continue processing.
  • Set VirtioFSMount.StrictOwnershipPreparation to true to require complete preparation before networking/backend startup.
  • Invalid configuration, root acquisition failures, and cancellation remain fatal.
  • OverrideUID/OverrideGID now request preparation for read-only exports as well as writable exports. ReadOnly continues to enforce guest and host-device write protection independently.
  • Public PrepareOwnership is always strict. Host ownership/permissions and existing guest mode bits are preserved; matching metadata is not rewritten.
  • Non-opted-in mounts and Linux user-namespace behavior remain unchanged.

Lifecycle and caller obligations

Public examples/tests cover snapshot preparation before explicit host sealing, worktrees prepared before consumer-level registration under an existing export, and synchronized post-merge replacements. Preparing at host mode 0600 then sealing to 0400 retains guest mode 0600; read-only export enforcement still denies guest writes.

Writing xattrs requires OS permission: an unannotated 0400 file normally returns a permission error for an unprivileged caller. No copying, staging subsystem, chmod/chown widening, watcher, or new mode-setting API is introduced.

Keep export roots stable, authorize hard-linked inodes, and synchronize host changes and guest metadata changes/access. Preparation is nontransactional and does not invalidate guest caches.

Validation

  • Formatting, CI-equivalent pure-Go lint, full pure-Go tests/build/vet, targeted race tests
  • Darwin arm64 compilation and FreeBSD compilation of preparation packages
  • Regression tests for best-effort continuation/reporting, strict startup abort, read-only overrides, confinement, metadata preservation and lifecycle examples
  • Independent security, API usability and spec/test review; portable declaration issue fixed

Local full CGO checks require unavailable libkrun.pc; repository CI covers Linux/macOS builds/tests. No live Apple Silicon guest behavior is claimed.

Release notes

See docs/RELEASE_NOTES.md. Not released; follow normal reviewed merge and tag-triggered release process.

@JAORMX
JAORMX merged commit 7e148d8 into main Sep 22, 2026
7 checks passed
@JAORMX
JAORMX deleted the feat/virtiofs-ownership-preparation branch September 22, 2026 13:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant