Actor rootfs `/` is mode 0700, so non-root users cannot traverse the root filesystem
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 76/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- go, linux
- Ambito
- operating-systems
Direzione di ricerca
Inizia da internal/imagecache/bundle_linux.go:61-66 e verifica come vengono creati rootfs, upper e work prima del mount overlay alla riga 81. Leggi applyDirFixups in internal/imagecache/implicitdirs.go per determinare se la root unita viene gestita. Il lavoro è completato quando la root di un’immagine standard rimane attraversabile dagli utenti non-root, con un controllo di regressione per il comportamento 0700 della root segnalato.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
Inside a gVisor actor, the root directory / is root:root 0700. A workload that drops to a non-root user cannot resolve any path at all, not even /bin/sh, because the first path component is not traversable. Docker and containerd keep the image root's mode (normally 0755). As shipped, any non-root workload fails on Substrate.
Impact
- Who hits it: every integrator whose workload runs as, or switches to, a non-root user. Agent runtimes and most hardened images do this.
- What breaks:
su,runuserand any exec as a non-root uid fail withPermission denied. The workload cannot start. - Cost: each integrator has to add a root-privileged fixup at actor start.
- Severity: High.
- Proposed priority: P1. It blocks non-root workloads out of the box. A workaround exists but needs root at startup, which depends on the uid-0 start (see Workload has no
userfield or no-new-privileges setting…).
Environment
- Substrate
d277088b(v1alpha). - GKE 1.36.x.
- gVisor sandbox class, unprivileged WorkerPool workers.
Steps to reproduce / evidence
- Create the actor (verified live). Use an ActorTemplate whose image is a Debian-based image with a non-root user (for example
useradd -u 1000 agent). Create an actor from it. - Check the root mode inside the actor, as root (verified live):
$ stat -c '%a:%U:%G %n' / 700:root:root / - Switch to the non-root user (verified live):
$ su agent -s /bin/sh -c id su: failed to execute /bin/sh: Permission denied/bin/shis itself 0755. The failure is at the traversal of/. - Show that a 0755 root is sufficient (verified live). After
chmod 755 /(as root),suandrunuserto the non-root uid both succeed. The same test also chowned the user's home directory; the exec itself (su … -c id) depends only on/being traversable. - Cause (code-read at
d277088b):internal/imagecache/bundle_linux.go:61-66creates<bundle>/rootfs,upperandworkwithos.MkdirAll(d, 0o700).- The overlay is then mounted at
rootfswith that upperdir (bundle_linux.go:81). - The merged overlay root takes its attributes from the upperdir root.
applyDirFixupsininternal/imagecache/implicitdirs.gorepairs implicit parent directories. It does not appear to cover/itself.
Expected vs actual
- Expected: the actor's
/has the image root's mode (0755 for standard base images), as under Docker, containerd and Kubernetes. - Actual:
/is 0700 and owned by root. No non-root uid can traverse it.
Workaround
At actor start, while still uid 0, an integrator can:
chmod 755 /if/is more restrictive than that.- Check that the workload user can traverse the rootfs (for example that
/bin/shresolves). - Fail closed if it cannot.
This only works because the workload starts as root.
Additional detail
- Suggested fix: create the bundle rootfs/upperdir root with 0755, or copy the image root's mode onto it after the overlay is mounted.
- Related issues (same class, image metadata lost in the actor rootfs):
- Image-layer file ownership appears as uid 0 inside the actor (
image-layer-file-ownership-lost.md). - Actor rootfs drops setuid, setgid and sticky bits from image layers (
/tmpis 0777) (actor-rootfs-drops-special-mode-bits.md).
- Image-layer file ownership appears as uid 0 inside the actor (
- Lingua principale
- Go
- Stelle
- 4.4k
- Fork
- 515
- Merge medio
- 2g 15h
- PR unite (30g)
- 258
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di agent-substrate/substrate
-
area/security
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
agent-substrate/substrate#2276 ·
I maintainer di solito rispondono entro 1 giorno
-
area/security
Difficoltà 2/5 1-3 ore Idoneità per principianti 67/100
agent-substrate/substrate#2274 ·
I maintainer di solito rispondono entro 1 giorno
-
area/network kind/bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
agent-substrate/substrate#2245 ·
I maintainer di solito rispondono entro 1 giorno
-
[Bug]: e2e script flag parsing is brokenForse già presa @ericcurtin l’ha presa 1 giorno fa. Apertaarea/dev-infra area/tests kind/bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
agent-substrate/substrate#2217 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Reject trailing YAML documents in actor-template create manifestsForse già presa @ericcurtin l’ha presa 3 giorni fa. Apertaarea/cli kind/bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
agent-substrate/substrate#2156 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di agent-substrate/substrate
Issue simili
-
status:approved type:bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
Gentleman-Programming/gentle-ai#5326 ·
I maintainer di solito rispondono entro 1 giorno
-
area/testing kind/cleanup priority/backlog triage/accepted
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
lexfrei/cloudflare-tunnel-gateway-controller#999 ·
I maintainer di solito rispondono entro 1 giorno
-
automation models
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 1 giorno
-
Can the search results with Year Released be in enclosed in the ( ) like Movie/TV(Year Released)Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
Dhairya3391/kari#32 ·