Actor rootfs `/` is mode 0700, so non-root users cannot traverse the root filesystem
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 76/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- go, linux
調査の方向性
internal/imagecache/bundle_linux.go:61-66 から始め、81 行目の overlay mount の前に rootfs、upper、work がどのように作成されるかを確認してください。internal/imagecache/implicitdirs.go の applyDirFixups を読み、統合された root が処理されるかどうかを判断してください。標準イメージの root が非 root ユーザーから引き続き辿れる状態になり、報告された 0700 root の挙動に対するリグレッションチェックがあれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Summary
Inside a gVisor actor, the root directory / is root:root 0700. A workload that drops to a non-root user cannot resolve any path at all, not even /bin/sh, because the first path component is not traversable. Docker and containerd keep the image root's mode (normally 0755). As shipped, any non-root workload fails on Substrate.
Impact
- Who hits it: every integrator whose workload runs as, or switches to, a non-root user. Agent runtimes and most hardened images do this.
- What breaks:
su,runuserand any exec as a non-root uid fail withPermission denied. The workload cannot start. - Cost: each integrator has to add a root-privileged fixup at actor start.
- Severity: High.
- Proposed priority: P1. It blocks non-root workloads out of the box. A workaround exists but needs root at startup, which depends on the uid-0 start (see Workload has no
userfield or no-new-privileges setting…).
Environment
- Substrate
d277088b(v1alpha). - GKE 1.36.x.
- gVisor sandbox class, unprivileged WorkerPool workers.
Steps to reproduce / evidence
- Create the actor (verified live). Use an ActorTemplate whose image is a Debian-based image with a non-root user (for example
useradd -u 1000 agent). Create an actor from it. - Check the root mode inside the actor, as root (verified live):
$ stat -c '%a:%U:%G %n' / 700:root:root / - Switch to the non-root user (verified live):
$ su agent -s /bin/sh -c id su: failed to execute /bin/sh: Permission denied/bin/shis itself 0755. The failure is at the traversal of/. - Show that a 0755 root is sufficient (verified live). After
chmod 755 /(as root),suandrunuserto the non-root uid both succeed. The same test also chowned the user's home directory; the exec itself (su … -c id) depends only on/being traversable. - Cause (code-read at
d277088b):internal/imagecache/bundle_linux.go:61-66creates<bundle>/rootfs,upperandworkwithos.MkdirAll(d, 0o700).- The overlay is then mounted at
rootfswith that upperdir (bundle_linux.go:81). - The merged overlay root takes its attributes from the upperdir root.
applyDirFixupsininternal/imagecache/implicitdirs.gorepairs implicit parent directories. It does not appear to cover/itself.
Expected vs actual
- Expected: the actor's
/has the image root's mode (0755 for standard base images), as under Docker, containerd and Kubernetes. - Actual:
/is 0700 and owned by root. No non-root uid can traverse it.
Workaround
At actor start, while still uid 0, an integrator can:
chmod 755 /if/is more restrictive than that.- Check that the workload user can traverse the rootfs (for example that
/bin/shresolves). - Fail closed if it cannot.
This only works because the workload starts as root.
Additional detail
- Suggested fix: create the bundle rootfs/upperdir root with 0755, or copy the image root's mode onto it after the overlay is mounted.
- Related issues (same class, image metadata lost in the actor rootfs):
- Image-layer file ownership appears as uid 0 inside the actor (
image-layer-file-ownership-lost.md). - Actor rootfs drops setuid, setgid and sticky bits from image layers (
/tmpis 0777) (actor-rootfs-drops-special-mode-bits.md).
- Image-layer file ownership appears as uid 0 inside the actor (
- 主要言語
- Go
- スター
- 4.4k
- フォーク
- 515
- 平均マージ
- 2日 10時間
- マージ済み PR(30日)
- 311
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
agent-substrate/substrate のほかの issue
-
Router dynamic xDS gRPC control plane runs plaintext on 0.0.0.0:18000対応中かも @LiorLieberman が 1 日前に担当しました。 オープンarea/network area/security kind/bug
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
agent-substrate/substrate#2276 · コメント 1 件 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
-
area/network kind/bug
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
agent-substrate/substrate#2245 ·
メンテナーはふだん 1 日以内に返信
-
[Bug]: e2e script flag parsing is broken対応中かも @ericcurtin が 3 日前に担当しました。 オープンarea/dev-infra area/tests kind/bug
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
agent-substrate/substrate#2217 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
Reject trailing YAML documents in actor-template create manifests対応中かも @ericcurtin が 6 日前に担当しました。 オープンarea/cli kind/bug
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
agent-substrate/substrate#2156 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
area/storage kind/bug
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
agent-substrate/substrate#2155 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
agent-substrate/substrate の issue をすべて見る
似ている issue
-
Discriminator mapping keys are listed in a random order対応中かも @reuvenharrison が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
Idle compaction monitors LIST the replica every tick when the newest destination file spans more than one TXID対応中かも @pishuv が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
benbjohnson/litestream#1563 ·
メンテナーはふだん 2 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信
-
agent-research agent-review-finding chore
難易度 2/5 1〜3時間 初心者へのやさしさ 66/100
jordansmall/spindrift#4922 ·
メンテナーはふだん 1 日以内に返信
-
gcsartifact: deleting a missing version returns an error対応中かも @ktsoator が今日担当しました。 オープンbug
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 2 日以内に返信