Skip to content

Allow shifterimg to parse config in user namespaces - #339

Draft
dingp wants to merge 2 commits into
masterfrom
dingpf/shifterimg-skip-config-permission-check
Draft

dingp wants to merge 2 commits into
masterfrom
dingpf/shifterimg-skip-config-permission-check

Conversation

@dingp

@dingp dingp commented Aug 18, 2026 •

Copy link
Copy Markdown

Summary

  • add an internal parser flag that allows an unprivileged caller to skip only the UID-0 ownership check for udiRoot.conf
  • use that flag only in shifterimg
  • keep the default parser strict for shifter, setupRoot, unsetupRoot, the Slurm integration, and other runtime callers
  • continue rejecting group- or world-writable configuration files
  • document the security boundary and add focused ownership/mode tests

Root cause

When shifterimg runs in a user namespace, host UID 0 may be unmapped and reported as an overflow UID. A host-root-owned /etc/shifter/udiRoot.conf therefore fails the existing st_uid == 0 check before an image pull can begin.

shifterimg is an unprivileged image-gateway client and does not need the privileged runtime's owner check. The runtime remains unchanged and continues to require a root-owned configuration.

User impact

Image pulls can run from JAWS/scrontab workflows that place commands in a user namespace. No command-line, environment, or udiRoot.conf option is added; the exception is internal to shifterimg.

Validation

  • built shifterimg, shifter, setupRoot, and unsetupRoot
  • focused UdiRootConfig suite: 5 tests, 64 checks passed
  • unshare -Urn local_build/shifterimg --help succeeds
  • unshare -Urn local_build/shifter --help still fails with the root-owner error
  • git diff --check master...HEAD passes

@coveralls

Copy link
Copy Markdown

Coverage Status

coverage: 87.645% (+0.1%) from 87.521% — dingpf/shifterimg-skip-config-permission-check into master

@dingp
dingp requested a balanced review from Copilot August 18, 2026 16:07

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Enables shifterimg to parse configuration inside user namespaces without weakening privileged runtime validation.

Changes:

  • Adds an opt-in parser flag that skips only UID-0 ownership validation.
  • Applies the exception exclusively to shifterimg.
  • Adds permission tests and documents the security boundary.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated no comments.

Show a summary per file
File Description
src/UdiRootConfig.h Declares the parser flag and opt-in API.
src/UdiRootConfig.c Implements conditional ownership validation.
src/shifterimg.c Enables the ownership exception for shifterimg.
src/test/test_UdiRootConfig.cpp Tests strict ownership and writable-file rejection.
src/test/Makefile.am Enables ownership checks for parser tests.
doc/security.rst Documents configuration trust boundaries.
doc/config/udiRoot.conf.rst Documents caller-specific ownership requirements.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants