Conversation
There was a problem hiding this comment.
Pull request overview
Enables shifterimg to parse configuration inside user namespaces without weakening privileged runtime validation.
Changes:
- Adds an opt-in parser flag that skips only UID-0 ownership validation.
- Applies the exception exclusively to
shifterimg. - Adds permission tests and documents the security boundary.
Reviewed changes
Copilot reviewed 7 out of 7 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
src/UdiRootConfig.h |
Declares the parser flag and opt-in API. |
src/UdiRootConfig.c |
Implements conditional ownership validation. |
src/shifterimg.c |
Enables the ownership exception for shifterimg. |
src/test/test_UdiRootConfig.cpp |
Tests strict ownership and writable-file rejection. |
src/test/Makefile.am |
Enables ownership checks for parser tests. |
doc/security.rst |
Documents configuration trust boundaries. |
doc/config/udiRoot.conf.rst |
Documents caller-specific ownership requirements. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
udiRoot.confshifterimgshifter,setupRoot,unsetupRoot, the Slurm integration, and other runtime callersRoot cause
When
shifterimgruns in a user namespace, host UID 0 may be unmapped and reported as an overflow UID. A host-root-owned/etc/shifter/udiRoot.conftherefore fails the existingst_uid == 0check before an image pull can begin.shifterimgis an unprivileged image-gateway client and does not need the privileged runtime's owner check. The runtime remains unchanged and continues to require a root-owned configuration.User impact
Image pulls can run from JAWS/scrontab workflows that place commands in a user namespace. No command-line, environment, or
udiRoot.confoption is added; the exception is internal toshifterimg.Validation
shifterimg,shifter,setupRoot, andunsetupRootUdiRootConfigsuite: 5 tests, 64 checks passedunshare -Urn local_build/shifterimg --helpsucceedsunshare -Urn local_build/shifter --helpstill fails with the root-owner errorgit diff --check master...HEADpasses