Say before the run when a writable mount is a Docker Desktop shared folder - #41
Merged
Merged
Conversation
…older On Docker Desktop, a macOS folder bind-mounted into a container is a fakeowner filesystem, and under Landlock a command there can create a file but not write to it. The ruleset grants the mount; the kernel refuses the open anyway, leaving empty files and a bare Permission denied. porta now reads /proc/self/mountinfo and, when a writable -v lies on fakeowner, says so once, with what to use instead. docs/enforcement.md describes the limit. Closes #36 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #36.
On Docker Desktop, a macOS folder bind-mounted into a container is a
fakeownerfilesystem. Under Landlock, a command there can create a file but not write to it. Nothing in porta's ruleset causes this; the kernel refuses the open for writing whatever the grant says. Until now the command was left with an empty file and a barePermission denied.native/sandbox_exec/linux.rs:ruleset()first reads/proc/self/mountinfo. If a writable-vlies onfakeowner, it prints this once:porta: /h is a Docker Desktop shared folder (fakeowner), where under Landlock a command can create a file but not write to it; give the command a Docker volume or a tmpfs to write to, and copy out after the runThe filesystem is the deepest mount point that contains the path; when several are mounted on the same point, the last one listed wins. Octal escapes in mount points (
\040) are decoded.docs/enforcement.md: the limit and what to use instead.Verified
/hxis not under/h), an escaped space, and empty input. I ran it on macOS with rustc, with the functions extracted from linux.rs. The#[cfg(test)]module in linux.rs is Linux-only, and CI does not run the Rust tests, so it only ran that way.🤖 Generated with Claude Code