Skip to content

Say before the run when a writable mount is a Docker Desktop shared folder - #41

Merged
O6lvl4 merged 1 commit into
developfrom
fix/fakeowner-36
Sep 28, 2026
Merged

O6lvl4 merged 1 commit into
developfrom
fix/fakeowner-36

Conversation

@O6lvl4

@O6lvl4 O6lvl4 commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Closes #36.

On Docker Desktop, a macOS folder bind-mounted into a container is a fakeowner filesystem. Under Landlock, a command there can create a file but not write to it. Nothing in porta's ruleset causes this; the kernel refuses the open for writing whatever the grant says. Until now the command was left with an empty file and a bare Permission denied.

  • native/sandbox_exec/linux.rs: ruleset() first reads /proc/self/mountinfo. If a writable -v lies on fakeowner, it prints this once:
    porta: /h is a Docker Desktop shared folder (fakeowner), where under Landlock a command can create a file but not write to it; give the command a Docker volume or a tmpfs to write to, and copy out after the run
    The filesystem is the deepest mount point that contains the path; when several are mounted on the same point, the last one listed wins. Octal escapes in mount points (\040) are decoded.
  • docs/enforcement.md: the limit and what to use instead.

Verified

🤖 Generated with Claude Code

…older

On Docker Desktop, a macOS folder bind-mounted into a container is a
fakeowner filesystem, and under Landlock a command there can create a
file but not write to it. The ruleset grants the mount; the kernel
refuses the open anyway, leaving empty files and a bare Permission
denied. porta now reads /proc/self/mountinfo and, when a writable -v
lies on fakeowner, says so once, with what to use instead.

docs/enforcement.md describes the limit.

Closes #36

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@O6lvl4
O6lvl4 merged commit 5f8802c into develop Sep 28, 2026
4 checks passed
@O6lvl4
O6lvl4 deleted the fix/fakeowner-36 branch September 28, 2026 00:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

On Docker Desktop, a -v of a host-shared (fakeowner) directory is creatable but not writable under Landlock, and porta says nothing

1 participant