Repository navigation
Conversation
Snapshot tars no longer decide which host paths to mount or delete. Fixes agent-substrate#2083 We now take one rootfs upper per container in both gvisor and microvm runtimes. We take one tar per durable volume when durabledirs are used. We create the layout before extracting into it, so the snapshot has no control. #### Breaking change Old snapshots will not resume properly after this change. Because we are pre-1.0 and this is a security fix, we are moving forward with the straightforward fix. Fixes agent-substrate#2083 > It's a good idea to open an issue first for discussion. - [x] Tests pass - [x] Appropriate changes to documentation are included in the PR (cherry picked from commit 893b1ed)
…bstrate#2111) Snapshot tars are restored as root on the host, and Extract would mknod any device and set any trusted.overlay.* xattr the archive named. Only 0:0 char devices (overlay whiteouts) are now created, and Create skips other devices so a stray one cannot make a snapshot unrestorable. xattrs are limited to user.* plus the path-based overlay attributes the rootfs mount actually writes (opaque, redirect, impure). On the micro-VM host, the rootfs overlay and the binds into the virtio-fs share are now nosuid,nodev. The guest applies its own mount flags, so setuid binaries still work inside the sandbox. Fixes agent-substrate#2090 - [x] Tests pass - [x] Appropriate changes to documentation are included in the PR (cherry picked from commit 8da7649) Adapted to the line: the line still mounts the merged rootfs overlay and the share binds through mount(8), so nosuid,nodev joins the overlay's -o options and BindIntoShare calls setNosuidNodev after the rbind; the RemountReadOnly and Unmount tests of the same hunk test helpers the line does not have and are left out.
Member
Author
|
Replaced by #260: the same picks on a fresh branch of giantswarm after the crashed-actor teardown merged, FORK.md rows after its row. (Written by an agent.) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
A workspace tree deeper than
PATH_MAXcrashes the actor at its checkpoint and loses the session on every harness: the snapshot tar walked and stat'ed each entry by its full host path (filepath.WalkDir,d.Info,os.Readlink), which fails withENAMETOOLONGonce the path passesPATH_MAX. The snapshot tar also decided which host paths a restore mounted or deleted, and its extract, which runs as root on the host, created any device node and set anytrusted.overlay.*xattr the archive named. Tracking: giantswarm/giantswarm#38054.Upstream fixed all of it in agent-substrate/substrate#2110 and agent-substrate/substrate#2111, both merged on 2026-10-06, after the line's pin v0.4.0-alpha1 (2026-10-04).
Proposed solution
Carry both as
git cherry-pick -xof upstream's squash commits, authorship kept, plus their twoFORK.mdrows:893b1edb(snapshot rootfs uppers as one tar per container agent-substrate/substrate#2110): the snapshot takes one rootfs-upper tar per container and one tar per durable volume, the layout is created before the extract, and the tar is written and read through anos.Root(fd-relative, component by component), so no full host path is ever handed to the kernel. Clean pick.8da76493(tarutil: refuse device nodes and unvetted xattrs on extract agent-substrate/substrate#2111):tarutilextracts only0:0character devices (overlay whiteouts),Createskips other devices, xattrs are limited touser.*and the path-based overlay attributes; on the micro-VM host the rootfs overlay and the share binds arenosuid,nodev. Adapted to the line: it still mounts throughmount(8), sonosuid,nodevjoins the overlay's-ooptions andBindIntoSharecalls upstream'ssetNosuidNodevafter the rbind; the hunk'sRemountReadOnly/Unmounttests cover helpers the line does not have and are left out.Upgrade note (upstream's breaking change): snapshots written before agent-substrate#2110 do not resume after it. The rollout needs the snapshot reset (golden and actor snapshots) before the roll.
The patches fall away at the re-pin onto the first upstream release that carries agent-substrate#2110 and agent-substrate#2111.
Acceptance criteria
go test ./internal/tarutil/... ./cmd/ateom-gvisor/... ./cmd/ateom-microvm/...andgo vet ./internal/... ./cmd/...green on the branchPATH_MAXsuspends and resumes, and its harness reads its own files afterwardsThis pull request was written by an agent.