Skip to content

fix(snapshot): carry upstream's PATH_MAX-safe snapshot tars - #259

Closed
teemow wants to merge 3 commits into
giantswarmfrom
fork/pathmax-tar-2110-2111
Closed

teemow wants to merge 3 commits into
giantswarmfrom
fork/pathmax-tar-2110-2111

Conversation

@teemow

@teemow teemow commented Oct 10, 2026

Copy link
Copy Markdown
Member

Problem

A workspace tree deeper than PATH_MAX crashes the actor at its checkpoint and loses the session on every harness: the snapshot tar walked and stat'ed each entry by its full host path (filepath.WalkDir, d.Info, os.Readlink), which fails with ENAMETOOLONG once the path passes PATH_MAX. The snapshot tar also decided which host paths a restore mounted or deleted, and its extract, which runs as root on the host, created any device node and set any trusted.overlay.* xattr the archive named. Tracking: giantswarm/giantswarm#38054.

Upstream fixed all of it in agent-substrate/substrate#2110 and agent-substrate/substrate#2111, both merged on 2026-10-06, after the line's pin v0.4.0-alpha1 (2026-10-04).

Proposed solution

Carry both as git cherry-pick -x of upstream's squash commits, authorship kept, plus their two FORK.md rows:

  • 893b1edb (snapshot rootfs uppers as one tar per container agent-substrate/substrate#2110): the snapshot takes one rootfs-upper tar per container and one tar per durable volume, the layout is created before the extract, and the tar is written and read through an os.Root (fd-relative, component by component), so no full host path is ever handed to the kernel. Clean pick.
  • 8da76493 (tarutil: refuse device nodes and unvetted xattrs on extract agent-substrate/substrate#2111): tarutil extracts only 0:0 character devices (overlay whiteouts), Create skips other devices, xattrs are limited to user.* and the path-based overlay attributes; on the micro-VM host the rootfs overlay and the share binds are nosuid,nodev. Adapted to the line: it still mounts through mount(8), so nosuid,nodev joins the overlay's -o options and BindIntoShare calls upstream's setNosuidNodev after the rbind; the hunk's RemountReadOnly/Unmount tests cover helpers the line does not have and are left out.

Upgrade note (upstream's breaking change): snapshots written before agent-substrate#2110 do not resume after it. The rollout needs the snapshot reset (golden and actor snapshots) before the roll.

The patches fall away at the re-pin onto the first upstream release that carries agent-substrate#2110 and agent-substrate#2111.

Acceptance criteria

  • go test ./internal/tarutil/... ./cmd/ateom-gvisor/... ./cmd/ateom-microvm/... and go vet ./internal/... ./cmd/... green on the branch
  • CI green, rebase-merged, a release candidate published
  • On the release candidate: an actor whose workspace holds a tree deeper than PATH_MAX suspends and resumes, and its harness reads its own files afterwards

This pull request was written by an agent.

Snapshot tars no longer decide which host paths to mount or delete.

Fixes agent-substrate#2083

We now take one rootfs upper per container in both gvisor and microvm
runtimes.
We take one tar per durable volume when durabledirs are used.

We create the layout before extracting into it, so the snapshot has no
control.

#### Breaking change

Old snapshots will not resume properly after this change.
Because we are pre-1.0 and this is a security fix, we are moving forward
with the straightforward fix.

Fixes agent-substrate#2083

> It's a good idea to open an issue first for discussion.

- [x] Tests pass
- [x] Appropriate changes to documentation are included in the PR

(cherry picked from commit 893b1ed)
…bstrate#2111)

Snapshot tars are restored as root on the host, and Extract would mknod
any device and set any trusted.overlay.* xattr the archive named.

Only 0:0 char devices (overlay whiteouts) are now created, and Create
skips other devices so a stray one cannot make a snapshot unrestorable.
xattrs are limited to user.* plus the path-based overlay attributes the
rootfs mount actually writes (opaque, redirect, impure).

On the micro-VM host, the rootfs overlay and the binds into the
virtio-fs share are now nosuid,nodev. The guest applies its own mount
flags, so setuid binaries still work inside the sandbox.

Fixes agent-substrate#2090

- [x] Tests pass
- [x] Appropriate changes to documentation are included in the PR

(cherry picked from commit 8da7649)
Adapted to the line: the line still mounts the merged rootfs overlay
and the share binds through mount(8), so nosuid,nodev joins the
overlay's -o options and BindIntoShare calls setNosuidNodev after the
rbind; the RemountReadOnly and Unmount tests of the same hunk test
helpers the line does not have and are left out.
@teemow
teemow requested a review from a team as a code owner October 10, 2026 10:50
@teemow

teemow commented Oct 10, 2026

Copy link
Copy Markdown
Member Author

Replaced by #260: the same picks on a fresh branch of giantswarm after the crashed-actor teardown merged, FORK.md rows after its row. (Written by an agent.)

@teemow teemow closed this Oct 10, 2026
@teemow
teemow deleted the fork/pathmax-tar-2110-2111 branch October 10, 2026 11:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants