Skip to content

Validate v1.1 rootless Podman on Fedora SELinux #100

Description

@BrettKinny

This was generated by AI during triage.

Type: HITL

What to build

Validate the v1.1 rootless Podman adapter on a real Fedora host with enforcing SELinux. Confirm that the host user is mapped coherently to the Box's dev account, Box-tier provisioning works through scoped sudo, Workspace and Managed-home ownership persist, and the documented label=disable policy does not mutate host labels.

Record the Candidate version, source SHA, image digest, Fedora/Podman versions, host UID/GID, SELinux mode, before/after labels, and pass/fail evidence in this issue.

Acceptance criteria

  • Fresh install uses keep-id:uid=1000,gid=1000; the running and exec user is dev, while files created in the Workspace are owned by the invoking host user.
  • PUID/PGID values different from the invoking rootless host identity are rejected before resource mutation.
  • Selected tmux plus a compiler-backed setup path installs successfully through scoped sudo under the production capability set.
  • Managed-home state and Workspace files survive stop/start, Box replacement, and rebuild under one Install identity.
  • Workspace, SSH fallback, installation config, and system-file SELinux labels are unchanged before/after the run.
  • The documented --security-opt label=disable tradeoff is confirmed on enforcing SELinux and no private :Z relabel is applied.
  • SSH-agent forwarding and the read-only SSH fallback both work without changing host key/config labels.
  • Uninstall and forced purge remove only recorded resources; adopted unlabeled Managed home remains force-gated.
  • Results and any failures are attached here and the v1.1 manual UAT checklist is updated.

Blocked by

None - can start immediately.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestready-for-humanRequires human implementation or judgment

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions