Skip to content

Qualify v1.2 rootless Podman on Fedora SELinux #127

Description

@BrettKinny

This was generated by AI during triage.

Type: HITL

Parent

What to build

Qualify the v1.2 rootless Podman adapter on a real Fedora host with enforcing
SELinux. Confirm coherent host-to-Box identity, scoped sudo provisioning,
persistent ownership, and the documented label=disable policy without
mutating host labels.

Record the Candidate version, source SHA, image digest, Fedora and Podman
versions, host UID/GID, SELinux mode, before/after labels, and pass/fail
evidence.

Acceptance criteria

  • Fresh install uses keep-id:uid=1000,gid=1000; the Box runs as dev while Workspace files remain owned by the invoking host user.
  • Conflicting PUID/PGID values are rejected before resource mutation.
  • Box-tier and Managed-home provisioning paths complete through the production capability and verification controls.
  • Managed-home and Workspace data survive stop/start, Box replacement, and rebuild under one Install identity.
  • Workspace, SSH fallback, installation config, and system-file SELinux labels are unchanged before and after qualification.
  • Agent forwarding and the read-only SSH fallback both work without relabeling host files.
  • Uninstall and force-gated purge remove only resources recorded by the Install identity.
  • Results and failures are attached here and reflected in the v1.2 UAT checklist.

Blocked by

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestready-for-humanRequires human implementation or judgment

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions