user: fix ToHost treating a non-root uid equal to the remapped-root base as the remapped root - #242
Open
okhowang wants to merge 1 commit into
Open
Conversation
okhowang
force-pushed
the
fix/identity-mapping-tohost-low-base-remap
branch
2 times, most recently
from
August 4, 2026 07:54
41cf740 to
89c80ea
Compare
…se unmapped ToHost translated container ids to host ids, but special-cased the container root by skipping the id-map lookup whenever the container uid matched the host remapped-root base (RootPair). That comparison was wrong: the input is a container-namespace id, so it must never be compared against a host value. When the subuid/subgid base is below 65536 (e.g. 'rootless:1000:65536', used to align dind-rootless container uids), a non-root container uid that equals the base (e.g. 1000) was incorrectly left unmapped and therefore appeared as root inside the container. Drop the special case entirely and always translate every id through toHost. toHost(0) already resolves to the host remapped-root base (which is exactly what RootPair returns), so the container root is handled correctly without any guard. An empty (nil) mapping is treated as identity. Add a regression test covering standard, low-base, and empty mappings. Signed-off-by: okhowang(王沛文) <okhowang@tencent.com>
okhowang
force-pushed
the
fix/identity-mapping-tohost-low-base-remap
branch
from
August 4, 2026 11:43
89c80ea to
5d658c5
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fixes #241
ToHost translated container ids to host ids, but special-cased the
container root by skipping the id-map lookup whenever the container uid
matched the host remapped-root base (RootPair). That comparison was
wrong: the input is a container-namespace id, so it must never be
compared against a host value.
When the subuid/subgid base is below 65536 (e.g. 'rootless:1000:65536',
used to align dind-rootless container uids), a non-root container uid
that equals the base (e.g. 1000) was incorrectly left unmapped and
therefore appeared as root inside the container.
Drop the special case entirely and always translate every id through
toHost. toHost(0) already resolves to the host remapped-root base (which
is exactly what RootPair returns), so the container root is handled
correctly without any guard. An empty (nil) mapping is treated as
identity.
Add a regression test covering standard, low-base, and empty mappings.