Skip to content

scratch: PR-head + unshare probe (diagnostic) - #3285

Closed
code-yeongyu wants to merge 5 commits into
mainfrom
ci-probe-pr3280
Closed

scratch: PR-head + unshare probe (diagnostic)#3285
code-yeongyu wants to merge 5 commits into
mainfrom
ci-probe-pr3280

Conversation

@code-yeongyu

Copy link
Copy Markdown
Collaborator

Temporary diagnostic PR on top of #3280 head (will be closed).

procaffe121 and others added 5 commits July 31, 2026 17:08
No behavior change. Move the inline probe out of
unshare_user_namespace_works into a reusable unshare_probe helper and a
cached working_unshare_mapping() that picks the first working candidate
from UNSHARE_MAPPING_CANDIDATES, so the launcher and the capability probe
share one code path.
…icted

Plain `unshare --user --map-root-user` fails on kernels and containers
that block unprivileged writes to /proc/self/uid_map (e.g. GitHub Actions,
restricted AppArmor profiles). On those systems util-linux delegates to the
setuid newuidmap/newgidmap helpers when --map-auto is also present.

Add the combined form as a fallback candidate and build the launcher args
from the probed mapping, so systems without newuidmap/newgidmap or a
/etc/subuid range keep using the plain form.
… fallback

The fallback candidate relies on the setuid newuidmap/newgidmap helpers
(uidmap package) plus a subuid/subgid range for the current user. Note in
the candidate docs that the startup probe rejects the candidate when those
are missing, so the plain --map-root-user form is used instead.
@code-yeongyu

Copy link
Copy Markdown
Collaborator Author

Diagnostic complete: mechanism confirmed. Closing.

@code-yeongyu
code-yeongyu deleted the ci-probe-pr3280 branch August 6, 2026 10:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants