Skip to content

fix(vm): reject conflicting workload identity selectors - #4036

Open
shiju-nv wants to merge 5 commits into
mainfrom
fix/3950-vm-workload-identity-021400
Open

shiju-nv wants to merge 5 commits into
mainfrom
fix/3950-vm-workload-identity-021400

Conversation

@shiju-nv

@shiju-nv shiju-nv commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

MicroVM silently accepts a policy requesting 10000:10000 when the driver runs the workload as 1000:1000. Reject conflicting user or group selectors before launch or policy acceptance, preserve the overlay's resolved owner, and report that UID:GID in sandbox status. Matching numeric selectors, the guest's sandbox account, and omitted selectors retain the driver-owned identity for canonical and exec processes.

Related Issue

Fixes #3950. Part of #3955. The maintainer reproduced the mismatch and accepted the issue on 2026-09-30.

Changes

  • Validate user and group independently before creating or recovering the writable overlay. Rejected selectors leave existing ownership unchanged.
  • Validate startup and global-update policies before acceptance, including policies discovered from the image and repairs to a rejected policy.
  • Check the wire policy again before boundary attachment or process start. The guard compares selectors with the protected runtime identity; guest init owns account setup and credential selection.
  • Restore the persisted overlay owner before publishing stopped and terminal sandboxes. Invalid identity metadata leaves the inactive resource visible and deletable without reporting an untrusted identity. Align policy-generation guidance with fixed MicroVM ownership.
  • Report the resolved pair through WorkloadIdentity, preserve it in lifecycle status, and document how MicroVM resolves identity.

Testing

  • Focused checks appropriate to the changed code pass. Broad lint and test gates run in CI.
  • Regression tests added and exercised against the faulty behavior.

Local verification passed for the VM driver correction: formatting, diff and license checks, the package check, and exact regressions for stopped/terminal identity restoration and deletion with invalid metadata. The restoration regressions failed before the fix. Earlier supervisor and policy verification remains applicable to unchanged code. The stop/start E2E fixture flushes its initial write before readiness and reports observed identities before comparing them. Its target compiles; see the linked hosted VM run for the restart result.

Current signed head: e62095dbd577. Hosted verification: Branch Checks and Branch E2E Checks. The test:e2e label is enabled for runtime tests.

Hosted VM E2E runs on Linux. Fresh physical-Mac qualification remains pending.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

@copy-pr-bot

copy-pr-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

@shiju-nv
shiju-nv added this pull request to stack #4041 October 1, 2026 11:51
@shiju-nv
shiju-nv marked this pull request as ready for review October 1, 2026 19:19
Reject conflicting policy users and groups before VM image preparation
and before guest attach or process startup changes state. Validate
supervisor policy updates against the protected VM workload identity.

Preserve the gateway CA transport and capability-free sandbox launcher.

Signed-off-by: Shiju <shiju@nvidia.com>
Name invalid user and group fixtures distinctly and move the final
workload identity into its group mismatch test.

Signed-off-by: Shiju <shiju@nvidia.com>
@shiju-nv
shiju-nv force-pushed the fix/3950-vm-workload-identity-021400 branch from f772f3d to 40e8e7d Compare October 2, 2026 21:06
Pass the optional rejection-log key for VM identity failures and keep
generic startup-write regressions free of VM identity constraints.

Repair the call sites after the branch rebase so the identity and cleanup
proposals compile against the current startup helpers.

Signed-off-by: Shiju <shiju@nvidia.com>

@drew drew left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

The accepted identity-mismatch bug makes this PR project-valid, but the initial review found two blocking gaps in the new identity contract.

Action required: Please preserve the resolved identity across stopped and terminal VM restores, and align the public policy-generation guidance with the new MicroVM constraint.

Blocking findings:

  • GATOR-042bc237-01: stopped and terminal restores lose the resolved workload identity
  • GATOR-042bc237-02: the public policy-generation skill can produce selectors the VM now rejects

Carried findings:

  • None

Non-blocking suggestions:

  • None
Gator metadata
  • Validation: Maintainer-authored fix for accepted issue #3950
  • Docs: Fern runtime and policy docs updated; public policy-generation skill remains inconsistent
  • Checks: Current required non-E2E checks are green
  • E2E: VM behavior requires test:e2e, but dispatch waits until review feedback is resolved
  • Head SHA: 042bc23704c66cd8ed527ee50c509da3bdb6c531
  • Base SHA: ec49209da25be39840742df29b64ec694d159c2f
  • Merge base SHA: ec49209da25be39840742df29b64ec694d159c2f
  • Patch ID: cc0d52ed749d59b75e5b65a25895e879240c78be
  • Gator payload: 10
  • Review mode: initial
  • Previous reviewed SHA: none
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:in-review

Comment thread crates/openshell-driver-vm/src/driver.rs
Comment thread docs/how-it-works/policies/schema.mdx
@drew drew added the gator:in-review Gator is reviewing or awaiting PR review feedback label Oct 3, 2026
Recover the persisted overlay owner before publishing stopped and terminal
sandboxes. Keep resources manageable when identity metadata is invalid.
Clarify fixed MicroVM ownership in policy-generation guidance.

Signed-off-by: Shiju <shiju@nvidia.com>
@shiju-nv shiju-nv added the test:e2e Requires end-to-end coverage label Oct 3, 2026
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown

Label test:e2e applied for 042bc23. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

@drew drew left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

The follow-up restores the persisted workload identity for stopped and terminal VM sandboxes and aligns the public policy-generation guidance with the enforced MicroVM contract. Both prior findings are resolved, and the delta review found no new blocking issues.

Blocking findings:

  • No blocking findings remain

Carried findings:

  • GATOR-042bc237-01: resolved by persisted owner recovery and stopped/terminal restore coverage
  • GATOR-042bc237-02: resolved by the updated MicroVM policy-generation guidance
Gator metadata
  • Validation: Accepted issue #3950 establishes the identity-mismatch fix as project-valid
  • Docs: Fern runtime and policy docs plus the public policy-generation skill are updated
  • Checks: Current-head Branch Checks are queued; completed required checks are green
  • E2E: test:e2e is applied and the current-head Branch E2E workflow is queued
  • Head SHA: fd1a801cfe025bb41c3a493797808baf674cc59e
  • Base SHA: ec49209da25be39840742df29b64ec694d159c2f
  • Merge base SHA: ec49209da25be39840742df29b64ec694d159c2f
  • Patch ID: eb624b52498095fc44feaa488dd2197d3e964f9c
  • Gator payload: 10
  • Review mode: follow_up
  • Previous reviewed SHA: 042bc23704c66cd8ed527ee50c509da3bdb6c531
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:watch-pipeline

@drew drew added gator:watch-pipeline Gator is monitoring PR CI/CD status and removed gator:in-review Gator is reviewing or awaiting PR review feedback labels Oct 3, 2026
Persist the canonical identity file before readiness and report the observed
exec, canonical and file-owner identities before comparing them.

Signed-off-by: Shiju <shiju@nvidia.com>

@drew drew left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

The latest test-only delta flushes the VM identity fixture before readiness and improves failure diagnostics without changing the reviewed identity contract. The bounded follow-up review found no new blocking issues, and both prior findings remain resolved.

Blocking findings:

  • No blocking findings remain

Carried findings:

  • GATOR-042bc237-01: resolved by persisted owner recovery and stopped/terminal restore coverage
  • GATOR-042bc237-02: resolved by the updated MicroVM policy-generation guidance
Gator metadata
  • Validation: Accepted issue #3950 establishes the identity-mismatch fix as project-valid
  • Docs: Existing Fern runtime and policy docs plus the public policy-generation skill remain aligned; this test-only delta needs no documentation update
  • Checks: Branch Checks, Helm Lint, and Trivy Changes are green; required E2E is still running
  • E2E: test:e2e is applied and the current-head workflow is in progress
  • Head SHA: e62095dbd577c5eb8db06dba8785044ccf576aa1
  • Base SHA: ec49209da25be39840742df29b64ec694d159c2f
  • Merge base SHA: ec49209da25be39840742df29b64ec694d159c2f
  • Patch ID: 3a26e617838e0145c914fbf2a81b24fa05c3e365
  • Gator payload: 10
  • Review mode: follow_up
  • Previous reviewed SHA: fd1a801cfe025bb41c3a493797808baf674cc59e
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:watch-pipeline

@drew drew added gator:approval-needed Gator completed review; maintainer approval needed and removed gator:watch-pipeline Gator is monitoring PR CI/CD status labels Oct 3, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gator:approval-needed Gator completed review; maintainer approval needed test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reject conflicting VM user requests and report the identity that runs the workload

2 participants