Expand description
Deciding whether a sandbox needs raw.idmap.
The requirement is only ever that a host uid/gid lands on a guest uid/gid so a bind mount is writable. Three hosts, three answers:
- A host whose
/etc/subuidgives root a range that does NOT contain the uid (plus aroot:1000:1delegation): the default map puts the container elsewhere, andraw.idmapis what pulls the id through. - A nested box where root’s range starts at 0: the default map is already the
identity, and asking for
raw.idmapis refused (“Host ID is in the range of subids”). - macOS and its
isb machineVM: bind sources are the Mac home over Apple’s virtiofs, which reports every file as owned by whoever asks and writes as the Mac user, so every guest uid can already write them.
Only a real RANGE (count > 1) counts. A root:1000:1 line is the delegation
that permits raw.idmap to map 1000 at all, not a range the default map draws
from; treating it as one answers “not needed” on exactly the host that needs it.
Structs§
- SubIds
- Host facts that decide the idmap. Read from
/etc/subuidand/etc/subgid(empty where those do not exist).
Constants§
- CALLER_
OWNED_ ENV - Set in the
isb machineVM, whose bind sources are the shared Mac home. - VM_
IDMAP_ MIN_ INCUS - The oldest incus verified to hand a VM’s
raw.idmapto virtiofsd as--translate-uid/--translate-gid(7.5.1). An older or unreadable version may ignore the key and share the host directory untranslated, so isb refuses rather than guess.
Functions§
- in_
subid_ range - Whether
idfalls inside a subordinate id RANGE (count > 1) owned byowner(rootor0) in subuid/subgid file content. - incus_
translates_ vm_ shares - Whether
server_version(environment.server_version, e.g.7.5.1) is at leastVM_IDMAP_MIN_INCUS. - invoking_
ids - The (uid, gid) of the user running isb.
- plan_
container - What a container spec decides about
raw.idmap: the mode (for the plan’s “unset by hand” note, none for{raw: ...}) and the value to set. - plan_vm
- What a VM spec decides about
raw.idmap: the mode that applies (for the plan’s “unset by hand” note) and the value to set. A VM with no host bind mount needs neither. An incus that may not translate VM shares is an error unless the spec opts out withidmap: none, which warns. - resolve
- The
raw.idmapvalue for a spec on this host, orNoneif it should not be set. - resolve_
vm - The
raw.idmapvalue for a VM that bind-mounts host directories, orNonewhen the spec opts out (idmap: none). - vm_
service_ ids - The guest (uid, gid) a VM’s host shares map to by default: the service
user’s numeric
user:(1000or1000:1000), root when it is unset orroot, and 1000 for a named user (thedevuser of dev-base).