fix(helm): reject boolean sandbox UID and GID

Signed-off-by: Eric Curtin <eric.curtin@docker.com>
This commit is contained in:
Eric Curtin
2026-10-01 21:51:10 +01:00
parent 6a07ea843b
commit ca73dcf603
2 changed files with 16 additions and 1 deletions
+2 -1
View File
@@ -384,11 +384,12 @@ Render a sandbox UID/GID chart value as an integer, or nothing when unset.
Takes a dict with `name` (the values key, for errors) and `value`. The bounds
match openshell_policy::MIN_SANDBOX_UID..=MAX_SANDBOX_UID. Helm parses YAML
numbers as float64, so the integer conversion also avoids `2e+09` rendering.
Booleans are rejected because they would otherwise convert to 1 or 0.
*/}}
{{- define "openshell.sandboxId" -}}
{{- if not (or (kindIs "invalid" .value) (eq (toString .value) "")) -}}
{{- $id := int64 .value -}}
{{- if or (ne (float64 .value) (float64 $id)) (lt $id 1) (gt $id 4294967294) -}}
{{- if or (kindIs "bool" .value) (ne (float64 .value) (float64 $id)) (lt $id 1) (gt $id 4294967294) -}}
{{- fail (printf "%s must be an integer between 1 and 4294967294" .name) -}}
{{- end -}}
{{- $id -}}
@@ -77,3 +77,17 @@ tests:
asserts:
- failedTemplate:
errorPattern: "server.sandboxUid must be an integer between 1 and 4294967294"
- it: rejects a boolean sandbox UID
set:
server.sandboxUid: true
asserts:
- failedTemplate:
errorPattern: "server.sandboxUid must be an integer between 1 and 4294967294"
- it: rejects a boolean sandbox GID
set:
server.sandboxGid: true
asserts:
- failedTemplate:
errorPattern: "server.sandboxGid must be an integer between 1 and 4294967294"