mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-08 02:32:47 +08:00
* fix(podman): create managed workspace volumes owned by the workload identity Podman now creates the managed /sandbox volume with uid/gid options for the resolved workload identity, so the workload starts directly as that identity. This fixes rootful sandboxes whose image USER or policy run_as_user could not write to a root-owned /sandbox, and removes the root-then-drop workspace chown start path. Resource admission accepts the managed workspace volume when its options match the workload container's final identity, or are empty for volumes created by older gateways. The channel volume still requires empty options. Signed-off-by: Matthew Grossman <mgrossman@nvidia.com> * test(podman): cover managed volume reuse and workspace access Signed-off-by: Evan Lezar <elezar@nvidia.com> * refactor(podman): clarify managed volume creation and validation Signed-off-by: Evan Lezar <elezar@nvidia.com> * test(podman): verify workspace access across user namespaces Signed-off-by: Evan Lezar <elezar@nvidia.com> --------- Signed-off-by: Matthew Grossman <mgrossman@nvidia.com> Signed-off-by: Evan Lezar <elezar@nvidia.com> Co-authored-by: Evan Lezar <elezar@nvidia.com>