mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-03 16:11:17 +08:00
The VM driver bound control.sock and ssh.sock inside the per-sandbox state directory, which defaults to $HOME/.local/state/openshell/vm-driver/sandboxes/<uuid>/. On macOS the sun_path field of sockaddr_un holds 104 bytes, so a normal home directory plus the sandbox UUID already pushes the socket path past the limit and bind fails with "path too long". Bind both sockets under a short driver-owned namespace instead: /tmp/os-<uid>-<128-bit-hex>/<sandbox-id>/. The worst case with a UUID sandbox id is 101 bytes. Security properties of the new location: - The root is created with mkdir mode 0700 and a random 128-bit name, retrying on EEXIST, so a local user cannot pre-create the path to block the driver or plant a symlink. - The root's directory FD is held for the driver lifetime. Per-sandbox leaves are created and removed with mkdirat/unlinkat relative to that FD, so there is no path re-resolution between check and mutation. - Leaf creation rejects any sandbox id whose socket path would still exceed sun_path, returning a clear error instead of a bind failure. The driver removes the whole root on shutdown so restarts do not accumulate orphaned roots in /tmp. VM children are kill_on_drop, so no socket is live at that point. Restore-on-restart goes through the normal launch path and recreates leaves under the new root. Signed-off-by: Florent Benoit <fbenoit@redhat.com>