Files
Florent BENOIT 11f1fe5806 fix(vm): relocate per-sandbox Unix sockets to /tmp to fit macOS sun_path (#3544)
The VM driver bound control.sock and ssh.sock inside the per-sandbox
state directory, which defaults to
$HOME/.local/state/openshell/vm-driver/sandboxes/<uuid>/. On macOS the
sun_path field of sockaddr_un holds 104 bytes, so a normal home
directory plus the sandbox UUID already pushes the socket path past the
limit and bind fails with "path too long".

Bind both sockets under a short driver-owned namespace instead:
/tmp/os-<uid>-<128-bit-hex>/<sandbox-id>/. The worst case with a UUID
sandbox id is 101 bytes.

Security properties of the new location:

- The root is created with mkdir mode 0700 and a random 128-bit name,
  retrying on EEXIST, so a local user cannot pre-create the path to
  block the driver or plant a symlink.
- The root's directory FD is held for the driver lifetime. Per-sandbox
  leaves are created and removed with mkdirat/unlinkat relative to that
  FD, so there is no path re-resolution between check and mutation.
- Leaf creation rejects any sandbox id whose socket path would still
  exceed sun_path, returning a clear error instead of a bind failure.

The driver removes the whole root on shutdown so restarts do not
accumulate orphaned roots in /tmp. VM children are kill_on_drop, so no
socket is live at that point. Restore-on-restart goes through the
normal launch path and recreates leaves under the new root.

Signed-off-by: Florent Benoit <fbenoit@redhat.com>
2026-09-23 14:36:57 +00:00
..