Skip to content

[Request]: Propagate permissions on all mounted Unix domain sockets from host into container. #1750

Description

@jglogan

Feature or enhancement request details

At present, when a user runs a container with --ssh, container-runtime-linux reads the permission bits on the host SSH_AUTH_SOCK and establishes the same permissions on the container end of the socket relay.

We should do this for all host-to-container socket mounts; otherwise, the sockets are unusable by non-root workloads.

Code of Conduct

  • I agree to follow this project's Code of Conduct

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

networkIssues and features associated with networking and DNS.storageissues and features associated with storage.

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

    Sponsor
    SponsoredKunjungi sekarang
    Promo