Skip to content

fs2: support OwnerUID - #84

Open
kolyshkin wants to merge 2 commits into
opencontainers:mainfrom
kolyshkin:fs2-owner-uid
Open

kolyshkin wants to merge 2 commits into
opencontainers:mainfrom
kolyshkin:fs2-owner-uid

Conversation

@kolyshkin

Copy link
Copy Markdown
Contributor

Cgroup ownership (chowning the container's cgroup to the host UID mapped
to the container's root user, when the container has a private cgroup
namespace and a read-write cgroupfs) was only implemented for the systemd
cgroup v2 manager; fs2 manager silently ignored OwnerUID.

This PR:

  • moves the chown code from systemd's UnifiedManager.Apply to a new
    internal/delegate package (no functional change);
  • uses it from fs2 Manager.Apply, and adds a test case;
  • updates the OwnerUID documentation.

Fixes: #66

Move the code which chowns the cgroup v2 directory and its
delegatable files to the owner UID from systemd's UnifiedManager.Apply
to a new internal package, so it can be reused by fs2 manager.

No functional change.

Signed-off-by: Kir Kolyshkin <kolyshkin@gmail.com>
Cgroup ownership (chowning the container's cgroup to the host UID
mapped to the container's root, in case the container has a private
cgroup namespace and a read-write cgroupfs) was only implemented for
systemd cgroup v2 manager. Implement it for fs2 manager as well.

Add a test case.

Fixes: opencontainers#66
Signed-off-by: Kir Kolyshkin <kolyshkin@gmail.com>
@kolyshkin
kolyshkin requested a review from a team as a code owner October 2, 2026 20:51
@kolyshkin kolyshkin added this to the 0.1.1 milestone Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

cgroup ownership (delegation chown) is only implemented in the systemd cgroup manager, not the fs driver

1 participant