Uh oh!
There was an error while loading. Please reload this page.
config: add "umask" field to POSIX "user" section - #941
Conversation
Users may want to specify the umask(2) of the init process in a container. This value is identical in semantics to POSIX. This is in order to allow usage of an OCI container for a service which normally only inherits the umask given to it. Signed-off-by: Aleksa Sarai <asarai@suse.de>
34da7a6 to
6b04c63Comparecrosbymichael
commented
Dec 6, 2017
When do you plan to set this during init? Right before exec or when the rootfs is being setup like the existing umask settings? |
| * **`uid`** (int, REQUIRED) specifies the user ID in the [container namespace](glossary.md#container-namespace). | ||
| * **`gid`** (int, REQUIRED) specifies the group ID in the [container namespace](glossary.md#container-namespace). | ||
| * **`umask`** (int, OPTIONAL) specifies the [umask][umask_2] of the user. If unspecified, the umask should not be changed from the calling process' umask. |
There was a problem hiding this comment.
nit: the possessive of “process” is “process's”, see us here and the Linux man pages here.
nit: the “If unspecified…” sentence should go on its own line.
| "GID": { | ||
| "$ref": "#/definitions/uint32" | ||
| }, | ||
| "Umask": { |
There was a problem hiding this comment.
The indent here is a bit strange. You can automatically format these files by running make fmt in the schema directory.
wking
commented
Dec 6, 2017
The way the spec reads now (#700), runtimes will be able to chose either of those as they see fit. |
| [selinux]:http://selinuxproject.org/page/Main_Page | ||
| [no-new-privs]: https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt | ||
| [proc_2]: https://www.kernel.org/doc/Documentation/filesystems/proc.txt | ||
| [umask.2]: http://pubs.opengroup.org/onlinepubs/009695399/functions/umask.html |
There was a problem hiding this comment.
nit: POSIX functions should go be in section 3 (or 3p), so umask.2 should be umask.3. umask.2 would be the Linux kernel docs for umask.
nit: you're linking to the 2004 edition of POSIX. I'd rather stay consistent with our other links and use the 2016 edition (#858).
| // GID is the group id. | ||
| GID uint32 `json:"gid" platform:"linux,solaris"` | ||
| // Umask is the umask for the init process. | ||
| Umask uint32 `json:"umask,omitempty" platform:"linux,solaris"` |
There was a problem hiding this comment.
Zero is a valid umask (it means “leave the permissions entirely up to the process itself”), so I think we need a pointer here.
cyphar
commented
Dec 6, 2017
@crosbymichael In |
vbatts
commented
Apr 4, 2018
@cyphar@crosbymichael I interpret this as being set right before exec. Perhaps that could be clearer. |
wking
commented
Apr 4, 2018
via email
On Wed, Apr 04, 2018 at 03:08:23PM -0700, Vincent Batts wrote:
@cyphar@crosbymichael I interpret this as being set right before
exec. Perhaps that could be clearer. If you want that interpretation to be portable across compliant
runtimes, I think you'd want to land wording to that effect around
[1], with something like:
Runtimes MUST NOT apply process.user.umask as part of creation; that
property is only applied during [start](#start).
[1]: https://github.com/opencontainers/runtime-spec/blame/v1.0.1/runtime.md#L103 |
stain
commented
Oct 17, 2018
As this is still pending approval since April - what needs to be done to progress this PR? |
leberknecht
commented
Nov 19, 2018
Anything we can do here? |
| "user": { | ||
| "uid": 1, | ||
| "gid": 1, | ||
| "umask": 63, |
There was a problem hiding this comment.
i get that they're just ints, but i wish octals were a viewable in json, and 077 wouldn't be 77
vbatts
commented
Nov 19, 2018
I would see this as right before exec. What would you're hopes be? |
cyphar
commented
Nov 19, 2018
I think right before exec would be most reasonable, since it's a setting about the container and not about configuring devices and others such things. Generally most |
rhatdan
commented
Aug 6, 2019
This has come up again in a request for Podman. Is there anything we could do to move this forward? |
giuseppe
commented
Aug 6, 2019
doing it just before exec seems like the correct thing to me. Currently runc does it in |
leberknecht
commented
Oct 7, 2019
caniszczyk
commented
Oct 7, 2019
RFC @opencontainers/runtime-spec-maintainers |
tianon
commented
Oct 7, 2019
I think @wking's comments look to be relevant and should be addressed (especially the inconsistent formatting). It also seems like a good idea IMO to clarify when this is expected to be applied, per @crosbymichael's comments. |
zhangyoufu
commented
Dec 22, 2025
Why |
Users may want to specify the umask(2) of the init process in a
container. This value is identical in semantics to POSIX. This is in
order to allow usage of an OCI container for a service which normally
only inherits the umask given to it.
See-also: opencontainers/runc#1650
Requested-by: @leberknecht
Signed-off-by: Aleksa Sarai asarai@suse.de