Skip to content

The launcher suite checks from the host that a zone's pid 1 has its own ipc, uts and cgroup namespaces, as the architecture says - #327

Draft
DevomB wants to merge 1 commit into
mainfrom
zone-namespaces-checked
Draft

DevomB wants to merge 1 commit into
mainfrom
zone-namespaces-checked

Conversation

@DevomB

@DevomB DevomB commented Oct 9, 2026

Copy link
Copy Markdown
Owner

What was wrong

docs/architecture.md says every zone gets its own user, pid, ipc, uts, mount, cgroup and time namespaces, plus its own network namespace. The launcher suite's T11 runs as root and reads a running zone's pid 1 from the host. It compared only five of the zone's namespaces with the host's pid 1: user, pid, mnt, net and time.

Nothing checked the ipc or cgroup namespace at run time, anywhere: adversarial.sh only checks that isolate.rs names the flags. The uts namespace was checked only indirectly, through J9's hostname. So a launch that lost CLONE_NEWIPC (SysV shared memory and message queues shared with zone 0) or CLONE_NEWCGROUP would have passed every suite.

What changed

T11 compares all eight namespaces (user pid mnt net time ipc uts cgroup) between the zone's pid 1 and the host's pid 1, and its pass line names them.

docs/architecture.md needs no change: each row of its zone table, and each claim of what a zone cannot do, now has a check behind it. While checking, I found that compartments/README.md needs none either: each of its five "cannot" claims has its own section in compartments/tests/adversarial.sh, and its example's limits are enforced by zones-check (pids-limit, cpu-max-set) and launcher F5 (io_max).

How the run proves it

T11 runs in the Distro run's zones-test, step 3, where the launcher suite runs as root on the target kernel. launcher suite exit 0 and the accepted-gaps line together carry T11 passing with all eight namespaces compared.

…wn ipc, uts and cgroup namespaces, as the architecture says

docs/architecture.md gives zones their own user, pid, ipc, uts, mount,
cgroup and time namespaces, and their own network namespace. The root
launcher check that reads a running zone's pid 1 from the host compared five
of them with the host's pid 1: user, pid, mnt, net and time. Nothing checked
ipc or cgroup at run time, and uts only through the zone's hostname.

It now compares all eight, so a zone that shared any of them with the host
fails the check.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant