Problem
lxd-runin.sh mounts current directory read-only.
The official way to share host dirs with containers is to use disk device.
$ lxc config device add <container> <sharename> disk source="$PWD" \
path="/root/$(basename "$PWD")"
And that makes all files inside container owned by nobody:nobody. The issue is described at lxc/incus#2025 and the solution is to direct kernel to map uid/gid of user from host to uid/gid of user from guest (which is root in this case).
The proposed solution raises a security issue - if container process with mapped uid/gid escapes filesystem boundaries, it will be able to steal private keys of host user. Secure solution is to rewrite file owner on filesystem access layer without touching container gid/uid.
Solution 1 - Patch LXD
The logical way is to add another device called dir-proxy to LXD that will do the necessary conversion. It requires knowledge of LXD and may not be feasible, because LXD is a wrapper over standard Linux containers and may be limited to what containers are capable of.
Solution 2 - Use 9p server on host and access it with FUSE client on guest
While kernel has support for 9p filesystem, it won't allow to mount it from unprivileged container. Other FUSE clients don't have this limitation. An additional benefit will be the ability to mount local project dir to remote LXD container (#26) provided that there is a secure channel between guest and host (LXD proxy devices?).
I am looking to add these features to lxd-runin.sh script. The stumbling block right now is to find a binary for 9p client that will provide FUSE server and could be easily injected in remote container.
Problem
lxd-runin.shmounts current directory read-only.The official way to share host dirs with containers is to use disk device.
And that makes all files inside container owned by
nobody:nobody. The issue is described at lxc/incus#2025 and the solution is to direct kernel to mapuid/gidof user from host touid/gidof user from guest (which isrootin this case).The proposed solution raises a security issue - if container process with mapped
uid/gidescapes filesystem boundaries, it will be able to steal private keys of host user. Secure solution is to rewrite file owner on filesystem access layer without touching containergid/uid.Solution 1 - Patch LXD
The logical way is to add another device called
dir-proxyto LXD that will do the necessary conversion. It requires knowledge of LXD and may not be feasible, because LXD is a wrapper over standard Linux containers and may be limited to what containers are capable of.Solution 2 - Use 9p server on host and access it with FUSE client on guest
While
kernelhas support for9pfilesystem, it won't allow to mount it from unprivileged container. Other FUSE clients don't have this limitation. An additional benefit will be the ability to mount local project dir to remote LXD container (#26) provided that there is a secure channel between guest and host (LXD proxy devices?).I am looking to add these features to
lxd-runin.shscript. The stumbling block right now is to find a binary for 9p client that will provide FUSE server and could be easily injected in remote container.