feat(docker): terminal.docker_snap_compat opt-out for snap-packaged Docker under AppArmor (#9730)
On hosts where Docker ships as a snap (Ubuntu cloud images / Azure VMs), the
snap's AppArmor confinement turns two sandbox hardening flags into a dead
container at start: `--init` fails with "exec /sbin/docker-init: operation not
permitted" and `--security-opt no-new-privileges` then fails every exec the
same way ("exec /usr/bin/sleep: operation not permitted"). This is snapd
LP#1908448 — not probeable from the client, and docker_extra_args cannot remove
flags we add.
`terminal.docker_snap_compat: true` drops exactly those two flags; cap-drop ALL,
the tmpfs hardening, PID limits and the privdrop caps are unchanged, and a
warning is logged at container start. Bridged everywhere the other docker_*
keys are (CLI env map, gateway env map, `hermes config set` sync, terminal_tool
env read, the shared container_config shaper, DEFAULT_CONFIG).
This commit is contained in:
@@ -293,6 +293,7 @@ _TERMINAL_ENV_MAPPINGS = {
|
||||
"ssh_host", "ssh_user", "ssh_port", "ssh_key", "container_cpu", "container_memory",
|
||||
"container_disk", "container_persistent", "docker_volumes", "docker_env", "docker_extra_args",
|
||||
"docker_shm_size", "docker_mount_cwd_to_workspace", "docker_network", "docker_run_as_host_user",
|
||||
"docker_snap_compat",
|
||||
"docker_persist_across_processes", "docker_shared_container_key", "docker_orphan_reaper",
|
||||
"sandbox_dir", "persistent_shell",
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user