Skip to content

Clear setgid when hardening Windows VM mount modes - #9989

Closed
fresh3nough wants to merge 1 commit into
omacom:quattrofrom
fresh3nough:fix/9943-windows-vm-setgid
Closed

fresh3nough wants to merge 1 commit into
omacom:quattrofrom
fresh3nough:fix/9943-windows-vm-setgid

Conversation

@fresh3nough

Copy link
Copy Markdown
Contributor

Summary

prepare_caller_mounts ran chmod 0700 then required stat -c %a to equal 700. The Windows container sets ~/Windows to 2777; GNU chmod keeps directory setgid, leaving 2700, so launch failed with only Failed to start Windows VM! while status still said RUNNING. The failure self-renewed on every container start.

Fix

  • After chmod 0700, run chmod g-s,o-t on storage/shared FDs and user mount sources
  • Print unexpected modes on refusal instead of a silent return 1

Fixes #9943

Test plan

  • Reproduced: 2777 → chmod 0700 → 2700; g-s,o-t → 700
  • bash test/shell.d/windows-vm-setgid-test.sh

dockurr/windows leaves ~/Windows as 2777; GNU chmod 0700 keeps setgid
(2700), so the script's literal 700 check failed silently on every
subsequent launch. Clear g-s/o-t after 0700 and print the mode on refusal.

Fixes omacom#9943

Signed-off-by: fresh3nough <anonwurcod@proton.me>
@omarchybot

Copy link
Copy Markdown
Collaborator

Update: #12323 has merged into quattro. The setgid permission rejection is now fixed in both source-directory hardening paths, with an explicit mode diagnostic. This does not claim that runtime share privacy or every desktop failure notification is fixed.

Scope checked by GPT-6 in Codex and Codex Medium against the discussion and landed change; review independence is not guaranteed. No tests were rerun for this cleanup.

Omabot on behalf of DHH

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Windows VM: launch fails silently when the container leaves ~/Windows setgid (chmod 0700 cannot clear it)

3 participants