Skip to content

Fix GPU and pi sandbox access under OpenShell v0.1.2 - #227

Merged
wseaton merged 3 commits into
mainfrom
gpu-landlock-paths
Oct 8, 2026
Merged

wseaton merged 3 commits into
mainfrom
gpu-landlock-paths

Conversation

@wseaton

@wseaton wseaton commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

OpenShell v0.1.2's kubernetes driver never sets the openshell.gpu claim, so landlock denies /dev/nvidia* in GPU sandboxes. Crucible now sends those paths in the create-time filesystem policy when a sandbox requests GPUs. Pi's egress policy also allows /usr/bin/node-*, since v0.1.2 matches the canonical binary and UBI's /usr/bin/node is a symlink to node-22.

Changelog: Fixed: GPU sandboxes can open their NVIDIA devices and pi turns reach the model again under OpenShell v0.1.2

OpenShell v0.1.2 adds /dev/nvidia* to a sandbox's landlock rules only when
the boundary carries the openshell.gpu claim, which the kubernetes driver
never sets. Send the same paths in the create-time filesystem policy.
On UBI 10 /usr/bin/node is a symlink to node-22, and v0.1.2 matches egress
by the canonical executable without resolving symlinks on kubernetes.
@wseaton
wseaton enabled auto-merge October 7, 2026 17:17
@wseaton
wseaton merged commit 056d66d into main Oct 8, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant