mesos-reviews mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Gilbert Song <>
Subject Re: Review Request 61120: Fixed the sandbox_path volume source path ownership.
Date Wed, 26 Jul 2017 06:41:39 GMT

This is an automatically generated e-mail. To reply, visit:

(Updated July 25, 2017, 11:41 p.m.)

Review request for mesos, Greg Mann, Ilya Pronin, Jie Yu, James Peach, Vinod Kone, and Jiang
Yan Xu.

Bugs: MESOS-7830

Repository: mesos


This bugfix addresses the issue from MESOS-7830. Basically, the
sandbox path volume ownership was not set correctly. This issue
can be exposed if a framework user is non-root while the agent
process runs as root. Then, the non-root user does not have
permissions to write to this volume.

The correct solution should be giving permissions to corresponding
users by leveraging supplementary groups. But we can still
introduce a workaround in this patch by changing the ownership
of the sandbox path volume to its sandbox's ownership.

Diffs (updated)

  src/slave/containerizer/mesos/isolators/volume/sandbox_path.cpp 6f7304d4aa40eb1b4815ffc1fec61f7e98291cba




make check


Gilbert Song

  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message