chroot: fix many issues with chroot #7057
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This merge request fixes several issues in the behavior of
chroot
, mostly around settinggroup IDs. It ensures that supplemental groups provided by
--groups
are properly handled with respect to the groups implied by--userspec
. It ensures that we fall back to numeric parsing when attempting to lookup user and group IDs from their names.It changes the type of
Options.groups
to beOption<Vec<String>>
so thatthe absence of the
--groups
option is meaningfully distinguished froman empty list of groups. This is important because
chroot --groups=''
is used specifically to disable supplementary group lookup.
It improves the parsing of the
--groups
parameter tochroot
so that ithandles more error cases and better matches the behavior of GNU
chroot
. For example, multiple adjacent commas are allowed:but spaces between commas are not allowed:
This fixes all but one of the test cases in the GNU test file
tests/chroot/chroot-credentials.sh
.