User Story
As an operator setting a sandbox's user and group, I want OpenShell to report the identity that actually runs my code and reject incompatible requests, so that I can reason about workspace ownership and permissions.
Problem Statement
The local v0.1.2 VM accepted a process policy requesting user/group 10000:10000 and reported that policy as effective, while canonical and exec processes ran as the driver's resolved 1000:1000. VM identity is deliberately driver-owned, but the accepted policy did not make the conflict visible.
Impact / Why This Matters
Users can investigate file-access and ownership failures using an effective-policy value that does not match execution. They may believe a user selection was applied when the runtime preserved its different driver identity.
Acceptance Criteria
Reproduction Steps
- Use the v0.1.2 VM driver with an image/configuration that resolves its sandbox account to 1000:1000.
- In the
process section of an otherwise valid policy, set run_as_user and run_as_group to "10000".
- Inspect the stored policy and its reported effective status.
- Run
id -u and id -g through sandbox exec and compare the result with the policy selectors. The recorded result was 1000:1000.
Environment
- OpenShell: v0.1.2; current-source comparison at
b8ffe5244cb244a1d74a4a03d69afe3da07e5f08.
- Platform: Apple Silicon macOS 26.7; MicroVM backend.
- Installation: released CLI, gateway and VM driver
Logs
User Story
As an operator setting a sandbox's user and group, I want OpenShell to report the identity that actually runs my code and reject incompatible requests, so that I can reason about workspace ownership and permissions.
Problem Statement
The local v0.1.2 VM accepted a process policy requesting user/group 10000:10000 and reported that policy as effective, while canonical and exec processes ran as the driver's resolved 1000:1000. VM identity is deliberately driver-owned, but the accepted policy did not make the conflict visible.
Impact / Why This Matters
Users can investigate file-access and ownership failures using an effective-policy value that does not match execution. They may believe a user selection was applied when the runtime preserved its different driver identity.
Acceptance Criteria
Reproduction Steps
processsection of an otherwise valid policy, setrun_as_userandrun_as_groupto"10000".id -uandid -gthrough sandbox exec and compare the result with the policy selectors. The recorded result was 1000:1000.Environment
b8ffe5244cb244a1d74a4a03d69afe3da07e5f08.Logs