Skip to content

Fix Pyxis host-wide user namespace override cleanup - #1420

Merged
michael-balint merged 1 commit into
masterfrom
dholt/1412-pyxis-sysctl-optout
Oct 6, 2026
Merged

michael-balint merged 1 commit into
masterfrom
dholt/1412-pyxis-sysctl-optout

Conversation

@dholt

@dholt dholt commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Fixes #1412.

What changes

  • Keep the opt-in sysctl setting and scoped AppArmor profile behavior unchanged.
  • On opt-out, remove only the role-owned key and delete its drop-in if empty. Preserve unrelated entries byte-for-byte.
  • Hand control back to the remaining system settings by reapplying only the user namespace key through systemd-sysctl, including on retries after interrupted cleanup. This does not restore an unknown earlier value.
  • Check the runtime value and fail with administrator reconciliation guidance if it remains permissive. Never force a restrictive value over administrator policy.
  • In check mode, predict file cleanup without replaying policy or changing runtime state.

Removal uses lineinfile rather than the sysctl module because the latter normalizes unrelated entries and removes duplicate keys even with reload disabled.

Validation

  • Offline regression: 20 real Ansible invocations passed their success/failure expectations, with procps and systemd operating only on isolated fixture files.
  • Negative control on the original code fails because opt-out leaves the runtime value permissive.
  • Coverage includes opt-in, opt-out, idempotence, interrupted cleanup, administrator policy, absent policy, unrelated entries, node/kernel guards, check mode, missing replay executable, read/replay failures, and systemd symlink/mask/glob handling.
  • Role lint: passed, 323 files processed.
  • Playbook syntax: passed, 12 playbooks.
  • Whitespace checks: passed.

No live-host validation or branch CI result is claimed. Package installation, AppArmor profile loading, and Slurm execution are outside the offline fixture.

Retract only the role-owned global override and replay the target key
through systemd-sysctl on every opt-out run. Preserve unrelated policy,
report unresolved permissive state, and never guess a historical value.
Check mode predicts cleanup without replaying host policy.

Add offline regression coverage using real Ansible and sysctl tools
against namespace-isolated files, including policy precedence and retries.

Signed-off-by: Doug Holt <dholt@nvidia.com>
Co-Authored-By: Paperclip <noreply@paperclip.ing>
@dholt
dholt requested a review from michael-balint October 5, 2026 17:10
@michael-balint
michael-balint merged commit 96cf878 into master Oct 6, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

pyxis: turning pyxis_userns_allow_globally back off does not undo the host-wide sysctl

2 participants