Skip to content

Read private cohort backup files with their owning UID - #18

Merged
kaanyagci merged 1 commit into
mainfrom
fix/cohort-backup-file-access
Sep 6, 2026
Merged

kaanyagci merged 1 commit into
mainfrom
fix/cohort-backup-file-access

Conversation

@kaanyagci

Copy link
Copy Markdown
Member

The real cohort capture failed when a capability-free container tried to read a mode-0600 dump owned by the capture account. Run the dump-validation and restore clients with the file-owning caller’s UID/GID, retaining private file permissions, read-only mounts and dropped capabilities.

Validation: ShellCheck, cohort hardening/cleanup/forced-command contracts and cohort evidence tests passed.

@kaanyagci
kaanyagci merged commit af1aac0 into main Sep 6, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant