Skip to content

Manage /etc/subuid and /etc/subgid#48

Open
r-vdp wants to merge 1 commit into
nikstur:mainfrom
r-vdp:subids
Open

Manage /etc/subuid and /etc/subgid#48
r-vdp wants to merge 1 commit into
nikstur:mainfrom
r-vdp:subids

Conversation

@r-vdp

@r-vdp r-vdp commented Jun 12, 2026

Copy link
Copy Markdown

Subordinate id ranges have the same reuse risk as normal user ids: files
created by a user's unprivileged containers are owned by ids in their
range, so reassigning the range to another user grants access to those
files.

We cannot precompute suitable ranges outside of userborn because we need
to take into account existing ranges, and with only 31 bits of usable id
space, assigning a static range to each user can quickly run out of space
(especially with some tools like incus assigning massive ranges by
default).

So we treat sub{u,g}id in the same way as normal {u,g}ids: read the
existing file, allocate non-overlapping ranges for users that need one,
and never remove entries.

This is one of the missing pieces for making userborn the default
user/group management tool in NixOS, where the perl activation script
currently handles users.users.<name>.subUidRanges / subGidRanges and
autoSubUidGidRange.

Closes #7

CC: @nikstur

Subordinate id ranges have the same reuse risk as normal user ids: files
created by a user's unprivileged containers are owned by ids in their
range, so reassigning the range to another user grants access to those
files.
We cannot precompute suitable ranges outside of userborn because we need
to take into account existing ranges, and with only 31 bits of usable
id space, assigning a static range to each user can quickly run out of
space (especially with some tools like incus assigning massive ranges by
default).

So we treat sub{u,g}id in the same way as normal {u,g}ids: read the
existing file, allocate non-overlapping ranges for users that need one,
and never remove entries.

Closes nikstur#7
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Feature request: subuid and subgid

1 participant