fix(bundle): Run brig-ctl's ctr inside the rootless namespace - #8
Merged
Merged
Conversation
This was referenced Sep 25, 2026
`brig-ctl ctr` failed on a rootless install: $ brig-ctl ctr tasks ls ctr: cannot access socket unix:///run/containerd/containerd.sock: stat unix:///run/containerd/containerd.sock: no such file or directory Two things were wrong. ctr stats --address as a file path before it dials, and brig-env.sh writes the address with a unix:// scheme, which nerdctl wants. Since brig-ctl takes the address from brig-env.sh, ctr failed that stat on every install, root or rootless, and `brig-ctl status` listed no plugins. And on a rootless install the socket exists only inside the rootlesskit namespace. nerdctl enters that namespace by itself; ctr does not. brig-ctl now strips the scheme for ctr. For a caller who is not root on a rootless bundle, it runs ctr through `containerd-rootless-setuptool.sh nsenter`, which the bundle already ships with nerdctl. With no rootless containerd running, it says how to start one. `ctr` and `status` share that path. The nerdctl and run subcommands need no change. tests/brig-ctl.sh generates brig-ctl with the build's own function, for a bundle with and without the rootless path, and runs it against a stub ctr and setup tool. It checks that a rootless caller's ctr goes through the namespace on a bare socket path, that status does the same, that a missing daemon gets a hint, and that a plain bundle runs ctr directly on a bare path. Against the previous build-bundle.sh it fails the first check, with ctr called directly on unix:///run/containerd/containerd.sock. Checked live on an Ubuntu 24.04 host with a rootless user install. `ctr version` now reports the server, `ctr tasks ls` lists a running sandbox's task, and `status` lists the snapshotter plugins. The previous brig-ctl, on the same install, fails with the error above and lists no plugins. Signed-off-by: Anastassios Nanos <ananos@nofire.ai>
ananos
force-pushed
the
fix/brig-ctl-ctr-rootless
branch
from
September 25, 2026 22:45
8940184 to
7084c94
Compare
ananos
marked this pull request as ready for review
September 25, 2026 22:48
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
brig-ctl ctrfailed on a rootless install:Two things were wrong, and #4 surfaced both. ctr stats
--addressas a filepath before it dials, and
brig-env.shwrites the address with aunix://scheme, which nerdctl wants. Since #4,
brig-ctltakes the address frombrig-env.sh, so ctr failed that stat on every install, root or rootless, andbrig-ctl statuslisted no plugins. On top of that, a rootless install's socketexists only inside the rootlesskit namespace. nerdctl enters that namespace by
itself; ctr does not.
Changes
brig-ctlstrips theunix://scheme for ctr.brig-env.shmakes), ctr runs through
containerd-rootless-setuptool.sh nsenter, which thebundle already ships with nerdctl. It handles the
--detach-netnscase andthe working directory the way nerdctl's own tooling does.
failing inside nsenter on a missing
child_pid.ctrandstatusshare that path.nerdctlandrunneed no change.tests/brig-ctl.sh, run by theScript testsCI step (the same step as fix(rootless): Give each user a device grant of their own #6 andfix(install): Name the bundle in the install summary #9, word for word).
Testing
tests/brig-ctl.shgeneratesbrig-ctlwith the build's ownwrite_brig_ctl,for a bundle with and without the rootless path, and runs it against a stub
ctrand setup tool that log their argv:The same test against
main'sbuild-bundle.sh:sh -n(dash) andshellcheck -s shpass overinstall.sh,build-bundle.sh, the three generated scripts and the test.Live, on an Ubuntu 24.04 host with a rootless user install
brig-ctlgenerated from this branch, in the user's installed tree:The v0.1.0-rc8
brig-ctlon the same install (main's generator reproduces itbyte for byte), retargeted to that prefix:
and its
statusended after the unit's journal with no plugin table.🤖 Generated with Claude Code