This was generated by AI during triage.
Type: HITL
What to build
Validate the v1.1 rootless Podman adapter on a real Fedora host with enforcing SELinux. Confirm that the host user is mapped coherently to the Box's dev account, Box-tier provisioning works through scoped sudo, Workspace and Managed-home ownership persist, and the documented label=disable policy does not mutate host labels.
Record the Candidate version, source SHA, image digest, Fedora/Podman versions, host UID/GID, SELinux mode, before/after labels, and pass/fail evidence in this issue.
Acceptance criteria
Blocked by
None - can start immediately.
Type: HITL
What to build
Validate the v1.1 rootless Podman adapter on a real Fedora host with enforcing SELinux. Confirm that the host user is mapped coherently to the Box's
devaccount, Box-tier provisioning works through scoped sudo, Workspace and Managed-home ownership persist, and the documentedlabel=disablepolicy does not mutate host labels.Record the Candidate version, source SHA, image digest, Fedora/Podman versions, host UID/GID, SELinux mode, before/after labels, and pass/fail evidence in this issue.
Acceptance criteria
keep-id:uid=1000,gid=1000; the running and exec user isdev, while files created in the Workspace are owned by the invoking host user.--security-opt label=disabletradeoff is confirmed on enforcing SELinux and no private:Zrelabel is applied.Blocked by
None - can start immediately.