Skip to content

[Nexthop] Make component build containers privileged#916

Open
travisb-nexthop wants to merge 2 commits intofacebook:mainfrom
nexthop-ai:distro_privileged_component-part7b
Open

[Nexthop] Make component build containers privileged#916
travisb-nexthop wants to merge 2 commits intofacebook:mainfrom
nexthop-ai:distro_privileged_component-part7b

Conversation

@travisb-nexthop
Copy link
Contributor

Pre-submission checklist

  • I've ran the linters locally and fixed lint errors related to the files I modified in this PR. You can install the linters by running pip install -r requirements-dev.txt && pre-commit install
  • pre-commit run

Summary

Some kinds of builds require a privileged containers, such as builds
which need to use containers within themselves.

Make the component build containers all privileged.

This requires making /etc/shadow root-readable because CentOS uses
special permission capability overrides to read the file which are not
configured in the host user namespace.

Test Plan

Build the Demo Container other_dependency from
#911 which motivated this need.

raghav-nexthop and others added 2 commits February 7, 2026 00:29
Add abstract build component framework for managing build operations.

- Implement AbstractComponent base class for build components
- Add component lifecycle management (prepare, build, extract)
- Integrate with artifact store, download, and execute modules
- Enable extensible component-based build architecture

Tests utilizing the above infrastructure will be added when component build supports are included.
<!-- Thanks for submitting a pull request! We appreciate you spending
the time to work on these changes. Please provide enough information so
that others can review your pull request. -->

**Pre-submission checklist**
- [X] I've ran the linters locally and fixed lint errors related to the
files I modified in this PR. You can install the linters by running `pip
install -r requirements-dev.txt && pre-commit install`
- [X] `pre-commit run`

<!-- Explain the motivation for making this change and any other context
that you think would help reviewers of your code. What existing problem
does the pull request solve? -->

Some kinds of builds require a privileged containers, such as builds
which need to use containers within themselves.

Make the component build containers all privileged.

This requires making /etc/shadow root-readable because CentOS uses
special permission capability overrides to read the file which are not
configured in the host user namespace.

<!-- Demonstrate the code is solid. Example: The exact commands you ran
and their output, screenshots / videos if the pull request changes the
user interface. How exactly did you verify that your PR solves the issue
you wanted to solve? -->

<!-- If a relevant Github issue exists for this PR, please make sure you
link that issue to this PR -->

Build the Demo Container other_dependency from
facebook#911 which motivated this need.
@meta-cla meta-cla bot added the CLA Signed label Feb 9, 2026
@travisb-nexthop travisb-nexthop marked this pull request as ready for review February 9, 2026 22:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants