Steam nested namespaces can expose credential-path ancestors as unmapped UID 65534
During the Valve Soldier investigation for #1109, a separate credential-path failure appeared in a nested user namespace. A host-root bind-mounted ancestor of /var/home appeared inside the runtime as unmapped UID 65534. The server rejected that ancestor because its owner was neither root nor the current user.
This is distinct from the user-owned /home link and missing process tools reported in #1059. PR #1109 fixes those two causes. Godot AI 4.2.2 publication is pending when this follow-up is prepared.
Evidence and limits
The PR author's reproduction used Valve's actual SteamLinuxRuntime_soldier launcher, Soldier 2.0.20260805.254767, and pressure-vessel 0.20260805.0 under x86-64 Linux in Docker. With Godot 4.7, process/listener checks worked without PATH tools, and lifecycle proof passed with a protected fixture directory. The author also reports that a protected shared capability record could be published inside the runtime and read and removed by an outside client.
The Bazzite-style /home -> var/home fixture exposed the unmapped-ancestor failure separately. Those protected-fixture successes do not establish that the default home path works in this nested configuration. The original #1059 reporter's setup is not established to have this UID 65534 failure.
The reproduction and its limits are recorded in verification.md at the reviewed source. Independent PR review verified protected same-user links on Linux and the ordinary missing-tools behavior. It did not independently repeat the nested Soldier setup.
Bounded follow-up
- Reproduce with the actual Soldier launcher and nested user namespace. Retain the runtime versions, UID mapping, and owner/mode of each selected credential-path ancestor as seen inside the editor environment. Do not collect capability values.
- Compare the default home path with a protected fixture path. Record the exact ancestor and ownership error that prevent startup.
- Determine whether a credential location can meet the existing ownership and permission checks while remaining accessible to both the editor backend and the outside client bridge. Prove shared access with an actual authenticated connection, rather than matching environment-variable strings.
- Add a regression for the reproduced outcome. A supported solution must retain rejection of unverifiable owners and writable ancestors. If the namespace cannot supply a verifiably private shared location, document that concrete boundary and surface an actionable diagnosis.
Do not accept UID 65534 as trusted, change system directory permissions, or weaken process ownership checks. Do not automatically switch to XDG_RUNTIME_DIR. The prior investigation found that Valve does not reliably expose that directory to host clients; its presence in the environment is not evidence of shared access.
Steam nested namespaces can expose credential-path ancestors as unmapped UID 65534
During the Valve Soldier investigation for #1109, a separate credential-path failure appeared in a nested user namespace. A host-root bind-mounted ancestor of
/var/homeappeared inside the runtime as unmapped UID 65534. The server rejected that ancestor because its owner was neither root nor the current user.This is distinct from the user-owned
/homelink and missing process tools reported in #1059. PR #1109 fixes those two causes. Godot AI 4.2.2 publication is pending when this follow-up is prepared.Evidence and limits
The PR author's reproduction used Valve's actual
SteamLinuxRuntime_soldierlauncher, Soldier2.0.20260805.254767, and pressure-vessel0.20260805.0under x86-64 Linux in Docker. With Godot 4.7, process/listener checks worked without PATH tools, and lifecycle proof passed with a protected fixture directory. The author also reports that a protected shared capability record could be published inside the runtime and read and removed by an outside client.The Bazzite-style
/home -> var/homefixture exposed the unmapped-ancestor failure separately. Those protected-fixture successes do not establish that the default home path works in this nested configuration. The original #1059 reporter's setup is not established to have this UID 65534 failure.The reproduction and its limits are recorded in verification.md at the reviewed source. Independent PR review verified protected same-user links on Linux and the ordinary missing-tools behavior. It did not independently repeat the nested Soldier setup.
Bounded follow-up
Do not accept UID 65534 as trusted, change system directory permissions, or weaken process ownership checks. Do not automatically switch to
XDG_RUNTIME_DIR. The prior investigation found that Valve does not reliably expose that directory to host clients; its presence in the environment is not evidence of shared access.