Discovered by the first full Walk v0.2.3 -> Leash native-v0.3.5 -> BME beta.63 -> Codex ACP dogfood run for Leash #78. Walk issue #67 records the caller-side failure: host worktree UID/GID 1000 is bind-mounted unchanged into walk33-bmad-codex:v0.2.3, whose configured user is agent UID/GID 1001. BME cannot create state and Codex cannot edit source. Docker 29.1.3 exposes no per-bind idmap option; unprivileged idmapped-mount attachment is denied; numeric USER override breaks the named identity and HOME. Leash already owns the privileged container bootstrap boundary and is the smallest safe layer for the missing capability. Acceptance: expose a bounded per-volume identity mapping contract from host owner UID/GID to the unchanged target Config.User UID/GID; create the idmapped view during privileged bootstrap before non-root workload exec; preserve the configured non-root identity, HOME, Leash policy, and credential staging; never chown the host tree or run the workload as root; validate mapping/path conflicts and fail before agent execution when unsupported; clean every temporary mount/helper on success, failure, cancellation, and signal; add real Linux Docker coverage proving a UID-1001 target can create/edit files that remain UID-1000 on the host and can still use its writable image HOME. Walk #67 will consume this capability in a stacked PR.
Discovered by the first full Walk v0.2.3 -> Leash native-v0.3.5 -> BME beta.63 -> Codex ACP dogfood run for Leash #78. Walk issue #67 records the caller-side failure: host worktree UID/GID 1000 is bind-mounted unchanged into walk33-bmad-codex:v0.2.3, whose configured user is agent UID/GID 1001. BME cannot create state and Codex cannot edit source. Docker 29.1.3 exposes no per-bind idmap option; unprivileged idmapped-mount attachment is denied; numeric USER override breaks the named identity and HOME. Leash already owns the privileged container bootstrap boundary and is the smallest safe layer for the missing capability. Acceptance: expose a bounded per-volume identity mapping contract from host owner UID/GID to the unchanged target Config.User UID/GID; create the idmapped view during privileged bootstrap before non-root workload exec; preserve the configured non-root identity, HOME, Leash policy, and credential staging; never chown the host tree or run the workload as root; validate mapping/path conflicts and fail before agent execution when unsupported; clean every temporary mount/helper on success, failure, cancellation, and signal; add real Linux Docker coverage proving a UID-1001 target can create/edit files that remain UID-1000 on the host and can still use its writable image HOME. Walk #67 will consume this capability in a stacked PR.