{"task": {"agent_timeout": 3000, "task": "codegen__containerd__containerd-5203", "verifier_timeout": 3000, "instruction": "This is a code generation task. You are expected to write working code that solves the described problem.\n<issue>\n      **What is the problem you're trying to solve**\nI'm investigating https://github.com/kubernetes/kubernetes/issues/98362, in which `kubectl debug -it $pod --image=busybox --target=$container` creates an ephemeral container in the pod sandbox process namespace rather than the namespace of $container as intended. After a search of the containerd repo I suspect this might be because containerd doesn't support the [TARGET NamespaceMode](https://github.com/kubernetes/kubernetes/blob/5cfce4e5cb4dc6ff429c088ec25973e2ebae2d86/staging/src/k8s.io/cri-api/pkg/apis/runtime/v1/api.proto#L226)\n\n**Describe the solution you'd like**\nI'd like help confirming whether containerd supports `NamespaceMode_TARGET`, and if not request adding support as described in [Targeting a Specific Container's Namespace](https://github.com/kubernetes/enhancements/tree/master/keps/sig-node/495-pod-pid-namespace#targeting-a-specific-containers-namespace)\n\n**Additional context**\n`TARGET` is only used with [EphemeralContainers](http://features.k8s.io/277), an alpha feature targeting beta in Kubernetes 1.21.\n\n</issue>\nFocus on implementing the required functionality correctly and efficiently. Treat this as a programming challenge.\nYou are not allowed to read git history.\n", "memory": "8192m", "runnable": false, "difficulty": "hard", "language": "", "cpus": "", "instruction_truncated": false, "category": "code-generation", "compose": false, "has_solution": true, "oracle": null, "docker_image": "", "taskset": "devopsgym", "tags": ["code-generation", "devops-bench"]}, "runs": []}