Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #66760

Bug#898446: Please reconsider enabling the user namespaces by default

From Ben Hutchings <ben@decadent.org.uk>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#898446: Please reconsider enabling the user namespaces by default
Date 2020-04-15 04:00 +0200
Message-ID <zVFvj-3gi-1@gated-at.bofh.it> (permalink)
References <vOlh7-2Ek-5@gated-at.bofh.it> <zPZwK-5AZ-9@gated-at.bofh.it> <vOlh7-2Ek-5@gated-at.bofh.it> <zPZwK-5AZ-9@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Mon, 2020-03-30 at 10:56 +0100, Simon McVittie wrote:
> On Fri, 11 May 2018 at 20:44:50 +0200, Laurent Bigonville wrote:
> > Firefox (and probably other applications) are using user namespaces these
> > days to enhance the security.
> > 
> > Debian is disabling these since 2013, the original patch states it's a
> > short term solution, but we are here 5 years later and they are still
> > disabled.
> > 
> > Apparently debian (and ubuntu) and arch are the only distributions
> > disabling the user namespaces.
> 
> A cross-distro status update:
> 
> - Debian still disables user namespaces by default with our
>   /proc/sys/kernel/unprivileged_userns_clone patch.
> 
> - Ubuntu now enables user namespaces by default. I think they still apply
>   the /proc/sys/kernel/unprivileged_userns_clone patch, but with the
>   default flipped?
> 
> - Arch Linux now enables user namespaces in their default kernel. There
>   is a non-default kernel, "linux-hardened", which applies the same patch
>   as Debian.
> 
> - Apparently RHEL 7 also disables user namespaces, although instead of
>   patching in a new sysctl, they set /proc/sys/user/max_user_namespaces
>   to 0 (which is an upstream thing since Linux 4.9).

And CentOS 8 appears to enable user namespaces by default.  So at this
point I think we probably need to follow suit, if only because users
and developers will expect it to be enabled.

> On Sun, 13 May 2018 at 22:57:56 +0200, Moritz Mühlenhoff wrote:
> > Ben Hutchings wrote:
> > > And this still mitigates a significant fraction of the security issues
> > > found in the kernel.
> > 
> > A quite significant fraction; on average this neutralises a root privilege
> > escalation every month or so. This is really not something that we should
> > re-enable any time soon.
> 
> Is this still the case, or has the status of user namespaces settled down?

I certinaly have the impression that things have settled down.  I'd
need to spend some time reviewing recent security issues, to be sure of
that.

> bubblewrap works around the restriction by being setuid root (and
> imposing restrictions in user-space that are intended to be more
> restrictive than those imposed by upstream kernels), but this makes
> bubblewrap bugs into potential root privilege escalations, so I would love
> to see bubblewrap no longer need to be setuid (like in Ubuntu).
[...]
> In
> Firefox, if I understand correctly, the fallback path is to not sandbox
> in this way at all; in Chrome/Chromium, there is a setuid fallback
> (which is enabled by the Debian chromium package), but it does not
> receive new upstream development, and it seems to be ambiguous whether
> its use is discouraged.
[...]

I think you've made a good case that user namespaces are likely to be a
net positive for security on Debian desktop systems.

This might not be true yet for servers that aren't container hosts.

Ben.

-- 
Ben Hutchings
It is a miracle that curiosity survives formal education.
                                                      - Albert Einstein


Back to linux.debian.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#898446: Please reconsider enabling the user namespaces by default Laurent Bigonville <bigon@debian.org> - 2018-05-11 20:50 +0200
  Processed: Re: Bug#898446: Please reconsider enabling the user  namespaces by default "Debian Bug Tracking System" <owner@bugs.debian.org> - 2018-05-13 01:40 +0200
  Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2018-05-13 01:40 +0200
    Bug#898446: Please reconsider enabling the user namespaces by default Frederik Himpe <frederik@frehi.be> - 2018-05-13 19:40 +0200
      Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2018-05-14 04:50 +0200
    Bug#898446: Please reconsider enabling the user namespaces by default Moritz Mühlenhoff <jmm@inutil.org> - 2018-05-13 23:10 +0200
      Bug#898446: Please reconsider enabling the user namespaces by default Simon McVittie <smcv@debian.org> - 2020-03-30 12:10 +0200
        Bug#898446: Please reconsider enabling the user namespaces by default Moritz Mühlenhoff <jmm@inutil.org> - 2020-03-30 14:30 +0200
        Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-04-15 04:00 +0200
          Bug#898446: Please reconsider enabling the user namespaces by default Simon McVittie <smcv@debian.org> - 2020-04-15 09:40 +0200
            Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-04-16 04:20 +0200
              Bug#898446: Please reconsider enabling the user namespaces by default Simon McVittie <smcv@debian.org> - 2020-10-20 18:30 +0200
                Bug#898446: Please reconsider enabling the user namespaces by default Salvatore Bonaccorso <carnil@debian.org> - 2020-10-22 23:00 +0200
                Bug#898446: Please reconsider enabling the user namespaces by default Moritz Muehlenhoff <jmm@inutil.org> - 2020-10-22 23:10 +0200
                Bug#898446: Please reconsider enabling the user namespaces by default Bastian Blank <waldi@debian.org> - 2020-10-23 09:00 +0200
                Bug#898446: Please reconsider enabling the user namespaces by default Antoine Beaupré <anarcat@debian.org> - 2020-11-17 17:30 +0100
                Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-11-17 19:00 +0100
                Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-12-13 17:40 +0100
                Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-10-24 03:30 +0200
    Bug#898446: Please reconsider enabling the user namespaces by default Laurent Bigonville <bigon@debian.org> - 2018-05-14 07:30 +0200
  Processed: Re: Bug#898446: Please reconsider enabling the user  namespaces by default "Debian Bug Tracking System" <owner@bugs.debian.org> - 2018-05-14 04:50 +0200
  Bug#898446: (no subject) Nikolas Nyby <nikolas@gnu.org> - 2019-03-06 15:50 +0100
  Bug#898446: Please reconsider enabling the user namespaces by default Jordan Glover <Golden_Miller83@protonmail.ch> - 2020-10-23 17:30 +0200
  Bug#898446: marked as done (Please reconsider enabling the user  namespaces by default) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2020-12-17 13:10 +0100

csiph-web