Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #60171 > unrolled thread
| Started by | Peter Wienemann <wienemann@physik.uni-bonn.de> |
|---|---|
| First post | 2018-02-08 15:20 +0100 |
| Last post | 2018-02-09 17:40 +0100 |
| Articles | 2 — 2 participants |
Back to article view | Back to linux.debian.kernel
Plans for user namespaces Peter Wienemann <wienemann@physik.uni-bonn.de> - 2018-02-08 15:20 +0100
Re: Plans for user namespaces Ben Hutchings <ben@decadent.org.uk> - 2018-02-09 17:40 +0100
| From | Peter Wienemann <wienemann@physik.uni-bonn.de> |
|---|---|
| Date | 2018-02-08 15:20 +0100 |
| Subject | Plans for user namespaces |
| Message-ID | <vgVdn-4CJ-1@gated-at.bofh.it> |
Dear kernel experts, I've got some questions concerning the plans for user namespaces: 1. In stretch unprivileged user namespaces are enabled in the compile-time configuration of the kernel but disabled in the run-time configuration by default. As a consequence one needs to set "kernel.unprivileged_userns_clone=1" before one can make use of them. Are there any plans to change the default run-time configuration for buster? 2. If the answer to the first question is "no", what is the preferred behaviour upon installation of packages requiring the above feature? a) Warn the user and ask him/her to switch them on? b) Silently switch them on? c) Add instructions in README.Debian? d) Something else? Cheers, Peter
[toc] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2018-02-09 17:40 +0100 |
| Message-ID | <vhjSp-5Wf-7@gated-at.bofh.it> |
| In reply to | #60171 |
[Multipart message — attachments visible in raw view] — view raw
On Thu, 2018-02-08 at 14:18 +0100, Peter Wienemann wrote:
> Dear kernel experts,
>
> I've got some questions concerning the plans for user namespaces:
>
> 1. In stretch unprivileged user namespaces are enabled in the
> compile-time configuration of the kernel but disabled in the run-time
> configuration by default. As a consequence one needs to set
> "kernel.unprivileged_userns_clone=1" before one can make use of them.
> Are there any plans to change the default run-time configuration for buster?
No, this default mitigates a lot of security vulnerabilities.
> 2. If the answer to the first question is "no", what is the preferred
> behaviour upon installation of packages requiring the above feature?
>
> a) Warn the user and ask him/her to switch them on?
> b) Silently switch them on?
> c) Add instructions in README.Debian?
> d) Something else?
I think (a) and/or (c).
Ben.
--
Ben Hutchings
Lowery's Law:
If it jams, force it. If it breaks, it needed replacing anyway.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.kernel
csiph-web