Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #60171 > unrolled thread

Plans for user namespaces

Started byPeter Wienemann <wienemann@physik.uni-bonn.de>
First post2018-02-08 15:20 +0100
Last post2018-02-09 17:40 +0100
Articles 2 — 2 participants

Back to article view | Back to linux.debian.kernel


Contents

  Plans for user namespaces Peter Wienemann <wienemann@physik.uni-bonn.de> - 2018-02-08 15:20 +0100
    Re: Plans for user namespaces Ben Hutchings <ben@decadent.org.uk> - 2018-02-09 17:40 +0100

#60171 — Plans for user namespaces

FromPeter Wienemann <wienemann@physik.uni-bonn.de>
Date2018-02-08 15:20 +0100
SubjectPlans for user namespaces
Message-ID<vgVdn-4CJ-1@gated-at.bofh.it>
Dear kernel experts,

I've got some questions concerning the plans for user namespaces:

1. In stretch unprivileged user namespaces are enabled in the
compile-time configuration of the kernel but disabled in the run-time
configuration by default. As a consequence one needs to set
"kernel.unprivileged_userns_clone=1" before one can make use of them.
Are there any plans to change the default run-time configuration for buster?

2. If the answer to the first question is "no", what is the preferred
behaviour upon installation of packages requiring the above feature?

   a) Warn the user and ask him/her to switch them on?
   b) Silently switch them on?
   c) Add instructions in README.Debian?
   d) Something else?

Cheers, Peter

[toc] | [next] | [standalone]


#60181

FromBen Hutchings <ben@decadent.org.uk>
Date2018-02-09 17:40 +0100
Message-ID<vhjSp-5Wf-7@gated-at.bofh.it>
In reply to#60171

[Multipart message — attachments visible in raw view] — view raw

On Thu, 2018-02-08 at 14:18 +0100, Peter Wienemann wrote:
> Dear kernel experts,
> 
> I've got some questions concerning the plans for user namespaces:
> 
> 1. In stretch unprivileged user namespaces are enabled in the
> compile-time configuration of the kernel but disabled in the run-time
> configuration by default. As a consequence one needs to set
> "kernel.unprivileged_userns_clone=1" before one can make use of them.
> Are there any plans to change the default run-time configuration for buster?

No, this default mitigates a lot of security vulnerabilities.

> 2. If the answer to the first question is "no", what is the preferred
> behaviour upon installation of packages requiring the above feature?
> 
>    a) Warn the user and ask him/her to switch them on?
>    b) Silently switch them on?
>    c) Add instructions in README.Debian?
>    d) Something else?

I think (a) and/or (c).

Ben.

-- 
Ben Hutchings
Lowery's Law:
        If it jams, force it. If it breaks, it needed replacing anyway.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web