Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1106446

Bug#1012547: linux: disable user namespaces per default

From Ben Hutchings <ben@decadent.org.uk>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#1012547: linux: disable user namespaces per default
Date 2022-06-13 18:40 +0200
Message-ID <ExVgB-4zu2-9@gated-at.bofh.it> (permalink)
References (1 earlier) <ExTRv-4yJz-5@gated-at.bofh.it> <EwdUm-3xRS-7@gated-at.bofh.it> <ExUDT-4z0h-7@gated-at.bofh.it> <EwdUm-3xRS-7@gated-at.bofh.it> <ExUDT-4z0h-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Mon, 2022-06-13 at 17:46 +0200, Diederik de Haas wrote:
> On Monday, 13 June 2022 16:56:35 CEST Ben Hutchings wrote:
> > We made the decision that the benefits of sandboxing with user
> > namespaces are likely to outweigh the risks, on most systems.  Nothing
> > you've said convinces me to alter that assessment.
> 
> I don't really/fully understand this topic, but I did look into it and from 
> the Kconfig file I understood that it was (highly?) recommended to also enable 
> CONFIG_MEMCG, while is defined as '=y' in debian/config/config.
> So that seems great.
> 
> What I also found was the following in debian/config/armel/config.marvell:
> # CONFIG_MEMCG is not set
> 
> Salsa commit fac721e3016478d286254eff2658954b15a70190 seems to be the 'cause' 
> for that and commit title is "[armel] Fold config-reduced into config.marvell"
> Lots of changes in that commit, but I didn't see an explicit reason why 
> CONFIG_MEMCG should be disabled (IIUC) on that platform.
> Is that something that needs to be corrected? (Just asking, I have no idea)

Many (most?) of the machines supported by that configuration have a
dedicated kernel partition in flash, so we try to limit the kernel
image size.  That was one of the options that added significantly to
the image size and seemed less likely to be needed on armel.  I don't
know whether it still makes sense to disable it, since we gave up on
fitting into 2 MiB partitions.

Ben.

-- 
Ben Hutchings
It's easier to fight for one's principles than to live up to them.

Back to linux.debian.bugs.dist | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#1012547: linux: disable user namespaces per default Philippe Cerfon <philcerf@gmail.com> - 2022-06-09 02:10 +0200
  Bug#1012547: linux: disable user namespaces per default Ben Hutchings <ben@decadent.org.uk> - 2022-06-13 17:10 +0200
    Bug#1012547: linux: disable user namespaces per default Diederik de Haas <didi.debian@cknow.org> - 2022-06-13 18:00 +0200
      Bug#1012547: linux: disable user namespaces per default Ben Hutchings <ben@decadent.org.uk> - 2022-06-13 18:40 +0200
    Bug#1012547: linux: disable user namespaces per default Philippe Cerfon <philcerf@gmail.com> - 2022-06-16 18:30 +0200
      Bug#1012547: linux: disable user namespaces per default Philippe Cerfon <philcerf@gmail.com> - 2022-07-05 15:30 +0200

csiph-web