Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #60181

Re: Plans for user namespaces

From Ben Hutchings <ben@decadent.org.uk>
Newsgroups linux.debian.kernel
Subject Re: Plans for user namespaces
Date 2018-02-09 17:40 +0100
Message-ID <vhjSp-5Wf-7@gated-at.bofh.it> (permalink)
References <vgVdn-4CJ-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Thu, 2018-02-08 at 14:18 +0100, Peter Wienemann wrote:
> Dear kernel experts,
> 
> I've got some questions concerning the plans for user namespaces:
> 
> 1. In stretch unprivileged user namespaces are enabled in the
> compile-time configuration of the kernel but disabled in the run-time
> configuration by default. As a consequence one needs to set
> "kernel.unprivileged_userns_clone=1" before one can make use of them.
> Are there any plans to change the default run-time configuration for buster?

No, this default mitigates a lot of security vulnerabilities.

> 2. If the answer to the first question is "no", what is the preferred
> behaviour upon installation of packages requiring the above feature?
> 
>    a) Warn the user and ask him/her to switch them on?
>    b) Silently switch them on?
>    c) Add instructions in README.Debian?
>    d) Something else?

I think (a) and/or (c).

Ben.

-- 
Ben Hutchings
Lowery's Law:
        If it jams, force it. If it breaks, it needed replacing anyway.

Back to linux.debian.kernel | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

Plans for user namespaces Peter Wienemann <wienemann@physik.uni-bonn.de> - 2018-02-08 15:20 +0100
  Re: Plans for user namespaces Ben Hutchings <ben@decadent.org.uk> - 2018-02-09 17:40 +0100

csiph-web