Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1004772
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#898446: Please reconsider enabling the user namespaces by default |
| Date | 2020-04-16 04:20 +0200 |
| Message-ID | <zW2id-S5-3@gated-at.bofh.it> (permalink) |
| References | (1 earlier) <zPZwK-5AZ-9@gated-at.bofh.it> <zVFvj-3gi-1@gated-at.bofh.it> <zVKOl-6Jw-1@gated-at.bofh.it> <vOlh7-2Ek-5@gated-at.bofh.it> <zVKOl-6Jw-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
[Multipart message — attachments visible in raw view] - view raw
On Wed, 2020-04-15 at 08:32 +0100, Simon McVittie wrote: > On Wed, 15 Apr 2020 at 02:52:11 +0100, Ben Hutchings wrote: > > I think you've made a good case that user namespaces are likely to be a > > net positive for security on Debian desktop systems. > > > > This might not be true yet for servers that aren't container hosts. > > Perhaps Debian's kernel should continue to disable unprivileged creation > of user namespaces for now, but we should have a package that installs > a /etc/sysctl.d/*.conf fragment that will enable them, and packages > that benefit from them (bubblewrap, web browsers, sbuild) should have > a Depends or Recommends on that package instead of shipping a setuid-root > namespace-creation helper? [...] But if users install, say, Chrome or Docker from upstream, it won't know how to do this Debian magic. Also, I don't think we should keep patching in kernel.unprivileged_userns_clone forever, so the documented way to disable user namespaces should be setting user.max_user_namespaces to 0. But then there's no good way to have a drop-in file that changes back to the upstream default, because that's dependent on system memory size. So I think we should do something like this: * Document user.max_user_namespaces in procps's shipped /etc/sysctl.conf * Set kernel.unprivileged_userns_clone to 1 by default, and deprecate it (log a warning if it's changed) * Document the change in bullseye release notes Ben. -- Ben Hutchings Always try to do things in chronological order; it's less confusing that way.
Back to linux.debian.bugs.dist | Previous | Next — Previous in thread | Find similar | Unroll thread
Bug#898446: Please reconsider enabling the user namespaces by default Simon McVittie <smcv@debian.org> - 2020-03-30 12:10 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Moritz Mühlenhoff <jmm@inutil.org> - 2020-03-30 14:30 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-04-15 04:00 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Simon McVittie <smcv@debian.org> - 2020-04-15 09:40 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-04-16 04:20 +0200
csiph-web