From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id E751D15A47; Mon, 15 Dec 2025 12:27:43 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id A9F5915A30; Mon, 15 Dec 2025 12:27:40 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.8 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_MISSING,RCVD_IN_DNSWL_LOW,SPF_HELO_PASS autolearn=unavailable autolearn_force=no version=4.0.1 Received: from fout-b6-smtp.messagingengine.com (fout-b6-smtp.messagingengine.com [202.12.124.149]) by atuin.qyliss.net (Postfix) with ESMTPS id E1C98159BA for ; Mon, 15 Dec 2025 12:27:39 +0000 (UTC) Received: from phl-compute-04.internal (phl-compute-04.internal [10.202.2.44]) by mailfout.stl.internal (Postfix) with ESMTP id 51F5B1D00084; Mon, 15 Dec 2025 07:27:37 -0500 (EST) Received: from phl-mailfrontend-01 ([10.202.2.162]) by phl-compute-04.internal (MEProxy); Mon, 15 Dec 2025 07:27:37 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=alyssa.is; h=cc :cc:content-transfer-encoding:content-type:date:date:from:from :in-reply-to:message-id:mime-version:reply-to:subject:subject:to :to; s=fm3; t=1765801657; x=1765888057; bh=UFj6xPFLwiGYGuTztUga5 SMSFDnUcvLkrgKjDnpvFvI=; b=fLBPA5MvbVdAqwOZna0XZYtxOxtKQc1K+hBPj 3geVRfjNQ+MEriAfATAkfU/3FnoQtdk9+Og5BLH9jHjPVe2JKMOF6Hknv4PY924n U3K1w/5qfpIJArL4nuFTHXYws61bxxLfvNngZY5pufuz5NT+48/toX/56sFhO6it v/MuoqQ0U7k/v/bKjfW0auq3NzKS/iW0QCDE9pEf9KIejf2AXN/EHRAANDkYMzOz a52HCqA2AFnmusg9NLWOy6nuOrFF4UeHH7vhTDxykhfesJg0iHWRbKIyykkoUnqV +le9SHTqA2dulwUFPefK67kFaspWWiSKkggE5nh9pHsjpVOYg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:message-id:mime-version:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm1; t= 1765801657; x=1765888057; bh=UFj6xPFLwiGYGuTztUga5SMSFDnUcvLkrgK jDnpvFvI=; b=O9QB+AI9PYsdEvvXPRISQhIpD5MMCZ7YE0d7Jq3ngDQ+kEXpt7g XQui0hd9mMvgaZfQxoMM2+QZYt4+z4sQn7OrACS/JfCpK5rGb8z3DvOLdqPSPLEm Ax9K1aEqSmpFXLH/SBXKfyoXsPCURsS0C80xA73S4d9fRCJcLzz8GqAa9Z/pBOv+ JzBU/UtbaRl7dIdl7LQ6ub1SQsdNFzNL+44o7c1zNm2nSodAnKowSeQlEWHABjeh 0W3k7lqPGxRO6f6tORF2iUONKfzLW1FTj0fCedc7SvfJt8mZiyGTq2/7xbXGrKXG 0f10LreVW1fQyBTMOvwez6s/RebSrAYzqtQ== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefgedrtddtgdefieekudcutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpuffrtefokffrpgfnqfghnecuuegr ihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmdenucfjug hrpefhvfevufffkffoggfgsedtkeertdertddtnecuhfhrohhmpeetlhihshhsrgcutfho shhsuceohhhisegrlhihshhsrgdrihhsqeenucggtffrrghtthgvrhhnpeehkefgtdevte dtkeduudeguefgudejheeugfelgeettdfhffduhfehudfhudeuhfenucevlhhushhtvghr ufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfhhrohhmpehhihesrghlhihsshgrrdhish dpnhgspghrtghpthhtohepvddpmhhouggvpehsmhhtphhouhhtpdhrtghpthhtohepuggv mhhiohgsvghnohhurhesghhmrghilhdrtghomhdprhgtphhtthhopeguvghvvghlsehsph gvtghtrhhumhdqohhsrdhorhhg X-ME-Proxy: Feedback-ID: i12284293:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 15 Dec 2025 07:27:36 -0500 (EST) Received: by mbp.qyliss.net (Postfix, from userid 1000) id 3100D6D7F5A6; Mon, 15 Dec 2025 13:27:31 +0100 (CET) From: Alyssa Ross To: devel@spectrum-os.org Subject: [PATCH 1/2] host/rootfs: remove /proc/kcore bind mounts Date: Mon, 15 Dec 2025 13:27:06 +0100 Message-ID: <20251215122707.116898-1-hi@alyssa.is> X-Mailer: git-send-email 2.51.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Message-ID-Hash: S3IXFRKMUPO5GBQU23RWDSXGWKYX7Y3R X-Message-ID-Hash: S3IXFRKMUPO5GBQU23RWDSXGWKYX7Y3R X-MailFrom: hi@alyssa.is X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Demi Marie Obenour X-Mailman-Version: 3.3.9 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Neither of these services run as root any more, so they don't have access to /proc/kcore any more regardless. (Also we don't have /proc/kcore on aarch64 so this previously errored there.) Fixes: 62590b8 ("host/rootfs: Sandbox crosvm") Fixes: ec47d36 ("host/rootfs: Sandbox Cloud Hypervisor") Signed-off-by: Alyssa Ross --- .../service/vm-services/template/data/service/vhost-user-gpu/run | 1 - host/rootfs/image/usr/bin/run-vmm | 1 - 2 files changed, 2 deletions(-) diff --git a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/vhost-user-gpu/run b/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/vhost-user-gpu/run index b1f9bac..e063a82 100755 --- a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/vhost-user-gpu/run +++ b/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/vhost-user-gpu/run @@ -40,7 +40,6 @@ bwrap --tmpfs /proc/irq --remount-ro /proc/irq --ro-bind /dev/null /proc/timer_list - --ro-bind /dev/null /proc/kcore --ro-bind /dev/null /proc/kallsyms --ro-bind /dev/null /proc/sysrq-trigger -- diff --git a/host/rootfs/image/usr/bin/run-vmm b/host/rootfs/image/usr/bin/run-vmm index 0640239..e30b14c 100755 --- a/host/rootfs/image/usr/bin/run-vmm +++ b/host/rootfs/image/usr/bin/run-vmm @@ -113,7 +113,6 @@ bwrap --tmpfs /proc/irq --remount-ro /proc/irq --ro-bind /dev/null /proc/timer_list - --ro-bind /dev/null /proc/kcore --ro-bind /dev/null /proc/kallsyms --ro-bind /dev/null /proc/sysrq-trigger -- base-commit: 6ceeb9b236cc50d2bba90068533ca1b7ff229c8b -- 2.51.0