patches and low-level development discussion
 help / color / mirror / code / Atom feed
From: Demi Marie Obenour <demiobenour@gmail.com>
To: Alyssa Ross <hi@alyssa.is>
Cc: Spectrum OS Development <devel@spectrum-os.org>
Subject: Re: [PATCH] host/rootfs: Avoid using bwrap to enter new PID namespace
Date: Mon, 13 Jul 2026 10:17:08 -0400	[thread overview]
Message-ID: <6903a8b2-0932-4445-bf60-8a023e2f43c6@gmail.com> (raw)
In-Reply-To: <87jyqz1cwq.fsf@alyssa.is>


[-- Attachment #1.1: Type: text/plain, Size: 2178 bytes --]

On 7/13/26 05:01, Alyssa Ross wrote:
> Demi Marie Obenour <demiobenour@gmail.com> writes:
> 
>> On 7/10/26 10:39, Alyssa Ross wrote:
>>> Demi Marie Obenour <demiobenour@gmail.com> writes:
>>>
>>>> diff --git a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/vhost-user-gpu/run b/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/vhost-user-gpu/run
>>>> index c3bfafe02ec6d2ee418fe56b033bbc4c7a73b186..f5c0f15184f0e72457f9c0bfa546590b9308eb9c 100755
>>>> --- a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/vhost-user-gpu/run
>>>> +++ b/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/vhost-user-gpu/run
>>>> @@ -17,9 +17,10 @@ s6-applyuidgid -UzG 15 # wayland
>>>>  s6-ipcserverd -1c 1
>>>>  
>>>>  bwrap
>>>> -  --unshare-all
>>>> -  # --unshare-all only implies --unshare-user-try.
>>>> -  # Make this more than a "try".
>>>> +  --unshare-net
>>>> +  --unshare-ipc
>>>> +  --unshare-uts
>>>> +  --unshare-cgroup
>>>>    --unshare-user
>>>>    --bind $WAYLAND_DISPLAY $WAYLAND_DISPLAY
>>>>    --ro-bind /usr /usr
>>>
>>> There's a subtle behaviour change here.  The pid namespace is reused
>>> between runs of crosvm, because if crosvm exits, s6-ipcserverd will stay
>>> running and wait for the next connection, then respawn crosvm.  It's
>>> done this way because crosvm has made the unusual decision to support
>>> being started on a connected socket, rather than a listening socket like
>>> one might expect.  Is that okay?  I'd guess yes, but I want to check
>>> with you!
>>
>> It's less robust than I would like, but there is no reason one cannot
>> have both s6-supervise and bubblewrap create PID namespaces.  That's
>> the approach I would go with.
> 
> What's the point of the intermediate PID namespace?

Ensure that there are no stale Cloud Hypervisor processes left behind.
Specifically, the PTY watcher ought to be moved to the main process
if there is only one PTY, but it’s currently a separate process.
-- 
Sincerely,
Demi Marie Obenour (she/her/hers)

[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

  reply	other threads:[~2026-07-13 14:17 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-09 23:46 [PATCH] host/rootfs: Avoid using bwrap to enter new PID namespace Demi Marie Obenour
2026-07-10 14:39 ` Alyssa Ross
2026-07-10 17:09   ` Demi Marie Obenour
2026-07-13  9:01     ` Alyssa Ross
2026-07-13 14:17       ` Demi Marie Obenour [this message]
2026-07-15 10:15         ` Alyssa Ross
2026-07-15 16:51           ` Demi Marie Obenour

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6903a8b2-0932-4445-bf60-8a023e2f43c6@gmail.com \
    --to=demiobenour@gmail.com \
    --cc=devel@spectrum-os.org \
    --cc=hi@alyssa.is \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this public inbox

	https://spectrum-os.org/git/doc
	https://spectrum-os.org/git/mktuntap
	https://spectrum-os.org/git/spectrum
	https://spectrum-os.org/git/ucspi-vsock

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).