From: Demi Marie Obenour <demiobenour@gmail.com>
To: Alyssa Ross <hi@alyssa.is>
Cc: Spectrum OS Development <devel@spectrum-os.org>
Subject: Re: [PATCH] host/rootfs: Avoid using bwrap to enter new PID namespace
Date: Mon, 13 Jul 2026 10:17:08 -0400 [thread overview]
Message-ID: <6903a8b2-0932-4445-bf60-8a023e2f43c6@gmail.com> (raw)
In-Reply-To: <87jyqz1cwq.fsf@alyssa.is>
[-- Attachment #1.1: Type: text/plain, Size: 2178 bytes --]
On 7/13/26 05:01, Alyssa Ross wrote:
> Demi Marie Obenour <demiobenour@gmail.com> writes:
>
>> On 7/10/26 10:39, Alyssa Ross wrote:
>>> Demi Marie Obenour <demiobenour@gmail.com> writes:
>>>
>>>> diff --git a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/vhost-user-gpu/run b/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/vhost-user-gpu/run
>>>> index c3bfafe02ec6d2ee418fe56b033bbc4c7a73b186..f5c0f15184f0e72457f9c0bfa546590b9308eb9c 100755
>>>> --- a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/vhost-user-gpu/run
>>>> +++ b/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/template/data/service/vhost-user-gpu/run
>>>> @@ -17,9 +17,10 @@ s6-applyuidgid -UzG 15 # wayland
>>>> s6-ipcserverd -1c 1
>>>>
>>>> bwrap
>>>> - --unshare-all
>>>> - # --unshare-all only implies --unshare-user-try.
>>>> - # Make this more than a "try".
>>>> + --unshare-net
>>>> + --unshare-ipc
>>>> + --unshare-uts
>>>> + --unshare-cgroup
>>>> --unshare-user
>>>> --bind $WAYLAND_DISPLAY $WAYLAND_DISPLAY
>>>> --ro-bind /usr /usr
>>>
>>> There's a subtle behaviour change here. The pid namespace is reused
>>> between runs of crosvm, because if crosvm exits, s6-ipcserverd will stay
>>> running and wait for the next connection, then respawn crosvm. It's
>>> done this way because crosvm has made the unusual decision to support
>>> being started on a connected socket, rather than a listening socket like
>>> one might expect. Is that okay? I'd guess yes, but I want to check
>>> with you!
>>
>> It's less robust than I would like, but there is no reason one cannot
>> have both s6-supervise and bubblewrap create PID namespaces. That's
>> the approach I would go with.
>
> What's the point of the intermediate PID namespace?
Ensure that there are no stale Cloud Hypervisor processes left behind.
Specifically, the PTY watcher ought to be moved to the main process
if there is only one PTY, but it’s currently a separate process.
--
Sincerely,
Demi Marie Obenour (she/her/hers)
[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 833 bytes --]
next prev parent reply other threads:[~2026-07-13 14:17 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-09 23:46 [PATCH] host/rootfs: Avoid using bwrap to enter new PID namespace Demi Marie Obenour
2026-07-10 14:39 ` Alyssa Ross
2026-07-10 17:09 ` Demi Marie Obenour
2026-07-13 9:01 ` Alyssa Ross
2026-07-13 14:17 ` Demi Marie Obenour [this message]
2026-07-15 10:15 ` Alyssa Ross
2026-07-15 16:51 ` Demi Marie Obenour
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6903a8b2-0932-4445-bf60-8a023e2f43c6@gmail.com \
--to=demiobenour@gmail.com \
--cc=devel@spectrum-os.org \
--cc=hi@alyssa.is \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
Code repositories for project(s) associated with this public inbox
https://spectrum-os.org/git/doc
https://spectrum-os.org/git/mktuntap
https://spectrum-os.org/git/spectrum
https://spectrum-os.org/git/ucspi-vsock
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).