From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id 4C3322C0A; Mon, 13 Jul 2026 11:21:56 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id AF74F2BAE; Mon, 13 Jul 2026 11:21:53 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.8 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_MISSING,RCVD_IN_DNSWL_LOW,SPF_HELO_PASS autolearn=unavailable autolearn_force=no version=4.0.1 Received: from fhigh-a5-smtp.messagingengine.com (fhigh-a5-smtp.messagingengine.com [103.168.172.156]) by atuin.qyliss.net (Postfix) with ESMTPS id 85D072BAD for ; Mon, 13 Jul 2026 11:21:52 +0000 (UTC) Received: from phl-compute-06.internal (phl-compute-06.internal [10.202.2.46]) by mailfhigh.phl.internal (Postfix) with ESMTP id AAF55140012F; Mon, 13 Jul 2026 07:21:51 -0400 (EDT) Received: from phl-frontend-03 ([10.202.2.162]) by phl-compute-06.internal (MEProxy); Mon, 13 Jul 2026 07:21:51 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=alyssa.is; h=cc :cc:content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:subject :subject:to:to; s=fm1; t=1783941711; x=1784028111; bh=7MEkjfd4Gf X7yKF9PHz+Wp1zP0xAvVUhLlb9JSe0rd8=; b=sS/ntrfHlCrOYTMlFV2pC/ARQZ 1ygg4t5kZkXv9CpZ+mLSc59mSk8uxnI5j9CTOkxdEumWWEPpYJM/juL5p5MsWevh qdERw9K3wQE1TKPr2BfNK7tf8eS2UgnhyNaOSRI4AKnrJlnHx9U7d1iaIFgvlWQ4 wHUq876CljbV5x4fTx+hMRP2cMGAi24eWeK82tSfBVW6aTx8jrlQD42Xve+DYlAQ bsghFlhPhZG+CePvYJoY6/PVCcNm3H18kHyG5JTK1LlZbVQ6UDcmrozG+VhRorZV 4iyu/zVU3lkNHnjnW3FkfHY3sSiluSFMWaOIinAhvO4lp2VAAZ1sUm7ihj3A== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t= 1783941711; x=1784028111; bh=7MEkjfd4GfX7yKF9PHz+Wp1zP0xAvVUhLlb 9JSe0rd8=; b=Hkguyl8OkSskYp2MQg+ItKwRKJxcv2O8Vht8YGw8WkhFrCmSYek NXP2jpl2nJf93Bz1czZFeWYnHAlKhKzb9yxtvdfmOt/yG/HS7i+axAmDl6TmfGUA aPZy7LGifXd5eleyQXdZqZXZBUzgQo8wNnfQ9KGbLHsShxS60yXtPNPaV3MfFuTP O5kTsZpbZPgxKKJypubBEqIOblhSQ5+xAC0p6HgGsLC6oAOx9IvTN1V6OOCJOD4A W92j85pqjqVg2kjIkNdsuPVYAHdoS7e3dk5XGzxa6yyZYC8lmzLjnv5iR0bPmB16 ZDNg6FdD8Nw+2VveD5HfV5Xh2skvsxyDhkA== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTG2LC+Xr6CQN+wNhJhW/Xy+y3GHKVXEHXrD/8b6ApAj5Jc3F1+nEshzhL510ahmjl nOEpNwBcuJ2YUoLZQhSQhKGMO9ExYDUEscYnZc5jqrgM3rQ+zcmw+oCqrwXcYGwv+/+pun dCfyXDKAD0uWySKbM/sVw7S5t14sglo575PR6yr6Dy+dEI5yxhgvG9O8A4dE7CKe2oQuH1 t0U5gCZroRi6fx/P93Mq0pN72ME07isa5Pf2VFQO2OfrqjLVCr/c8QKWfi7Y6sjYeepDuE alKSfAdlfPje09ANMCPtF5HlfEHA8yBMf9A5mCKqRp4v+bBf6bPkC+PDnclQWCAxLkoJL9 qoJCJVjUUAB5ObpOJ5up/323f8Gjb+DIECsxYapQzQBsML/yUXMAm+nA9J5S45Wdid/QGG ltCAUeTdluKkF8AaoitiF6SpOqoibP8rw6yKLFNXb7n2r53g7pISVW2wbrErAK9VMLvki6 SMt3nghO3TIO0eYdlOkiOMKzAjDB0Wpu8lcTDpYAeD45J7eVzEJD53SlcoZiH6jCnz5n4C ZWgnrQyxxPgzn5tJR7cmcbpQdaQytFcjemay3LxfCvNFPlUWstxJi7L5ugYH2Mi7FVN4wu KJazx3Ua+XPLvXd4LK58L5MKmKm3J7d4ZHPY+4Dioms2aHCFennPlYGmEJwQ X-ME-Proxy: Feedback-ID: i12284293:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 13 Jul 2026 07:21:51 -0400 (EDT) Received: by mbp.qyliss.net (Postfix, from userid 1000) id 5EC7E890F45E; Mon, 13 Jul 2026 11:01:32 +0200 (CEST) From: Alyssa Ross To: Demi Marie Obenour Subject: Re: [PATCH] host/rootfs: Avoid using bwrap to enter new PID namespace In-Reply-To: <47d40c5e-ef44-4101-857e-3f656f1d14bf@gmail.com> References: <20260709-s6-pid-namespaces-v1-1-61a56abd1e7c@gmail.com> <87ldbiaoyh.fsf@alyssa.is> <47d40c5e-ef44-4101-857e-3f656f1d14bf@gmail.com> Date: Mon, 13 Jul 2026 11:01:25 +0200 Message-ID: <87jyqz1cwq.fsf@alyssa.is> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Message-ID-Hash: X2SUPANJSYARIFUMZ3QJKHI5V5YWU4NB X-Message-ID-Hash: X2SUPANJSYARIFUMZ3QJKHI5V5YWU4NB X-MailFrom: hi@alyssa.is X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Spectrum OS Development X-Mailman-Version: 3.3.10 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Demi Marie Obenour writes: > On 7/10/26 10:39, Alyssa Ross wrote: >> Demi Marie Obenour writes: >>=20 >>> diff --git a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-s= ervices/template/data/service/vhost-user-gpu/run b/host/rootfs/image/etc/s6= -linux-init/run-image/service/vm-services/template/data/service/vhost-user-= gpu/run >>> index c3bfafe02ec6d2ee418fe56b033bbc4c7a73b186..f5c0f15184f0e72457f9c0b= fa546590b9308eb9c 100755 >>> --- a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services= /template/data/service/vhost-user-gpu/run >>> +++ b/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services= /template/data/service/vhost-user-gpu/run >>> @@ -17,9 +17,10 @@ s6-applyuidgid -UzG 15 # wayland >>> s6-ipcserverd -1c 1 >>>=20=20 >>> bwrap >>> - --unshare-all >>> - # --unshare-all only implies --unshare-user-try. >>> - # Make this more than a "try". >>> + --unshare-net >>> + --unshare-ipc >>> + --unshare-uts >>> + --unshare-cgroup >>> --unshare-user >>> --bind $WAYLAND_DISPLAY $WAYLAND_DISPLAY >>> --ro-bind /usr /usr >>=20 >> There's a subtle behaviour change here. The pid namespace is reused >> between runs of crosvm, because if crosvm exits, s6-ipcserverd will stay >> running and wait for the next connection, then respawn crosvm. It's >> done this way because crosvm has made the unusual decision to support >> being started on a connected socket, rather than a listening socket like >> one might expect. Is that okay? I'd guess yes, but I want to check >> with you! > > It's less robust than I would like, but there is no reason one cannot > have both s6-supervise and bubblewrap create PID namespaces. That's > the approach I would go with. What's the point of the intermediate PID namespace? --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQRV/neXydHjZma5XLJbRZGEIw/wogUCalSpZQAKCRBbRZGEIw/w oslqAP9iA2Ax0Y0IFFgMt4dO/fYX1bUjQKX+EECO66koNNaMYwD/el/N2fCPdiLH XVHDmEyZVgHQbDf8TAulWKjduyCCRgc= =bDgg -----END PGP SIGNATURE----- --=-=-=--