From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id 4C4746E8; Fri, 10 Jul 2026 14:39:41 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id 7ED066D1; Fri, 10 Jul 2026 14:39:39 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.8 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_MISSING,RCVD_IN_DNSWL_LOW,SPF_HELO_PASS autolearn=unavailable autolearn_force=no version=4.0.1 Received: from fhigh-a2-smtp.messagingengine.com (fhigh-a2-smtp.messagingengine.com [103.168.172.153]) by atuin.qyliss.net (Postfix) with ESMTPS id BED0C6D0 for ; Fri, 10 Jul 2026 14:39:38 +0000 (UTC) Received: from phl-compute-06.internal (phl-compute-06.internal [10.202.2.46]) by mailfhigh.phl.internal (Postfix) with ESMTP id 148A914000E5; Fri, 10 Jul 2026 10:39:38 -0400 (EDT) Received: from phl-frontend-03 ([10.202.2.162]) by phl-compute-06.internal (MEProxy); Fri, 10 Jul 2026 10:39:38 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=alyssa.is; h=cc :cc:content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:subject :subject:to:to; s=fm1; t=1783694378; x=1783780778; bh=UfPKVLX2EH 6qOOypzK3PAC06B02Ab0v9ClBj9fGwIN8=; b=PREF9puDtPpQUuwo1Otf0mb6O2 il28gTCl3f30EACqpLOfUcbgoJ2ibGmDuBFBEUZHS8MctshRorOAQxpuUJ5lLD0F D9HzYzW1qDsVOJUkp+VCV9OZwQ/e3EhwVeO4LmAAzCSKkYGcvnaHRIR9epbhJgXY HFowYyv+vRNiXl0V6kVcmtetFBsGrI3ossTVyWIxoiufv3ljdRYI9f8Xrxdi9mh7 Jqx6OWfJPlIB1TRHKJbJ8OoDdcDj0SVwc7AxV1Gzt4HPZLpO9jvIM3m3sfyEYpRd ajHi3hx6hmyA+Gd92vwvCCgaRRMNnLIimbliR8HiPROZRJEn6611yvqE7Qwg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t= 1783694378; x=1783780778; bh=UfPKVLX2EH6qOOypzK3PAC06B02Ab0v9ClB j9fGwIN8=; b=qZIbTReLL6OnEmC2HnxW72Ap7pBNuj/GAD5qpHXhVqRpuG8Vop7 gKg3dyUGhQUf5MNbt3Vjjoc/UHf6umHPMTd1QyKkBybyTSLeO1iHcj6NjsG6bgwL 2RS40o9w7v5wPbsnaNAJ66KO/3HchQVzCFPhmSfwVFU7UzkDK2UqFGdZSWPiiozb V6XfT7j6sbh5BCTdBlslTaoDbXrl3tN357bEDIEK0uqBEmTDwoU5yd1lr/HlYxmp WW1CEi/cNv6XgyN4/PzZRza6sgh+nPPTkZFQL7uqcgN11koXzxOfGKIWTGqjLsaI duIR9Y+aRATei701ek6GdGF+af326TzgrWw== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTFBxPmYbFRisDfapNF6D5TfcdFyGW9Cd0MteEw8prSwNZj5PWxHzkqX0HqbEzyB2B GlunBJc5mGpabWkt8Z+kf8O5KpnMop09pp6jUqWRa8u6CJ1QKWrWGO4Uw7BTBbdYZL4bRR oz/t+OC/V813cA8Nh22u0X3IFpZqoHCfMe/t09QZuE0mZLusvo0+fCY+PJ4wdjOemE2fCt Oi3v0zd0ZVaTr3ptTA9OnSRtIbhil7kKFz2nMGwfds34Udpgp4TNLwgvME7i9eDFQDTlZ6 4fmzuGdd03wUH8zo/nFWwvFEQ58Z1+4aDgZTa6PIlyL1I5fQ4zIfpkijIweXka2A2O4BFM jze9cjMMDV3itsoPNsYx/etWNezJfUP7kE4Ac04uS8dVWPsY5kxnLQVFpdvkBKXXicMIAF WwQKnUUpelfzEHTg0U7BeKiX8/tnNZ/RU4CkJ5bij1SegCkhiF1GkztmE404DPswLBwHu3 dUxOkprj/4A4oJkTNoSi4sgVVF8F0MlM4CpI6HTMHjmc4tivjh312yBgd4i+5PUCN5eDll KvHojbqfb3cN4fbY0tOhO6jhNCXPqbp4aMfXpjkfKk5pXHxjasXcEnjkQC2PymP1b1Zmju qj7N1cSuzI4up3i4lfaNAexTKODTzzIQrbDjPh1Tg6cBDwe2hWswE16OilAw X-ME-Proxy: Feedback-ID: i12284293:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Fri, 10 Jul 2026 10:39:37 -0400 (EDT) Received: by fw12.qyliss.net (Postfix, from userid 1000) id A3D11C174445; Fri, 10 Jul 2026 16:39:35 +0200 (CEST) From: Alyssa Ross To: Demi Marie Obenour Subject: Re: [PATCH] host/rootfs: Avoid using bwrap to enter new PID namespace In-Reply-To: <20260709-s6-pid-namespaces-v1-1-61a56abd1e7c@gmail.com> References: <20260709-s6-pid-namespaces-v1-1-61a56abd1e7c@gmail.com> Date: Fri, 10 Jul 2026 16:39:34 +0200 Message-ID: <87ldbiaoyh.fsf@alyssa.is> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Message-ID-Hash: DV6MHHYRT7VBDMYO7G7W5S7SJLY72Q47 X-Message-ID-Hash: DV6MHHYRT7VBDMYO7G7W5S7SJLY72Q47 X-MailFrom: hi@alyssa.is X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Spectrum OS Development X-Mailman-Version: 3.3.10 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Demi Marie Obenour writes: > s6-supervise can do so directly with less overhead. > > Signed-off-by: Demi Marie Obenour > --- > host/rootfs/file-list.mk | 2 ++ > .../template/data/service/spectrum-router/flag-newpidns | 0 > .../service/vm-services/template/data/service/spectrum-router/run | 5 += +++- > .../vm-services/template/data/service/vhost-user-gpu/flag-newpidns | 0 > .../service/vm-services/template/data/service/vhost-user-gpu/run | 7 += +++--- > 5 files changed, 10 insertions(+), 4 deletions(-) I guess this isn't done for run-vmm because it might not be run through s6? > diff --git a/host/rootfs/file-list.mk b/host/rootfs/file-list.mk > index 3899d620717fc97f42e669e5313c4100dcf5b1cd..951cb2e9f0af05839ef5e9c0b= 5384c13e56622ff 100644 > --- a/host/rootfs/file-list.mk > +++ b/host/rootfs/file-list.mk > @@ -30,10 +30,12 @@ FILES =3D \ > image/etc/s6-linux-init/run-image/service/vm-services/template/data/ser= vice/dbus/notification-fd \ > image/etc/s6-linux-init/run-image/service/vm-services/template/data/ser= vice/dbus/run \ > image/etc/s6-linux-init/run-image/service/vm-services/template/data/ser= vice/spectrum-router/down \ > + image/etc/s6-linux-init/run-image/service/vm-services/template/data/ser= vice/spectrum-router/flag-newpidns \ > image/etc/s6-linux-init/run-image/service/vm-services/template/data/ser= vice/spectrum-router/notification-fd \ > image/etc/s6-linux-init/run-image/service/vm-services/template/data/ser= vice/spectrum-router/run \ > image/etc/s6-linux-init/run-image/service/vm-services/template/data/ser= vice/vhost-user-fs/notification-fd \ > image/etc/s6-linux-init/run-image/service/vm-services/template/data/ser= vice/vhost-user-fs/run \ > + image/etc/s6-linux-init/run-image/service/vm-services/template/data/ser= vice/vhost-user-gpu/flag-newpidns \ > image/etc/s6-linux-init/run-image/service/vm-services/template/data/ser= vice/vhost-user-gpu/notification-fd \ > image/etc/s6-linux-init/run-image/service/vm-services/template/data/ser= vice/vhost-user-gpu/run \ > image/etc/s6-linux-init/run-image/service/vm-services/template/data/ser= vice/xdg-desktop-portal-spectrum-host/notification-fd \ > diff --git a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-ser= vices/template/data/service/spectrum-router/flag-newpidns b/host/rootfs/ima= ge/etc/s6-linux-init/run-image/service/vm-services/template/data/service/sp= ectrum-router/flag-newpidns > new file mode 100644 > index 0000000000000000000000000000000000000000..e69de29bb2d1d6434b8b29ae7= 75ad8c2e48c5391 > diff --git a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-ser= vices/template/data/service/spectrum-router/run b/host/rootfs/image/etc/s6-= linux-init/run-image/service/vm-services/template/data/service/spectrum-rou= ter/run > index 3de58c27facc78c48176d8f9a6dd1827ac926f1a..ce84ed951de1a179d1430faae= 412fe4c1a2fb1f1 100755 > --- a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/t= emplate/data/service/spectrum-router/run > +++ b/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/t= emplate/data/service/spectrum-router/run > @@ -25,7 +25,10 @@ if { > s6-setuidgid router >=20=20 > bwrap > - --unshare-all > + --unshare-net > + --unshare-ipc > + --unshare-uts > + --unshare-cgroup > --unshare-user > --dev-bind / / > --setenv RUST_LOG spectrum-router=3Ddebug,info > diff --git a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-ser= vices/template/data/service/vhost-user-gpu/flag-newpidns b/host/rootfs/imag= e/etc/s6-linux-init/run-image/service/vm-services/template/data/service/vho= st-user-gpu/flag-newpidns > new file mode 100644 > index 0000000000000000000000000000000000000000..e69de29bb2d1d6434b8b29ae7= 75ad8c2e48c5391 > diff --git a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-ser= vices/template/data/service/vhost-user-gpu/run b/host/rootfs/image/etc/s6-l= inux-init/run-image/service/vm-services/template/data/service/vhost-user-gp= u/run > index c3bfafe02ec6d2ee418fe56b033bbc4c7a73b186..f5c0f15184f0e72457f9c0bfa= 546590b9308eb9c 100755 > --- a/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/t= emplate/data/service/vhost-user-gpu/run > +++ b/host/rootfs/image/etc/s6-linux-init/run-image/service/vm-services/t= emplate/data/service/vhost-user-gpu/run > @@ -17,9 +17,10 @@ s6-applyuidgid -UzG 15 # wayland > s6-ipcserverd -1c 1 >=20=20 > bwrap > - --unshare-all > - # --unshare-all only implies --unshare-user-try. > - # Make this more than a "try". > + --unshare-net > + --unshare-ipc > + --unshare-uts > + --unshare-cgroup > --unshare-user > --bind $WAYLAND_DISPLAY $WAYLAND_DISPLAY > --ro-bind /usr /usr There's a subtle behaviour change here. The pid namespace is reused between runs of crosvm, because if crosvm exits, s6-ipcserverd will stay running and wait for the next connection, then respawn crosvm. It's done this way because crosvm has made the unusual decision to support being started on a connected socket, rather than a listening socket like one might expect. Is that okay? I'd guess yes, but I want to check with you! --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQQGoGac7QfI+H5ZtFCZddwkt31pFQUCalEEJgAKCRCZddwkt31p FWfuAP9mks4OcBzTEtkyJ2wdcTBPShPd83FWYRYRFg7Mp8UaWQEAtPdECUQCLY0R VwZV2++O+dUJPLmyCzwxmJJJwnoOHws= =lEIn -----END PGP SIGNATURE----- --=-=-=--