From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=iLCp572u; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by passt.top (Postfix) with ESMTPS id 7F2675A026E for ; Wed, 16 Sep 2026 10:50:59 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1789548658; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=FqjubSBN+XD6+Yp5r14MRts/+/681OO6yH/9o2oARNc=; b=iLCp572unRp4m3eITzgQVDM7jz2RMVF3Jc0lhai+4GiGYroRGNh7vp6+5xXwAGL14l+HBx Cb52vEBl6K7/V/ZZ82E4mXX1zElXpnZ2oE1VIITK8VMr6BPBRofu6SzfyTQ+8v0/SUR6PK wPgyzvT6GCEYtLRJ8gxkYTJ5JmYYbak= Received: from mail-wr1-f71.google.com (mail-wr1-f71.google.com [209.85.221.71]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-422-Vvsbb2BBPPmAdQ90FZiN-g-1; Wed, 16 Sep 2026 04:50:54 -0400 X-MC-Unique: Vvsbb2BBPPmAdQ90FZiN-g-1 X-Mimecast-MFC-AGG-ID: Vvsbb2BBPPmAdQ90FZiN-g_1789548653 Received: by mail-wr1-f71.google.com with SMTP id ffacd0b85a97d-4870487e33aso631907f8f.1 for ; Wed, 16 Sep 2026 01:50:54 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789548653; x=1790153453; h=date:content-transfer-encoding:content-type:mime-version :organization:references:in-reply-to:message-id:subject:cc:to:from :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=FqjubSBN+XD6+Yp5r14MRts/+/681OO6yH/9o2oARNc=; b=gIUywbA7ZPTz0XDrCy2K+EGKGyH83jzy/kVf8Wf84r4s6y08lyZlJAGsgJHic0Uez8 Tc4E0/wGr7HM6hmoKRv2V+5abn7Kpnwo+A7Nzw3y5pMbnZUt7MWGbhzDGy+quM6Y6KA+ 0i9gzATphuhY2t/Si+73gec04xofpLifzNK/VMK7vQ+wguzjSyj8szLvvqKSMo/QmSb5 OqKYBxTYjP8QEFS+Zk4YwZT8iMZVit4r1CGw/8h7tfeKtVXooRgNCVp2qrG+EBIffVtm hFU4B8S07xOkye2yeR4OutYm18ldff2Y6il/zWMEOOQfrMhWXV+S1ek3zWe2FuSbKEuO nX7Q== X-Gm-Message-State: AFuF++kOYOpwWmTIsJDw5VFpyObc+QsIf2gLtB+hmlc4vqJSFxBI+W1N RxiK5d7V6hNUUraiLsTCMbGroHYwBSxb1NMTXgBBhHhVZOZ+4y7eGsxNbEFiNPUyNMksSS4OUba mRR8XmmNaN3juU2p2RcXVhgFfm/jLYjamjRGt8MJgs7ZWgQrhBemSRQ== X-Gm-Gg: AYBFou3Z31EeH2BSI/M7lBfG6+BMIMyIF03KC84pU4THhLhlSxUAsoPYw+SfpJipeXU OD1I+tVgQNxpAYL/mAKYIPTYcRax1G2XxxEzpMg0s0jNWbSQ6GbynBp7le1F8Fb4OImddlAqdwH LeJQVhep7oUfrkT9lUMfDlwe26eTeojGR++SpjwsfoudfTnv7r22N9O8hezvlBvzQn5iMNwCijM cC0wFiW8V0uaVzT2ueZa1kVt32A9YcqE34cBe71J3JMPMzCzcb8MdlgUf+hXVD/5+Y8/OpdAzS9 1nLQPScQDKww0UVu+/s2UmsfHT18DUVmcUeDELCCx/Qkj9xg10l/6URuA0X4J1w/hR4M7pTQV0T nhLxC4VWpiJBfvginOr65uve3iGuu X-Received: by 2002:a05:600c:5394:b0:49c:fa21:e746 with SMTP id 5b1f17b1804b1-49eb7337437mr16094745e9.28.1789548653304; Wed, 16 Sep 2026 01:50:53 -0700 (PDT) X-Received: by 2002:a05:600c:5394:b0:49c:fa21:e746 with SMTP id 5b1f17b1804b1-49eb7337437mr16094435e9.28.1789548652766; Wed, 16 Sep 2026 01:50:52 -0700 (PDT) Received: from maya.myfinge.rs (ifcgrfdd.trafficplex.cloud. [176.103.220.4]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e83f54defsm39491065e9.0.2026.09.16.01.50.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 16 Sep 2026 01:50:52 -0700 (PDT) From: Stefano Brivio To: Christian Korneck Subject: Re: [PATCH] pasta: Add --no-pidns to keep spawned command in caller's PID namespace Message-ID: <20260916105050.5e4bb12d@elisabeth> In-Reply-To: <20260906131758.121019-1-christian@korneck.de> References: <20260906131758.121019-1-christian@korneck.de> Organization: Red Hat X-Mailer: Claws Mail 4.2.0 (GTK 3.24.49; x86_64-pc-linux-gnu) MIME-Version: 1.0 Date: Wed, 16 Sep 2026 10:50:51 +0200 (CEST) X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: F13C-9V2ca7Ud5bj6eXJEW2pyWCqc4y8Xr9_TKzj6PM_1789548653 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Message-ID-Hash: PEXEJ7ZLHLJCNMK4K5FRFTR7ET3MVSSB X-Message-ID-Hash: PEXEJ7ZLHLJCNMK4K5FRFTR7ET3MVSSB X-MailFrom: sbrivio@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: passt-dev@passt.top, David Gibson X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On Sun, 6 Sep 2026 15:17:58 +0200 Christian Korneck wrote: > This is to allow running pasta inside a container without unmasking > /proc for the whole container (Docker's --security-opt > systempaths=unconfined, Podman's --security-opt unmask=ALL), which is > undesirable as it exposes /proc/sysrq-trigger and other masked paths. > > In spawn mode, pasta clones the command with CLONE_NEWPID and mounts a > new procfs instance on /proc, so that it matches the new PID namespace. > > Mounting procfs in a new user namespace requires a fully visible, > unobstructed procfs. Container runtimes deliberately obstruct /proc > (Docker, for example, masks /proc/kcore and friends and mounts > /proc/sys read-only), so the mount is refused: > > Couldn't mount /proc: Operation not permitted > > We only warn and continue, leaving the command in a new PID namespace > while the visible /proc still numbers processes in the outer one. > Anything resolving its own PID through /proc then fails, for example > bubblewrap: > > bwrap: open /proc/22/ns/ns failed: No such file or directory > > Add a --no-pidns option: skip CLONE_NEWPID for the spawned command and > don't mount /proc, which is then not needed. User, network, mount, UTS > and IPC namespaces, --config-net and port forwarding are unaffected. > The option is rejected together with PID or --netns, as it only makes > sense when we spawn the command ourselves. > > Add a test checking that, by default, the command runs in a new PID > namespace, and that --no-pidns keeps it in the caller's one. > > Signed-off-by: Christian Korneck Applied, thanks for the patch, and welcome to the git log! -- Stefano