From: Zhihang Wei <wzh@ilbers.de>
To: Felix Moessbauer <felix.moessbauer@siemens.com>,
isar-users@googlegroups.com
Cc: jan.kiszka@siemens.com, quirin.gylstorff@siemens.com
Subject: Re: [PATCH v8 00/17] add support to build isar unprivileged
Date: Fri, 17 Jul 2026 15:50:20 +0200 [thread overview]
Message-ID: <8642c7eb-3b27-41ed-a10a-bf3651cf4318@ilbers.de> (raw)
In-Reply-To: <20260715110548.3605767-1-felix.moessbauer@siemens.com>
Applied to next, thanks!
Zhihang
On 7/15/26 13:05, 'Felix Moessbauer' via isar-users wrote:
> Dear isar-users,
>
> currently isar requires password-less sudo and an environment
> where mounting file systems is possible. This has proven problematic
> for security reasons, both when running in a privileged container or
> locally.
>
> To solve this, we implement fully rootless builds that rely on the
> unshare syscall which allows us to avoid sudo and instead operate in
> temporary kernel namespaces as a user that is just privileged within
> that namespace. This comes with some challenges regarding the handling
> of mounts (they are cleared when leaving the namespace), as well as
> cross namespace deployments (the outer user might not be able to access
> the inner data). For that, we rework the handling of mounts and artifact
> passing to make it compatible with both chroot modes (schroot and
> unshare).
>
> Note, that this series can be tested on a custom kas-container build
> provided in [1]. Hints how to migrate downstream layers are provided
> in the API changelog.
>
> Changes since PATCH v7:
>
> - rebased onto next
> - consistently format apt args (-o ... instead of -o...)
> - rootfs: fix check for ISAR_USE_CACHED_BASE_REPO
> - rootfs: remove left-over debug statement
> - report error if idmap is not available in unshare mode (instead of crashing)
>
> Changes since PATCH v6:
>
> - rebased onto next
> - p10: revert rootfs_install_pkgs_download to bwrap-based implementation,
> restoring old build performances. The underlying issue was finally
> understood, so the pattern could stay also under rootless.
>
> Changes since PATCH v5:
>
> - rebased onto next
> - adjust to changes from "Rootfs install race fix for isar-apt packages":
> Manually add isar-apt mount in rootfs_install_pkgs_isar_download on
> rootless
> - adjust to changes in "image-postproc: gate systemd preset-all on masked
> unit state": Trivial change to use run_in_chroot instead of sudo chroot.
>
> Changes since PATCH v4:
>
> - fix cleanup trap in do_bootstrap (only functional change)
> - keep build_system entries as "isar" until we have official kas support
> (and for backwards compatibility). Add reasoning to commit message
> - improve RECIPE-API-CHANGELOG (the kas interfaces are stable now, but
> not yet released)
>
> Changes since PATCH v3:
>
> - fix dracut initrd build issue (p7)
> - testsuite: print if rootless mode is used in summary
> - testsuite: append newline after ISAR_ROOTLESS = "1" in ci config
> - run-tests.sh: catch -p rootless=1 flag and start container in rootless mode
> (requires a not-yet released kas-container, corresponding kas patches
> are currently under review)
>
> Changes since PATCH v2:
>
> - add support for cached base apt
> - rootfs sstate: do not rely on fd3 for copy out, as not always available
> - sbom: use local copy of sbom rootfs to not leave shared instance behind
> - testsuite: add parameter to run in rootless mode
> - rebased onto v1.0
>
> Changes since PATCH v1:
>
> - fixed broken rebase onto next
> - fix root_cleandirs implementation
>
> NOTE: This requires the kas series (v3) from [1] for rootless building.
>
> Changes since RFC 2:
>
> - rebased onto next
> - fix usage of root_cleandirs
> - simplify file permission handling by mapping caller user to
> root inside the namespace. By that, in most cases no changes
> to the imager are needed anymore.
> - implement support for devshell under rootless
> - switch to getpass.getuser() to query user (needed for dynamically
> created / remapped kas builder user)
> - rework mapping to be more similar to mapping used by mmdebstrap
> - sbuild: only copy-out of dpkg.log on schroot (unclear if needed
> on unshare. To be clarified)
> - imager-sbom: ensure sbom is extracted before entering the chroot
>
> Changes since RFC 1:
>
> - switch build_type to isar-rootless in isar.yaml (Note: switch back
> if testing locally in a unprepared kas container)
> - complete overhaul of the mounting in unshared namespaces
> - fixes the systemd presetting
> - fixes hangs when pulling from snapshot mirrors
> - rename the run_privileged_here to run_privileged_heredoc to clarify its intention
> - add support for
> - dpkg-source with do_fetch_common_source
> - vm images
> - container images
> - discoverable disk images
> - add helper script to clean build dir in unprivileged mode
> - reduce clutter we leave after finishing a build
> - fix issues when running in a privileged environment without sub user ids
> - bugfixes
>
> Note, that the rootless build dir must not reside in a git worktree (a normal git
> dir is fine). This is probably a bug in combination with kas-container.
>
> [1] https://groups.google.com/g/kas-devel/c/NWQFCU2aUHg
>
> Best regards,
> Felix Moessbauer
> Siemens AG
>
> Felix Moessbauer (17):
> refactor bootstrap: store rootfs tar with user permissions
> deb-dl-dir: export without root privileges
> download debs without locking
> introduce wrappers for privileged execution
> bootstrap: move cleanup trap to function
> rootfs: rework sstate caching of rootfs artifact
> rootfs_generate_initramfs: rework deployment to avoid chowning
> use bitbake function to generate mounting scripts
> apt-fetcher: prepare for chroot specific fetching
> add support for fully rootless builds
> add helper script to clean artifacts in build dir
> apt-fetcher: implement support for unshare backend
> dpkg-source: implement multiarch support for unshare backend
> use copy of sbom-chroot for sbom creation
> add support for devshell on unshare backend
> testsuite: add parameter to run tests in rootless mode
> run-tests: add support for isar-rootless mode
>
> RECIPE-API-CHANGELOG.md | 41 ++++
> doc/user_manual.md | 2 +
> meta/classes-global/base.bbclass | 128 +++++++++++-
> meta/classes-recipe/deb-dl-dir.bbclass | 22 +-
> meta/classes-recipe/dpkg-base.bbclass | 94 +++++++--
> meta/classes-recipe/dpkg-source.bbclass | 40 +++-
> meta/classes-recipe/dpkg.bbclass | 19 +-
> .../image-account-extension.bbclass | 4 +-
> .../image-locales-extension.bbclass | 13 +-
> .../image-postproc-extension.bbclass | 30 +--
> .../image-tools-extension.bbclass | 114 +++++++++-
> meta/classes-recipe/image.bbclass | 21 +-
> .../imagetypes_container.bbclass | 28 +--
> meta/classes-recipe/imagetypes_wic.bbclass | 10 +-
> meta/classes-recipe/rootfs.bbclass | 196 +++++++++---------
> meta/classes-recipe/sbuild.bbclass | 34 ++-
> meta/classes-recipe/sdk.bbclass | 22 +-
> meta/classes/sbom.bbclass | 28 ++-
> meta/conf/bitbake.conf | 7 +-
> meta/lib/aptsrc_fetcher.py | 87 +++++++-
> .../isar-mmdebstrap/isar-mmdebstrap.inc | 56 +++--
> .../sbom-chroot/sbom-chroot.bb | 11 +-
> .../sbuild-chroot/sbuild-chroot.inc | 24 ++-
> scripts/isar-clean-builddir | 73 +++++++
> scripts/run-tests.sh | 7 +-
> testsuite/cibuilder.py | 7 +
> .../unittests/test_image_account_extension.py | 9 +-
> 27 files changed, 886 insertions(+), 241 deletions(-)
> create mode 100755 scripts/isar-clean-builddir
>
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/8642c7eb-3b27-41ed-a10a-bf3651cf4318%40ilbers.de.
prev parent reply other threads:[~2026-07-17 13:50 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-15 11:05 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 01/17] refactor bootstrap: store rootfs tar with user permissions 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 02/17] deb-dl-dir: export without root privileges 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 03/17] download debs without locking 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 04/17] introduce wrappers for privileged execution 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 05/17] bootstrap: move cleanup trap to function 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 06/17] rootfs: rework sstate caching of rootfs artifact 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 07/17] rootfs_generate_initramfs: rework deployment to avoid chowning 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 08/17] use bitbake function to generate mounting scripts 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 09/17] apt-fetcher: prepare for chroot specific fetching 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 10/17] add support for fully rootless builds 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 11/17] add helper script to clean artifacts in build dir 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 12/17] apt-fetcher: implement support for unshare backend 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 13/17] dpkg-source: implement multiarch " 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 14/17] use copy of sbom-chroot for sbom creation 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 15/17] add support for devshell on unshare backend 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 16/17] testsuite: add parameter to run tests in rootless mode 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 17/17] run-tests: add support for isar-rootless mode 'Felix Moessbauer' via isar-users
2026-07-17 13:50 ` Zhihang Wei [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8642c7eb-3b27-41ed-a10a-bf3651cf4318@ilbers.de \
--to=wzh@ilbers.de \
--cc=felix.moessbauer@siemens.com \
--cc=isar-users@googlegroups.com \
--cc=jan.kiszka@siemens.com \
--cc=quirin.gylstorff@siemens.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox