public inbox for isar-users@googlegroups.com
 help / color / mirror / Atom feed
From: Zhihang Wei <wzh@ilbers.de>
To: Felix Moessbauer <felix.moessbauer@siemens.com>,
	isar-users@googlegroups.com
Cc: jan.kiszka@siemens.com, quirin.gylstorff@siemens.com
Subject: Re: [PATCH v8 00/17] add support to build isar unprivileged
Date: Fri, 17 Jul 2026 15:50:20 +0200	[thread overview]
Message-ID: <8642c7eb-3b27-41ed-a10a-bf3651cf4318@ilbers.de> (raw)
In-Reply-To: <20260715110548.3605767-1-felix.moessbauer@siemens.com>

Applied to next, thanks!

Zhihang

On 7/15/26 13:05, 'Felix Moessbauer' via isar-users wrote:
> Dear isar-users,
>
> currently isar requires password-less sudo and an environment
> where mounting file systems is possible. This has proven problematic
> for security reasons, both when running in a privileged container or
> locally.
>
> To solve this, we implement fully rootless builds that rely on the
> unshare syscall which allows us to avoid sudo and instead operate in
> temporary kernel namespaces as a user that is just privileged within
> that namespace. This comes with some challenges regarding the handling
> of mounts (they are cleared when leaving the namespace), as well as
> cross namespace deployments (the outer user might not be able to access
> the inner data). For that, we rework the handling of mounts and artifact
> passing to make it compatible with both chroot modes (schroot and
> unshare).
>
> Note, that this series can be tested on a custom kas-container build
> provided in [1]. Hints how to migrate downstream layers are provided
> in the API changelog.
>
> Changes since PATCH v7:
>
> - rebased onto next
> - consistently format apt args (-o ... instead of -o...)
> - rootfs: fix check for ISAR_USE_CACHED_BASE_REPO
> - rootfs: remove left-over debug statement
> - report error if idmap is not available in unshare mode (instead of crashing)
>
> Changes since PATCH v6:
>
> - rebased onto next
> - p10: revert rootfs_install_pkgs_download to bwrap-based implementation,
>    restoring old build performances. The underlying issue was finally
>    understood, so the pattern could stay also under rootless.
>
> Changes since PATCH v5:
>
> - rebased onto next
> - adjust to changes from "Rootfs install race fix for isar-apt packages":
>    Manually add isar-apt mount in rootfs_install_pkgs_isar_download on
>    rootless
> - adjust to changes in "image-postproc: gate systemd preset-all on masked
>    unit state": Trivial change to use run_in_chroot instead of sudo chroot.
>
> Changes since PATCH v4:
>
> - fix cleanup trap in do_bootstrap (only functional change)
> - keep build_system entries as "isar" until we have official kas support
>    (and for backwards compatibility). Add reasoning to commit message
> - improve RECIPE-API-CHANGELOG (the kas interfaces are stable now, but
>    not yet released)
>
> Changes since PATCH v3:
>
> - fix dracut initrd build issue (p7)
> - testsuite: print if rootless mode is used in summary
> - testsuite: append newline after ISAR_ROOTLESS = "1" in ci config
> - run-tests.sh: catch -p rootless=1 flag and start container in rootless mode
>    (requires a not-yet released kas-container, corresponding kas patches
>     are currently under review)
>
> Changes since PATCH v2:
>
> - add support for cached base apt
> - rootfs sstate: do not rely on fd3 for copy out, as not always available
> - sbom: use local copy of sbom rootfs to not leave shared instance behind
> - testsuite: add parameter to run in rootless mode
> - rebased onto v1.0
>
> Changes since PATCH v1:
>
> - fixed broken rebase onto next
> - fix root_cleandirs implementation
>
> NOTE: This requires the kas series (v3) from [1] for rootless building.
>
> Changes since RFC 2:
>
> - rebased onto next
> - fix usage of root_cleandirs
> - simplify file permission handling by mapping caller user to
>    root inside the namespace. By that, in most cases no changes
>    to the imager are needed anymore.
> - implement support for devshell under rootless
> - switch to getpass.getuser() to query user (needed for dynamically
>    created / remapped kas builder user)
> - rework mapping to be more similar to mapping used by mmdebstrap
> - sbuild: only copy-out of dpkg.log on schroot (unclear if needed
>    on unshare. To be clarified)
> - imager-sbom: ensure sbom is extracted before entering the chroot
>
> Changes since RFC 1:
>
> - switch build_type to isar-rootless in isar.yaml (Note: switch back
>    if testing locally in a unprepared kas container)
> - complete overhaul of the mounting in unshared namespaces
>    - fixes the systemd presetting
>    - fixes hangs when pulling from snapshot mirrors
> - rename the run_privileged_here to run_privileged_heredoc to clarify its intention
> - add support for
>    - dpkg-source with do_fetch_common_source
>    - vm images
>    - container images
>    - discoverable disk images
> - add helper script to clean build dir in unprivileged mode
> - reduce clutter we leave after finishing a build
> - fix issues when running in a privileged environment without sub user ids
> - bugfixes
>
> Note, that the rootless build dir must not reside in a git worktree (a normal git
> dir is fine). This is probably a bug in combination with kas-container.
>
> [1] https://groups.google.com/g/kas-devel/c/NWQFCU2aUHg
>
> Best regards,
> Felix Moessbauer
> Siemens AG
>
> Felix Moessbauer (17):
>    refactor bootstrap: store rootfs tar with user permissions
>    deb-dl-dir: export without root privileges
>    download debs without locking
>    introduce wrappers for privileged execution
>    bootstrap: move cleanup trap to function
>    rootfs: rework sstate caching of rootfs artifact
>    rootfs_generate_initramfs: rework deployment to avoid chowning
>    use bitbake function to generate mounting scripts
>    apt-fetcher: prepare for chroot specific fetching
>    add support for fully rootless builds
>    add helper script to clean artifacts in build dir
>    apt-fetcher: implement support for unshare backend
>    dpkg-source: implement multiarch support for unshare backend
>    use copy of sbom-chroot for sbom creation
>    add support for devshell on unshare backend
>    testsuite: add parameter to run tests in rootless mode
>    run-tests: add support for isar-rootless mode
>
>   RECIPE-API-CHANGELOG.md                       |  41 ++++
>   doc/user_manual.md                            |   2 +
>   meta/classes-global/base.bbclass              | 128 +++++++++++-
>   meta/classes-recipe/deb-dl-dir.bbclass        |  22 +-
>   meta/classes-recipe/dpkg-base.bbclass         |  94 +++++++--
>   meta/classes-recipe/dpkg-source.bbclass       |  40 +++-
>   meta/classes-recipe/dpkg.bbclass              |  19 +-
>   .../image-account-extension.bbclass           |   4 +-
>   .../image-locales-extension.bbclass           |  13 +-
>   .../image-postproc-extension.bbclass          |  30 +--
>   .../image-tools-extension.bbclass             | 114 +++++++++-
>   meta/classes-recipe/image.bbclass             |  21 +-
>   .../imagetypes_container.bbclass              |  28 +--
>   meta/classes-recipe/imagetypes_wic.bbclass    |  10 +-
>   meta/classes-recipe/rootfs.bbclass            | 196 +++++++++---------
>   meta/classes-recipe/sbuild.bbclass            |  34 ++-
>   meta/classes-recipe/sdk.bbclass               |  22 +-
>   meta/classes/sbom.bbclass                     |  28 ++-
>   meta/conf/bitbake.conf                        |   7 +-
>   meta/lib/aptsrc_fetcher.py                    |  87 +++++++-
>   .../isar-mmdebstrap/isar-mmdebstrap.inc       |  56 +++--
>   .../sbom-chroot/sbom-chroot.bb                |  11 +-
>   .../sbuild-chroot/sbuild-chroot.inc           |  24 ++-
>   scripts/isar-clean-builddir                   |  73 +++++++
>   scripts/run-tests.sh                          |   7 +-
>   testsuite/cibuilder.py                        |   7 +
>   .../unittests/test_image_account_extension.py |   9 +-
>   27 files changed, 886 insertions(+), 241 deletions(-)
>   create mode 100755 scripts/isar-clean-builddir
>

-- 
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/8642c7eb-3b27-41ed-a10a-bf3651cf4318%40ilbers.de.

      parent reply	other threads:[~2026-07-17 13:50 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-15 11:05 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 01/17] refactor bootstrap: store rootfs tar with user permissions 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 02/17] deb-dl-dir: export without root privileges 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 03/17] download debs without locking 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 04/17] introduce wrappers for privileged execution 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 05/17] bootstrap: move cleanup trap to function 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 06/17] rootfs: rework sstate caching of rootfs artifact 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 07/17] rootfs_generate_initramfs: rework deployment to avoid chowning 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 08/17] use bitbake function to generate mounting scripts 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 09/17] apt-fetcher: prepare for chroot specific fetching 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 10/17] add support for fully rootless builds 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 11/17] add helper script to clean artifacts in build dir 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 12/17] apt-fetcher: implement support for unshare backend 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 13/17] dpkg-source: implement multiarch " 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 14/17] use copy of sbom-chroot for sbom creation 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 15/17] add support for devshell on unshare backend 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 16/17] testsuite: add parameter to run tests in rootless mode 'Felix Moessbauer' via isar-users
2026-07-15 11:05 ` [PATCH v8 17/17] run-tests: add support for isar-rootless mode 'Felix Moessbauer' via isar-users
2026-07-17 13:50 ` Zhihang Wei [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=8642c7eb-3b27-41ed-a10a-bf3651cf4318@ilbers.de \
    --to=wzh@ilbers.de \
    --cc=felix.moessbauer@siemens.com \
    --cc=isar-users@googlegroups.com \
    --cc=jan.kiszka@siemens.com \
    --cc=quirin.gylstorff@siemens.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox