From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Fri, 17 Jul 2026 15:50:31 +0200 X-Sieve: CMU Sieve 2.4 Received: from mail-ed1-f56.google.com (mail-ed1-f56.google.com [209.85.208.56]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 66HDoUqB004761 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Fri, 17 Jul 2026 15:50:30 +0200 Received: by mail-ed1-f56.google.com with SMTP id 4fb4d7f45d1cf-69cd6606b19sf4850597a12.1 for ; Fri, 17 Jul 2026 06:50:30 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1784296225; cv=pass; d=google.com; s=arc-20260327; b=pMYmdAsWheDyzUrizl3tuDAzms6x71gdkpUJnfbQh9kGPnreJiqKOt6goYJKxfX0wD VcClW+uZ+g0oV3gFoCYX85JCC9o3b2xWrQvcqFzUmwna27NcQ9N90CLgAWKEba/tKk/H hYyh5GPnVWKQFxJtHG0wPm7tEltjz7q9tOIYfAJ3NeZLarkcBka0SAuxLJ7mqDDWWSaW b/LRc5MqoAxFdVKaZbZugeP+6SErQYxvUo5ZYhUvq2TbcU/GO5k+47GjT/xjTNRttDoJ EuJvAeClkKGjSUZsvYkrmcMaMOS0aFO0MkdeDD9HSwjSOZzt1dIiiXj89+apuz7+Gt1K yv4A== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :sender:dkim-signature; bh=feU5lgzZCZzJPnxScv7e4JqvpAuwlKyDz/1zqmc75P0=; fh=1zGG4SJodXHW2x4kb1ff2X80XCRpFxwIJA9k1UjRQ50=; b=sUVe6rdlmSZN20MUfV7fM5ZYJxUDZjV+HRu3YvA69vjMl19qArI7KyCLqYgoJM15Ot xn5rBRv51HPsglVzYKwyxmsTMOYLlIomQMSQOie8cGdaMFXqNqYc2mHCQxnSmP99i3jw d7BnavMj8UgilOLfYH1v4ObApTnAmg5d2oDZRk9ivXmYTDlQNhZPd3XCx2w98E8rkkhw 4wiUrCxCj40bx9lXOtiwDeoHHEXBVMw6UknLWZuyHg2VNh7DRYuDStddW4uG9xd5ZQHS ffOShbAoHuwvupMX0ShfwwSdj/igipsNNgBXFnU2cFMn5V/eSein/aJYxhMk3aSm4AuJ 80JA==; darn=ilbers.de ARC-Authentication-Results: i=2; gmr-mx.google.com; spf=pass (google.com: domain of wzh@ilbers.de designates 85.214.156.166 as permitted sender) smtp.mailfrom=wzh@ilbers.de DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20251104; t=1784296225; x=1784901025; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-authentication-results :x-original-sender:content-type:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :sender:from:to:cc:subject:date:message-id:reply-to:content-type; bh=feU5lgzZCZzJPnxScv7e4JqvpAuwlKyDz/1zqmc75P0=; b=punm4VS1mvUKZPW2MmMlimciWxaKIfKBbyOKFnMFF8QSLdZkPYAu1MK8OYhDSYQ92G lL3ljMGBbgpqP5dNoJ6ocrwpH8QqKH6B8xSNd/ADqtgEsB4OMeDujVVlH1N7zQ/RL1yq 2wV6pMhyCuLp+TZsjC4jFeF1YDBGExPgXo+VaJ/IkarnjIr91uSlO9f+VW/0T0ibUtKP 8pQyDtRTJ5vSJavMvurt38oBTxk3FzvM1tQZmLfneb02FDzeNie6y0YXpGrGBwgu3wOk QMqUqAPcYZH3G+GPhYg1gvi+loo/9SblTLXNCETlODkA3/MSNqcG9knl+hVzQonQAjsW gesg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784296225; x=1784901025; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence :x-original-authentication-results:x-original-sender:content-type :in-reply-to:from:content-language:references:cc:to:subject :user-agent:mime-version:date:message-id:x-beenthere :x-gm-message-state:sender:from:to:cc:subject:date:message-id :reply-to:content-type; bh=feU5lgzZCZzJPnxScv7e4JqvpAuwlKyDz/1zqmc75P0=; b=sKFyyP1cP9N1m1XWj8n4n8cnsXJmfj7PPMFaiuOhXePRVMdanqO2R0wR+TimY2jzVG p74xoCP297Q1o6aW9/Mj7iDP4R8vacNNiKXG+vFA+Pc4n9S25v1Vs8WRn1HaVBew7yPU D/Ffy1Br5lTtF6khiVRU9huUgY3BBJW7JXn3y6m5wgSZKVqekFRRCnV8pz2wnmY7P/Or CxbpE8R6ZmEDb4rMDQGIgIasRkbvRC4Gnx1Yz598MnXuvyyq0ymn/pIeaH/NPtQ76aWl 13BiYUHl+YIzsMRcX82QGSQD4vwTf4M/c9oT2HFlVyiMlc8Wx9mocUGVItman8B9juWq 68YQ== Sender: isar-users@googlegroups.com X-Forwarded-Encrypted: i=2; AHgh+Rqe5v9raZ9T427Z9BzaHLxgpaXCLyZVVFOxitjg7/sTknqtqRpUrhx1VI9t1SfyogZx1ziD@ilbers.de X-Gm-Message-State: AOJu0Yw5ovr5Scq/3uYHxw/pezwy3H51zvYFZNxKm1pxmIj36tDuKMyD l7RIXiz90tu50rZDYS5F9rczgPQP7xpIGNZzMWlLMjrwNzSSaxnX1je0 X-Received: by 2002:a05:6402:a514:10b0:69a:bce:f1de with SMTP id 4fb4d7f45d1cf-69e652aed2bmr788063a12.26.1784296225197; Fri, 17 Jul 2026 06:50:25 -0700 (PDT) X-BeenThere: isar-users@googlegroups.com; h="Aa7YSPT5eDcQ5u+dk581UoBfmyXGYNFWJxbihOZKskuC6H78NQ==" Received: by 2002:a05:6402:3041:20b0:697:59b1:5eb9 with SMTP id 4fb4d7f45d1cf-69e4cc97be4ls1660252a12.2.-pod-prod-03-eu; Fri, 17 Jul 2026 06:50:22 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RoZziOR1OIJSP0lpEhQG5FIRdTHJ/YJOi5XzRU/ZFIWahGAcyrsjilVZD0FlNj4lC0MxNjq9DPNNVO5@googlegroups.com X-Received: by 2002:a05:6402:2410:b0:69c:769d:6eb6 with SMTP id 4fb4d7f45d1cf-69e652c23d2mr1122814a12.31.1784296222022; Fri, 17 Jul 2026 06:50:22 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1784296222; cv=none; d=google.com; s=arc-20260327; b=bf6niQW2Pynw1ulCTu0LusS3le7Oi+qGbfeiErePY+xKrjpo8I0yQbO8DHFLDUoB7Q W9KtOBxtGnPQQ7SsErnNNiL08wpBbJqzn6hTmkgQuP3nRm/sk5kfYvULDZpwy251v5j+ tqEVEx8vaVfP3KpAjgkOPRzDIw0wX8HlWvuPItWx9Ns3r8kTsQimn2ORy9R+wnDyh6R8 boE7fNOudi6II6RGg9WO/eSQhLyILvTLuWU5dwK61iJ6Z96+wTzGAQ6yV+fbvOIL7/2S Ter4pE29tObVwC0F0/LCVWampaJSyclgsR4xnD8FVrrEUNdTuU35FprCm75JMWquliSW uA6g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id; bh=Y//T88pyEyEOXgxO459K0PJRS0gsaHuz/8zq8sQ06Sg=; fh=aM+XVJzw2ahpEoNJzMYTk1qqXlaHrvkUStg13X+UaOc=; b=FrNDgCGNBztN0sO+UnH5F4IIM40Jw38cK/DchqhzUnpogRsuQ+CZ70A9mt21G0Loya yeWBb1fceyV8W7R6khKymCrZYQiocBMndEJbEZhnMgA3qsojUBK6/zg2l21Bin6Gea6U D+4hbhIsSGll7e/9V8zn6T28/T4aVUIBOh6zRMh5+papzdArBjC+JTAhexlVGTUYRpV/ jc8IH9mHo6BBAAzAVmCn+7NVA+lmLG5zf4BVp2ieMo6jBfF4HWqysS0N31RNM0mXmmGP DowohgrlhDuOR/VsWoE8pWwTxv4/s9+b3ZaLzLBGvY91ZUXAJsTRndae072i9zrmkH7/ cMNw==; dara=google.com ARC-Authentication-Results: i=1; gmr-mx.google.com; spf=pass (google.com: domain of wzh@ilbers.de designates 85.214.156.166 as permitted sender) smtp.mailfrom=wzh@ilbers.de Received: from shymkent.ilbers.de (shymkent.ilbers.de. [85.214.156.166]) by gmr-mx.google.com with ESMTPS id 4fb4d7f45d1cf-69e6ffe198csi34744a12.6.2026.07.17.06.50.21 for (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Fri, 17 Jul 2026 06:50:21 -0700 (PDT) Received-SPF: pass (google.com: domain of wzh@ilbers.de designates 85.214.156.166 as permitted sender) client-ip=85.214.156.166; Received: from [192.168.178.148] ([88.130.203.42]) (authenticated bits=0) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPSA id 66HDoK7b004749 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 17 Jul 2026 15:50:21 +0200 Message-ID: <8642c7eb-3b27-41ed-a10a-bf3651cf4318@ilbers.de> Date: Fri, 17 Jul 2026 15:50:20 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v8 00/17] add support to build isar unprivileged To: Felix Moessbauer , isar-users@googlegroups.com Cc: jan.kiszka@siemens.com, quirin.gylstorff@siemens.com References: <20260715110548.3605767-1-felix.moessbauer@siemens.com> Content-Language: en-US From: Zhihang Wei In-Reply-To: <20260715110548.3605767-1-felix.moessbauer@siemens.com> Content-Type: text/plain; charset="UTF-8"; format=flowed X-Spam-Status: No, score=-4.6 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_EF,HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H2, RCVD_IN_RP_CERTIFIED,RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-Original-Sender: wzh@ilbers.de X-Original-Authentication-Results: gmr-mx.google.com; spf=pass (google.com: domain of wzh@ilbers.de designates 85.214.156.166 as permitted sender) smtp.mailfrom=wzh@ilbers.de Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-TUID: DPjl2DyawlIN Applied to next, thanks! Zhihang On 7/15/26 13:05, 'Felix Moessbauer' via isar-users wrote: > Dear isar-users, > > currently isar requires password-less sudo and an environment > where mounting file systems is possible. This has proven problematic > for security reasons, both when running in a privileged container or > locally. > > To solve this, we implement fully rootless builds that rely on the > unshare syscall which allows us to avoid sudo and instead operate in > temporary kernel namespaces as a user that is just privileged within > that namespace. This comes with some challenges regarding the handling > of mounts (they are cleared when leaving the namespace), as well as > cross namespace deployments (the outer user might not be able to access > the inner data). For that, we rework the handling of mounts and artifact > passing to make it compatible with both chroot modes (schroot and > unshare). > > Note, that this series can be tested on a custom kas-container build > provided in [1]. Hints how to migrate downstream layers are provided > in the API changelog. > > Changes since PATCH v7: > > - rebased onto next > - consistently format apt args (-o ... instead of -o...) > - rootfs: fix check for ISAR_USE_CACHED_BASE_REPO > - rootfs: remove left-over debug statement > - report error if idmap is not available in unshare mode (instead of crashing) > > Changes since PATCH v6: > > - rebased onto next > - p10: revert rootfs_install_pkgs_download to bwrap-based implementation, > restoring old build performances. The underlying issue was finally > understood, so the pattern could stay also under rootless. > > Changes since PATCH v5: > > - rebased onto next > - adjust to changes from "Rootfs install race fix for isar-apt packages": > Manually add isar-apt mount in rootfs_install_pkgs_isar_download on > rootless > - adjust to changes in "image-postproc: gate systemd preset-all on masked > unit state": Trivial change to use run_in_chroot instead of sudo chroot. > > Changes since PATCH v4: > > - fix cleanup trap in do_bootstrap (only functional change) > - keep build_system entries as "isar" until we have official kas support > (and for backwards compatibility). Add reasoning to commit message > - improve RECIPE-API-CHANGELOG (the kas interfaces are stable now, but > not yet released) > > Changes since PATCH v3: > > - fix dracut initrd build issue (p7) > - testsuite: print if rootless mode is used in summary > - testsuite: append newline after ISAR_ROOTLESS = "1" in ci config > - run-tests.sh: catch -p rootless=1 flag and start container in rootless mode > (requires a not-yet released kas-container, corresponding kas patches > are currently under review) > > Changes since PATCH v2: > > - add support for cached base apt > - rootfs sstate: do not rely on fd3 for copy out, as not always available > - sbom: use local copy of sbom rootfs to not leave shared instance behind > - testsuite: add parameter to run in rootless mode > - rebased onto v1.0 > > Changes since PATCH v1: > > - fixed broken rebase onto next > - fix root_cleandirs implementation > > NOTE: This requires the kas series (v3) from [1] for rootless building. > > Changes since RFC 2: > > - rebased onto next > - fix usage of root_cleandirs > - simplify file permission handling by mapping caller user to > root inside the namespace. By that, in most cases no changes > to the imager are needed anymore. > - implement support for devshell under rootless > - switch to getpass.getuser() to query user (needed for dynamically > created / remapped kas builder user) > - rework mapping to be more similar to mapping used by mmdebstrap > - sbuild: only copy-out of dpkg.log on schroot (unclear if needed > on unshare. To be clarified) > - imager-sbom: ensure sbom is extracted before entering the chroot > > Changes since RFC 1: > > - switch build_type to isar-rootless in isar.yaml (Note: switch back > if testing locally in a unprepared kas container) > - complete overhaul of the mounting in unshared namespaces > - fixes the systemd presetting > - fixes hangs when pulling from snapshot mirrors > - rename the run_privileged_here to run_privileged_heredoc to clarify its intention > - add support for > - dpkg-source with do_fetch_common_source > - vm images > - container images > - discoverable disk images > - add helper script to clean build dir in unprivileged mode > - reduce clutter we leave after finishing a build > - fix issues when running in a privileged environment without sub user ids > - bugfixes > > Note, that the rootless build dir must not reside in a git worktree (a normal git > dir is fine). This is probably a bug in combination with kas-container. > > [1] https://groups.google.com/g/kas-devel/c/NWQFCU2aUHg > > Best regards, > Felix Moessbauer > Siemens AG > > Felix Moessbauer (17): > refactor bootstrap: store rootfs tar with user permissions > deb-dl-dir: export without root privileges > download debs without locking > introduce wrappers for privileged execution > bootstrap: move cleanup trap to function > rootfs: rework sstate caching of rootfs artifact > rootfs_generate_initramfs: rework deployment to avoid chowning > use bitbake function to generate mounting scripts > apt-fetcher: prepare for chroot specific fetching > add support for fully rootless builds > add helper script to clean artifacts in build dir > apt-fetcher: implement support for unshare backend > dpkg-source: implement multiarch support for unshare backend > use copy of sbom-chroot for sbom creation > add support for devshell on unshare backend > testsuite: add parameter to run tests in rootless mode > run-tests: add support for isar-rootless mode > > RECIPE-API-CHANGELOG.md | 41 ++++ > doc/user_manual.md | 2 + > meta/classes-global/base.bbclass | 128 +++++++++++- > meta/classes-recipe/deb-dl-dir.bbclass | 22 +- > meta/classes-recipe/dpkg-base.bbclass | 94 +++++++-- > meta/classes-recipe/dpkg-source.bbclass | 40 +++- > meta/classes-recipe/dpkg.bbclass | 19 +- > .../image-account-extension.bbclass | 4 +- > .../image-locales-extension.bbclass | 13 +- > .../image-postproc-extension.bbclass | 30 +-- > .../image-tools-extension.bbclass | 114 +++++++++- > meta/classes-recipe/image.bbclass | 21 +- > .../imagetypes_container.bbclass | 28 +-- > meta/classes-recipe/imagetypes_wic.bbclass | 10 +- > meta/classes-recipe/rootfs.bbclass | 196 +++++++++--------- > meta/classes-recipe/sbuild.bbclass | 34 ++- > meta/classes-recipe/sdk.bbclass | 22 +- > meta/classes/sbom.bbclass | 28 ++- > meta/conf/bitbake.conf | 7 +- > meta/lib/aptsrc_fetcher.py | 87 +++++++- > .../isar-mmdebstrap/isar-mmdebstrap.inc | 56 +++-- > .../sbom-chroot/sbom-chroot.bb | 11 +- > .../sbuild-chroot/sbuild-chroot.inc | 24 ++- > scripts/isar-clean-builddir | 73 +++++++ > scripts/run-tests.sh | 7 +- > testsuite/cibuilder.py | 7 + > .../unittests/test_image_account_extension.py | 9 +- > 27 files changed, 886 insertions(+), 241 deletions(-) > create mode 100755 scripts/isar-clean-builddir > -- You received this message because you are subscribed to the Google Groups "isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/8642c7eb-3b27-41ed-a10a-bf3651cf4318%40ilbers.de.