From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Fri, 29 May 2026 15:07:47 +0200 X-Sieve: CMU Sieve 2.4 Received: from mail-dy1-f184.google.com (mail-dy1-f184.google.com [74.125.82.184]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 64TD7jNL010406 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Fri, 29 May 2026 15:07:46 +0200 Received: by mail-dy1-f184.google.com with SMTP id 5a478bee46e88-2fe1cf409a1sf4030338eec.1 for ; Fri, 29 May 2026 06:07:46 -0700 (PDT) ARC-Seal: i=3; a=rsa-sha256; t=1780060059; cv=pass; d=google.com; s=arc-20240605; b=C215cwfhIWAzZzpPDylE77brgVFQeDuJZPioOcoOkMihZEbUYVwLIgZtHuW8abu49s DqKnMI06eUqxCF47UXuhkVw6KTAo7xXtOzbEJkh+1kcmcanFrGJmRHLpdVBmkiF2biFF tLZ4jw9jw8Sz+zZ0FyeN7M4IbgyWsaGnrZeVm7/GNCWErr1M5KvrdgXDwoAtsZJAWfw5 f7kaLniG1v64s51fz1duj8kwILmmr3Iy1U3a6avym/FTblmBBw6/8OnX3TrM2J8J2Gdm ysnYig7SHeVmXWcoAi1TYYhyFsIlLjw+0tQ9/icBPzkRl9kWP/21+zqnrxA2a8PgzFSc 3Hhg== ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:mime-version :content-transfer-encoding:content-id:user-agent:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:dkim-signature; bh=cLzlKk1P+ieAPMKmTqRMUMFWt48Nmyf/8aTyBVjkWz4=; fh=5uxsFZsVDQvTM5+KbBFGWg+AcVucrwZiGlOAk9sYL7o=; b=ki6laE5cv3LwKSyDaa561sg3jdcF+mM2B9jSrDBLUdrl6OitynGdT/t2DxNdeeTNqe ULvgz2+4jZJB/YaWC9Nj9j9RaWLlhL2Lqd8XvnDQr6z+pRZTpYsx5/kAhkOtT4RuDKAG BFzgOWv9AQmJx0agDkCN3VDCT9C1LHPuh4Co3W5yVjq3OLXAdYUoDrUTPIeE88Qh6yEa nUNKODZjPaEW6DEEUJnFc4v6Q4o7al7phpBQZ17DWBDmSppU1CeNaSZkNpntRVN8nugc 4ydaZgruGfppWDAJV9uLGDst/Bq6pojE/yfQLxCEonr/swnL3jKordGPtGFTz8hoPEtp 44NA==; darn=ilbers.de ARC-Authentication-Results: i=3; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=IewT1SAD; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::3 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20251104; t=1780060059; x=1780664859; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :content-transfer-encoding:content-id:user-agent:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:from:to:cc:subject:date:message-id :reply-to; bh=cLzlKk1P+ieAPMKmTqRMUMFWt48Nmyf/8aTyBVjkWz4=; b=dXlAzovahh+qLLE8U1WC3bWrVLko5xrzMrxJz/rfIF4IeEErND/h1UNQZtFiMp6LD/ 78UEkhNK22NLfCQIV9K9m4M4XzzUjTInRGVmtO308fatc7BbcVVJEspfw576vq39Mooc iVKlXt6pxUkIrP5YshTYJfqOCEoL7HKbRKiVq5waX8U1ykxWyOQJH1PNifCwEa+ZV1sy OM3XXzKfuJVvMV/ED+AZbx5IBm6o7itsuh4Hgq/PcA09Nb9NAr9mC8O5qhtx5GpDGas9 ViApxqOXbg0VKx+2Mi4fJ2p5SCPas47+Lq5tHO1dp5Q3sSai6FlYKdBcbzxNWKmREN48 bqmQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780060059; x=1780664859; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :content-transfer-encoding:content-id:user-agent:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:x-beenthere:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=cLzlKk1P+ieAPMKmTqRMUMFWt48Nmyf/8aTyBVjkWz4=; b=k69YWMvASqrMuFWyIN3NmP58rjZsMy0eUGyeOkEomRgXNLLxlf50a+dbs7s35XmBOz +BSGcVcIF5NdNj+eZtTAWfPnHv/AM10d0YRVx+Jy0UCGGkh1cmLW5YSCoNjdKn7fPJaB ojxWDlEF8XfPu9Hla5ilkoUE0oGx4op8oJivXR9RKQtl69LQPvM9KSSoCbLnzcNpF5A2 20ST67gUpAepjcE/A0gZBo+P4s3x4YujApSMPqTgCbxlWdkN27bfQihhMYPYVNccuJL6 DRGo/lEna2KP/8TE8n+N0UIVIOvK2CZyZXAGHH5+YgHgOAFKd5ob3ETucskaLk+kwyFL rXoQ== X-Forwarded-Encrypted: i=3; AFNElJ+aHYmMe/u1ihT3ie42DbqelWM7HCRo3dUIvdOYs3C0it9gbSL/saIy6blnObC4UVpZSfy8@ilbers.de X-Gm-Message-State: AOJu0YzqVUXNSiKfePKdOs8Nm5gWrVFpLrEWFDM3Jcn5X/ox/N8twxeg ziQGoCLCSTxRRMXcem0o+uo4/ix2rfFaQSDDS5VXQZTX3eM+LRSavlrj X-Received: by 2002:a05:7022:eca:b0:132:5d96:3e48 with SMTP id a92af1059eb24-137aeee9510mr1090460c88.38.1780060059125; Fri, 29 May 2026 06:07:39 -0700 (PDT) X-BeenThere: isar-users@googlegroups.com; h="AUV6zMORwme0AEBP/8kOMgXJlyH6tP0KfgDAVNIsxjsP8HMv4Q==" Received: by 2002:a05:701a:c944:b0:128:ee51:a0f0 with SMTP id a92af1059eb24-13773ec0728ls945624c88.0.-pod-prod-04-us; Fri, 29 May 2026 06:07:37 -0700 (PDT) X-Forwarded-Encrypted: i=3; AFNElJ96tsZjN2FOp+Omji9kX6QtQZOTRR1zPT7m2QZYx9ws+F5e8p4liEJSwzsemwExX0uqZoJ6QeL8vHfT@googlegroups.com X-Received: by 2002:a05:7300:8ca7:b0:304:5a53:7dac with SMTP id 5a478bee46e88-304eb1d10c2mr1155834eec.25.1780060057060; Fri, 29 May 2026 06:07:37 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1780060057; cv=pass; d=google.com; s=arc-20240605; b=iQYJAfBcV8UVPmNHhNiSwrE8bBxIptAEDMfWvW4cUG9F8lx8+DL7vq709UbvWy0kKa LWJaQFRbciQLkFhlu5jaDd/UTCNWpqAfcdPlpqpjQdO9iTxwUhKd2mKXbVRo5DDCNhK4 EgHP0AEy3n9yaOeARBapZpjyQZMVnlII2TMQE3ixcYLsWiEcqKvs3ZiN14CHpDbgE6Hf rV4GS7E4To8ht9eLEfmntsBAZsXIbJDY9rFu6P+BlYB02paPZJJMdxAcmKlh5yJlAsHm wxIh2DXcahmFCrTdLRSAJT35fQnnKk6lc9nHYbYf4GsjmVB3j0A/rHxnkd6LD23AH4rB pAwg== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=mime-version:content-transfer-encoding:content-id:user-agent :content-language:accept-language:in-reply-to:references:message-id :date:thread-index:thread-topic:subject:cc:to:from:dkim-signature; bh=zNMyZPKAI5u3lUhDshAma+qnUj8b/SDQs631H/w6F7s=; fh=1OYwjxuzjLQA5I7ae2/k5FD/lA9HbhyyKAFqyV5DoNw=; b=Zia7tvYaObX3cDWA+a6hIV+aOqmBx73KWv3jrAhuTILENvKBKkyi9W1PAvUM47uSZx zl12II113wEm7+K+U8agrq4cKkMzhvh+CR7pbNsfgXMjwTowLacEiNlOgoMtrw4JDZgn CsVGR8mhqAtvcSyeUIVtIOmfLTaoKCYwEIvcTGieErUpJRei4qEcBAquiPW1nAad9CRZ IObRgvLgKaXHO9Pc6TV0GsB3PrYe28vOLji3xGveczmQLwqEwKpLIZZjwpaa4EL7Nned Nr53aT2T/hQo+3NRrQwAE/rRQX5HK6hMifM8N5PfVobmjaUqtmrHS0aH0phCQCpKFX4z RaEQ==; dara=google.com ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=IewT1SAD; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::3 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com Received: from AS8PR04CU009.outbound.protection.outlook.com (mail-westeuropeazlp170110003.outbound.protection.outlook.com. [2a01:111:f403:c201::3]) by gmr-mx.google.com with ESMTPS id 5a478bee46e88-304ed0fc036si56019eec.0.2026.05.29.06.07.36 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 29 May 2026 06:07:36 -0700 (PDT) Received-SPF: pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::3 as permitted sender) client-ip=2a01:111:f403:c201::3; ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=b68vGo0Ni8IyGKff/JJNXGlCzcd6PEp0iUrgngoXRvpH3Z/S55Q4Ak9LZLuaN6i6K3Q3fSqsEEkO6WZzlkIBvSf75wE+Fa3KAvoJwEiCiQbzo8Qy7gjkm968Ss2tS20xkrmbC9zapO/iFB8oAFr/2T2P3zQXzCinc+ShL+4/5vpZHFC4TCVx7QNef+06ukqJxZAvDEfWNPTRM7W3EQfIsNqFGd1Sto0MtA/dAHH1Qxg/FLAX364m5fruwsecMYQXXdm2J8ZujSiJLHhlejAC+XMVc295QF4blE9kvXDbKyW1vYk7j8pN/ztFHcfS6H5yOvyD38bZirtKs4HPdv9a/A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=zNMyZPKAI5u3lUhDshAma+qnUj8b/SDQs631H/w6F7s=; b=Up1H4JMoPhg3cYF6FbHa0LL6Pf3Numlcyu1OLTR43CnrhVuzpjvfn1fctmqzvjRZWXDI370TS2/2IphvjjCrMDkdXnmNWegfgYOwlY+JK8hzlsMQ6TlmJhyihtarzNrd2+8mawBRrXFynGQ7z1Lrip+osOwxt+3WjYeTzs+xPo1kAyDPV+Nxc54cQyc3Bx98+HKV6KHQcBMpAnYDIQgJjqR1N0gy1Knd6Pu+GD0Hx+uznOqTrj0f2s1b33QxF7rKQH4iWUNWqT3PMlm9Xo+zQ4jrDhMEj5qlGKBotmkWyWZ/ckYnQx6rSpsQDNr5Bk7/ere5K8MTeeCv/GCOp5FQ9w== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none Received: from AS8PR10MB5952.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:52f::15) by PR3PR10MB4061.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:a1::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.71.15; Fri, 29 May 2026 13:07:33 +0000 Received: from AS8PR10MB5952.EURPRD10.PROD.OUTLOOK.COM ([fe80::2547:a1f4:bf9d:cb19]) by AS8PR10MB5952.EURPRD10.PROD.OUTLOOK.COM ([fe80::2547:a1f4:bf9d:cb19%3]) with mapi id 15.21.0071.014; Fri, 29 May 2026 13:07:33 +0000 From: "'MOESSBAUER, Felix' via isar-users" To: Zhihang Wei , "isar-users@googlegroups.com" CC: "Kiszka, Jan" , "Gylstorff, Quirin" Subject: Re: [PATCH v3 00/16] add support to build isar unprivileged Thread-Topic: [PATCH v3 00/16] add support to build isar unprivileged Thread-Index: AQHcxpoUqrGtSm3Ub0eOFZAq1Hv7kbYgWvmAgATlNICAAArYgA== Date: Fri, 29 May 2026 13:07:33 +0000 Message-ID: References: <20260407142310.2327696-1-felix.moessbauer@siemens.com> <88aa53960d349c6679345286a5bed59113b0661d.camel@siemens.com> <892939b2-5d73-4bd2-b1d8-dbd918f9fb23@ilbers.de> In-Reply-To: <892939b2-5d73-4bd2-b1d8-dbd918f9fb23@ilbers.de> Accept-Language: de-DE, en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: user-agent: Evolution 3.56.2-9 x-ms-publictraffictype: Email x-ms-traffictypediagnostic: AS8PR10MB5952:EE_|PR3PR10MB4061:EE_ x-ms-office365-filtering-correlation-id: 56373fed-6c86-4d2c-6bc8-08debd833f75 x-ms-exchange-atpmessageproperties: SA x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|376014|366016|38070700021|55112099003|18002099003|22082099003|6133799003|3023799007|56012099006|4143699003|5023799004|11063799006; x-microsoft-antispam-message-info: dwGDBrDQsxon7Hi97o/Hcnd/sN8QT3S3ouZ128C+abm3OourMQKp8jg8AR7kLFsh5bcaXX8NhsHePP+Zq4WnwVs8VoG9lTUKdZYkoKT6P9LpAaEQm3FNHUoDocCCOZQa4knPzgDFBnyXudgvGQ2N1XJA2SOZei8o4RN986PKkyj59tGM4Aej6sQUOeWXgGM0Blqf62VwS6Oouxi8PJGMjKlserHDrxpHBzAY8AHH6lToPlSVpPxrkIkLeBHY+JsvKivxGtzC4r2s7J17GxfO2+pp+J9jWYYUQ356cVsvAZ1riyUO4y3hNS5yt3GFeAfPsc0iwWPoOnfNDGnJcIb111oyZ1ywmCz25WAFipOcMv6sH5qmpRTARSDklkp3IFsi2RvmFNBSbweW/DmIKKHSwLYu5yJvDYZfQKv1RT8JyQbtmcmZa/5UYjgovt8fEJA5IYR2U/GUSXveTjJTiidJwvmV1rKANzBpE+GM2F2PcQKyv+5w7m1VTn2QPIGXEhpHSr2AJlbzfhXjCH3iDWJC0dw/6W4/M1aMunKk3NXhj6GHSG7Tk1NZ5KlXs0o3wGtRO+Kum2oIj79oHsgfgDQywQVOy96PN4DtnOnCt3Ml34RtoydBXhQhIcMndrqoWLecjdKGwKR5ExHS1QRhG0i3PERounGMOMLenEIq/GpRffBqdkaHFXyljnGG1yzzNpBv59uw5wq/GshhyAi4ybjr8g== x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AS8PR10MB5952.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(376014)(366016)(38070700021)(55112099003)(18002099003)(22082099003)(6133799003)(3023799007)(56012099006)(4143699003)(5023799004)(11063799006);DIR:OUT;SFP:1101; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?utf-8?B?WnFLOExKSmg2Wll6TVMyZnJhbkw3NmlKeHE2d2hObkJhU0xKR0Y1V2VVRitk?= =?utf-8?B?NG1IcnJwNmF5ZmR5NGljbFdrSVhCVXpUN2pqU1BVQm9nQi9lMWE3YW1XVEJZ?= =?utf-8?B?cldPSFYxTTdSQjVuRkNWamVod0NwZWlkbVRqUzR5bExDM2dPRFNmR2g1Q3Zp?= =?utf-8?B?MDBtaEJNaXZtYVRob3EwR3hSTFlHVmk3UlRFeWJEWXBXOXJTcG4ySExNNm9r?= =?utf-8?B?YTF0ZWlDQkZOazAzeDNBaGU5RVZUdmR6cjk2OHk2MytkSUhOTEhQalBlRFJQ?= =?utf-8?B?YnZXWDRhWUg3TEM0Tng5dEdrTlNGQWFsSjFWWElOaHBrN0hlMCtrWDJqak81?= =?utf-8?B?M2RSNUdmZy9QaG9Kblh5ZmdpRzZ0UmRPYzM5WjVOdGtIK1JlUzRKZjdscW9I?= =?utf-8?B?UlQ2ckZvUWNJZ2NHUER3ZDFaN1pVUEQrQmxiQ05kZ3pMZjlXWDJPTGhwb0lG?= =?utf-8?B?elRQVDE3MkM0V1UvZmdmWjVrZ21IMlhLMVN2SkY1dHBDWlpDUTYxQXNiWXdD?= =?utf-8?B?VmJnVTZZMCsxVnlNU0J6MjJqcHdlc1QrQkx4UGtpYXg0eC9JblFsdVhCTDB1?= =?utf-8?B?UDd3NkNzUXl5RGp3Vm8xUi95anZTaW1vRks1QzBGSTZGVnRvTDhsdDR6UlpV?= =?utf-8?B?VDA0Vlc2blpOZDc5L1FNR1hCOTVxSFk5ZHprZ3pVUEI3SnhhM3NkQ3VBWFor?= =?utf-8?B?cG9LeTdnUEh1Rk51YkFZVDdkcHcxUVpHRVI1eXZXeVlsSlZtRTR6aUgrUnV2?= =?utf-8?B?MnI5Qk1HbERIVGRud1VqQmFrckd6NDZQY2hZLzA2ZXF0TVBxL3hnZmZjeG5D?= =?utf-8?B?R3JMTVRnWnhTMW9YNGFsRkIzNFNTdlgxaXVvdjZiK3NEQ3h0cHlmRVA3WlAv?= =?utf-8?B?aW1ZdHZreTV4MXR4Q0pnOUM0akFOWG52WWxWYTJlU1ZxM0VHNGJCeWhkem5o?= =?utf-8?B?RUlzK2RFbWk4NnlJNy9ZSVd5WE9NVUZmUWZyTlozOGFFdkZhUlhPb3I2dXh4?= =?utf-8?B?WDFWZGxQU0wzSXN5UjhMNWdmM1pMMDdQWVNObXJYdFAzMTJMdGNJQkdLUUtW?= =?utf-8?B?VmI0ei9iRUpZU0xPVThKb2JDdXZkRjJKTGpjYjhTdlRKVjN3by80SlpRRXd0?= =?utf-8?B?eVYrK1dqL0JBUXpycmhkMWJFazhPWGpZamdkaGhoRTJ6Nkp2UWxlaE5rN1Y3?= =?utf-8?B?LzhGTHRJWGxkY1NxNTJoL0R1OWdreVNzNWpGaVF2UjZMNE0vZy9iSGxCTWtv?= =?utf-8?B?UU15VXBrdm1rQmZRZGx1TVVWV2NEN3EvM0R3TGJZeXlqL3FpeDhUS0w5cTdp?= =?utf-8?B?UWpOd3I1U3BvWTN0VnBQUVVOdUpyeW1LWjVXNVFJTU5NOFdiRjNXaHA5Ym1M?= =?utf-8?B?L05Pd3VQSk5GTUZhNzNXNGQ4UlpSUkd1N1hwM0t3WVFKSEFQK29VUXpTSkEy?= =?utf-8?B?Q0hHK1NVYlJXS2lNeTQwaC92MU9zcDgwTkkxbHFHYUdOeFVSU0ZtMy9PR05o?= =?utf-8?B?UHdpMGNZZnRraGNIRnMzaE94d3pRaWZyY041TndEQUg4bGxoUFFMQmxDUXB0?= =?utf-8?B?cXZTVm5wM3ZNVHR3K1VEUmk1RUQxUmd5VW42QzljdEJ0RFZOSjBPVzYwUmhF?= =?utf-8?B?WmNYV0l0YjUwcGpFazc0OWttQnBUdVh4bUJWaDlHYjU1SjROYTR4QTIyTXlJ?= =?utf-8?B?UHZpNVJnL0YrUHNaOFl6dHBxTDg2eVRsSVI0dUpCNGZVa1dZU1ZodkxrL2h3?= =?utf-8?B?RTkxbXdnSVhUZU56OVFlOHRjMENmekhWL1gvc0M2SktEYmU5Und0c29WNHhR?= =?utf-8?B?NWw1cXR2M0d4cWloejcrUVdmdDFWbFlTNTkraDV3eHlWNXB3NXN1cW01Y1Bz?= =?utf-8?B?eG1kWlc0QndRZEhiaWZEeklUSUQ0bndXN3RCQTdNSUF5WS9hRHVYNmdsR28w?= =?utf-8?B?Wk11U0wzRTZyUVcvc3h4M0dPUzk4YU9VZWNPbW1WT2NIV2NLTUZJRGtjSitC?= =?utf-8?B?VTV3VXNJSUhCWTNqZWMyZ1hqYTlZOU41bVVqV1AzMWlPNTJXaEtVaFdXYWUw?= =?utf-8?B?N3RNdlNoOGd6aTF4Z29zdTVCUGRzSC9Dc1EveWVZbkNDaHNoKyswTG5ITFNw?= =?utf-8?B?T3I3MFNEeUlFcGFIdnYvazByU3NGa28zY1NIVlNtWlZBVUpwVUVBdnhSVEU0?= =?utf-8?B?SjRkUnUwMXI2NGV0ZmhmempKdHQwcUJJVXBsT2dDRFE1cGx0T0JuZWxSRHUy?= =?utf-8?B?dWk3T0s1SmEzcGh1VkF4dWxVWm53OEhMVVdrUkFHNThiVStaaDFQanJoRUsw?= =?utf-8?B?S1pkZ2tUdDBLM21JemVqcnJBaVJ1NnEyV3F3MVUvZGt0TEViN2szUT09?= Content-Type: text/plain; charset="UTF-8" Content-ID: <52BB480A0E67744EBEF80B32578547FF@EURPRD10.PROD.OUTLOOK.COM> Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: AS8PR10MB5952.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-Network-Message-Id: 56373fed-6c86-4d2c-6bc8-08debd833f75 X-MS-Exchange-CrossTenant-originalarrivaltime: 29 May 2026 13:07:33.5764 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: jr3Cp+TrBr9vaU3SFFCqYa/+boMY7n2Gi/zBeHl9XrQWQkE5jKDvIuE8Lz9CJMIc9tO/bWjq9gd6uO1XucdTOvI5wbgMs6ZFqe3jWQNVE38= X-MS-Exchange-Transport-CrossTenantHeadersStamped: PR3PR10MB4061 X-Original-Sender: felix.moessbauer@siemens.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=IewT1SAD; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c201::3 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com X-Original-From: "MOESSBAUER, Felix" Reply-To: "MOESSBAUER, Felix" Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Status: No, score=-4.9 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H3,RCVD_IN_MSPIKE_WL, RCVD_IN_RP_CERTIFIED,RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-TUID: fokOiVkQ194R On Fri, 2026-05-29 at 14:28 +0200, Zhihang Wei wrote: > On 5/26/26 11:43, 'MOESSBAUER, Felix' via isar-users wrote: > > On Tue, 2026-04-07 at 16:22 +0200, Felix Moessbauer wrote: > > > Dear isar-users, > > >=20 > > > currently isar requires password-less sudo and an environment > > > where mounting file systems is possible. This has proven problematic > > > for security reasons, both when running in a privileged container or > > > locally. > > >=20 > > > To solve this, we implement fully rootless builds that rely on the > > > unshare syscall which allows us to avoid sudo and instead operate in > > > temporary kernel namespaces as a user that is just privileged within > > > that namespace. This comes with some challenges regarding the handlin= g > > > of mounts (they are cleared when leaving the namespace), as well as > > > cross namespace deployments (the outer user might not be able to acce= ss > > > the inner data). For that, we rework the handling of mounts and artif= act > > > passing to make it compatible with both chroot modes (schroot and > > > unshare). > > Any news on this one? Do you want me to send a rebase? I did not > > receive any objections regarding the proposed interface on the kas > > side. By that, I would like to move forward with this. > >=20 > > I'm also fine with scheduling this behind the testsuite execution > > series ("Improve testsuite executability, basic GitHub CI"), as this > > significantly simplifies testing. > >=20 > > Just let me know. > >=20 > > Best regards, > > Felix >=20 > Hi Felix, >=20 > We were testing this patch on downstreams and in CI. Tests on=20 > downstreams seem > fine. Hi, that's good to know. The corresponding kas patches are now also rebased and will be added to kas:next soon [1] [1] https://groups.google.com/g/kas-devel/c/ibWQT0-FtCg >=20 > One issue did show up on CI. "InitRdCrossTests.test_dracut_in_image" in f= ull > failed. (There are two test cases named as test_dracut_in_image, one in= =20 > fast, > one in full). >=20 > Specifically, the built image isar-image-ci-debian-bookworm-qemuarm64=20 > does not > boot. I found nothing was added into the initrd. The generated initrd=20 > image has > a size of zero bytes. I'll have a look. Thanks for the detailed report. Just for clarification: Does this fail under rootless or default / root? Best regards, Felix >=20 > The log=20 > tmp/work/debian-bookworm-arm64/isar-dracut-qemuarm64/1.0-r0/temp/log.do_g= enerate_initramfs > coule be relevant. It's pasted below. >=20 > Zhihang >=20 > DEBUG: Executing python function sstate_task_prefunc > DEBUG: Python function sstate_task_prefunc finished > DEBUG: Executing python function do_generate_initramfs > DEBUG: Executing python function rootfs_do_mounts > DEBUG: Executing shell function rootfs_do_mounts_priv > DEBUG: Shell function rootfs_do_mounts_priv finished > DEBUG: Python function rootfs_do_mounts finished > DEBUG: Executing shell function rootfs_do_qemu > DEBUG: Shell function rootfs_do_qemu finished > DEBUG: Executing shell function rootfs_generate_initramfs > Total number of modules: 3684 > Generating initrd for kernel version: 6.1.0-49-arm64 > dracut: Executing: /usr/bin/dracut --force --kver 6.1.0-49-arm64 --add=20 > example-lighttpd > dracut: dracut module 'mksh' will not be installed, because command=20 > 'mksh' could not be found! > dracut: dracut module 'systemd-coredump' will not be installed, because= =20 > command 'coredumpctl' could not be found! > dracut: dracut module 'systemd-coredump' will not be installed, because= =20 > command '/usr/lib/systemd/systemd-coredump' could not be found! > dracut: dracut module 'systemd-portabled' will not be installed, because= =20 > command 'portablectl' could not be found! > dracut: dracut module 'systemd-portabled' will not be installed, because= =20 > command '/usr/lib/systemd/systemd-portabled' could not be found! > dracut: dracut module 'modsign' will not be installed, because command=20 > 'keyctl' could not be found! > dracut: dracut module 'busybox' will not be installed, because command=20 > 'busybox' could not be found! > dracut: dracut module 'dbus-broker' will not be installed, because=20 > command 'dbus-broker' could not be found! > dracut: dracut module 'rngd' will not be installed, because command=20 > 'rngd' could not be found! > dracut: dracut module 'connman' will not be installed, because command=20 > 'connmand' could not be found! > dracut: dracut module 'connman' will not be installed, because command=20 > 'connmanctl' could not be found! > dracut: dracut module 'connman' will not be installed, because command=20 > 'connmand-wait-online' could not be found! > dracut: dracut module 'network-legacy' will not be installed, because=20 > command 'pgrep' could not be found! > dracut: dracut module 'url-lib' will not be installed, because command=20 > 'curl' could not be found! > dracut: 62bluetooth: Could not find any command of=20 > '/usr/lib/bluetooth/bluetoothd /usr/libexec/bluetooth/bluetoothd'! > dracut: dracut module 'lvmmerge' will not be installed, because command= =20 > 'lvm' could not be found! > dracut: dracut module 'lvmthinpool-monitor' will not be installed,=20 > because command 'lvm' could not be found! > dracut: dracut module 'btrfs' will not be installed, because command=20 > 'btrfs' could not be found! > dracut: dracut module 'dmraid' will not be installed, because command=20 > 'dmraid' could not be found! > dracut: dracut module 'lvm' will not be installed, because command 'lvm'= =20 > could not be found! > dracut: dracut module 'mdraid' will not be installed, because command=20 > 'mdadm' could not be found! > dracut: dracut module 'multipath' will not be installed, because command= =20 > 'multipath' could not be found! > dracut: dracut module 'crypt-gpg' will not be installed, because command= =20 > 'gpg' could not be found! > dracut: dracut module 'pcsc' will not be installed, because command=20 > 'pcscd' could not be found! > dracut: dracut module 'tpm2-tss' will not be installed, because command= =20 > 'tpm2' could not be found! > dracut: dracut module 'cifs' will not be installed, because command=20 > 'mount.cifs' could not be found! > dracut: dracut module 'fcoe' will not be installed, because command=20 > 'dcbtool' could not be found! > dracut: dracut module 'fcoe' will not be installed, because command=20 > 'fipvlan' could not be found! > dracut: dracut module 'fcoe' will not be installed, because command=20 > 'lldpad' could not be found! > dracut: dracut module 'fcoe' will not be installed, because command=20 > 'fcoemon' could not be found! > dracut: dracut module 'fcoe' will not be installed, because command=20 > 'fcoeadm' could not be found! > dracut: dracut module 'fcoe-uefi' will not be installed, because command= =20 > 'dcbtool' could not be found! > dracut: dracut module 'fcoe-uefi' will not be installed, because command= =20 > 'fipvlan' could not be found! > dracut: dracut module 'fcoe-uefi' will not be installed, because command= =20 > 'lldpad' could not be found! > dracut: dracut module 'iscsi' will not be installed, because command=20 > 'iscsi-iname' could not be found! > dracut: dracut module 'iscsi' will not be installed, because command=20 > 'iscsiadm' could not be found! > dracut: dracut module 'iscsi' will not be installed, because command=20 > 'iscsid' could not be found! > dracut: dracut module 'nbd' will not be installed, because command=20 > 'nbd-client' could not be found! > dracut: 95nfs: Could not find any command of 'rpcbind portmap'! > dracut: dracut module 'nvmf' will not be installed, because command=20 > 'nvme' could not be found! > dracut: dracut module 'ssh-client' will not be installed, because=20 > command 'ssh' could not be found! > dracut: dracut module 'ssh-client' will not be installed, because=20 > command 'scp' could not be found! > dracut: dracut module 'biosdevname' will not be installed, because=20 > command 'biosdevname' could not be found! > dracut: dracut module 'memstrack' will not be installed, because command= =20 > 'pgrep' could not be found! > dracut: dracut module 'memstrack' will not be installed, because command= =20 > 'pkill' could not be found! > dracut: dracut module 'memstrack' will not be installed, because command= =20 > 'memstrack' could not be found! > dracut: memstrack is not available > dracut: If you need to use rd.memdebug>=3D4, please install memstrack and= =20 > procps-ng > dracut: *** Including module: systemd *** > dracut: *** Including module: systemd-network-management *** > dracut: *** Including module: systemd-hostnamed *** > dracut: *** Including module: systemd-initrd *** > dracut: *** Including module: systemd-networkd *** > dracut: *** Including module: systemd-resolved *** > dracut: *** Including module: systemd-sysusers *** > dracut: *** Including module: systemd-timedated *** > dracut: *** Including module: systemd-timesyncd *** > dracut: *** Including module: dbus-daemon *** > dracut: *** Including module: dbus *** > dracut: *** Including module: i18n *** > dracut: *** Including module: network *** > dracut-install: ERROR: installing 'pgrep' > dracut: FAILED: /usr/lib/dracut/dracut-install -D=20 > /var/tmp/dracut.SLoX4R/initramfs -a ip sed awk grep pgrep tr > dracut: *** Including module: ifcfg *** > dracut: *** Including module: example-lighttpd *** > /usr/lib/dracut/modules.d/50example-lighttpd/module-setup.sh: line 48:=20 > inst_sysusers: command not found > dracut: *** Including module: crypt *** > dracut: *** Including module: dm *** > dracut: Skipping udev rule: 10-dm.rules > dracut: Skipping udev rule: 13-dm-disk.rules > dracut: Skipping udev rule: 64-device-mapper.rules > dracut: *** Including module: kernel-modules *** > dracut: *** Including module: kernel-modules-extra *** > dracut: *** Including module: kernel-network-modules *** > dracut: *** Including module: nvdimm *** > dracut: *** Including module: overlay-root *** > dracut: *** Including module: qemu *** > dracut: *** Including module: qemu-net *** > dracut: *** Including module: lunmask *** > dracut: *** Including module: resume *** > dracut: *** Including module: rootfs-block *** > dracut: *** Including module: terminfo *** > dracut: *** Including module: udev-rules *** > dracut: Skipping udev rule: 40-redhat.rules > dracut: Skipping udev rule: 91-permissions.rules > dracut: Skipping udev rule: 80-drivers-modprobe.rules > dracut: *** Including module: virtiofs *** > dracut: *** Including module: dracut-systemd *** > dracut: *** Including module: usrmount *** > dracut: *** Including module: base *** > dracut: *** Including module: fs-lib *** > dracut: *** Including module: shutdown *** > dracut: *** Including modules done *** > dracut: *** Installing kernel module dependencies *** > dracut: *** Installing kernel module dependencies done *** > dracut: *** Resolving executable dependencies *** > dracut: *** Resolving executable dependencies done *** > dracut: *** Hardlinking files *** > dracut: Mode:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0real > dracut: Method:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0sha256 > dracut: Files:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 1709 > dracut: Linked:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A01 files > dracut: Compared:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A00 xattrs > dracut: Compared:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0240 files > dracut: Saved:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 690 B > dracut: Duration:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A00.022064 seconds > dracut: *** Hardlinking files done *** > dracut: Could not find 'strip'. Not stripping the initramfs. > dracut: *** Store current command line parameters *** > dracut: *** Creating image file '/boot/initrd.img-6.1.0-49-arm64' *** > dracut: Using auto-determined compression method 'gzip' > dracut: *** Creating initramfs image file=20 > '/boot/initrd.img-6.1.0-49-arm64' done *** > cat:=20 > /isar/build/tmp/work/debian-bookworm-arm64/isar-dracut-qemuarm64/1.0-r0/r= ootfs/boot/initrd.img-6.1.0-49-arm64:=20 > Permission denied > DEBUG: Shell function rootfs_generate_initramfs finished > DEBUG: Executing python function rootfs_do_umounts > DEBUG: Executing shell function rootfs_do_umounts_priv > DEBUG: Shell function rootfs_do_umounts_priv finished > DEBUG: Python function rootfs_do_umounts finished > DEBUG: Python function do_generate_initramfs finished > DEBUG: Executing python function sstate_task_postfunc > NOTE: Using umask 0o002 (not 22) for sstate packaging > DEBUG: Preparing tree=20 > /isar/build/tmp/work/debian-bookworm-arm64/isar-dracut-qemuarm64/1.0-r0/d= eploy=20 > for packaging at=20 > /isar/build/tmp/work/debian-bookworm-arm64/isar-dracut-qemuarm64/1.0-r0/s= state-build-generate_initramfs/deploy > DEBUG: Executing python function sstate_hardcode_path > NOTE: Removing hardcoded paths from sstate package: 'find=20 > /isar/build/tmp/work/debian-bookworm-arm64/isar-dracut-qemuarm64/1.0-r0/s= state-build-generate_initramfs/=20 > \( -name "*.la" -o -name "*-config" -o -name "*_config" -o -name=20 > "postinst-*" \) -type f | xargs grep -l -e 'None' -e 'None' -e 'None' |= =20 > tee=20 > /isar/build/tmp/work/debian-bookworm-arm64/isar-dracut-qemuarm64/1.0-r0/s= state-build-generate_initramfs/fixmepath=20 > | xargs --no-run-if-empty sed -i -e 's:None:FIXMESTAGINGDIRHOST:g' -e=20 > 's:None:FIXMESTAGINGDIRTARGET:g' -e 's:None:FIXME_HOSTTOOLS_DIR:g'' > DEBUG: Python function sstate_hardcode_path finished > DEBUG: Executing shell function rootfs_install_sstate_prepare > DEBUG: Shell function rootfs_install_sstate_prepare finished > DEBUG: Executing python function sstate_report_unihash > DEBUG: Python function sstate_report_unihash finished > DEBUG: Executing shell function sstate_create_package > DEBUG: Shell function sstate_create_package finished > DEBUG: Executing python function sstate_hardcode_path_unpack > DEBUG: Python function sstate_hardcode_path_unpack finished > DEBUG: Staging files from=20 > /isar/build/tmp/work/debian-bookworm-arm64/isar-dracut-qemuarm64/1.0-r0/d= eploy=20 > to /isar/build/tmp/deploy/images/qemuarm64 > DEBUG: Executing shell function rootfs_install_sstate_finalize > DEBUG: Shell function rootfs_install_sstate_finalize finished > DEBUG: Python function sstate_task_postfunc finished --=20 You received this message because you are subscribed to the Google Groups "= isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/= bdc61fdf418877bb36ecca901a1c234e4d7c349e.camel%40siemens.com.