Sunday, 2019-05-26

*** jamesmcarthur has joined #zuul00:42
*** jamesmcarthur has joined #zuul00:45
*** jamesmcarthur has quit IRC00:49
fungiso's stuff as basic as chroot on linux without granting non-default capabilities01:47
SpamapStristanC:well I didn't say it was exactly like bubblewrap :)02:02
fungibubblewrap would need superuser invocation too by default02:03
tristanCfungi: right, though bubblewrap (and rootless containers by extension) are meant to be used by regular user, assuming they don't weaken the system security.02:07
fungiit's invoked setuid=0 in our deployment at least02:07
*** saneax has joined #zuul02:08
fungiso invoked by a normal user but runs in the context of the root superuser anyway02:08
tristanCif the kernel support user namespace, then you bwrap can still work without setuid02:08
tristanCat least by default, further isolation system like docker block user namespace creation with seccomp02:16
tristanCyou can try that with the "unshare" tool, e.g. "unshare --pid --mount --user --map-root-user --fork" let a regular user become root in a namespace, without using any setuid02:33
tristanCand i think this is the relevant policy that blocks that in docker: https://github.com/moby/moby/blob/master/profiles/seccomp/default.json#L592-L60302:43
SpamapSYep, bubblewrap is only installed w/o setuid bits in distros whose kernels support USERNS03:00
SpamapSWhich does not include Debian Jessie or CentOS 703:01
*** jamesmcarthur has joined #zuul03:47
*** jamesmcarthur has quit IRC03:50
*** altlogbot_3 has quit IRC06:29
*** altlogbot_1 has joined #zuul06:31
*** tobiash has quit IRC08:58
*** etp has quit IRC09:03
*** tobiash has joined #zuul09:05
*** tobiash has quit IRC09:09
*** tobiash has joined #zuul09:10
*** etp has joined #zuul09:33
*** etp has quit IRC09:48
*** tosky has joined #zuul13:05
*** lennyb has quit IRC14:02
*** lennyb has joined #zuul14:03
*** lennyb has quit IRC14:03
*** lennyb has joined #zuul14:04
*** sanjayu_ has joined #zuul14:24
*** saneax has quit IRC14:26
*** sanjayu__ has joined #zuul14:30
*** sanjayu_ has quit IRC14:32
*** jamesmcarthur has joined #zuul16:14
*** jamesmcarthur has quit IRC16:33
*** jamesmcarthur has joined #zuul16:34
*** jamesmcarthur has quit IRC16:38
*** jamesmcarthur has joined #zuul17:05
openstackgerritTobias Henkel proposed zuul/zuul master: Annotate logs around build states  https://review.opendev.org/66148917:39
openstackgerritTobias Henkel proposed zuul/zuul master: Annotate logs around reporting  https://review.opendev.org/66149017:39
openstackgerritTobias Henkel proposed zuul/zuul master: Annotate logs around finished builds  https://review.opendev.org/66149117:39
*** jamesmcarthur has quit IRC17:46
*** tosky has quit IRC17:48
*** tosky has joined #zuul17:49
*** jamesmcarthur has joined #zuul18:02
*** jamesmcarthur has quit IRC18:07
*** jamesmcarthur has joined #zuul18:17
*** jamesmcarthur has quit IRC18:40
openstackgerritTobias Henkel proposed zuul/zuul master: Annotate logs around build states  https://review.opendev.org/66148918:42
openstackgerritTobias Henkel proposed zuul/zuul master: Annotate logs around reporting  https://review.opendev.org/66149018:42
openstackgerritTobias Henkel proposed zuul/zuul master: Annotate logs around finished builds  https://review.opendev.org/66149118:42
*** jamesmcarthur has joined #zuul18:43
*** jamesmcarthur has quit IRC18:45
*** jamesmcarthur has joined #zuul18:46
*** jamesmcarthur has quit IRC18:59
*** jamesmcarthur has joined #zuul19:00
openstackgerritTobias Henkel proposed zuul/zuul master: Create zuul/web/static on demand  https://review.opendev.org/66149819:02
*** sanjayu__ has quit IRC19:34
*** jamesmcarthur has quit IRC19:38
*** tosky has quit IRC20:18
*** jamesmcarthur has joined #zuul20:25
*** tosky has joined #zuul20:26
*** jamesmcarthur has quit IRC20:45
*** tosky has quit IRC21:17
openstackgerritTristan Cacqueray proposed zuul/zuul master: Skip file matcher for pipeline using timer trigger  https://review.opendev.org/66085622:40

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!