From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp1 ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms11 with LMTPS id ZY9/F2iOnF9oPgAA0tVLHw (envelope-from ) for ; Fri, 30 Oct 2020 22:06:32 +0000 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp1 with LMTPS id CDi8EmiOnF8BRQAAbx9fmQ (envelope-from ) for ; Fri, 30 Oct 2020 22:06:32 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id D92479404C4 for ; Fri, 30 Oct 2020 22:06:31 +0000 (UTC) Received: from localhost ([::1]:49902 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1kYcXU-00049F-LV for larch@yhetil.org; Fri, 30 Oct 2020 18:06:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:42406) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kYcX4-000497-DX for bug-guix@gnu.org; Fri, 30 Oct 2020 18:06:02 -0400 Received: from debbugs.gnu.org ([209.51.188.43]:48499) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1kYcX4-0003i9-4K for bug-guix@gnu.org; Fri, 30 Oct 2020 18:06:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1kYcX3-0002zR-TT for bug-guix@gnu.org; Fri, 30 Oct 2020 18:06:01 -0400 X-Loop: help-debbugs@gnu.org Subject: bug#44261: running a daemon with userns in relocateble pack breaks Resent-From: Jan Nieuwenhuizen Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Fri, 30 Oct 2020 22:06:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 44261 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: Ludovic =?UTF-8?Q?Court=C3=A8s?= Received: via spool by 44261-submit@debbugs.gnu.org id=B44261.160409552011442 (code B ref 44261); Fri, 30 Oct 2020 22:06:01 +0000 Received: (at 44261) by debbugs.gnu.org; 30 Oct 2020 22:05:20 +0000 Received: from localhost ([127.0.0.1]:60045 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1kYcWO-0002yU-0e for submit@debbugs.gnu.org; Fri, 30 Oct 2020 18:05:20 -0400 Received: from eggs.gnu.org ([209.51.188.92]:42218) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1kYcWM-0002yF-OU for 44261@debbugs.gnu.org; Fri, 30 Oct 2020 18:05:19 -0400 Received: from fencepost.gnu.org ([2001:470:142:3::e]:55268) by eggs.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1kYcWF-0003Ti-Vt; Fri, 30 Oct 2020 18:05:12 -0400 Received: from [2001:980:1b4f:1:42d2:832d:bb59:862] (port=59316 helo=dundal.janneke.lilypond.org) by fencepost.gnu.org with esmtpsa (TLS1.2:RSA_AES_256_CBC_SHA1:256) (Exim 4.82) (envelope-from ) id 1kYcWF-0002uh-D7; Fri, 30 Oct 2020 18:05:11 -0400 From: Jan Nieuwenhuizen Organization: AvatarAcademy.nl References: <87blgn30w0.fsf@gnu.org> <875z6v2zz5.fsf@gnu.org> <871rhfxutl.fsf@gnu.org> X-Url: http://AvatarAcademy.nl Date: Fri, 30 Oct 2020 23:05:08 +0100 In-Reply-To: <871rhfxutl.fsf@gnu.org> ("Ludovic =?UTF-8?Q?Court=C3=A8s?="'s message of "Fri, 30 Oct 2020 22:33:42 +0100") Message-ID: <877dr7s73f.fsf@gnu.org> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.1 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Spam-Score: -2.3 (--) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-Spam-Score: -3.3 (---) X-BeenThere: bug-guix@gnu.org List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: 44261@debbugs.gnu.org Errors-To: bug-guix-bounces+larch=yhetil.org@gnu.org Sender: "bug-Guix" X-Scanner: ns3122888.ip-94-23-21.eu Authentication-Results: aspmx1.migadu.com; dkim=none; dmarc=pass (policy=none) header.from=gnu.org; spf=pass (aspmx1.migadu.com: domain of bug-guix-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=bug-guix-bounces@gnu.org X-Spam-Score: -1.51 X-TUID: I6riAt0B6dqi Ludovic Court=C3=A8s writes: Hi! > As discussed on IRC, my initial advice about MS_PRIVATE was misguided. > The real issue is the =E2=80=9Crm_rf (new_root);=E2=80=9D call, which rem= oves the root > directory and thus leaves child processes (the daemon) with nothing. Yes, I'm not entirely sure what I thought to see yesterday; anyway the rm_rf (new_root) is indeed the thing that makes the daemon crash. > The attached patch adds a test loosely based on yours and a fix for > that. The fix (for the =E2=80=9Cuserns=E2=80=9D engine) is to make NEW_R= OOT a tmpfs, > such that upon completion, all we need to do is to unmount it and remove > it; it lives on as the root file system of child processes. > > In the =E2=80=9Cfakechroot=E2=80=9D case, we have to leave NEW_ROOT behin= d, which is not > great but acceptable (it=E2=80=99s user-owned, #o700, and it=E2=80=99s un= der /tmp). The > test only checks the =E2=80=9Cuserns=E2=80=9D engine. Yes, I think this is acceptable. > If you confirm that it works for you and looks reasonable, we can apply > it. Yes, this works. The test and also my reproducer now work fine. Thanks a lot! Janneke --=20 Jan Nieuwenhuizen | GNU LilyPond http://lilypond.org Freelance IT http://JoyofSource.com | Avatar=C2=AE http://AvatarAcademy.com