unshare: support for systemd-nsresourced, --map-foreign option - #4560
Skyb0rg007 wants to merge 2 commits into
Conversation
| unshare_flags |= CLONE_NEWUSER; | ||
| mapuser = real_euid; | ||
| mapgroup = real_egid; | ||
| target_mode = TARGET_CURRENT; |
There was a problem hiding this comment.
Do we really need target_mode? It's also a variable set in multiple getopt cases, so the final content depends on the order of the command-line options. Seems fragile.
What about adding maplocal for OPT_MAPUSER/MAPGROUP and rejecting its use with map_foreign? And the final switch with target_mode y can be replaced with
nsresourced_target = (mapuser == 0) ? 0 : -1There was a problem hiding this comment.
nsresourced lets you configure a different target user when using the "type": "managed" option. I stripped out all that code for this PR so some of these choices probably seem odd.
There was a problem hiding this comment.
If you assume we will add some other types, then it will make more sense. (Note that I don't know anything about nsresourced.)
There was a problem hiding this comment.
I’m honestly not sure — that’s the main reason I marked this PR as draft. I would use the mode I implemented here; the other modes are more specialized so I’d personally not use them so I need others to make that determination.
|
BTW, in and Ah, now I see OPT_MAP_FOREIGN vs. OPT_MAPFOREIGN name mess ;-) |
Adds the `--map-foreign` option, which uses systemd-nsresourced to setup the uid and gid maps, additionally asking the service to map the foreign UID range. The `--map-current-user` and `--map-root-user` options are also compatible.
44bc15c to
8a53e64
Compare
Use the builtin command-line collision helpers, and properly follow dynamic library loading conventions.
1c9021c to
a6b89c8
Compare
|
Thanks for the patch, and sorry for the slow follow-up. The approach looks right to me: the varlink payload matches the A few things to fix before this can leave draft state. major1.
It is also unnecessary — for 2. The
sed -e "s/^\([0-9]\+\) $1 /\1 SELF /"fixes this and issue 7 below. 3. No guard for "user namespaces unavailable" — The two top-level guards cover "built without varlink" and "no "$TS_CMD_UNSHARE" --user --map-root-user /bin/true &>/dev/null || ts_skip "user namespaces not supported"minor4. 5. 6. 7. 8. Commits — neither commit carries a nit9. 10. 11. 12. 13. One last note: — assisted by Claude Code |
|
Don't feel bad taking a long time to review -- I marked it as draft in hopes that someone else would be interested in this functionality; I'm not that interested in merging this until at least one other person has some input into what the design would look like. I guess I should've pinged @brauner since he liked my discussion post. But I'll try to go over those comments when I have the time. |
Adds the
--map-foreignoption, which usessystemd-nsresourced.service(8)to setup the uid and gid maps, specifically for asking the service to map the foreign UID range. The--map-current-userand--map-root-useroptions are also compatible:--map-current-useris the default, and--map-root-usertranslates into"target": 0.systemd-nsresourcedhas other options, but the primary use case that I envisionunshareto be used for is to manage files owned by theforeign-0-foreign-65534UIDs and GIDs.Specifically, running
unshare --map-foreign --map-root-user -- rm -rf ./dirto delete local files that were created usingsystemd-nspawn(1)orsystemd-mountfsd.service(8)'sio.systemd.MountFileSystem.MakeDirectoryVarlink method.The important thing to note is that the foreign UID range is a systemd concept, so
newuidmapis not usually able to map those uids into the user namespace.This is a draft PR to garner feedback, as this is a new idea.