Re: bubblewrap: needs transition to non-setuid to accompany linux/5.10.x

2020-12-26 Thread Simon McVittie
On Sat, 26 Dec 2020 at 19:43:22 +0100, Moritz Mühlenhoff wrote: > Am Mon, Dec 21, 2020 at 06:55:36PM + schrieb Simon McVittie: > > The simplest and most robust thing would be for bubblewrap to depend on > > procps, and ship a file /usr/lib/sysctl.d/50-bubblewrap.conf containing: > > > > ke

Re: bubblewrap: needs transition to non-setuid to accompany linux/5.10.x

2020-12-26 Thread Moritz Mühlenhoff
Am Mon, Dec 21, 2020 at 06:55:36PM + schrieb Simon McVittie: > Package: bubblewrap > Version: 0.4.1-1 > Severity: important > Tags: security > X-Debbugs-Cc: debian-kernel@lists.debian.org, t...@security.debian.org > The simplest and most robust thing would be for bubblewrap to depend on > procp

Bug#977841: bubblewrap: needs transition to non-setuid to accompany linux/5.10.x

2020-12-21 Thread Simon McVittie
Package: bubblewrap Version: 0.4.1-1 Severity: important Tags: security X-Debbugs-Cc: debian-kernel@lists.debian.org, t...@security.debian.org bubblewrap can operate in two modes: - User namespace (Ubuntu, Fedora, RHEL >= 8): /usr/bin/bwrap is not setuid, and relies on having a kernel that allo