[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Bug 1829459] Re: qemu seems to lack support for pid namespace.
From: |
Laurent Vivier |
Subject: |
[Bug 1829459] Re: qemu seems to lack support for pid namespace. |
Date: |
Thu, 02 Jan 2020 12:09:03 -0000 |
PID namespace prevents to execute some syscalls, even if you use --map-
root-user. This is managed at kernel level by the capabilities.
Could you try to do the exact same thing with the native architecture
binaries in the chroot to see if the problem really comes from qemu-
user?
Could you try to use the latest unshare version (util-linux package)
that adds a "--keep-caps" parameter (v2.35-rc1) to preserve the
capabilities?
--
You received this bug notification because you are a member of qemu-
devel-ml, which is subscribed to QEMU.
https://bugs.launchpad.net/bugs/1829459
Title:
qemu seems to lack support for pid namespace.
Status in QEMU:
New
Bug description:
# Version
qemu-4.0.0
glibc-2.28
# commands used to launch qemu-aarch64 in user mode.
: ${QEMU_BINFMT_FLAGS:=OC}
printf '%s\n' ':qemu-
aarch64:M::\x7fELF\x02\x01\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\xb7\x00:\xff\xff\xff\xff\xff\xff\xff\x00\xff\xff\xff\xff\xff\xff\xff\xff\xfe\xff\xff\xff:/usr/bin
/qemu-aarch64:'"${QEMU_BINFMT_FLAGS}"
>/proc/sys/fs/binfmt_misc/register
> sudo cp /usr/bin/qemu-aarch64 $RPI/usr/bin
> sudo chroot $RPI /bin/ksh -l
# host
Gentoo Linux amd64
# Guest
Gentoo Linux aarch64
# The problem that I have
"emerge" program fails due to the error, "qemu: qemu_thread_create: Invalid
argument".
"emerge" is Gentoo's package manager that compiles and installs packages.
# Workaround
Disable pid-sandbox in emerge.
# How to reproduce the issue
Execute
unshare --pid -- echo hello world
or
python -c "import portage.process; portage.process.spawn(['echo',
'hello', 'world'], unshare_pid=True)"
To manage notifications about this bug go to:
https://bugs.launchpad.net/qemu/+bug/1829459/+subscriptions
- [Bug 1829459] Re: qemu seems to lack support for pid namespace.,
Laurent Vivier <=