DNM: fix: add support for cap add/drop in QEMU's SSH session #55742
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
chroot will break nested unshares
bwrap uses pivot_root which works for unshares, but will not work inside a ramfs
as a workaround, we switch_root from ramfs into a tmpfs, then pivot_root will work, and we can use
bwrap-shell
instead of theChrootDirectory
option of sshdThis needs to be tested thoroughly as it's a potentially big change compared to the "simple" ssh+chroot current situation
Fixes: https://github.com/chainguard-dev/prodsec/issues/282
Goes in hand with Melange PR: chainguard-dev/melange#2032
for passing the caps add/drop via env variables