|
|
Subscribe / Log in / New account

Mounting images inside a user namespace

Mounting images inside a user namespace

Posted Jun 13, 2023 17:47 UTC (Tue) by vadim (subscriber, #35271)
In reply to: Mounting images inside a user namespace by bluca
Parent article: Mounting images inside a user namespace

What's that supposed to mean?

It's good, welcome functionality. Think for instance of things like AppImage and Flatpak -- applications in a container that an unprivileged user would want to be able to mount easily and safely.

I think ideally we'd have a secure, privilege separated system for doing such things. A simple very, readonly, easy to validate for correctness filesystem. A sandboxed userspace driver to interpret it for good measure. And a good sandbox for the actual application running within.


to post comments

Mounting images inside a user namespace

Posted Jun 13, 2023 22:28 UTC (Tue) by bluca (subscriber, #118303) [Link]

Mounting images inside a user namespace

Posted Jun 14, 2023 10:58 UTC (Wed) by tao (subscriber, #17563) [Link] (4 responses)

It's probably just yet another immature person who refuses to see any value in anything systemd-related.

Mounting images inside a user namespace

Posted Jun 14, 2023 11:40 UTC (Wed) by mezcalero (subscriber, #45103) [Link] (3 responses)

Luca is a systemd maintainer. A very funny one, apparently. ;-)

Lennart

Mounting images inside a user namespace

Posted Jun 14, 2023 12:09 UTC (Wed) by bluca (subscriber, #118303) [Link] (2 responses)

My top-notch humor is wasted it seems.

Mounting images inside a user namespace

Posted Jun 14, 2023 16:08 UTC (Wed) by Karellen (subscriber, #67644) [Link]

Without a winking smiley or other blatant display of humor, it is utterly impossible to parody a Creationistanti-systemd troll in such a way that someone won't mistake for the genuine article.

-- Poe's Law

It's not that your humour is bad, it's that it's so on point that it's hard to distinguish it from the thing it's making fun of.

Mounting images inside a user namespace

Posted Aug 1, 2023 11:24 UTC (Tue) by tao (subscriber, #17563) [Link]

Ah, sorry, my apologies for not being able to recognise that you were joking. Keep up the good work on systemd!

Mounting images inside a user namespace

Posted Jun 15, 2023 9:14 UTC (Thu) by gray_-_wolf (subscriber, #131074) [Link]

Ignoring the previous comment (I think it was somewhat funny, but that is a matter of taste, and I have a poor one), I have to admit I am not sure why this is required. You mention AppImage and Flatpak, but why do they need disk images? Rootless podman works on my machine today, so I am not sure why they cannot use the same mechanism for distributing the files they need. Why does it need to be a disk image?


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds