From: Paul Barker <paul@pbarker.dev>
To: "David Nyström" <david.nystrom@est.tech>,
bitbake-devel@lists.openembedded.org
Subject: Re: [bitbake-devel] [PATCH [RFC] 2/2] bitbake-worker: Call landlock_restrict_network for tasks without network
Date: Mon, 15 Jun 2026 09:30:00 +0100 [thread overview]
Message-ID: <d0e431f8bab663642342ad0bbb732b7c99cd09eb.camel@pbarker.dev> (raw)
In-Reply-To: <20260612-landlock-v1-2-77891f63ed7f@est.tech>
[-- Attachment #1: Type: text/plain, Size: 1557 bytes --]
On Fri, 2026-06-12 at 13:38 +0200, David Nyström wrote:
> Call bb.utils.landlock_restrict_network() for tasks without the 'network'
> varflag. This to support basic network restrictions in unprivileged
> docker containers.
>
> Signed-off-by: David Nyström <david.nystrom@est.tech>
> ---
> bin/bitbake-worker | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/bin/bitbake-worker b/bin/bitbake-worker
> index aa14ef191..5f3fd9933 100755
> --- a/bin/bitbake-worker
> +++ b/bin/bitbake-worker
> @@ -287,6 +287,8 @@ def fork_off_task(cfg, data, databuilder, workerdata, extraconfigdata, runtask):
> bb.utils.disable_network(uid, gid)
> else:
> logger.debug("Skipping disable network for %s since %s is not a local uid." % (taskname, uid))
> + if not bb.utils.landlock_restrict_network():
> + logger.debug("Skipping Landlock network restriction for %s since kernel lacks ABI v4+ support." % taskname)
In disable_network, the logger.debug() calls for failure are handled
within the function instead of by the caller. We should do the same for
landlock_restrict_network() as suggested in my reply to patch 1/2 and
drop the debug print from here.
>
> # exported_vars() returns a generator which *cannot* be passed to os.environ.update()
> # successfully. We also need to unset anything from the environment which shouldn't be there
Best regards,
--
Paul Barker
[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 252 bytes --]
next prev parent reply other threads:[~2026-06-15 8:30 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-12 11:38 [PATCH RFC 0/2] bitbake: Add basic landlock support David Nyström
2026-06-12 11:38 ` [PATCH [RFC] 1/2] utils: Add landlock_restrict_network function David Nyström
2026-06-13 11:52 ` [bitbake-devel] " Alexander Kanavin
2026-06-13 14:26 ` Richard Purdie
2026-06-15 8:28 ` Paul Barker
2026-07-17 18:11 ` David Nyström
2026-06-12 11:38 ` [PATCH [RFC] 2/2] bitbake-worker: Call landlock_restrict_network for tasks without network David Nyström
2026-06-15 8:30 ` Paul Barker [this message]
2026-07-16 15:44 ` [bitbake-devel] [PATCH RFC 0/2] bitbake: Add basic landlock support Richard Purdie
2026-07-16 15:50 ` David Nyström
2026-09-09 16:30 ` Richard Purdie
2026-09-11 7:52 ` David Nyström
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=d0e431f8bab663642342ad0bbb732b7c99cd09eb.camel@pbarker.dev \
--to=paul@pbarker.dev \
--cc=bitbake-devel@lists.openembedded.org \
--cc=david.nystrom@est.tech \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.