Re: RFC: baseline requirements for Ubuntu rootfs: xattrs and fscaps

2018-08-03 Thread Steve Langasek
On Thu, Aug 02, 2018 at 01:29:26PM -0700, Kees Cook wrote: > > > > - Users who are unpacking root tarballs need to take care to pass > > > >--xattrs-include=* to tar. > > > > - Users who are backing up or streaming Ubuntu root filesystems with > > > > tar or > > > >rsync will need to tak

Re: RFC: baseline requirements for Ubuntu rootfs: xattrs and fscaps

2018-08-03 Thread Colin Watson
On Wed, Aug 01, 2018 at 05:58:56PM -0700, Steve Langasek wrote: > This will require bugfixes in various places, but ideally on a one-time > basis only. The primary areas of concern are: I think launchpad-buildd needs a couple of fixes for this, but there are some things to fix that aren't quite o

Re: Globally refreshing new group membership - would be needed after some package installations

2018-08-03 Thread Robie Basak
On Fri, Aug 03, 2018 at 12:13:15PM +0100, Robie Basak wrote: > Yeah, so for example starting virt-manager from the desktop shell will > continue to be a problem until the next login session. Actually, now that I think about it, we could adjust the desktop file to use a wrapper there also. signat

Re: Globally refreshing new group membership - would be needed after some package installations

2018-08-03 Thread Christian Ehrhardt
On Fri, Aug 3, 2018 at 1:13 PM Robie Basak wrote: > On Fri, Aug 03, 2018 at 12:13:30PM +0200, Christian Ehrhardt wrote: > [...] > > - And the UI itself when click-starting things will not have changed > > Yeah, so for example starting virt-manager from the desktop shell will > continue to be a p

Re: Globally refreshing new group membership - would be needed after some package installations

2018-08-03 Thread Robie Basak
On Fri, Aug 03, 2018 at 12:13:30PM +0200, Christian Ehrhardt wrote: > If working this could maybe fixup the terminal it is running in but not > more than that. Yes - it would be limited in scope. But for CLI tools (say lxc), if lxc is wrapped with newgrp, then it should be sufficient. > - And the

Re: Globally refreshing new group membership - would be needed after some package installations

2018-08-03 Thread Christian Ehrhardt
On Thu, Aug 2, 2018 at 1:32 PM Robie Basak wrote: > On Thu, Aug 02, 2018 at 01:16:04PM +0200, Christian Ehrhardt wrote: > > I was wondering if there is a common pattern to resolve this that might > > just be unknown to me yet and that I could use in packaging. > > I have in mind to write a wrappe