[RFC PATCH] Linux: Workaround seccomp() issue with faccessat2()
Petr Vorel
pvorel@suse.cz
Thu Mar 4 08:27:54 GMT 2021
Hi all,
> There are some indications that not all container runtimes will pick up
> the runc kludge (thanks for developing that by the way). So it's likely
> that the general issue will be with us for a while longer. Maybe the
> competitive pressure from other working container runtimes will
> encourage other re-evaluate their approach, I don't know.
Hopefully.
> We still don't plan to throw in downstream-only glibc patches to paper
> over this (given that it's been rejected by kernel and glibc developers
> alike, I really think it's the wrong way to go). So far management
> isn't breathing down our necks.
As workaround exists (for openSUSE using podman with newest runc v1.0.0-rc93)
I understand the reluctance to accept a workaround. It just reminds me occasional
musl approach to be correct no matter what problems it brings to users.
Kind regards,
Petr
> Thanks,
> Florian
More information about the Libc-alpha
mailing list