You are not logged in.

#1 2015-01-27 11:13:57

wichtel16
Member
Registered: 2015-01-27
Posts: 3

LXC Isolation

Hello,

I am fairly new to Arch, but have been using Debian and Ubuntu for quite a while. I am trying out LXC containers for the first time now and am quite pleased. I noticed one thing, however, that worries me a bit; an LXC Arch guest ist running on my Arch host, and every time I start the guest, the host gets influenced in the following way:

  • The audio volume is changed (reset?)

  • The keyboard repeat rate setting is changed (reset?)

Now I've got two questions which I hope this community can help me find an answer to:

  • Is there any way of isolating the guest from these host settings? I have already tried denying access to tty devices (4:1, 5:0, 5:1, 5:2) in the container config

  • Is there a way to find out what other "leaks" are there for the guest to see? I would like to ultimately run untrusted code in the container, and I'm using LXC to prevent it from causing harm to my host system.

I've noticed some people reporting similar issues (see below), but no fix has been found so far.
In case I need to post any configuration or details about my setup to investigate this issue, I'm more than willing to do so upon request.

Thank you!

Similar/related threads:
https://lists.archlinux.org/pipermail/a … 35959.html
http://stackoverflow.com/questions/2400 … -container
edit: https://bbs.archlinux.org/viewtopic.php?id=190683

Last edited by wichtel16 (2015-01-27 11:15:31)

Offline

Board footer

Powered by FluxBB