HNHacker News
TopNewBestAskShowJobs

anybody8824

18 karma · joined August 1, 2024

submissionscomments
anybody8824··on Landrun: Sandbox any Linux process using Landlock, no root or containers
The user.max_user_namespaces sysctl itself is namespace aware and is used by bubblewrap's --disable-userns option.

But a prctl like NO_NEW_PRIVS would be better, since it could avoid an intermediary namespace that is needed for the namespace-aware sysctl.

anybody8824··on Linux as co-operative Windows process (2017)
You could try to use the Win32 debug API in the same way like Linux UML by using ptrace. But it would probably still be much slower because of missing things like PTRACE_SYSCALL.

More performant would be a noMMU variant of UML for Windows, supporting only PIE executables, similar to nabla-linux [1]. This is also quite similar to how mssql for Linux works NT kernel+Win32 in a single usermode process (single address space) [2]. Interestingly, mssql also uses memory protection keys to recover a bit of fault tolerance but last time I checked Win32 does not have an API for MPKs.

[1] https://github.com/nabla-containers/nabla-linux

[2] https://threedots.ovh/slides/Drawbridge.pdf

anybody8824··on Install postmarketOS on Android phone and use Docker as a home server
With the upcoming Android 16 Terminal VM powered by the Android Virtualisation Framework (AVF), it should also be possible to run Docker in an Aarch64 Debian VM similar to WSL2 or ChromeOS crostini.

However, this may still be constrained by OEMs restricting access to AVF or by battery enhancements that make it virtually unusable.

anybody8824··on The end of ChromeOS is a new dawn for cheap Android laptops
In the EU, this will be the case from next year on (2025-06-20). No monthly security patch frequency requirement, but instead "security updates [...] need to be available to the user at the latest 4 months after the public release of the source code of an update of the underlying operating system" [1].

Complying with this new regulation and bumping the Linux kernel version during the device life cycle was also a topic at this year's Linux Plumbers Android MC. [2][3]. This is necessary because the Linux LTS support timeframe is shorter than the by law mandated minimum support period of 5 years.

[0] https://news.ycombinator.com/item?id=41128358

[1] https://eur-lex.europa.eu/eli/reg/2023/1670/oj

[2] https://youtu.be/b9xXCNYMWjY?si=yxDJUbJHko8HvFTA&t=458

[3] https://lpc.events/event/18/contributions/1740/attachments/1...

anybody8824··on New EU rules promoting repair of goods enter into force
"from the date of end of placement on the market to at least 5 years after that date"

IANAL but my interpretation of rule is: if you buy from a first-party seller, you should receive an update for at least five years, starting on the day you bought the device.

anybody8824··on New EU rules promoting repair of goods enter into force
Aside from the physical repair requirements, part of the same legislation also covers operating system updates for *smartphones* (see Annex II (EU) 2023/1670).

From 20 June 2025, de jure all smartphones sold in the EU must come with at least *five years* of updates.

Also the security updates must be made available to users within four months of them being fixed by the upstream project:

>security updates or corrective updates mentioned under point (a) need to be available to the user at the latest 4 months after the public release of the source code of an update of the underlying operating system or, if the source code is not publicly released, after an update of the same operating system is released by the operating system provider or on any other product of the same brand https://eur-lex.europa.eu/eli/reg/2023/1670/oj