2020
DOI: 10.1051/epjconf/202024507012
|View full text |Cite
|
Sign up to set email alerts
|

A fully unprivileged CernVM-FS

Abstract: The CernVM File System provides the software and container distribution backbone for most High Energy and Nuclear Physics experiments. It is implemented as a file system in user-space (Fuse) module, which permits its execution without any elevated privileges. Yet, mounting the file system in the first place is handled by a privileged suid helper program that is installed by the Fuse package on most systems. The privileged nature of the mount system call is a serious hindrance to running CernVM-FS on opportunis… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
4
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
3
1
1

Relationship

1
4

Authors

Journals

citations
Cited by 5 publications
(4 citation statements)
references
References 6 publications
(4 reference statements)
0
4
0
Order By: Relevance
“…The program requires a specific environment to work correctly: (i) external connectivity; (ii) the fusermount library or unprivileged namespace mount points or a setuid installation of Singularity/Apptainer. Blomer et al provide further details on the package [13].…”
Section: Software Dependencies Through Cvmfsmentioning
confidence: 99%
“…The program requires a specific environment to work correctly: (i) external connectivity; (ii) the fusermount library or unprivileged namespace mount points or a setuid installation of Singularity/Apptainer. Blomer et al provide further details on the package [13].…”
Section: Software Dependencies Through Cvmfsmentioning
confidence: 99%
“…Second is the configuration of the HPC runtime environment through the use of containers (they all support Singularity, except NERSC, where shifter is used). In addition, CVMFS [4] is available at all these HPC sites, either provided directly by the site or by mounting it in user space with the cvmfsexec package [5]. All these HPC sites provide outbound internet connectivity from the worker nodes as well, which makes integration a lot easier.…”
Section: Hepcloudmentioning
confidence: 99%
“…The program needs a specific environment to work correctly: (i) external connectivity; (ii) the fusermount library or unprivileged namespace mount points or a setuid installation of Singularity (efficient High-Performance Computing container technology). Blomer et al provide additional details about the package [10].…”
Section: Software Delivery On Supercomputersmentioning
confidence: 99%