BEGIN:VCALENDAR
VERSION:2.0
PRODID:Linklings LLC
BEGIN:VTIMEZONE
TZID:America/New_York
X-LIC-LOCATION:America/New_York
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:19700308T020000
RRULE:FREQ=YEARLY;BYMONTH=3;BYDAY=2SU
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:19701101T020000
RRULE:FREQ=YEARLY;BYMONTH=11;BYDAY=1SU
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTAMP:20260422T143140Z
LOCATION:B313
DTSTART;TZID=America/New_York:20241117T143000
DTEND;TZID=America/New_York:20241117T150000
UID:submissions.supercomputing.org_SC24_sess732_ws_canopie105@linklings.co
 m
SUMMARY:Zero-Consistency Root Emulation for Unprivileged Container Build
DESCRIPTION:Reid Priedhorsky, Michael Jennings, and Megan Phinney (Los Ala
 mos National Laboratory (LANL))\n\nDo Linux distribution package managers 
 need the privileged operations they request to actually happen? Apparently
  not, at least when building container images for HPC applications. We use
  this observation to implement a root emulation mode using a Linux seccomp
  filter that intercepts some privileged system calls, does nothing, and re
 turns success to the calling program. This approach provides no consistenc
 y whatsoever but appears sufficient to build a wide selection of Dockerfil
 es, including one that Docker itself cannot build, simplifying fully-unpri
 vileged workflows needed for HPC application containers.\n\nTag: Cloud Com
 puting, Middleware and System Software, State of the Practice\n\nRegistrat
 ion Category: Workshop Reg Pass\n\nSession Chairs: Richard Shane Canon (La
 wrence Berkeley National Laboratory (LBNL)); Alberto Madonna (ETH Zürich, 
 Swiss National Supercomputing Centre (CSCS)); Claudia Misale (CoreWeave, I
 nc.); and Andrew Younge (Sandia National Laboratories)\n\n
END:VEVENT
END:VCALENDAR
