<feed xmlns='http://www.w3.org/2005/Atom'>
<title>passt/contrib, branch 2026_10_02.cba3570</title>
<subtitle>Plug A Simple Socket Transport</subtitle>
<link rel='alternate' type='text/html' href='https://passt.top/passt/'/>
<entry>
<title>apparmor: Fixes for new user namespace detaching procedure</title>
<updated>2026-10-02T21:05:26+00:00</updated>
<author>
<name>Stefano Brivio</name>
<email>sbrivio@redhat.com</email>
</author>
<published>2026-10-02T13:19:58+00:00</published>
<link rel='alternate' type='text/html' href='https://passt.top/passt/commit/?id=032f082ffad094649066fa94822c5a78a246a766'/>
<id>032f082ffad094649066fa94822c5a78a246a766</id>
<content type='text'>
Commit 7bf1595c9242 ("isolation: Don't create our userns as nobody")
changed the procedure user namespaces are detached, also for passt,
and adds unconditional setting of UID and GID maps.

This needs AppArmor adjustments:

- rules to access gid_map, uid_map, and setgroups entries in procfs
  now need to be enabled for passt as well, not just for pasta: move
  them to the passt abstraction (which is included from the pasta
  abstraction)

- we now need to open a user namespace originally detached by a
  separate holder process, which requires us to open procfs entries
  that are disconnected (from an AppArmor perspective) from the
  original namespace: add the attach_disconnected flag to the profile
  for passt as well (this was already the case for pasta).

  This isn't ideal but there doesn't seem any way around it: opening
  the namespace from the holder process itself doesn't help either.

  We'll need to add this flag also in passt subprofiles for
  guestfs-tools (maintained in Debian) and libvirtd (which only
  applies when guests are started as root for the moment, maintained
  by libvirt upstream).

Reported-by: Michal Humpula &lt;bts@hudrydum.cz&gt;
Link: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1149683
Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Commit 7bf1595c9242 ("isolation: Don't create our userns as nobody")
changed the procedure user namespaces are detached, also for passt,
and adds unconditional setting of UID and GID maps.

This needs AppArmor adjustments:

- rules to access gid_map, uid_map, and setgroups entries in procfs
  now need to be enabled for passt as well, not just for pasta: move
  them to the passt abstraction (which is included from the pasta
  abstraction)

- we now need to open a user namespace originally detached by a
  separate holder process, which requires us to open procfs entries
  that are disconnected (from an AppArmor perspective) from the
  original namespace: add the attach_disconnected flag to the profile
  for passt as well (this was already the case for pasta).

  This isn't ideal but there doesn't seem any way around it: opening
  the namespace from the holder process itself doesn't help either.

  We'll need to add this flag also in passt subprofiles for
  guestfs-tools (maintained in Debian) and libvirtd (which only
  applies when guests are started as root for the moment, maintained
  by libvirt upstream).

Reported-by: Michal Humpula &lt;bts@hudrydum.cz&gt;
Link: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1149683
Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>selinux: Allow passt to use setgid and setuid capabilities in namespace</title>
<updated>2026-10-02T20:59:58+00:00</updated>
<author>
<name>Stefano Brivio</name>
<email>sbrivio@redhat.com</email>
</author>
<published>2026-10-02T06:48:49+00:00</published>
<link rel='alternate' type='text/html' href='https://passt.top/passt/commit/?id=f86196b822a64a14ac7f4ce8307d687135a486bd'/>
<id>f86196b822a64a14ac7f4ce8307d687135a486bd</id>
<content type='text'>
Starting from commit 7bf1595c9242 ("isolation: Don't create our userns
as nobody"), we unconditionally set uidmap and gidmap in the detached
user namespace.

Allow that in SELinux rules. We also need to allow explicit access to
the related files.

While at it, add the matching class requirements in pasta.te, which I
forgot (harmless as they were indirectly required, but not really
correct).

Link: https://bodhi.fedoraproject.org/updates/FEDORA-2026-3a8fb909da#comment-4790590
Fixes: 71b74e924426 ("isolation: Don't create our userns as nobody")
Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Starting from commit 7bf1595c9242 ("isolation: Don't create our userns
as nobody"), we unconditionally set uidmap and gidmap in the detached
user namespace.

Allow that in SELinux rules. We also need to allow explicit access to
the related files.

While at it, add the matching class requirements in pasta.te, which I
forgot (harmless as they were indirectly required, but not really
correct).

Link: https://bodhi.fedoraproject.org/updates/FEDORA-2026-3a8fb909da#comment-4790590
Fixes: 71b74e924426 ("isolation: Don't create our userns as nobody")
Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>apparmor: allow netns paths on /tmp again</title>
<updated>2026-10-02T05:21:38+00:00</updated>
<author>
<name>Paul Holzinger</name>
<email>pholzing@redhat.com</email>
</author>
<published>2026-10-01T12:55:29+00:00</published>
<link rel='alternate' type='text/html' href='https://passt.top/passt/commit/?id=3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b'/>
<id>3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b</id>
<content type='text'>
The change to the user-tmp abstraction broke pasta as it can no longer
open the netns path given by podman when it is under /tmp.

The abstraction uses "owner" while the kernel always seems to report
ouid=0 for the bind mounted netns reference. I originally fixed that
in commit 6cdc9fd51bf6 ("apparmor: allow netns paths on /tmp").

In order to fix the regression add /tmp explicitly again here while
keeping the abstraction to still allow /var/tmp for the other regular
files.

Link: https://github.com/podman-container-tools/podman/pull/29867#pullrequestreview-5378330040
Fixes: f2683d14802d ("apparmor: Use user-tmp abstraction, allow /var/tmp instead of /tmp only")
Signed-off-by: Paul Holzinger &lt;pholzing@redhat.com&gt;
[sbrivio: Replaced spaces with tabs, slightly reworded comment]
Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The change to the user-tmp abstraction broke pasta as it can no longer
open the netns path given by podman when it is under /tmp.

The abstraction uses "owner" while the kernel always seems to report
ouid=0 for the bind mounted netns reference. I originally fixed that
in commit 6cdc9fd51bf6 ("apparmor: allow netns paths on /tmp").

In order to fix the regression add /tmp explicitly again here while
keeping the abstraction to still allow /var/tmp for the other regular
files.

Link: https://github.com/podman-container-tools/podman/pull/29867#pullrequestreview-5378330040
Fixes: f2683d14802d ("apparmor: Use user-tmp abstraction, allow /var/tmp instead of /tmp only")
Signed-off-by: Paul Holzinger &lt;pholzing@redhat.com&gt;
[sbrivio: Replaced spaces with tabs, slightly reworded comment]
Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>apparmor: Use user-tmp abstraction, allow /var/tmp instead of /tmp only</title>
<updated>2026-09-25T20:38:51+00:00</updated>
<author>
<name>Stefano Brivio</name>
<email>sbrivio@redhat.com</email>
</author>
<published>2026-09-25T20:38:51+00:00</published>
<link rel='alternate' type='text/html' href='https://passt.top/passt/commit/?id=f2683d14802d1430b383f48eb3105f11361edda1'/>
<id>f2683d14802d1430b383f48eb3105f11361edda1</id>
<content type='text'>
Podman overrides TMPDIR to /var/tmp, and an upcoming change in the
requires pasta to write its PID file to TMPDIR.

To support this in the AppArmor policy, we need to loosen the existing
rule restricting file writes to /tmp/ and subpaths in order to include
common alternative paths for TMPDIR: the user-tmp abstraction does
exactly this.

Reported-by: Giuseppe Scrivano &lt;gscrivan@redhat.com&gt;
Link: https://github.com/podman-container-tools/container-libs/pull/1207
Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Podman overrides TMPDIR to /var/tmp, and an upcoming change in the
requires pasta to write its PID file to TMPDIR.

To support this in the AppArmor policy, we need to loosen the existing
rule restricting file writes to /tmp/ and subpaths in order to include
common alternative paths for TMPDIR: the user-tmp abstraction does
exactly this.

Reported-by: Giuseppe Scrivano &lt;gscrivan@redhat.com&gt;
Link: https://github.com/podman-container-tools/container-libs/pull/1207
Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>contrib/apparmor: add missing setfcap capability</title>
<updated>2026-09-08T14:15:39+00:00</updated>
<author>
<name>Sevinj Aghayeva</name>
<email>sevinj.aghayeva@gmail.com</email>
</author>
<published>2026-09-07T21:39:37+00:00</published>
<link rel='alternate' type='text/html' href='https://passt.top/passt/commit/?id=3a890a678fbeb930d41274c0258c1905f43cc068'/>
<id>3a890a678fbeb930d41274c0258c1905f43cc068</id>
<content type='text'>
Since Linux 5.12, writing a mapping from UID 0 to /proc/self/uid_map
requires CAP_SETFCAP. isolation.c already retains this capability for
the case where pasta spawns a child from a non-init user namespace,
but the AppArmor profile doesn't grant it, so the write is denied
whenever the profile is enforced.

Add setfcap to the AppArmor abstraction to match what isolation.c
expects.

Link: https://bugs.passt.top/show_bug.cgi?id=172
Signed-off-by: Sevinj Aghayeva &lt;sevinj.aghayeva@gmail.com&gt;
Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Since Linux 5.12, writing a mapping from UID 0 to /proc/self/uid_map
requires CAP_SETFCAP. isolation.c already retains this capability for
the case where pasta spawns a child from a non-init user namespace,
but the AppArmor profile doesn't grant it, so the write is denied
whenever the profile is enforced.

Add setfcap to the AppArmor abstraction to match what isolation.c
expects.

Link: https://bugs.passt.top/show_bug.cgi?id=172
Signed-off-by: Sevinj Aghayeva &lt;sevinj.aghayeva@gmail.com&gt;
Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>treewide: Sandbox qrap</title>
<updated>2026-07-28T16:09:54+00:00</updated>
<author>
<name>Stefano Brivio</name>
<email>sbrivio@redhat.com</email>
</author>
<published>2026-07-18T07:32:57+00:00</published>
<link rel='alternate' type='text/html' href='https://passt.top/passt/commit/?id=12b02aaebcc69d4506b1a65ef8251fc0453a1d1b'/>
<id>12b02aaebcc69d4506b1a65ef8251fc0453a1d1b</id>
<content type='text'>
No sunsetting or rightsizing for you, qrap: dig, bury, and cover.

Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
Reviewed-by: David Gibson &lt;david@gibson.dropbear.id.au&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
No sunsetting or rightsizing for you, qrap: dig, bury, and cover.

Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
Reviewed-by: David Gibson &lt;david@gibson.dropbear.id.au&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>selinux: Access to netns for podman-build, read access for netns in general</title>
<updated>2026-07-10T21:22:09+00:00</updated>
<author>
<name>Stefano Brivio</name>
<email>sbrivio@redhat.com</email>
</author>
<published>2026-07-02T16:15:31+00:00</published>
<link rel='alternate' type='text/html' href='https://passt.top/passt/commit/?id=e74a7c2c18242617e078fb4e4dc1580de585692e'/>
<id>e74a7c2c18242617e078fb4e4dc1580de585692e</id>
<content type='text'>
A few additional rules are needed when pasta is started by Podman in
particular cases:

- with podman-build or Buildah, pasta needs to access the target
  namespace reference using a procfs namespace link entry, instead of
  the usual directory under /run or /var/run. For that, we have a
  rule enabling access to container_t:lnk_file.

  On some systems, though, the class is 'dir' instead of 'lnk_file'.
  I don't have a concrete way to reproduce this or a full explanation,
  but in any case, an additional rule for that is obviously harmless:
  allow pasta_t to open, read, and search a container_t:dir

- with custom networks, pasta needs to write PID files to a location
  indicated by Podman. If the PID file already exists, the existing
  permissions aren't sufficient: we also need a 'read' rule. Add that,
  for 'dir' and 'file' objects labeled as either container_var_run_t
  or ifconfig_var_run_t (this depends on the installed Podman and
  container-selinux versions)

Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
A few additional rules are needed when pasta is started by Podman in
particular cases:

- with podman-build or Buildah, pasta needs to access the target
  namespace reference using a procfs namespace link entry, instead of
  the usual directory under /run or /var/run. For that, we have a
  rule enabling access to container_t:lnk_file.

  On some systems, though, the class is 'dir' instead of 'lnk_file'.
  I don't have a concrete way to reproduce this or a full explanation,
  but in any case, an additional rule for that is obviously harmless:
  allow pasta_t to open, read, and search a container_t:dir

- with custom networks, pasta needs to write PID files to a location
  indicated by Podman. If the PID file already exists, the existing
  permissions aren't sufficient: we also need a 'read' rule. Add that,
  for 'dir' and 'file' objects labeled as either container_var_run_t
  or ifconfig_var_run_t (this depends on the installed Podman and
  container-selinux versions)

Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>selinux: Allow pasta to create and use its control socket when started by Podman</title>
<updated>2026-05-26T10:16:03+00:00</updated>
<author>
<name>Stefano Brivio</name>
<email>sbrivio@redhat.com</email>
</author>
<published>2026-05-19T17:28:21+00:00</published>
<link rel='alternate' type='text/html' href='https://passt.top/passt/commit/?id=76fd54667ee516e7d6a7ff59befb4a00895b9863'/>
<id>76fd54667ee516e7d6a7ff59befb4a00895b9863</id>
<content type='text'>
If Podman starts us, we need to be able to create and use a UNIX
domain socket file under ifconfig_var_run_t or container_var_run_t:
add the related permissions.

The failure reported by Jan would have been fixed by a simple:

  allow pasta_t ifconfig_var_run_t:sock_file create;

but we'll need more than that for actual operation with pesto(1),
and to cover all possible cases.

Reported-by: Jan Rodák &lt;jrodak@redhat.com&gt;
Link: https://github.com/containers/podman/pull/28478
Fixes: 533577008942 ("selinux: Add file context and type enforcement for pesto")
Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
If Podman starts us, we need to be able to create and use a UNIX
domain socket file under ifconfig_var_run_t or container_var_run_t:
add the related permissions.

The failure reported by Jan would have been fixed by a simple:

  allow pasta_t ifconfig_var_run_t:sock_file create;

but we'll need more than that for actual operation with pesto(1),
and to cover all possible cases.

Reported-by: Jan Rodák &lt;jrodak@redhat.com&gt;
Link: https://github.com/containers/podman/pull/28478
Fixes: 533577008942 ("selinux: Add file context and type enforcement for pesto")
Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>fedora: Install pesto, its SELinux policy, and the man page from the spec file</title>
<updated>2026-05-07T06:06:30+00:00</updated>
<author>
<name>Stefano Brivio</name>
<email>sbrivio@redhat.com</email>
</author>
<published>2026-05-06T01:32:21+00:00</published>
<link rel='alternate' type='text/html' href='https://passt.top/passt/commit/?id=82523bc8a78c89f19de3c162aaab71bd29a239ae'/>
<id>82523bc8a78c89f19de3c162aaab71bd29a239ae</id>
<content type='text'>
It's time to ship it in packages.

Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
Reviewed-by: Laurent Vivier &lt;lvivier@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
It's time to ship it in packages.

Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
Reviewed-by: Laurent Vivier &lt;lvivier@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>selinux: Add file context and type enforcement for pesto</title>
<updated>2026-05-07T06:06:30+00:00</updated>
<author>
<name>Stefano Brivio</name>
<email>sbrivio@redhat.com</email>
</author>
<published>2026-05-06T01:30:29+00:00</published>
<link rel='alternate' type='text/html' href='https://passt.top/passt/commit/?id=5335770089427746986e4f2a6304b39181393083'/>
<id>5335770089427746986e4f2a6304b39181393083</id>
<content type='text'>
Loosely inspired by passt-repair's policy: pesto needs to be able to
run, check networking entries under /proc (for ip_local_port_range),
talk to passt and pasta, wherever the control socket is.

Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Loosely inspired by passt-repair's policy: pesto needs to be able to
run, check networking entries under /proc (for ip_local_port_range),
talk to passt and pasta, wherever the control socket is.

Signed-off-by: Stefano Brivio &lt;sbrivio@redhat.com&gt;
</pre>
</div>
</content>
</entry>
</feed>
