diff options
| author | Stefano Brivio <sbrivio@redhat.com> | 2026-10-02 15:19:58 +0200 |
|---|---|---|
| committer | Stefano Brivio <sbrivio@redhat.com> | 2026-10-02 23:05:26 +0200 |
| commit | 032f082ffad094649066fa94822c5a78a246a766 (patch) | |
| tree | 2c06bdedcd857f5d0597951b5c0b783624b55fc6 | |
| parent | a51d395de1daca9ddd3be4d5255e867cb4d470f9 (diff) | |
| download | passt-032f082ffad094649066fa94822c5a78a246a766.tar passt-032f082ffad094649066fa94822c5a78a246a766.tar.gz passt-032f082ffad094649066fa94822c5a78a246a766.tar.bz2 passt-032f082ffad094649066fa94822c5a78a246a766.tar.lz passt-032f082ffad094649066fa94822c5a78a246a766.tar.xz passt-032f082ffad094649066fa94822c5a78a246a766.tar.zst passt-032f082ffad094649066fa94822c5a78a246a766.zip | |
apparmor: Fixes for new user namespace detaching procedure
Commit 7bf1595c9242 ("isolation: Don't create our userns as nobody")
changed the procedure user namespaces are detached, also for passt,
and adds unconditional setting of UID and GID maps.
This needs AppArmor adjustments:
- rules to access gid_map, uid_map, and setgroups entries in procfs
now need to be enabled for passt as well, not just for pasta: move
them to the passt abstraction (which is included from the pasta
abstraction)
- we now need to open a user namespace originally detached by a
separate holder process, which requires us to open procfs entries
that are disconnected (from an AppArmor perspective) from the
original namespace: add the attach_disconnected flag to the profile
for passt as well (this was already the case for pasta).
This isn't ideal but there doesn't seem any way around it: opening
the namespace from the holder process itself doesn't help either.
We'll need to add this flag also in passt subprofiles for
guestfs-tools (maintained in Debian) and libvirtd (which only
applies when guests are started as root for the moment, maintained
by libvirt upstream).
Reported-by: Michal Humpula <bts@hudrydum.cz>
Link: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1149683
Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
| -rw-r--r-- | contrib/apparmor/abstractions/passt | 4 | ||||
| -rw-r--r-- | contrib/apparmor/abstractions/pasta | 4 | ||||
| -rw-r--r-- | contrib/apparmor/usr.bin.passt | 2 |
3 files changed, 4 insertions, 6 deletions
diff --git a/contrib/apparmor/abstractions/passt b/contrib/apparmor/abstractions/passt index f4570c1..0aeb19d 100644 --- a/contrib/apparmor/abstractions/passt +++ b/contrib/apparmor/abstractions/passt @@ -34,7 +34,9 @@ pivot_root "/tmp/" -> "/tmp/", umount "/", - owner @{PROC}/@{pid}/uid_map r, # conf_ugid() + owner @{PROC}/@{pid}/gid_map w, # make_ugid_map() + owner @{PROC}/@{pid}/setgroups w, + owner @{PROC}/@{pid}/uid_map rw, @{PROC}/sys/net/ipv4/ip_local_port_range r, # fwd_probe_ephemeral() diff --git a/contrib/apparmor/abstractions/pasta b/contrib/apparmor/abstractions/pasta index 251d4a2..89fa427 100644 --- a/contrib/apparmor/abstractions/pasta +++ b/contrib/apparmor/abstractions/pasta @@ -35,10 +35,6 @@ /dev/net/tun rw, # tap_ns_tun(), tap.c - owner @{PROC}/@{pid}/gid_map w, # pasta_start_ns(), conf_ugid() - owner @{PROC}/@{pid}/setgroups w, - owner @{PROC}/@{pid}/uid_map rw, - owner @{PROC}/sys/net/ipv4/ping_group_range w, # pasta_spawn_cmd(), pasta.c /{usr/,}bin/** Ux, diff --git a/contrib/apparmor/usr.bin.passt b/contrib/apparmor/usr.bin.passt index da49e37..ccc2ea9 100644 --- a/contrib/apparmor/usr.bin.passt +++ b/contrib/apparmor/usr.bin.passt @@ -15,7 +15,7 @@ abi <abi/4.0>, include <tunables/global> -profile passt /usr/bin/passt{,.avx2} { +profile passt /usr/bin/passt{,.avx2} flags=(attach_disconnected) { include <abstractions/passt> include <abstractions/user-tmp> # tap_sock_unix_open(), |
