diff options
| author | Paul Holzinger <pholzing@redhat.com> | 2026-10-01 14:55:29 +0200 |
|---|---|---|
| committer | Stefano Brivio <sbrivio@redhat.com> | 2026-10-02 07:21:38 +0200 |
| commit | 3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b (patch) | |
| tree | 1ee244218efad8beae2e1f338f3ac54069383ba6 | |
| parent | df90211db4b08a06ed4e499ffa40bf8811100a2f (diff) | |
| download | passt-3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b.tar passt-3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b.tar.gz passt-3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b.tar.bz2 passt-3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b.tar.lz passt-3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b.tar.xz passt-3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b.tar.zst passt-3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b.zip | |
The change to the user-tmp abstraction broke pasta as it can no longer
open the netns path given by podman when it is under /tmp.
The abstraction uses "owner" while the kernel always seems to report
ouid=0 for the bind mounted netns reference. I originally fixed that
in commit 6cdc9fd51bf6 ("apparmor: allow netns paths on /tmp").
In order to fix the regression add /tmp explicitly again here while
keeping the abstraction to still allow /var/tmp for the other regular
files.
Link: https://github.com/podman-container-tools/podman/pull/29867#pullrequestreview-5378330040
Fixes: f2683d14802d ("apparmor: Use user-tmp abstraction, allow /var/tmp instead of /tmp only")
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
[sbrivio: Replaced spaces with tabs, slightly reworded comment]
Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
| -rw-r--r-- | contrib/apparmor/usr.bin.pasta | 7 |
1 files changed, 5 insertions, 2 deletions
diff --git a/contrib/apparmor/usr.bin.pasta b/contrib/apparmor/usr.bin.pasta index 32dfad9..31469ad 100644 --- a/contrib/apparmor/usr.bin.pasta +++ b/contrib/apparmor/usr.bin.pasta @@ -22,8 +22,11 @@ profile pasta /usr/bin/pasta{,.avx2} flags=(attach_disconnected) { # tap_sock_unix_init(), pcap(), # pidfile_open(), # pidfile_write(), - # logfile_init(), - # pasta_open_ns() + # logfile_init() + + # user-tmp is using "owner" which is not compatible with netns paths + # as they show up with ouid=0 in the kernel AppArmor checks + /tmp/** rw, # pasta_open_ns() owner @{HOME}/** w, # pcap(), pidfile_open(), # pidfile_write() |
