aboutgitcodebugslistschat
diff options
context:
space:
mode:
authorPaul Holzinger <pholzing@redhat.com>2026-10-01 14:55:29 +0200
committerStefano Brivio <sbrivio@redhat.com>2026-10-02 07:21:38 +0200
commit3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b (patch)
tree1ee244218efad8beae2e1f338f3ac54069383ba6
parentdf90211db4b08a06ed4e499ffa40bf8811100a2f (diff)
downloadpasst-3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b.tar
passt-3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b.tar.gz
passt-3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b.tar.bz2
passt-3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b.tar.lz
passt-3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b.tar.xz
passt-3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b.tar.zst
passt-3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b.zip
apparmor: allow netns paths on /tmp againHEADmaster
The change to the user-tmp abstraction broke pasta as it can no longer open the netns path given by podman when it is under /tmp. The abstraction uses "owner" while the kernel always seems to report ouid=0 for the bind mounted netns reference. I originally fixed that in commit 6cdc9fd51bf6 ("apparmor: allow netns paths on /tmp"). In order to fix the regression add /tmp explicitly again here while keeping the abstraction to still allow /var/tmp for the other regular files. Link: https://github.com/podman-container-tools/podman/pull/29867#pullrequestreview-5378330040 Fixes: f2683d14802d ("apparmor: Use user-tmp abstraction, allow /var/tmp instead of /tmp only") Signed-off-by: Paul Holzinger <pholzing@redhat.com> [sbrivio: Replaced spaces with tabs, slightly reworded comment] Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
-rw-r--r--contrib/apparmor/usr.bin.pasta7
1 files changed, 5 insertions, 2 deletions
diff --git a/contrib/apparmor/usr.bin.pasta b/contrib/apparmor/usr.bin.pasta
index 32dfad9..31469ad 100644
--- a/contrib/apparmor/usr.bin.pasta
+++ b/contrib/apparmor/usr.bin.pasta
@@ -22,8 +22,11 @@ profile pasta /usr/bin/pasta{,.avx2} flags=(attach_disconnected) {
# tap_sock_unix_init(), pcap(),
# pidfile_open(),
# pidfile_write(),
- # logfile_init(),
- # pasta_open_ns()
+ # logfile_init()
+
+ # user-tmp is using "owner" which is not compatible with netns paths
+ # as they show up with ouid=0 in the kernel AppArmor checks
+ /tmp/** rw, # pasta_open_ns()
owner @{HOME}/** w, # pcap(), pidfile_open(),
# pidfile_write()