diff options
Diffstat (limited to 'contrib/apparmor')
| -rw-r--r-- | contrib/apparmor/abstractions/passt | 18 | ||||
| -rw-r--r-- | contrib/apparmor/abstractions/pasta | 6 | ||||
| -rw-r--r-- | contrib/apparmor/usr.bin.passt | 28 | ||||
| -rw-r--r-- | contrib/apparmor/usr.bin.passt-repair | 29 | ||||
| -rw-r--r-- | contrib/apparmor/usr.bin.pasta | 12 | ||||
| -rw-r--r-- | contrib/apparmor/usr.bin.pesto | 23 |
6 files changed, 100 insertions, 16 deletions
diff --git a/contrib/apparmor/abstractions/passt b/contrib/apparmor/abstractions/passt index d245115..0aeb19d 100644 --- a/contrib/apparmor/abstractions/passt +++ b/contrib/apparmor/abstractions/passt @@ -11,7 +11,7 @@ # Copyright (c) 2022 Red Hat GmbH # Author: Stefano Brivio <sbrivio@redhat.com> - abi <abi/3.0>, + abi <abi/4.0>, include <abstractions/base> @@ -24,6 +24,8 @@ capability setpcap, capability net_admin, capability sys_ptrace, + capability setfcap, + userns, / r, # isolate_prefork(), isolation.c mount options=(rw, runbindable) -> /, @@ -32,7 +34,19 @@ pivot_root "/tmp/" -> "/tmp/", umount "/", - owner @{PROC}/@{pid}/uid_map r, # conf_ugid() + owner @{PROC}/@{pid}/gid_map w, # make_ugid_map() + owner @{PROC}/@{pid}/setgroups w, + owner @{PROC}/@{pid}/uid_map rw, + + @{PROC}/sys/net/ipv4/ip_local_port_range r, # fwd_probe_ephemeral() + + @{PROC}/sys/net/ipv4/tcp_syn_retries r, # tcp_get_rto_params(), tcp.c + @{PROC}/sys/net/ipv4/tcp_syn_linear_timeouts r, + @{PROC}/sys/net/ipv4/tcp_rto_max_ms r, + + # udp_get_timeout_params(), udp.c + @{PROC}/sys/net/netfilter/nf_conntrack_udp_timeout r, + @{PROC}/sys/net/netfilter/nf_conntrack_udp_timeout_stream r, network netlink raw, # nl_sock_init_do(), netlink.c diff --git a/contrib/apparmor/abstractions/pasta b/contrib/apparmor/abstractions/pasta index 9f73bee..89fa427 100644 --- a/contrib/apparmor/abstractions/pasta +++ b/contrib/apparmor/abstractions/pasta @@ -11,7 +11,7 @@ # Copyright (c) 2022 Red Hat GmbH # Author: Stefano Brivio <sbrivio@redhat.com> - abi <abi/3.0>, + abi <abi/4.0>, include <abstractions/passt> @@ -35,10 +35,6 @@ /dev/net/tun rw, # tap_ns_tun(), tap.c - owner @{PROC}/@{pid}/gid_map w, # pasta_start_ns(), conf_ugid() - owner @{PROC}/@{pid}/setgroups w, - owner @{PROC}/@{pid}/uid_map rw, - owner @{PROC}/sys/net/ipv4/ping_group_range w, # pasta_spawn_cmd(), pasta.c /{usr/,}bin/** Ux, diff --git a/contrib/apparmor/usr.bin.passt b/contrib/apparmor/usr.bin.passt index 9568189..ccc2ea9 100644 --- a/contrib/apparmor/usr.bin.passt +++ b/contrib/apparmor/usr.bin.passt @@ -11,15 +11,14 @@ # Copyright (c) 2022 Red Hat GmbH # Author: Stefano Brivio <sbrivio@redhat.com> -abi <abi/3.0>, +abi <abi/4.0>, include <tunables/global> -profile passt /usr/bin/passt{,.avx2} { +profile passt /usr/bin/passt{,.avx2} flags=(attach_disconnected) { include <abstractions/passt> - # Alternatively: include <abstractions/user-tmp> - owner /tmp/** w, # tap_sock_unix_open(), + include <abstractions/user-tmp> # tap_sock_unix_open(), # tap_sock_unix_init(), pcap(), # pidfile_open(), # pidfile_write(), @@ -27,4 +26,25 @@ profile passt /usr/bin/passt{,.avx2} { owner @{HOME}/** w, # pcap(), pidfile_open(), # pidfile_write() + + # Workaround: libvirt's profile comes with a passt subprofile which includes, + # in turn, <abstractions/passt>, and adds libvirt-specific rules on top, to + # allow passt (when started by libvirtd) to write socket and PID files in the + # location requested by libvirtd itself, and to execute passt itself. + # + # However, when libvirt runs as unprivileged user, the mechanism based on + # virt-aa-helper, designed to build per-VM profiles as guests are started, + # doesn't work. The helper needs to create and load profiles on the fly, which + # can't be done by unprivileged users, of course. + # + # As a result, libvirtd runs unconfined if guests are started by unprivileged + # users, starting passt unconfined as well, which means that passt runs under + # its own stand-alone profile (this one), which implies in turn that execve() + # of /usr/bin/passt is not allowed, and socket and PID files can't be written. + # + # Duplicate libvirt-specific rules here as long as this is not solved in + # libvirt's profile itself. + /usr/bin/passt r, + owner @{run}/user/[0-9]*/libvirt/qemu/run/passt/* rw, + owner @{run}/libvirt/qemu/passt/* rw, } diff --git a/contrib/apparmor/usr.bin.passt-repair b/contrib/apparmor/usr.bin.passt-repair new file mode 100644 index 0000000..23ff1ce --- /dev/null +++ b/contrib/apparmor/usr.bin.passt-repair @@ -0,0 +1,29 @@ +# SPDX-License-Identifier: GPL-2.0-or-later +# +# PASST - Plug A Simple Socket Transport +# for qemu/UNIX domain socket mode +# +# PASTA - Pack A Subtle Tap Abstraction +# for network namespace/tap device mode +# +# contrib/apparmor/usr.bin.passt-repair - AppArmor profile for passt-repair(1) +# +# Copyright (c) 2025 Red Hat GmbH +# Author: Stefano Brivio <sbrivio@redhat.com> + +abi <abi/4.0>, + +#include <tunables/global> + +profile passt-repair /usr/bin/passt-repair { + #include <abstractions/base> + /** rw, # passt's ".repair" socket might be anywhere + unix (connect, receive, send) type=stream, + + capability dac_override, # connect to passt's socket as root + capability net_admin, # currently needed for TCP_REPAIR socket option + capability net_raw, # what TCP_REPAIR should require instead + + network unix stream, # connect and use UNIX domain socket + network inet stream, # use TCP sockets +} diff --git a/contrib/apparmor/usr.bin.pasta b/contrib/apparmor/usr.bin.pasta index 2483968..31469ad 100644 --- a/contrib/apparmor/usr.bin.pasta +++ b/contrib/apparmor/usr.bin.pasta @@ -11,20 +11,22 @@ # Copyright (c) 2022 Red Hat GmbH # Author: Stefano Brivio <sbrivio@redhat.com> -abi <abi/3.0>, +abi <abi/4.0>, include <tunables/global> profile pasta /usr/bin/pasta{,.avx2} flags=(attach_disconnected) { include <abstractions/pasta> - # Alternatively: include <abstractions/user-tmp> - /tmp/** rw, # tap_sock_unix_open(), + include <abstractions/user-tmp> # tap_sock_unix_open(), # tap_sock_unix_init(), pcap(), # pidfile_open(), # pidfile_write(), - # logfile_init(), - # pasta_open_ns() + # logfile_init() + + # user-tmp is using "owner" which is not compatible with netns paths + # as they show up with ouid=0 in the kernel AppArmor checks + /tmp/** rw, # pasta_open_ns() owner @{HOME}/** w, # pcap(), pidfile_open(), # pidfile_write() diff --git a/contrib/apparmor/usr.bin.pesto b/contrib/apparmor/usr.bin.pesto new file mode 100644 index 0000000..0c072c7 --- /dev/null +++ b/contrib/apparmor/usr.bin.pesto @@ -0,0 +1,23 @@ +# SPDX-License-Identifier: GPL-2.0-or-later +# +# PESTO - Programmable Extensible Socket Translation Orchestrator +# front-end for passt(1) and pasta(1) forwarding configuration +# +# contrib/apparmor/usr.bin.pesto - AppArmor profile for pesto(1) +# +# Copyright (c) 2026 Red Hat GmbH +# Author: Stefano Brivio <sbrivio@redhat.com> + +abi <abi/4.0>, + +#include <tunables/global> + +profile pesto /usr/bin/pesto { + #include <abstractions/base> + /** rw, # control socket might be anywhere + unix (connect, receive, send) type=stream, + + capability dac_override, # connect to passt's socket as root + + network unix stream, # connect and use UNIX domain socket +} |
