From 3822e7dae5cb6b87e0b3d73e8db8b5c608b9aa4b Mon Sep 17 00:00:00 2001 From: Paul Holzinger Date: Thu, 1 Oct 2026 14:55:29 +0200 Subject: apparmor: allow netns paths on /tmp again The change to the user-tmp abstraction broke pasta as it can no longer open the netns path given by podman when it is under /tmp. The abstraction uses "owner" while the kernel always seems to report ouid=0 for the bind mounted netns reference. I originally fixed that in commit 6cdc9fd51bf6 ("apparmor: allow netns paths on /tmp"). In order to fix the regression add /tmp explicitly again here while keeping the abstraction to still allow /var/tmp for the other regular files. Link: https://github.com/podman-container-tools/podman/pull/29867#pullrequestreview-5378330040 Fixes: f2683d14802d ("apparmor: Use user-tmp abstraction, allow /var/tmp instead of /tmp only") Signed-off-by: Paul Holzinger [sbrivio: Replaced spaces with tabs, slightly reworded comment] Signed-off-by: Stefano Brivio --- contrib/apparmor/usr.bin.pasta | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/contrib/apparmor/usr.bin.pasta b/contrib/apparmor/usr.bin.pasta index 32dfad9..31469ad 100644 --- a/contrib/apparmor/usr.bin.pasta +++ b/contrib/apparmor/usr.bin.pasta @@ -22,8 +22,11 @@ profile pasta /usr/bin/pasta{,.avx2} flags=(attach_disconnected) { # tap_sock_unix_init(), pcap(), # pidfile_open(), # pidfile_write(), - # logfile_init(), - # pasta_open_ns() + # logfile_init() + + # user-tmp is using "owner" which is not compatible with netns paths + # as they show up with ouid=0 in the kernel AppArmor checks + /tmp/** rw, # pasta_open_ns() owner @{HOME}/** w, # pcap(), pidfile_open(), # pidfile_write() -- cgit v1.2.3