From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=DN8jIXxR; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by passt.top (Postfix) with ESMTPS id 4CFE25A026F for ; Thu, 09 Oct 2025 10:14:52 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1759997691; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=UPBopJde+U3rb/Z+aa9qctU4Jvcdt2hpud3rlDGj4WQ=; b=DN8jIXxRTje58hPjzETDzjMmhG3C8mAf56sSvy9VcHXUHwwRyJrq52iBComp3gLhswMcad cSLXfkJ0+JIw7/3y9ZN+V8/Goz4a5tt6MJjrQWCdqpUESPKJW3cd6J0ua68itcL+d72oqi LVGuIGGlvr4qKd2irX28JaJyV7LIx6E= Received: from mail-wm1-f72.google.com (mail-wm1-f72.google.com [209.85.128.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-539-HygP0c9FPzKoCHX3xm4Hqg-1; Thu, 09 Oct 2025 04:14:49 -0400 X-MC-Unique: HygP0c9FPzKoCHX3xm4Hqg-1 X-Mimecast-MFC-AGG-ID: HygP0c9FPzKoCHX3xm4Hqg_1759997689 Received: by mail-wm1-f72.google.com with SMTP id 5b1f17b1804b1-46e41c32209so3534285e9.0 for ; Thu, 09 Oct 2025 01:14:49 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1759997689; x=1760602489; h=content-transfer-encoding:mime-version:organization:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=UPBopJde+U3rb/Z+aa9qctU4Jvcdt2hpud3rlDGj4WQ=; b=NUvghgX2S2c272zzps/I3i+AH1pKoChNKg1te9p6AkL3j9F38UWTY/K4QwRlb6DSr2 qrtOpvsdX2CuN80JDttDl+7gT0eBu7mdKGz2fnqQb3LxmTuCu3Kkeq6PXX/jmmbYbHag Rgo2Wpg12IwhxlBnR+M5x5bO8dYo0XjPxPbzAucxV/jDmUzEg8C4ohSFYUAK8hv2MBKk IZHqyvdNxQtejV84bCL2f+xvbySgKbm5uQrhdyIso/FU7t1COB7ZsXdtfMG14EZZL8ro 4JbG+kvNSPJlqWnFb2JHPkbvJiM2xpI4L8+i6IoxI1Hb0iCicArHzeEzOmyrsYa03FJj ZZyQ== X-Gm-Message-State: AOJu0YzqEnDqvA2jVzs6MPcZhdBgYK23Yx+8pFrJIT5684U8sEVcEcun r+xi/gmjTvN1ZH65oFFVcf5ehhYQyiOl3qpDyk42bBxqqOYW+Kuj2ufJIouhXdpLJchCgYmcQrb JOmOtKdZb3wSpOeV81Vu7A7T6wXBo2muvGNm28jd0QTI11MLHfNlDTw== X-Gm-Gg: ASbGnct1LxBHjq+uhfR7qZYmrrnuUgaaaEJATqmVTunquAOYAF6rjOWnMixfiK2BgyY K7bsUiICwYrvJLcEd7vfeMeiVxS9uRK8OLb9ZWRffyg8Aiu0jQ4IeNlCxxJDol9jXX5sRH8rde7 8EdRi9KNASMee9uuKkAwAn0bfPF0jtijBiUsapx5E627EUMMwoEI4KFrxiShlcNVrKzD2Gqm9wt +Mz0PSdqrW816Bbybh1lthpdutDm9Gnfte3VBunzXMKv4cgs5Yn/g3Yy6vBvIk84duMKanrdq1c vClTrmpAOBrfyZT4haIsStD2YdH/AW32nFfwrjbaHRC/T7yr/utTm95tlKGNXN5OXiLDp1zlag= = X-Received: by 2002:a05:600d:4203:b0:46e:6af4:ed83 with SMTP id 5b1f17b1804b1-46fa9af9099mr46729945e9.23.1759997688529; Thu, 09 Oct 2025 01:14:48 -0700 (PDT) X-Google-Smtp-Source: AGHT+IGqXNAxy7xwueReyXK/bMyJYjLoYn+bMhoT5M5S0ECvvFjut3k4OQ4NiFXPCQzIwHkv65r5PQ== X-Received: by 2002:a05:600d:4203:b0:46e:6af4:ed83 with SMTP id 5b1f17b1804b1-46fa9af9099mr46729725e9.23.1759997688073; Thu, 09 Oct 2025 01:14:48 -0700 (PDT) Received: from maya.myfinge.rs (ifcgrfdd.trafficplex.cloud. [176.103.220.4]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-46fab3d2d65sm30868545e9.2.2025.10.09.01.14.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 09 Oct 2025 01:14:47 -0700 (PDT) Date: Thu, 9 Oct 2025 10:14:45 +0200 From: Stefano Brivio To: Cole Robinson Subject: Re: [PATCH v2] isolation: keep CAP_DAC_OVERRIDE initially Message-ID: <20251009101445.67408f7a@elisabeth> In-Reply-To: <38d6578a1d8dd10e96b0f1d8e6a29ff5db17f57d.1759935556.git.crobinso@redhat.com> References: <38d6578a1d8dd10e96b0f1d8e6a29ff5db17f57d.1759935556.git.crobinso@redhat.com> Organization: Red Hat X-Mailer: Claws Mail 4.2.0 (GTK 3.24.49; x86_64-pc-linux-gnu) MIME-Version: 1.0 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: uRZvW9J_Dm1VPVkvXp8c5meN7a-9LpY0KKPYCGWtMww_1759997689 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Message-ID-Hash: V5VTTGKY2QITXFU6GLB44AXL6G46AYLX X-Message-ID-Hash: V5VTTGKY2QITXFU6GLB44AXL6G46AYLX X-MailFrom: sbrivio@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: passt-dev@passt.top, david@gibson.dropbear.id.au, Yumei Huang , "Richard W.M. Jones" X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On Wed, 8 Oct 2025 11:01:33 -0400 Cole Robinson wrote: > Reproducer that I'd expect to work: > > $ cd $HOME > $ sudo passt --runas $UID --socket foo.sock > Failed to bind UNIX domain socket: Permission denied > > A more practical example is for libguestfs apps when run as user=root: > > + libguestfs connects to libvirt qemu:///system > + libvirt qemu:///system defaults to user=qemu > + libvirt chowns /run/libvirt/qemu/passt dir to user=qemu > + libguestfs instead requests the VM run as user=root > + patches in progress but we are blocked by this issue > + passt is launched as root, but because CAP_DAC_OVERRIDE has been > dropped, passt fails to create socket in qemu owned > /run/libvirt/qemu/passt > > Fix it by not dropping CAP_DAC_OVERRIDE in isolate_initial. > > This might look sketchy, but isolate_initial already keeps > CAP_SYS_ADMIN and CAP_NET_ADMIN, so we are probably no worse off. > > Reviewed-by: David Gibson > Signed-off-by: Cole Robinson > --- > v2: improve commit message Applied, thanks, and welcome to the git log! -- Stefano