From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=fyTHwjyj; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by passt.top (Postfix) with ESMTPS id BA5F15A0269 for ; Mon, 20 Jul 2026 19:44:09 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784569448; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=F1pRcvS++1uM56QpIZ9lAu2K5nwumgmMBN7HDYLPvK0=; b=fyTHwjyjGf+KJLOgpFne6Nn8GARhSW/bqAaR3pmdHdpkJ2TiNQh2+FnFGIB0HbbaOF/k7h LIGHoa9m4G4/4VVwFNEIT/XJTLNy+zljHTbIX5ZNhGh4AiSaz0evz+yrhkE34SrEQoA64e InqL0pAYngJB73u5Dvdxg3CM8teRnUo= Received: from mail-wr1-f69.google.com (mail-wr1-f69.google.com [209.85.221.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-654-BROJDaLJO1yHJ84Et7aZ1g-1; Mon, 20 Jul 2026 13:44:05 -0400 X-MC-Unique: BROJDaLJO1yHJ84Et7aZ1g-1 X-Mimecast-MFC-AGG-ID: BROJDaLJO1yHJ84Et7aZ1g_1784569444 Received: by mail-wr1-f69.google.com with SMTP id ffacd0b85a97d-47162f83c75so2491049f8f.1 for ; Mon, 20 Jul 2026 10:44:05 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784569444; x=1785174244; h=date:content-transfer-encoding:content-type:mime-version :organization:references:in-reply-to:message-id:subject:cc:to:from :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=F1pRcvS++1uM56QpIZ9lAu2K5nwumgmMBN7HDYLPvK0=; b=Glb1hg54cUj/PoIBTG13fVTd7d/CmMLWE3NIpfrtfeCYqBkml1ebko1ry02O+ImAz6 bJ5cAy4sYwOfr4YFiDQ5omN+0KNAhqenguFAO2yZOyIO0oJiP6y1l9MGjK6yurP6rz+5 zsYROymX5LoQjaedgBeI9eGgUttjpmTw1NAHyMx19yQzln2QPe9IHyOY9477pRvvydxJ 5ortq1ZvttqrL3WuixikM50XO4S46JYx539D5+uylkZYy4WDQRci+wVtgDOtzVo/5/+1 jL8jimdXCLuLGi5XtQ2SjtbFF2M8Azu1IfVS1AlitVzJP5fIbUFmXEe8df7DB/JrLAHn cGag== X-Gm-Message-State: AOJu0YwYk8w0fcr3E/OZAqDx9q2YSif9F5gkbf8HjrbX5rDWGHVHvCGm Mqo+owlJjOF3Qldkad0Vt4fTPaS5/2MFzGEe86H06CVOb8QVq74zbz4T21035bRW4zUgkTKm+aS CsAtT6zu3iC0pABm0epwd13qT6wkOdEyAnOiCDj08kq44Ij3hLRADrQ== X-Gm-Gg: AR+sD11wOayRUUHLW6NekNs8z6mqCBULS8i10ni0y2+Xh29d2zsnMrHFghuHi87ZAb/ Z2vLSSP9a/L/rr1M4HGGGeyk97OUzkzqp802APF4kJPZbVimXeX/sGxiWhK33dazw2qJArzLfZ3 8F/Jsck2JzlS15F4Ne2PyCFQfNMNp/a+zkxKi+dchBYWr36tJtr+L5Y3uhTg1AVckYcjihhf6Et fLBDJgZ1KaExXFjqHYVQMd617ejZ1RgsZyE+ODPfTLc9ratzg8mAVe5X2cJETcTdYdKQGuzJrsl t9qgk2nnktgAMuGc2FkJmgAApJkAI21+DlT/ryxDb6KSrzhK9IJETerre3mz5mA/Y8NeUGctIAF YJAUprLQ4KQS75gObQ6ZERJ+uKD6h X-Received: by 2002:a05:6000:2083:b0:47f:72c3:a320 with SMTP id ffacd0b85a97d-47f72c3a46fmr8308999f8f.20.1784569443925; Mon, 20 Jul 2026 10:44:03 -0700 (PDT) X-Received: by 2002:a05:6000:2083:b0:47f:72c3:a320 with SMTP id ffacd0b85a97d-47f72c3a46fmr8308956f8f.20.1784569443387; Mon, 20 Jul 2026 10:44:03 -0700 (PDT) Received: from maya.myfinge.rs (ifcgrfdd.trafficplex.cloud. [176.103.220.4]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f63ed2313sm31501721f8f.23.2026.07.20.10.44.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 10:44:02 -0700 (PDT) From: Stefano Brivio To: Richard Lawrence Subject: Re: [PATCH v3] feat: Add cli option '--pass-fds' for pasta mode. Message-ID: <20260720194401.2eb998dd@elisabeth> In-Reply-To: <20260719200300.201469-1-rlawrence@tamu.edu> References: <20260719200300.201469-1-rlawrence@tamu.edu> Organization: Red Hat X-Mailer: Claws Mail 4.2.0 (GTK 3.24.49; x86_64-pc-linux-gnu) MIME-Version: 1.0 Date: Mon, 20 Jul 2026 19:44:02 +0200 (CEST) X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: 6RUJkqAy8lv41szGmDYEHplxDHqGBVai27irYPjPxXI_1784569444 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Message-ID-Hash: ZCNS4PUCE4SLHMMB4L3E7DZ6ONSSDEOZ X-Message-ID-Hash: ZCNS4PUCE4SLHMMB4L3E7DZ6ONSSDEOZ X-MailFrom: sbrivio@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: passt-dev@passt.top, jbash@jbash.com, Richard Lawrence , David Gibson X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Hi Richard, On Sun, 19 Jul 2026 15:03:00 -0500 Richard Lawrence wrote: > From: Richard Lawrence > > When pasta mode is used to launch an executable (`pasta [COMMAND]`) and that executable accepts inputs in the form of arbitrary file descriptors (such as `bwrap`), then passt should not stand in the way of the parent process handing off those file descriptors to the child process. See bug 204 for additional discussion. > > The `pass-fds` option accepts a comma-separated list of file descriptor numbers. `conf_pass_fds()` parses the command line argument, then `isolate_fds()` skips closing the specified fds by calling `close_range()` on the gaps between them. > > Additionally, the tap fd is safely relocated to the lowest unused fd number which it at least 3, to avoid accidentally overwriting an existing fd. Thanks for following up. I haven't had a chance to review this in detail yet, but it looks significantly simpler than v2. While I agree with David that the use case should be clearly mentioned in the commit message (it's not entirely clear to me, either, what advantage you get by letting pasta spawn a somehow isolated process), both you and John seem to have the same use case, which I would take as an indication that there's some actual convenience in this. So, as long as it's harmless and sufficiently secure, I don't really have anything against this (except for the pending comments that need to be addressed). Another thing I've been discussing offline with David was the possibility of making pasta spawn the command before closing other open file descriptors. That would be even simpler, and it should be possible to do so without any race condition (contrary to what I previously thought) as the child process waits anyway on a signal from the parent before proceeding. So we could leave those files (optionally) open in the child process taking care of the execvp(), and close them in the parent before the actual networking setup takes place, and before the command is spawned, making sure pasta itself has no possible access to any accidentally leaked file descriptor (which is the security concern here, we don't really care if the spawned command can access them). I haven't really thought this through but it might be worth a try and satisfy your use case anyway, in a simpler way. If that doesn't work for whatever reason I'm ignoring, let's stick to your approach instead. I'll review your patch within a couple of days in that case. Sorry for the delay. -- Stefano