From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=MSdKvGDs; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by passt.top (Postfix) with ESMTPS id 7181D5A0262 for ; Sun, 06 Sep 2026 12:05:34 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788689133; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=tzAbgNCOiRDTSpJsqQHFA0ZAPcI/NUdCysfee/VY5Fs=; b=MSdKvGDsA+2p03F2IncJneumij530RtrPGWRctfDuWKHwVIqYpKoeMaF/IqB+ooRDjDOgd 5j8bP15Y2/8sxCpBNfN5n3YH95afy+ObVsUCq7/go0CXeiIz/8emo+LMw0FHondJoOxIDf ENvHowfXx5cCYiQMO4Ka541FOpdvtvQ= Received: from mail-wr1-f70.google.com (mail-wr1-f70.google.com [209.85.221.70]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-612-cb9Oyk-zMtySPMg5oWEA4w-1; Sun, 06 Sep 2026 06:05:31 -0400 X-MC-Unique: cb9Oyk-zMtySPMg5oWEA4w-1 X-Mimecast-MFC-AGG-ID: cb9Oyk-zMtySPMg5oWEA4w_1788689130 Received: by mail-wr1-f70.google.com with SMTP id ffacd0b85a97d-48589603501so1355008f8f.3 for ; Sun, 06 Sep 2026 03:05:31 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788689130; x=1789293930; h=date:content-transfer-encoding:content-type:mime-version :organization:references:in-reply-to:message-id:subject:cc:to:from :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=tzAbgNCOiRDTSpJsqQHFA0ZAPcI/NUdCysfee/VY5Fs=; b=Pmj4avK1M5ixXw7ZvIf/3pqgUKiaCemLeg+HaT9xskSKWW2aiCMJjHPcisyxXDwTfP GbCC3M/2PqwzpTplpsd5IG+2gntiOcukML9XBfTAZbc4gCNF0fEWcGcYsL0IzgByJtGX ddCnDvwsnwUnyCH7MyyW1lFU6DBzigi7piR/dgRm8yWyNuG1eAyPltMu9cHb63bVZRbZ VUZi6q9hF9lOgF70mKRynPm7Zj0PgDR9YcMrfMWGmkN69xigTuXFRvv2PvYoqLks9mIc oyDHxmqkp0Vk5bRAkc7Jxo9Q4tf6hduojof3lQ6c6Rlfc3gS5g2rTqzBKXCtjNuGTHbR 4XAg== X-Gm-Message-State: AFuF++kkS3g+5dbKUuTRLBre025ug88GUQu0yzYc7BIeDN3cauvSkfiz cx3Il+a524vhtutxWDBtxfnFUT6WO+lXCa1kUcSPS79BHzSzaFzncaD9F4MSngKkhtd5yOCUFBi 6r4BM9tDbm4gSqnqCoCQbycQm4AxKnGDLpCf+34LbEzPbnLFHwaJEGQ== X-Gm-Gg: AYBFou2S6HQlTVpfeAGFQZARqtI4ERkVf6iQOb3lEC6nLTdOSH95R6TEub2aMnVjG4K cUVuYk0XN3xQT5NjB5he1CQtAgJ7fjULQyZooBt1ERu/my76Px0wgiBoZ4hH8JkmgH82uyrFxrF SUbsS5P7pJX7KdH/Ac6NhqUP0Ancui56bjtCDUEoTLyzRF9BxXBgGZaLjFxFP8Sh2xnxyGUPUdF ty9S1OhGyGWnrNPVUgTbeu+d2XEjtsRUcwgvEJaelQZQAYONomHK2GZ/k2jWPMUE34loNzNVEkV M1/LI/9k8DvnA96zWFwLECU487m96tC7s/L/vXdND2BsH4mDzGoVIfoy2ozS7flsm8Ce2Pnl3QA 2Fe3rUYlZSYQ= X-Received: by 2002:a05:6000:186b:b0:485:8c16:a35b with SMTP id ffacd0b85a97d-4858c16a72bmr16097475f8f.51.1788689130198; Sun, 06 Sep 2026 03:05:30 -0700 (PDT) X-Received: by 2002:a05:6000:186b:b0:485:8c16:a35b with SMTP id ffacd0b85a97d-4858c16a72bmr16097423f8f.51.1788689129654; Sun, 06 Sep 2026 03:05:29 -0700 (PDT) Received: from maya.myfinge.rs (ifcgrfdd.trafficplex.cloud. [2a10:fc81:a806:d6a9::1]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-485885bfdf6sm21484320f8f.34.2026.09.06.03.05.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 06 Sep 2026 03:05:28 -0700 (PDT) From: Stefano Brivio To: David Gibson Subject: Re: [PATCH] RFC: Don't override system's default ping_group_range for pasta Message-ID: <20260906120526.67bc10d6@elisabeth> In-Reply-To: <20260820071748.1014070-1-david@gibson.dropbear.id.au> References: <20260820071748.1014070-1-david@gibson.dropbear.id.au> Organization: Red Hat X-Mailer: Claws Mail 4.2.0 (GTK 3.24.49; x86_64-pc-linux-gnu) MIME-Version: 1.0 Date: Sun, 06 Sep 2026 12:05:27 +0200 (CEST) X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: EUG4yR1rBTqxnHJBHr0SWaHyKUp-p6Pl5BxK5KSq9jE_1788689130 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Message-ID-Hash: SUDZMAHSGJBZWMHWDBLJGGB4MMLV5UVH X-Message-ID-Hash: SUDZMAHSGJBZWMHWDBLJGGB4MMLV5UVH X-MailFrom: sbrivio@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: passt-dev@passt.top, Laurent Vivier X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On Thu, 20 Aug 2026 17:17:48 +1000 David Gibson wrote: > When spawning a command, pasta sets the net.ipv4.ping_group_range sysctl > to 0 0, meaning only group 0 can use ping sockets within the namespace. > Since group 0 is the only one we map in the userns, that's equivalent to > anyone being able to use ping sockets. > > Although the kernel default for this is 1 0 (nobody can use ping sockets), > common distros - at least ones using systemd or even just systemd-udevd - > appear to set it to "0 2147483647" meaning effectively anyone can use > ping sockets. This wasn't the case on CirrOS (https://github.com/cirros-dev/cirros) and on some more common distributions. For example Alpine sets it to "999 59999", so group 0 is excluded. I haven't checked other distributions not running systemd, but I would expect similar outcomes. > There's no obvious reason that we need to override the system's default > behaviour here. The override was introduced in 32d07f5e5 ("passt, pasta: > Completely avoid dynamic memory allocation") as part of a large chunk which > kind of looks like it was meant to be in another patch, so the git history > isn't particularly informative. Kind of: the override was actually introduced by 089dec90ca99 ("pasta: Set ping_group_range upon namespace creation"), which I dropped by mistake (pasta.c not committed) in 675174d4ba25 ("conf, tap: Split netlink and pasta functions, allow interface configuration"), and finally added back by committing pasta.c in 32d07f5e59f2 ("passt, pasta: Completely avoid dynamic memory allocation"). It's not really informative anyway. But, in any case, unless this does any harm, I'd rather keep the override, because ping might otherwise break on a number of distributions. > Signed-off-by: David Gibson > --- > pasta.c | 3 --- > 1 file changed, 3 deletions(-) > > diff --git a/pasta.c b/pasta.c > index 5aa56b78..4248b508 100644 > --- a/pasta.c > +++ b/pasta.c > @@ -198,9 +198,6 @@ static int pasta_spawn_cmd(void *arg) > if (mount("", "/proc", "proc", 0, NULL)) > warn_perror("Couldn't mount /proc"); > > - if (write_file("/proc/sys/net/ipv4/ping_group_range", "0 0")) > - warn("Cannot set ping_group_range, ICMP requests might fail"); > - > a = (const struct pasta_spawn_cmd_arg *)arg; > > conf_hostname_len = strlen(a->c->hostname); -- Stefano