From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=G3XIFnZH; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by passt.top (Postfix) with ESMTPS id 012E95A0272 for ; Tue, 08 Sep 2026 17:32:43 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788881562; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=gCPBK7dEcVK1fXSSoQY/0xal1sAHZR7qFWube0nvu6g=; b=G3XIFnZH73ZkhvOg/xOLIfPsw6g2VA2avsHO89M3nbnu+UTmK9yQRqe85uYuPFrDNVmuCt u3ninT9etYcbYYHTMU5LxAuV3EiJNh5MhuRP5dlj51R0LRIu1UxmCJLyE/RMFXT/xHdrd2 AHl4y0d3hyewb+PIo8QHDEsTXXV+hiY= Received: from mail-wm1-f71.google.com (mail-wm1-f71.google.com [209.85.128.71]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-456-qll10_zSPC6Vqq-MYFesoQ-1; Tue, 08 Sep 2026 11:32:41 -0400 X-MC-Unique: qll10_zSPC6Vqq-MYFesoQ-1 X-Mimecast-MFC-AGG-ID: qll10_zSPC6Vqq-MYFesoQ_1788881560 Received: by mail-wm1-f71.google.com with SMTP id 5b1f17b1804b1-490a767c7dcso35948555e9.2 for ; Tue, 08 Sep 2026 08:32:41 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788881560; x=1789486360; h=date:content-transfer-encoding:content-type:mime-version :organization:references:in-reply-to:message-id:subject:cc:to:from :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=gCPBK7dEcVK1fXSSoQY/0xal1sAHZR7qFWube0nvu6g=; b=aqjG/Et6Msd/LCE/4npME3UFgmKxMj9eS5Kju0Dd66UYOv9GQbwigVguA1Kb+QLx/n HMUKqg1MN6i7lAsso1AwxghSvatRy+Cd94rQ0qKwN08iEYfTUeKKUt+cxsg3X+6ozyz1 3DGF0xle1sCavzuL+rvlU1I2QGWQwDXPiUlELo7X3JrXtO/BshvRW8Uw/g7ndIDoogF2 yX3w8JQMqW27HPXmkKfscE5iwTS5brSao/oqq8kzyIOZ8m5MyFQjmXR+AxkElIgNwdnm eFvJizbQB4hwZPhmnih2tzPhZiMfgBKLTr8e6NWsNobompUb0fKSGhb76WNp7krS8Ry4 PtTA== X-Gm-Message-State: AFuF++mfTt1aU23EFxrwXoBS4YYORGJix3ZiaMahDGbCZCNBIuhFv2uy JsWAJCKABgDCHE3R/0LbKk8xN5tCIa5rHoks6y0effoKp6MNggG/7gvYuRlcED+QJWxXiEcg0Of W4cJCvVn3xPw3J1bSj6/9kmSQhHQDXK4/w65rmlZgE/BoPDeUhGotxg== X-Gm-Gg: AYBFou1NkGJyQxVbuXSK+noSqCeu3gbGIDo9GBblNZOLuNPfKXgoAb/bpSMwyAGaBtC FMCi/OxIdL6JsP8BrRBRQ4tn1llGmvuky0QPgpmYlPLn9DPbi7+QqJ8E5HbWh4PwEhb7X+K/59Y gjzEApxE9qb+mf6sPyw3zLdPuHIejaTdSKGGgK6YxqdbxJ4BfL4D+NPP7B4XJJbrqHv1CajqcH4 QjHzdfzYxKniv9J7UdOW0NRbpifCpC3FctyeDggkGM0VhojaLjEhdL2LaEOu+9BqK0r14SDwXMe 2iOU8Il+hL+kVRwfg0mI9va53vpAAWoUo9+MNCZYtQ7kxIBYvRMHQLoclmeskRrTKOazGNZfOLV VFj+ZinKxo1ZaXuCr+Fma1j+H3NFS X-Received: by 2002:a05:600c:46d5:b0:49c:fc6c:be04 with SMTP id 5b1f17b1804b1-49cfc6cc091mr251504995e9.27.1788881559851; Tue, 08 Sep 2026 08:32:39 -0700 (PDT) X-Received: by 2002:a05:600c:46d5:b0:49c:fc6c:be04 with SMTP id 5b1f17b1804b1-49cfc6cc091mr251504255e9.27.1788881559269; Tue, 08 Sep 2026 08:32:39 -0700 (PDT) Received: from maya.myfinge.rs (ifcgrfdd.trafficplex.cloud. [176.103.220.4]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49cf7740d44sm878185495e9.15.2026.09.08.08.32.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 08 Sep 2026 08:32:38 -0700 (PDT) From: Stefano Brivio To: David Gibson Subject: Re: [PATCH] RFC: Don't override system's default ping_group_range for pasta Message-ID: <20260908173237.46db8656@elisabeth> In-Reply-To: References: <20260820071748.1014070-1-david@gibson.dropbear.id.au> <20260906120526.67bc10d6@elisabeth> Organization: Red Hat X-Mailer: Claws Mail 4.2.0 (GTK 3.24.49; x86_64-pc-linux-gnu) MIME-Version: 1.0 Date: Tue, 08 Sep 2026 17:32:37 +0200 (CEST) X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: 8CNfRkSqTHLbOHrAsivCrNtlgOPZmxSwFhq4hWojhMY_1788881560 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Message-ID-Hash: SLH5T7YCYDJXQTWXY3E7ZAXJDRQ4TC4K X-Message-ID-Hash: SLH5T7YCYDJXQTWXY3E7ZAXJDRQ4TC4K X-MailFrom: sbrivio@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: passt-dev@passt.top, Laurent Vivier X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On Tue, 8 Sep 2026 16:24:04 +1000 David Gibson wrote: > On Sun, Sep 06, 2026 at 12:05:27PM +0200, Stefano Brivio wrote: > > On Thu, 20 Aug 2026 17:17:48 +1000 > > David Gibson wrote: > > > > > When spawning a command, pasta sets the net.ipv4.ping_group_range sysctl > > > to 0 0, meaning only group 0 can use ping sockets within the namespace. > > > Since group 0 is the only one we map in the userns, that's equivalent to > > > anyone being able to use ping sockets. > > > > > > Although the kernel default for this is 1 0 (nobody can use ping sockets), > > > common distros - at least ones using systemd or even just systemd-udevd - > > > appear to set it to "0 2147483647" meaning effectively anyone can use > > > ping sockets. > > > > This wasn't the case on CirrOS (https://github.com/cirros-dev/cirros) > > and on some more common distributions. For example Alpine sets it to > > "999 59999", so group 0 is excluded. > > Ah, hm, right. > > > I haven't checked other distributions not running systemd, but I would > > expect similar outcomes. > > > > > There's no obvious reason that we need to override the system's default > > > behaviour here. The override was introduced in 32d07f5e5 ("passt, pasta: > > > Completely avoid dynamic memory allocation") as part of a large chunk which > > > kind of looks like it was meant to be in another patch, so the git history > > > isn't particularly informative. > > > > Kind of: the override was actually introduced by 089dec90ca99 ("pasta: > > Set ping_group_range upon namespace creation"), which I dropped by mistake > > (pasta.c not committed) in 675174d4ba25 ("conf, tap: Split netlink and > > pasta functions, allow interface configuration"), and finally added back > > by committing pasta.c in 32d07f5e59f2 ("passt, pasta: Completely avoid > > dynamic memory allocation"). > > > > It's not really informative anyway. But, in any case, unless this does > > any harm, I'd rather keep the override, because ping might otherwise > > break on a number of distributions. > > Doesn't really do any harm - that's why this is RFC. I had plans to > move lots of the stuff in this function to various other places in > order to facilitate dealing with the close_range() versus spawned > process problem. > > But yeah, if a bunch of distros don't allow ping from group 0, that > will break things. > > Although... currently we map UID 0 in the namespace to the calling > user in the parent (like unshare -Ur). In some ways it would make > more sense to identity map the parent UID (like unshare -Uc), but let > the spawned process retain CAP_NET_ADMIN so it can still configure the > network. We're operating basically in the parent filesystem, in which > context we "feel" close to being the parent user than root, even > though we have root-like privilege to control the pasta network. > > If we did so, that would fix the ping issue as a side effect - if > we're in the ping group range as the parent UID (which pasta would > need to forward pings anyway) then we should also be so in the > namespace. ...maybe, yeah. It doesn't really feel like a priority to me though. -- Stefano