public inbox for passt-dev@passt.top
 help / color / mirror / code / Atom feed
* [PATCH] apparmor: allow netns paths on /tmp again
@ 2026-10-01 12:55 Paul Holzinger
  2026-10-02  5:24 ` Stefano Brivio
  0 siblings, 1 reply; 2+ messages in thread
From: Paul Holzinger @ 2026-10-01 12:55 UTC (permalink / raw)
  To: passt-dev; +Cc: Paul Holzinger

The change to the user-tmp abstraction broke pasta as it can no longer
open the netns path given by podman when it is under /tmp.

The abstraction uses "owner" while the kernel always seems to report
ouid=0 for the bind mounted netns reference. I originally fixed that
in commit 6cdc9fd51bf6 ("apparmor: allow netns paths on /tmp").

In order to fix the regression add /tmp explicitly again here while
keeping the abstraction to still allow /var/tmp for the other regular
files.

Link: https://github.com/podman-container-tools/podman/pull/29867#pullrequestreview-5378330040
Fixes: f2683d14802d ("apparmor: Use user-tmp abstraction, allow /var/tmp instead of /tmp only")
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
---
 contrib/apparmor/usr.bin.pasta | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/contrib/apparmor/usr.bin.pasta b/contrib/apparmor/usr.bin.pasta
index 32dfad9..f641649 100644
--- a/contrib/apparmor/usr.bin.pasta
+++ b/contrib/apparmor/usr.bin.pasta
@@ -22,8 +22,11 @@ profile pasta /usr/bin/pasta{,.avx2} flags=(attach_disconnected) {
 						# tap_sock_unix_init(), pcap(),
 						# pidfile_open(),
 						# pidfile_write(),
-						# logfile_init(),
-						# pasta_open_ns()
+						# logfile_init()
+
+  # user-tmp is using "owner" which is not compatible with netns paths
+  # which show up as ouid=0 in the kernel apparmor checks
+  /tmp/**                              rw,      # pasta_open_ns()
 
   owner @{HOME}/**			w,	# pcap(), pidfile_open(),
 						# pidfile_write()
-- 
2.55.0


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] apparmor: allow netns paths on /tmp again
  2026-10-01 12:55 [PATCH] apparmor: allow netns paths on /tmp again Paul Holzinger
@ 2026-10-02  5:24 ` Stefano Brivio
  0 siblings, 0 replies; 2+ messages in thread
From: Stefano Brivio @ 2026-10-02  5:24 UTC (permalink / raw)
  To: Paul Holzinger; +Cc: passt-dev

On Thu,  1 Oct 2026 14:55:29 +0200
Paul Holzinger <pholzing@redhat.com> wrote:

> The change to the user-tmp abstraction broke pasta as it can no longer
> open the netns path given by podman when it is under /tmp.
> 
> The abstraction uses "owner" while the kernel always seems to report
> ouid=0 for the bind mounted netns reference. I originally fixed that
> in commit 6cdc9fd51bf6 ("apparmor: allow netns paths on /tmp").
> 
> In order to fix the regression add /tmp explicitly again here while
> keeping the abstraction to still allow /var/tmp for the other regular
> files.
> 
> Link: https://github.com/podman-container-tools/podman/pull/29867#pullrequestreview-5378330040
> Fixes: f2683d14802d ("apparmor: Use user-tmp abstraction, allow /var/tmp instead of /tmp only")
> Signed-off-by: Paul Holzinger <pholzing@redhat.com>

Applied (replaced spaces with tabs, reworded comment slightly), thanks,
and sorry for breaking this.

-- 
Stefano


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-02  5:24 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-01 12:55 [PATCH] apparmor: allow netns paths on /tmp again Paul Holzinger
2026-10-02  5:24 ` Stefano Brivio

Code repositories for project(s) associated with this public inbox

	https://passt.top/passt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for IMAP folder(s).