From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=VNgMYNcw; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by passt.top (Postfix) with ESMTPS id 93E3E5A0265 for ; Thu, 01 Oct 2026 14:56:33 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1790859392; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=RRf/36VinUTCkS2q0Z+bUCF7IQNwYsTrS8qN3BNF3Ts=; b=VNgMYNcwjlTlOTSdwkgSK4PyLgbNTokuixFIsor24fFSSUdS2WDLUeDZh//0OItUjTbWid bhY80DGjEwTO85MO+C2fPy9wT9T4iwjtwcP3RXknUQaRbBgQZgDhZyin1qq4IT6TYgEOui bzwmU52A0DyDUfOhTMOWPZWSU5ZfcvQ= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-176-hZ_VHmntOP6X7A_W5wCKrw-1; Thu, 01 Oct 2026 08:56:31 -0400 X-MC-Unique: hZ_VHmntOP6X7A_W5wCKrw-1 X-Mimecast-MFC-AGG-ID: hZ_VHmntOP6X7A_W5wCKrw_1790859390 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 78F15180067A for ; Thu, 1 Oct 2026 12:56:30 +0000 (UTC) Received: from pholzing-fedora.redhat.corp (headnet05.pony-001.prod.iad2.dc.redhat.com [10.2.32.117]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 2FCA01800446; Thu, 1 Oct 2026 12:56:28 +0000 (UTC) From: Paul Holzinger To: passt-dev@passt.top Subject: [PATCH] apparmor: allow netns paths on /tmp again Date: Thu, 1 Oct 2026 14:55:29 +0200 Message-ID: <20261001125528.78194-2-pholzing@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: krclNcVbS7M4xEPnC4cadtkpjz-qt91wxmy92UO-GP4_1790859390 X-Mimecast-Originator: redhat.com Content-Transfer-Encoding: 8bit content-type: text/plain; charset="US-ASCII"; x-default=true Message-ID-Hash: OKZ7243ER2AUKHEJLRZKHEVCVHZ7YZDE X-Message-ID-Hash: OKZ7243ER2AUKHEJLRZKHEVCVHZ7YZDE X-MailFrom: pholzing@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Paul Holzinger X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: The change to the user-tmp abstraction broke pasta as it can no longer open the netns path given by podman when it is under /tmp. The abstraction uses "owner" while the kernel always seems to report ouid=0 for the bind mounted netns reference. I originally fixed that in commit 6cdc9fd51bf6 ("apparmor: allow netns paths on /tmp"). In order to fix the regression add /tmp explicitly again here while keeping the abstraction to still allow /var/tmp for the other regular files. Link: https://github.com/podman-container-tools/podman/pull/29867#pullrequestreview-5378330040 Fixes: f2683d14802d ("apparmor: Use user-tmp abstraction, allow /var/tmp instead of /tmp only") Signed-off-by: Paul Holzinger --- contrib/apparmor/usr.bin.pasta | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/contrib/apparmor/usr.bin.pasta b/contrib/apparmor/usr.bin.pasta index 32dfad9..f641649 100644 --- a/contrib/apparmor/usr.bin.pasta +++ b/contrib/apparmor/usr.bin.pasta @@ -22,8 +22,11 @@ profile pasta /usr/bin/pasta{,.avx2} flags=(attach_disconnected) { # tap_sock_unix_init(), pcap(), # pidfile_open(), # pidfile_write(), - # logfile_init(), - # pasta_open_ns() + # logfile_init() + + # user-tmp is using "owner" which is not compatible with netns paths + # which show up as ouid=0 in the kernel apparmor checks + /tmp/** rw, # pasta_open_ns() owner @{HOME}/** w, # pcap(), pidfile_open(), # pidfile_write() -- 2.55.0