public inbox for passt-dev@passt.top
 help / color / mirror / code / Atom feed
From: Stefano Brivio <sbrivio@redhat.com>
To: passt-dev@passt.top
Cc: Paul Holzinger <pholzing@redhat.com>,
	David Gibson <david@gibson.dropbear.id.au>
Subject: [PATCH v2] selinux: Allow passt to use setgid and setuid capabilities in namespace
Date: Fri,  2 Oct 2026 23:02:40 +0200	[thread overview]
Message-ID: <20261002210240.2521252-1-sbrivio@redhat.com> (raw)

Starting from commit 7bf1595c9242 ("isolation: Don't create our userns
as nobody"), we unconditionally set uidmap and gidmap in the detached
user namespace.

Allow that in SELinux rules. We also need to allow explicit access to
the related files.

While at it, add the matching class requirements in pasta.te, which I
forgot (harmless as they were indirectly required, but not really
correct).

Link: https://bodhi.fedoraproject.org/updates/FEDORA-2026-3a8fb909da#comment-4790590
Fixes: 71b74e924426 ("isolation: Don't create our userns as nobody")
Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
---
v2: Dropped spurious files, spotted by Paul

 contrib/selinux/passt.te | 7 +++++--
 contrib/selinux/pasta.te | 2 +-
 2 files changed, 6 insertions(+), 3 deletions(-)

diff --git a/contrib/selinux/passt.te b/contrib/selinux/passt.te
index 6995df8..e540473 100644
--- a/contrib/selinux/passt.te
+++ b/contrib/selinux/passt.te
@@ -23,6 +23,7 @@ require {
 	type user_home_t;
 	type tmpfs_t;
 	type root_t;
+	type nsfs_t;
 
 	# Workaround: passt --vhost-user needs to map guest memory, but
 	# libvirt doesn't maintain its own policy, which makes updates
@@ -61,7 +62,7 @@ require {
 	type sysctl_net_t;
 
 	class capability { sys_tty_config setuid setgid };
-	class cap_userns { setpcap sys_admin sys_ptrace };
+	class cap_userns { setpcap setgid setuid sys_admin sys_ptrace };
 	class user_namespace create;
 }
 
@@ -104,11 +105,13 @@ allow syslogd_t self:cap_userns sys_ptrace;
 
 allow passt_t self:process setcap;
 allow passt_t self:capability { sys_tty_config setpcap net_bind_service setuid setgid};
-allow passt_t self:cap_userns { setpcap sys_admin sys_ptrace };
+allow passt_t self:cap_userns { setgid setuid setpcap sys_admin sys_ptrace };
 allow passt_t self:user_namespace create;
 
 auth_read_passwd(passt_t)
 
+allow passt_t nsfs_t:file { open read };
+
 allow passt_t proc_net_t:file read;
 allow passt_t tmp_t:sock_file { create unlink write };
 allow passt_t self:netlink_route_socket { bind create nlmsg_read read write setopt };
diff --git a/contrib/selinux/pasta.te b/contrib/selinux/pasta.te
index 9394f97..d0c9c32 100644
--- a/contrib/selinux/pasta.te
+++ b/contrib/selinux/pasta.te
@@ -87,7 +87,7 @@ require {
 	type init_t;
 
 	class capability { sys_tty_config setuid setgid };
-	class cap_userns { setpcap sys_admin sys_ptrace net_bind_service net_admin };
+	class cap_userns { setpcap sys_admin sys_ptrace net_bind_service net_admin setgid setuid };
 	class user_namespace create;
 
 	# Container requires
-- 
2.43.0


                 reply	other threads:[~2026-10-02 21:02 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002210240.2521252-1-sbrivio@redhat.com \
    --to=sbrivio@redhat.com \
    --cc=david@gibson.dropbear.id.au \
    --cc=passt-dev@passt.top \
    --cc=pholzing@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this public inbox

	https://passt.top/passt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for IMAP folder(s).