From mboxrd@z Thu Jan 1 00:00:00 1970 Received: by passt.top (Postfix, from userid 1000) id 4574D5A0271; Fri, 02 Oct 2026 23:04:11 +0200 (CEST) From: Stefano Brivio To: passt-dev@passt.top Subject: [PATCH] apparmor: Fixes for new user namespace detaching procedure Date: Fri, 2 Oct 2026 23:04:11 +0200 Message-ID: <20261002210411.2522002-1-sbrivio@redhat.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Message-ID-Hash: KMFGLJ7LQVXJEG5LAJQ5XKOBEGIIQ2SM X-Message-ID-Hash: KMFGLJ7LQVXJEG5LAJQ5XKOBEGIIQ2SM X-MailFrom: sbrivio@passt.top X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Michal Humpula , David Gibson X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Commit 7bf1595c9242 ("isolation: Don't create our userns as nobody") changed the procedure user namespaces are detached, also for passt, and adds unconditional setting of UID and GID maps. This needs AppArmor adjustments: - rules to access gid_map, uid_map, and setgroups entries in procfs now need to be enabled for passt as well, not just for pasta: move them to the passt abstraction (which is included from the pasta abstraction) - we now need to open a user namespace originally detached by a separate holder process, which requires us to open procfs entries that are disconnected (from an AppArmor perspective) from the original namespace: add the attach_disconnected flag to the profile for passt as well (this was already the case for pasta). This isn't ideal but there doesn't seem any way around it: opening the namespace from the holder process itself doesn't help either. We'll need to add this flag also in passt subprofiles for guestfs-tools (maintained in Debian) and libvirtd (which only applies when guests are started as root for the moment, maintained by libvirt upstream). Reported-by: Michal Humpula Link: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1149683 Signed-off-by: Stefano Brivio --- contrib/apparmor/abstractions/passt | 4 +++- contrib/apparmor/abstractions/pasta | 4 ---- contrib/apparmor/usr.bin.passt | 2 +- 3 files changed, 4 insertions(+), 6 deletions(-) diff --git a/contrib/apparmor/abstractions/passt b/contrib/apparmor/abstractions/passt index f4570c1..0aeb19d 100644 --- a/contrib/apparmor/abstractions/passt +++ b/contrib/apparmor/abstractions/passt @@ -34,7 +34,9 @@ pivot_root "/tmp/" -> "/tmp/", umount "/", - owner @{PROC}/@{pid}/uid_map r, # conf_ugid() + owner @{PROC}/@{pid}/gid_map w, # make_ugid_map() + owner @{PROC}/@{pid}/setgroups w, + owner @{PROC}/@{pid}/uid_map rw, @{PROC}/sys/net/ipv4/ip_local_port_range r, # fwd_probe_ephemeral() diff --git a/contrib/apparmor/abstractions/pasta b/contrib/apparmor/abstractions/pasta index 251d4a2..89fa427 100644 --- a/contrib/apparmor/abstractions/pasta +++ b/contrib/apparmor/abstractions/pasta @@ -35,10 +35,6 @@ /dev/net/tun rw, # tap_ns_tun(), tap.c - owner @{PROC}/@{pid}/gid_map w, # pasta_start_ns(), conf_ugid() - owner @{PROC}/@{pid}/setgroups w, - owner @{PROC}/@{pid}/uid_map rw, - owner @{PROC}/sys/net/ipv4/ping_group_range w, # pasta_spawn_cmd(), pasta.c /{usr/,}bin/** Ux, diff --git a/contrib/apparmor/usr.bin.passt b/contrib/apparmor/usr.bin.passt index da49e37..ccc2ea9 100644 --- a/contrib/apparmor/usr.bin.passt +++ b/contrib/apparmor/usr.bin.passt @@ -15,7 +15,7 @@ abi , include -profile passt /usr/bin/passt{,.avx2} { +profile passt /usr/bin/passt{,.avx2} flags=(attach_disconnected) { include include # tap_sock_unix_open(), -- 2.43.0