public inbox for passt-dev@passt.top
 help / color / mirror / code / Atom feed
492d0ab10ad9f78312d4bf6bf175dd7de8a77a79 blob 3604 bytes (raw)

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
 
From 2a7824f0a4863f0cee33370d994e28c584d6922c Mon Sep 17 00:00:00 2001
From: Stefano Brivio <sbrivio@redhat.com>
Date: Fri, 16 Jan 2026 16:48:46 +0100
Subject: [PATCH] selinux: Enable open permissions on netns directory,
 operations on container_var_run_t

Tuomo reports two further SELinux denials after upgrading to a
passt-selinux version that includes the transition to pasta_t for
containers, one I could reproduce:

  denied  { open } for  pid=3343050 comm="pasta.avx2" path="/run/user/1000/netns" dev="tmpfs" ino=51 scontext=unconfined_u:unconfined_r:pasta_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:user_tmp_t:s0 tclass=dir permissive=1

which I didn't take care of in the previous commit, d2c5133990a7
("selinux: Enable read and watch permissions on netns directory as
well"), as it didn't appear in my quick test. But I can make pasta use
"open" on the network namespace entry by simply using it to make
connections.

So, for that, add "open" to the existing rule for user_tmp_t:dir.

Then, another one I couldn't reproduce instead:

  denied  { write } for  pid=3589324 comm="pasta.avx2" name="rootless-netns" dev="tmpfs" ino=36 scontext=unconfined_u:unconfined_r:pasta_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:container_var_run_t:s0 tclass=dir permissive=0

which, I think, comes from a specific combination of versions of
container-selinux, Podman, and passt-selinux packages, which
prevents the expected type transition on container_var_run_t unless
restorecon is invoked manually, or until a reboot.

Allowing the same permissions on container_var_run_t as we do on
ifconfig_var_run_t is harmless, so do that to prevent this further
denial.

Reported-by: Tuomo Soini <tis@foobar.fi>
Fixes: d2c5133990a7 ("selinux: Enable read and watch permissions on netns directory as well")
Fixes: 7aeda16a7818 ("selinux: Transition to pasta_t in containers")
Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
---
Max, for context, this was reported at
https://issues.redhat.com/browse/RHEL-136495, which is a public
ticket but not necessarily a stable link as far as I know, so I'm
not adding that as a Link: tag. I hope it's the last one! :)

 contrib/selinux/pasta.te | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/contrib/selinux/pasta.te b/contrib/selinux/pasta.te
index 3eb58f6..fb51416 100644
--- a/contrib/selinux/pasta.te
+++ b/contrib/selinux/pasta.te
@@ -149,7 +149,7 @@ allow pasta_t root_t:dir mounton;
 manage_files_pattern(pasta_t, pasta_pid_t, pasta_pid_t)
 files_pid_filetrans(pasta_t, pasta_pid_t, file)
 
-allow pasta_t user_tmp_t:dir { add_name read remove_name search watch write };
+allow pasta_t user_tmp_t:dir { add_name open read remove_name search watch write };
 allow pasta_t user_tmp_t:fifo_file append;
 allow pasta_t user_tmp_t:file { create open write };
 allow pasta_t user_tmp_t:sock_file { create unlink };
@@ -249,7 +249,9 @@ type_transition container_runtime_t user_tmp_t : dir ifconfig_var_run_t "netns";
 type_transition container_runtime_t container_var_run_t : dir ifconfig_var_run_t "netns";
 type_transition container_runtime_t user_tmp_t : dir ifconfig_var_run_t "rootless-netns";
 type_transition container_runtime_t container_var_run_t : dir ifconfig_var_run_t "rootless-netns";
+allow pasta_t container_var_run_t:dir { add_name open rmdir write };
 allow pasta_t ifconfig_var_run_t:dir { add_name open rmdir write };
+allow pasta_t container_var_run_t:file { create open write };
 allow pasta_t ifconfig_var_run_t:file { create open write };
 allow systemd_user_runtimedir_t ifconfig_var_run_t:dir rmdir;
 
-- 
2.43.0

debug log:

solving 492d0ab ...
found 492d0ab in https://archives.passt.top/passt-dev/20261002070045.2065145-1-sbrivio@redhat.com/

applying [1/1] https://archives.passt.top/passt-dev/20261002070045.2065145-1-sbrivio@redhat.com/
diff --git a/contrib/selinux/0001-selinux-Enable-open-permissions-on-netns-directory-o.patch b/contrib/selinux/0001-selinux-Enable-open-permissions-on-netns-directory-o.patch
new file mode 100644
index 0000000..492d0ab

1:60: trailing whitespace.
 
1:75: trailing whitespace.
 
1:76: trailing whitespace.
-- 
Checking patch contrib/selinux/0001-selinux-Enable-open-permissions-on-netns-directory-o.patch...
1:78: new blank line at EOF.
+
Applied patch contrib/selinux/0001-selinux-Enable-open-permissions-on-netns-directory-o.patch cleanly.
warning: 4 lines add whitespace errors.

index at:
100644 492d0ab10ad9f78312d4bf6bf175dd7de8a77a79	contrib/selinux/0001-selinux-Enable-open-permissions-on-netns-directory-o.patch

Code repositories for project(s) associated with this public inbox

	https://passt.top/passt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for IMAP folder(s).