* [PATCH 0/2] pasta: Do not configure ID mappings when invoked with --netns-only @ 2026-07-21 15:37 Dwayne B. Bent 2026-07-21 15:37 ` [PATCH 1/2] pasta: Regression test for bug 216 Dwayne B. Bent 2026-07-21 15:37 ` [PATCH 2/2] pasta: Do not configure ID mappings when invoked with --netns-only Dwayne B. Bent 0 siblings, 2 replies; 5+ messages in thread From: Dwayne B. Bent @ 2026-07-21 15:37 UTC (permalink / raw) To: passt-dev; +Cc: Dwayne B. Bent This is a narrow fix for bug 216 where `pasta` attempts to configure user and group ID mappings when invoked with `--netns-only`. A new `bool` argument `config_idmaps` was added to `pasta_start_ns()` that guards the logic to configure user and group ID mappings. It is set to `false` when `netns_only` is `true`. OpenAI Codex was used to explore and understand the codebase. Code written myself. Test written by Codex guided and reviewed by me. Dwayne B. Bent (2): pasta: Regression test for bug 216 pasta: Do not configure ID mappings when invoked with --netns-only conf.c | 2 +- pasta.c | 24 ++++++++++++++---------- pasta.h | 3 ++- test/pasta_options/netns_only | 19 +++++++++++++++++++ test/run | 1 + 5 files changed, 37 insertions(+), 12 deletions(-) create mode 100644 test/pasta_options/netns_only -- 2.55.0 ^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH 1/2] pasta: Regression test for bug 216 2026-07-21 15:37 [PATCH 0/2] pasta: Do not configure ID mappings when invoked with --netns-only Dwayne B. Bent @ 2026-07-21 15:37 ` Dwayne B. Bent 2026-07-22 4:18 ` David Gibson 2026-07-21 15:37 ` [PATCH 2/2] pasta: Do not configure ID mappings when invoked with --netns-only Dwayne B. Bent 1 sibling, 1 reply; 5+ messages in thread From: Dwayne B. Bent @ 2026-07-21 15:37 UTC (permalink / raw) To: passt-dev; +Cc: Dwayne B. Bent Adds a test that asserts that when pasta is invoked via `unshare -r` in standalone mode with `--netns-only` it does not print any warnings, and the command executes successfully. Assisted-by: Codex:gpt-5.6-sol Signed-off-by: Dwayne B. Bent <dbb@dbb.dev> --- test/pasta_options/netns_only | 19 +++++++++++++++++++ test/run | 1 + 2 files changed, 20 insertions(+) create mode 100644 test/pasta_options/netns_only diff --git a/test/pasta_options/netns_only b/test/pasta_options/netns_only new file mode 100644 index 0000000..197ed44 --- /dev/null +++ b/test/pasta_options/netns_only @@ -0,0 +1,19 @@ +# SPDX-License-Identifier: GPL-2.0-or-later +# +# PASST - Plug A Simple Socket Transport +# for qemu/UNIX domain socket mode +# +# PASTA - Pack A Subtle Tap Abstraction +# for network namespace/tap device mode +# +# test/pasta_options/netns_only - Check --netns-only handling + +htools unshare grep + +test --netns-only skips id mapping configuration +set OUT __STATEDIR__/netns-only.out +set ERR __STATEDIR__/netns-only.err + +passt unshare -r -- ./pasta -q --netns-only -- echo TEST > __OUT__ 2> __ERR__ +check grep -qx TEST __OUT__ +check [ ! -s __ERR__ ] diff --git a/test/run b/test/run index f858e55..c4073cc 100755 --- a/test/run +++ b/test/run @@ -85,6 +85,7 @@ run() { setup pasta_options test pasta_options/log_to_file + test pasta_options/netns_only teardown pasta_options setup build -- 2.55.0 ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH 1/2] pasta: Regression test for bug 216 2026-07-21 15:37 ` [PATCH 1/2] pasta: Regression test for bug 216 Dwayne B. Bent @ 2026-07-22 4:18 ` David Gibson 0 siblings, 0 replies; 5+ messages in thread From: David Gibson @ 2026-07-22 4:18 UTC (permalink / raw) To: Dwayne B. Bent; +Cc: passt-dev [-- Attachment #1: Type: text/plain, Size: 2173 bytes --] On Tue, Jul 21, 2026 at 11:37:26AM -0400, Dwayne B. Bent wrote: > Adds a test that asserts that when pasta is invoked via `unshare -r` in > standalone mode with `--netns-only` it does not print any warnings, and > the command executes successfully. > > Assisted-by: Codex:gpt-5.6-sol > Signed-off-by: Dwayne B. Bent <dbb@dbb.dev> Content LGTM, however there's a detail in the packaging: Although having the test before the fix is obviously the right order while developing and testing it, for final merge we want the test either after the fix, or folded into the same patch: that way we don't risk breaking future bisects. > --- > test/pasta_options/netns_only | 19 +++++++++++++++++++ > test/run | 1 + > 2 files changed, 20 insertions(+) > create mode 100644 test/pasta_options/netns_only > > diff --git a/test/pasta_options/netns_only b/test/pasta_options/netns_only > new file mode 100644 > index 0000000..197ed44 > --- /dev/null > +++ b/test/pasta_options/netns_only > @@ -0,0 +1,19 @@ > +# SPDX-License-Identifier: GPL-2.0-or-later > +# > +# PASST - Plug A Simple Socket Transport > +# for qemu/UNIX domain socket mode > +# > +# PASTA - Pack A Subtle Tap Abstraction > +# for network namespace/tap device mode > +# > +# test/pasta_options/netns_only - Check --netns-only handling > + > +htools unshare grep > + > +test --netns-only skips id mapping configuration > +set OUT __STATEDIR__/netns-only.out > +set ERR __STATEDIR__/netns-only.err > + > +passt unshare -r -- ./pasta -q --netns-only -- echo TEST > __OUT__ 2> __ERR__ > +check grep -qx TEST __OUT__ > +check [ ! -s __ERR__ ] > diff --git a/test/run b/test/run > index f858e55..c4073cc 100755 > --- a/test/run > +++ b/test/run > @@ -85,6 +85,7 @@ run() { > > setup pasta_options > test pasta_options/log_to_file > + test pasta_options/netns_only > teardown pasta_options > > setup build > -- > 2.55.0 > -- David Gibson (he or they) | I'll have my music baroque, and my code david AT gibson.dropbear.id.au | minimalist, thank you, not the other way | around. http://www.ozlabs.org/~dgibson [-- Attachment #2: signature.asc --] [-- Type: application/pgp-signature, Size: 833 bytes --] ^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH 2/2] pasta: Do not configure ID mappings when invoked with --netns-only 2026-07-21 15:37 [PATCH 0/2] pasta: Do not configure ID mappings when invoked with --netns-only Dwayne B. Bent 2026-07-21 15:37 ` [PATCH 1/2] pasta: Regression test for bug 216 Dwayne B. Bent @ 2026-07-21 15:37 ` Dwayne B. Bent 2026-07-22 4:40 ` David Gibson 1 sibling, 1 reply; 5+ messages in thread From: Dwayne B. Bent @ 2026-07-21 15:37 UTC (permalink / raw) To: passt-dev; +Cc: Dwayne B. Bent Add a `bool` argument `config_idmaps` to `pasta_start_ns()` that guards the logic to configure user and group ID mappings. It is set to `false` when `netns_only` is `true`. Fixes bug 216. Assisted-by: Codex:gpt-5.6-sol Signed-off-by: Dwayne B. Bent <dbb@dbb.dev> --- conf.c | 2 +- pasta.c | 24 ++++++++++++++---------- pasta.h | 3 ++- 3 files changed, 17 insertions(+), 12 deletions(-) diff --git a/conf.c b/conf.c index 0fcba5c..2223604 100644 --- a/conf.c +++ b/conf.c @@ -1945,7 +1945,7 @@ void conf(struct ctx *c, int argc, char **argv) if (*netns) { pasta_open_ns(c, netns); } else { - pasta_start_ns(c, uid, gid, + pasta_start_ns(c, uid, gid, !netns_only, argc - optind, argv + optind); } } diff --git a/pasta.c b/pasta.c index 4e7ee54..5aa56b7 100644 --- a/pasta.c +++ b/pasta.c @@ -236,10 +236,11 @@ static int pasta_spawn_cmd(void *arg) * @c: Execution context * @uid: UID we're running as in the init namespace * @gid: GID we're running as in the init namespace + * @config_idmaps: Whether to configure user mappings * @argc: Number of arguments for spawned command * @argv: Command to spawn and arguments */ -void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, +void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, bool config_idmaps, int argc, char *argv[]) { char ns_fn_stack[NS_FN_STACK_SIZE] @@ -249,7 +250,6 @@ void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, .argv = argv, .c = c, }; - char uidmap[BUFSIZ], gidmap[BUFSIZ]; char *sh_argv[] = { NULL, NULL }; char sh_arg0[PATH_MAX + 1]; sigset_t set; @@ -259,16 +259,20 @@ void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, c->quiet = 1; /* Configure user and group mappings */ - if (snprintf_check(uidmap, BUFSIZ, "0 %u 1", uid)) - die_perror("Can't build uidmap"); + if (config_idmaps) { + char uidmap[BUFSIZ], gidmap[BUFSIZ]; - if (snprintf_check(gidmap, BUFSIZ, "0 %u 1", gid)) - die_perror("Can't build gidmap"); + if (snprintf_check(uidmap, BUFSIZ, "0 %u 1", uid)) + die_perror("Can't build uidmap"); - if (write_file("/proc/self/uid_map", uidmap) || - write_file("/proc/self/setgroups", "deny") || - write_file("/proc/self/gid_map", gidmap)) { - warn("Couldn't configure user mappings"); + if (snprintf_check(gidmap, BUFSIZ, "0 %u 1", gid)) + die_perror("Can't build gidmap"); + + if (write_file("/proc/self/uid_map", uidmap) || + write_file("/proc/self/setgroups", "deny") || + write_file("/proc/self/gid_map", gidmap)) { + warn("Couldn't configure user mappings"); + } } if (argc == 0) { diff --git a/pasta.h b/pasta.h index 07e04b3..edd7747 100644 --- a/pasta.h +++ b/pasta.h @@ -6,12 +6,13 @@ #ifndef PASTA_H #define PASTA_H +#include <stdbool.h> #include <unistd.h> extern int pasta_child_pid; void pasta_open_ns(struct ctx *c, const char *netns); -void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, +void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, bool config_idmaps, int argc, char *argv[]); void pasta_ns_conf(struct ctx *c); void pasta_child_handler(int signal); -- 2.55.0 ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH 2/2] pasta: Do not configure ID mappings when invoked with --netns-only 2026-07-21 15:37 ` [PATCH 2/2] pasta: Do not configure ID mappings when invoked with --netns-only Dwayne B. Bent @ 2026-07-22 4:40 ` David Gibson 0 siblings, 0 replies; 5+ messages in thread From: David Gibson @ 2026-07-22 4:40 UTC (permalink / raw) To: Dwayne B. Bent; +Cc: passt-dev [-- Attachment #1: Type: text/plain, Size: 3806 bytes --] On Tue, Jul 21, 2026 at 11:37:27AM -0400, Dwayne B. Bent wrote: > Add a `bool` argument `config_idmaps` to `pasta_start_ns()` that guards > the logic to configure user and group ID mappings. It is set to `false` > when `netns_only` is `true`. Fixes bug 216. > > Assisted-by: Codex:gpt-5.6-sol > Signed-off-by: Dwayne B. Bent <dbb@dbb.dev> Needs a Link: https://bugs.passt.top/show_bug.cgi?id=216 line. Otherwise looks fine to me. > --- > conf.c | 2 +- > pasta.c | 24 ++++++++++++++---------- > pasta.h | 3 ++- > 3 files changed, 17 insertions(+), 12 deletions(-) > > diff --git a/conf.c b/conf.c > index 0fcba5c..2223604 100644 > --- a/conf.c > +++ b/conf.c > @@ -1945,7 +1945,7 @@ void conf(struct ctx *c, int argc, char **argv) > if (*netns) { > pasta_open_ns(c, netns); > } else { > - pasta_start_ns(c, uid, gid, > + pasta_start_ns(c, uid, gid, !netns_only, > argc - optind, argv + optind); > } > } > diff --git a/pasta.c b/pasta.c > index 4e7ee54..5aa56b7 100644 > --- a/pasta.c > +++ b/pasta.c > @@ -236,10 +236,11 @@ static int pasta_spawn_cmd(void *arg) > * @c: Execution context > * @uid: UID we're running as in the init namespace > * @gid: GID we're running as in the init namespace > + * @config_idmaps: Whether to configure user mappings > * @argc: Number of arguments for spawned command > * @argv: Command to spawn and arguments > */ > -void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, > +void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, bool config_idmaps, > int argc, char *argv[]) > { > char ns_fn_stack[NS_FN_STACK_SIZE] > @@ -249,7 +250,6 @@ void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, > .argv = argv, > .c = c, > }; > - char uidmap[BUFSIZ], gidmap[BUFSIZ]; > char *sh_argv[] = { NULL, NULL }; > char sh_arg0[PATH_MAX + 1]; > sigset_t set; > @@ -259,16 +259,20 @@ void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, > c->quiet = 1; > > /* Configure user and group mappings */ > - if (snprintf_check(uidmap, BUFSIZ, "0 %u 1", uid)) > - die_perror("Can't build uidmap"); > + if (config_idmaps) { > + char uidmap[BUFSIZ], gidmap[BUFSIZ]; > > - if (snprintf_check(gidmap, BUFSIZ, "0 %u 1", gid)) > - die_perror("Can't build gidmap"); > + if (snprintf_check(uidmap, BUFSIZ, "0 %u 1", uid)) > + die_perror("Can't build uidmap"); > > - if (write_file("/proc/self/uid_map", uidmap) || > - write_file("/proc/self/setgroups", "deny") || > - write_file("/proc/self/gid_map", gidmap)) { > - warn("Couldn't configure user mappings"); > + if (snprintf_check(gidmap, BUFSIZ, "0 %u 1", gid)) > + die_perror("Can't build gidmap"); > + > + if (write_file("/proc/self/uid_map", uidmap) || > + write_file("/proc/self/setgroups", "deny") || > + write_file("/proc/self/gid_map", gidmap)) { > + warn("Couldn't configure user mappings"); > + } > } > > if (argc == 0) { > diff --git a/pasta.h b/pasta.h > index 07e04b3..edd7747 100644 > --- a/pasta.h > +++ b/pasta.h > @@ -6,12 +6,13 @@ > #ifndef PASTA_H > #define PASTA_H > > +#include <stdbool.h> > #include <unistd.h> > > extern int pasta_child_pid; > > void pasta_open_ns(struct ctx *c, const char *netns); > -void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, > +void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, bool config_idmaps, > int argc, char *argv[]); > void pasta_ns_conf(struct ctx *c); > void pasta_child_handler(int signal); > -- > 2.55.0 > -- David Gibson (he or they) | I'll have my music baroque, and my code david AT gibson.dropbear.id.au | minimalist, thank you, not the other way | around. http://www.ozlabs.org/~dgibson [-- Attachment #2: signature.asc --] [-- Type: application/pgp-signature, Size: 833 bytes --] ^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-07-22 5:16 UTC | newest] Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- 2026-07-21 15:37 [PATCH 0/2] pasta: Do not configure ID mappings when invoked with --netns-only Dwayne B. Bent 2026-07-21 15:37 ` [PATCH 1/2] pasta: Regression test for bug 216 Dwayne B. Bent 2026-07-22 4:18 ` David Gibson 2026-07-21 15:37 ` [PATCH 2/2] pasta: Do not configure ID mappings when invoked with --netns-only Dwayne B. Bent 2026-07-22 4:40 ` David Gibson
Code repositories for project(s) associated with this public inbox https://passt.top/passt This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox; as well as URLs for IMAP folder(s).