[PATCH] apparmor: Add attach_disconnected flag to passt libvirt-qemu subprofile
With passt commit 7bf1595c9242 ("isolation: Don't create our userns as nobody"), instead of a direct unshare() to detach the isolating user namespace, we now have a two-step process where we join the namespace by opening its procfs entry. After detaching the isolated namespace, AppArmor considers its procfs entry a disconnected object, so we don't have a way to refer to it unless we use the attach_disconnected flag in the relevant profile. For stand-alone passt(1) usage, this is taken care of in passt commit 032f082ffad0 ("apparmor: Fixes for new user namespace detaching procedure"), but libvirt (as non-root) runs passt as a separate subprofile, and that's where we need to add that flag. Link: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1149683 Signed-off-by: Stefano Brivio <sbrivio@redhat.com> --- src/security/apparmor/libvirt-qemu | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/security/apparmor/libvirt-qemu b/src/security/apparmor/libvirt-qemu index 9bf572692b..4c6e5689c8 100644 --- a/src/security/apparmor/libvirt-qemu +++ b/src/security/apparmor/libvirt-qemu @@ -209,7 +209,7 @@ # support for passt network back-end /usr/bin/passt Cx -> passt, - profile passt { + profile passt flags=(attach_disconnected) { /usr/bin/passt r, signal (receive) set=("term") peer=/usr/sbin/libvirtd, -- 2.43.0
participants (1)
-
Stefano Brivio