With passt commit 7bf1595c9242 ("isolation: Don't create our userns
as nobody"), instead of a direct unshare() to detach the isolating
user namespace, we now have a two-step process where we join the
namespace by opening its procfs entry.
After detaching the isolated namespace, AppArmor considers its procfs
entry a disconnected object, so we don't have a way to refer to it
unless we use the attach_disconnected flag in the relevant profile.
For stand-alone passt(1) usage, this is taken care of in passt commit
032f082ffad0 ("apparmor: Fixes for new user namespace detaching
procedure"), but libvirt (as non-root) runs passt as a separate
subprofile, and that's where we need to add that flag.
Link: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1149683
Signed-off-by: Stefano Brivio <[email protected]>
---
src/security/apparmor/libvirt-qemu | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/security/apparmor/libvirt-qemu
b/src/security/apparmor/libvirt-qemu
index 9bf572692b..4c6e5689c8 100644
--- a/src/security/apparmor/libvirt-qemu
+++ b/src/security/apparmor/libvirt-qemu
@@ -209,7 +209,7 @@
# support for passt network back-end
/usr/bin/passt Cx -> passt,
- profile passt {
+ profile passt flags=(attach_disconnected) {
/usr/bin/passt r,
signal (receive) set=("term") peer=/usr/sbin/libvirtd,
--
2.43.0