With passt commit 7bf1595c9242 ("isolation: Don't create our userns
as nobody"), instead of a direct unshare() to detach the isolating
user namespace, we now have a two-step process where we join the
namespace by opening its procfs entry.

After detaching the isolated namespace, AppArmor considers its procfs
entry a disconnected object, so we don't have a way to refer to it
unless we use the attach_disconnected flag in the relevant profile.

For stand-alone passt(1) usage, this is taken care of in passt commit
032f082ffad0 ("apparmor: Fixes for new user namespace detaching
procedure"), but libvirt (as non-root) runs passt as a separate
subprofile, and that's where we need to add that flag.

Link: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1149683
Signed-off-by: Stefano Brivio <[email protected]>
---
 src/security/apparmor/libvirt-qemu | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/src/security/apparmor/libvirt-qemu 
b/src/security/apparmor/libvirt-qemu
index 9bf572692b..4c6e5689c8 100644
--- a/src/security/apparmor/libvirt-qemu
+++ b/src/security/apparmor/libvirt-qemu
@@ -209,7 +209,7 @@
   # support for passt network back-end
   /usr/bin/passt Cx -> passt,
 
-  profile passt {
+  profile passt flags=(attach_disconnected) {
     /usr/bin/passt r,
 
     signal (receive) set=("term") peer=/usr/sbin/libvirtd,
-- 
2.43.0

Reply via email to