Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #82538

Bug#1050256: AppArmor breaks locking non-fs Unix sockets

Path csiph.com!fu-berlin.de!bofh.it!news.nic.it!robomod
From Luca Boccassi <bluca@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#1050256: AppArmor breaks locking non-fs Unix sockets
Date Tue, 21 May 2024 19:10:02 +0200
Message-ID <IGB9U-eTji-5@gated-at.bofh.it> (permalink)
References <Hc40G-7MXQ-27@gated-at.bofh.it> <HfrDr-9Sh6-3@gated-at.bofh.it> <HfrDr-9Sh6-3@gated-at.bofh.it> <H5AeZ-3Dvv-9@gated-at.bofh.it> <HI85X-bOgB-11@gated-at.bofh.it> <H5AeZ-3Dvv-9@gated-at.bofh.it> <HI85X-bOgB-9@gated-at.bofh.it> <HQJL3-haEJ-3@gated-at.bofh.it> <HQVCx-hjCK-1@gated-at.bofh.it> <IGB9U-eTji-7@gated-at.bofh.it> <IGB9U-eTji-9@gated-at.bofh.it> <H5AeZ-3Dvv-9@gated-at.bofh.it> <IGB9U-eTji-9@gated-at.bofh.it>
X-Mailbox-Line From debian-bugs-dist-request@lists.debian.org Tue May 21 17:03:12 2024
Old-Return-Path <debbugs@buxtehude.debian.org>
X-Spam-Flag NO
Reply-To Luca Boccassi <bluca@debian.org>, 1050256@bugs.debian.org
Resent-To debian-bugs-dist@lists.debian.org
Resent-Cc Debian Kernel Team <debian-kernel@lists.debian.org>
X-Debian-Pr-Message followup 1050256
X-Debian-Pr-Package src:linux
X-Debian-Pr-Keywords bookworm moreinfo sid trixie experimental confirmed upstream
X-Debian-Pr-Source linux
X-Forwarded-Encrypted i=1; AJvYcCVt3D8dM9xbg6/Lb74ESbITkxoZOUIhFX0euhWYqRwu6PisEmmXEYOiZkMh1XkB1uE+T4AcoNfYTCaFXEjMIAga4oz+wxkDMA==
X-Gm-Message-State AOJu0YxvttHONlMgIKVV/s54aGb/JKbDFy1oZVFwNLp78DdcEEYkAnRJ 7x1LbfuwMp+FvT3reSrxMgJM1SE6vL5MOCaRXGP+qECkHc5MuanQ
X-Google-SMTP-Source AGHT+IE4YVybpDd7fVTn5i9S/ueqkyitV3FdX9II+Xp8cuDucTiBMtGMTV08farbDnIa1bTd+4/10Q==
X-Received by 2002:adf:e8cc:0:b0:34d:b03c:9a97 with SMTP id ffacd0b85a97d-3504a95606cmr35786291f8f.48.1716310686286; Tue, 21 May 2024 09:58:06 -0700 (PDT)
Content-Type multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-GBw+pduBJVyORMpez2lA"
User-Agent Evolution 3.46.4-2
MIME-Version 1.0
X-Debian-Message from BTS
X-Mailing-List <debian-bugs-dist@lists.debian.org> archive/latest/1838649
List-ID <debian-bugs-dist.lists.debian.org>
List-URL <https://lists.debian.org/debian-bugs-dist/>
Approved robomod@news.nic.it
Lines 148
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Cc Mathias Gibbens <gibmat@debian.org>, 1050256@bugs.debian.org, John Johansen <john@apparmor.net>, Paul Gevers <elbrus@debian.org>, Antonio Terceiro <terceiro@debian.org>, pkg-systemd-maintainers <pkg-systemd-maintainers@lists.alioth.debian.org>, apparmor@lists.ubuntu.com, Harald Dunkel <harri@afaics.de>, Salvatore Bonaccorso <salvatore.bonaccorso@gmail.com>, Christian Ehrhardt <christian.ehrhardt@canonical.com>
X-Original-Date Tue, 21 May 2024 17:58:03 +0100
X-Original-Message-ID <c2d004fd01c5b085f74ea4dfa4fc99a971c812e8.camel@debian.org>
X-Original-References <da160344-8135-4eab-9261-bb1552238ad3@debian.org> <8f68c83b-1856-4fa2-8408-06ae36696698@debian.org> <8f68c83b-1856-4fa2-8408-06ae36696698@debian.org> <169271330498.34427.2191706613553030083.reportbug@pluto.milchstrasse.xx> <38461b24-1b42-45f7-98d6-e6e353c0d203@debian.org> <169271330498.34427.2191706613553030083.reportbug@pluto.milchstrasse.xx> <ZXDsAecCKiSuHsO2@eldamar.lan> <ZZA69zQAzpzPojD5@eldamar.lan> <9d6a5b2368016e2ef7b11c64b7c9db69419318ec.camel@debian.org> <b8bb1a0e-9b50-4f78-8473-4f0151677f25@canonical.com> <ZbYk7yOaAq0O8Rid@eldamar.lan> <169271330498.34427.2191706613553030083.reportbug@pluto.milchstrasse.xx> <ZbYk7yOaAq0O8Rid@eldamar.lan>
Xref csiph.com linux.debian.bugs.dist:1198197 linux.debian.kernel:82538

Cross-posted to 2 groups.

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

On Sun, 28 Jan 2024 10:57:03 +0100 Salvatore Bonaccorso
<salvatore.bonaccorso@gmail.com> wrote:
> Hi John,
> 
> On Sun, Jan 28, 2024 at 12:43:33AM -0800, John Johansen wrote:
> > On 12/30/23 20:24, Mathias Gibbens wrote:
> > > On Sat, 2023-12-30 at 16:44 +0100, Salvatore Bonaccorso wrote:
> > > > John, did you had a chance to work on this backport for 6.1.y
stable
> > > > upstream so we could pick it downstream in Debian in one of the
next
> > > > stable imports? Cherry-picking 1cf26c3d2c4c ("apparmor: fix
apparmor
> > > > mediating locking non-fs unix sockets") does not work, if not
> > > > havinging the work around e2967ede2297 ("apparmor: compute
policydb
> > > > permission on profile load") AFAICS, so that needs a 6.1.y
specific
> > > > backport submitted to stable@vger.kernel.org ?
> > > > 
> > > > I think we could have people from this bug as well providing a
> > > > Tested-by when necessary. I'm not feeling confident enough to
be able
> > > > to provide myself such a patch to sent to stable (and you only
giving
> > > > an Acked-by/Reviewed-by), so if you can help out here with your
> > > > upstream hat on that would be more than appreciated and welcome
:)
> > > > 
> > > > Thanks a lot for your work!
> > > 
> > >    I played around with this a bit the past week as well, and
came to
> > > the same conclusion as Salvatore did that commits e2967ede2297
and
> > > 1cf26c3d2c4c need to be cherry-picked back to the 6.1 stable
tree.
> > > 
> > >    I've attached the two commits rebased onto 6.1.y as patches to
this
> > > message. Commit e2967ede2297 needed a little bit of touchup to
apply
> > > cleanly, and 1cf26c3d2c4c just needed adjustments for line number
> > > changes. I included some comments at the top of each patch.
> > > 
> > >    With these two commits cherry-picked on top of the 6.1.69
kernel, I
> > > can boot a bookworm system and successfully start a service
within a
> > > container that utilizes `PrivateNetwork=yes`. Rebooting back into
an
> > > unpatched vanilla 6.1.69 kernel continues to show the problem.
> > > 
> > >    While I didn't see any immediate issues (ie, `aa-status` and
log
> > > files looked OK), I don't understand the changes in the first
commit
> > > well enough to be confident in sending these patches for
inclusion in
> > > the upstream stable tree on my own.
> > > 
> > > Mathias
> > 
> > Your backports look good to me, and you can stick my acked-by on
them.
> > The changes are strictly more than necessary for the fix. They are
> > part of a larger change set that is trying to cleanup the runtime
> > code by changing the permission mapping from a runtime operation
> > to something that is done only at policy load/unpack time.
> > 
> > The advantage of this approach is that while it is a larger change
> > than strictly necessary. It is backporting patches that are already
> > upstream, keep the code closer and making backports easier.
> > 
> > Georgia did a minimal backport fix by keeping the version as part
> > of policy and doing the permission mapping at runtime. I have
> > included that patch below. Its advantage is it is a minimal
> > change to fix the issue.
> > 
> > I am happy with either version going into stable. Do you want to
> > send them or do you want me to do it?
> Thanks a lot, that is *really* much appreicated!
> 
> if you can send them that would be great, because think then they
> come
> directly from you, the trust from Greg or Sasha is higher. otherwise
> I
> think they will then explicitly want an ack on that submission thread
> from you (or pointing to this Debian downstream bug).
> 
> Greg will probably want the backport apporach of the two commits if
> it
> feasible and we do not expect regression from it. But you are
> definitively in a better position to judge this :)
> 
> Thanks again!
> 
> Regards,
> Salvatore
> 
> p.s.: feel free to CC us as well in the upstream stable submission.

Hi John,

Is there any update on this? As far as I am aware this patch has not
been sent for backporting yet, so apparmor in 6.1 is still borken, and
the CI still fails because of it.

Is there any chance you could please take care of that, so that we can
finally fix this issue?

Thanks!

-- 
Kind regards,
Luca Boccassi

Back to linux.debian.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#1050256: AppArmor breaks locking non-fs Unix sockets Salvatore Bonaccorso <carnil@debian.org> - 2023-12-06 23:00 +0100
  Bug#1050256: AppArmor breaks locking non-fs Unix sockets Salvatore Bonaccorso <carnil@debian.org> - 2023-12-30 16:50 +0100
    Bug#1050256: AppArmor breaks locking non-fs Unix sockets Salvatore Bonaccorso <carnil@debian.org> - 2024-01-27 10:30 +0100
    Bug#1050256: AppArmor breaks locking non-fs Unix sockets Luca Boccassi <bluca@debian.org> - 2024-05-21 19:10 +0200
    Bug#1050256: AppArmor breaks locking non-fs Unix sockets Salvatore Bonaccorso <carnil@debian.org> - 2024-05-26 13:50 +0200
      Bug#1050256: AppArmor breaks locking non-fs Unix sockets Luca Boccassi <bluca@debian.org> - 2024-05-26 18:10 +0200
      Bug#1050256: AppArmor breaks locking non-fs Unix sockets Salvatore Bonaccorso <carnil@debian.org> - 2024-08-03 21:40 +0200
        Bug#1050256: AppArmor breaks locking non-fs Unix sockets Salvatore Bonaccorso <carnil@debian.org> - 2024-11-29 22:20 +0100
          Bug#1050256: AppArmor breaks locking non-fs Unix sockets Salvatore Bonaccorso <carnil@debian.org> - 2025-03-22 20:00 +0100
            Bug#1050256: AppArmor breaks locking non-fs Unix sockets Salvatore Bonaccorso <carnil@debian.org> - 2025-06-14 22:10 +0200

csiph-web