The change to the user-tmp abstraction broke pasta as it can no longer
open the netns path given by podman when it is under /tmp.
The abstraction uses "owner" while the kernel always seems to report
ouid=0 for the bind mounted netns reference. I originally fixed that
in commit 6cdc9fd51bf6 ("apparmor: allow netns paths on /tmp").
In order to fix the regression add /tmp explicitly again here while
keeping the abstraction to still allow /var/tmp for the other regular
files.
Link: https://github.com/podman-container-tools/podman/pull/29867#pullrequestrevie...
Fixes: f2683d14802d ("apparmor: Use user-tmp abstraction, allow /var/tmp instead of /tmp only")
Signed-off-by: Paul Holzinger
---
contrib/apparmor/usr.bin.pasta | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/contrib/apparmor/usr.bin.pasta b/contrib/apparmor/usr.bin.pasta
index 32dfad9..f641649 100644
--- a/contrib/apparmor/usr.bin.pasta
+++ b/contrib/apparmor/usr.bin.pasta
@@ -22,8 +22,11 @@ profile pasta /usr/bin/pasta{,.avx2} flags=(attach_disconnected) {
# tap_sock_unix_init(), pcap(),
# pidfile_open(),
# pidfile_write(),
- # logfile_init(),
- # pasta_open_ns()
+ # logfile_init()
+
+ # user-tmp is using "owner" which is not compatible with netns paths
+ # which show up as ouid=0 in the kernel apparmor checks
+ /tmp/** rw, # pasta_open_ns()
owner @{HOME}/** w, # pcap(), pidfile_open(),
# pidfile_write()
--
2.55.0