Starting from commit 7bf1595c9242 ("isolation: Don't create our userns as nobody"), we unconditionally set uidmap and gidmap in the detached user namespace.
Allow that in SELinux rules. We also need to allow explicit access to the related files.
While at it, add the matching class requirements in pasta.te, which I forgot (harmless as they were indirectly required, but not really correct).
Link: https://bodhi.fedoraproject.org/updates/FEDORA-2026-3a8fb909da#comment-47905... Fixes: 71b74e924426 ("isolation: Don't create our userns as nobody") Signed-off-by: Stefano Brivio
--- ...pen-permissions-on-netns-directory-o.patch | 72 +++++ contrib/selinux/passt.te | 7 +- contrib/selinux/pasta.te | 2 +- contrib/selinux/pasta.te.orig | 266 ++++++++++++++++++ 4 files changed, 344 insertions(+), 3 deletions(-) create mode 100644 contrib/selinux/0001-selinux-Enable-open-permissions-on-netns-directory-o.patch create mode 100644 contrib/selinux/pasta.te.orig I assume these two new files are not meant to be committed/part of this
On 02/10/2026 09:00, Stefano Brivio wrote: patch?