From 51e04aa93a513b666839470d6c02546d054d9f57 Mon Sep 17 00:00:00 2001 From: AlmaLinux RelEng Bot Date: Tue, 4 Aug 2026 16:57:33 -0400 Subject: [PATCH] import UBI passt-0^20251210.gd04c480-6.el9_8 --- ...o-netns-for-podman-build-read-access.patch | 62 +++++++++++++++++++ SPECS/passt.spec | 6 +- 2 files changed, 67 insertions(+), 1 deletion(-) create mode 100644 SOURCES/0021-selinux-Access-to-netns-for-podman-build-read-access.patch diff --git a/SOURCES/0021-selinux-Access-to-netns-for-podman-build-read-access.patch b/SOURCES/0021-selinux-Access-to-netns-for-podman-build-read-access.patch new file mode 100644 index 0000000..8188f1a --- /dev/null +++ b/SOURCES/0021-selinux-Access-to-netns-for-podman-build-read-access.patch @@ -0,0 +1,62 @@ +From 2056e4df60c36bc2effb5e112be7f1721c8b9f4d Mon Sep 17 00:00:00 2001 +From: Stefano Brivio +Date: Thu, 2 Jul 2026 12:15:31 -0400 +Subject: [PATCH] selinux: Access to netns for podman-build, read access for + netns in general + +A few additional rules are needed when pasta is started by Podman in +particular cases: + +- with podman-build or Buildah, pasta needs to access the target + namespace reference using a procfs namespace link entry, instead of + the usual directory under /run or /var/run. For that, we have a + rule enabling access to container_t:lnk_file. + + On some systems, though, the class is 'dir' instead of 'lnk_file'. + I don't have a concrete way to reproduce this or a full explanation, + but in any case, an additional rule for that is obviously harmless: + allow pasta_t to open, read, and search a container_t:dir + +- with custom networks, pasta needs to write PID files to a location + indicated by Podman. If the PID file already exists, the existing + permissions aren't sufficient: we also need a 'read' rule. Add that, + for 'dir' and 'file' objects labeled as either container_var_run_t + or ifconfig_var_run_t (this depends on the installed Podman and + container-selinux versions) + +Signed-off-by: Stefano Brivio +(cherry picked from commit e74a7c2c18242617e078fb4e4dc1580de585692e) +--- + contrib/selinux/pasta.te | 9 +++++---- + 1 file changed, 5 insertions(+), 4 deletions(-) + +diff --git a/contrib/selinux/pasta.te b/contrib/selinux/pasta.te +index abeafa4..f104b29 100644 +--- a/contrib/selinux/pasta.te ++++ b/contrib/selinux/pasta.te +@@ -174,6 +174,7 @@ allow pasta_t container_runtime_t:fifo_file { getattr write }; + allow pasta_t container_runtime_t:file read; + allow pasta_t container_runtime_t:lnk_file read; + allow pasta_t container_t:lnk_file read; ++allow pasta_t container_t:dir { open read search }; + allow pasta_t pasta_port_t:tcp_socket { name_bind name_connect }; + allow pasta_t pasta_port_t:udp_socket { name_bind }; + allow pasta_t http_port_t:tcp_socket { name_bind name_connect }; +@@ -248,10 +249,10 @@ type_transition container_runtime_t user_tmp_t : dir ifconfig_var_run_t "netns"; + type_transition container_runtime_t container_var_run_t : dir ifconfig_var_run_t "netns"; + type_transition container_runtime_t user_tmp_t : dir ifconfig_var_run_t "rootless-netns"; + type_transition container_runtime_t container_var_run_t : dir ifconfig_var_run_t "rootless-netns"; +-allow pasta_t container_var_run_t:dir { add_name open rmdir write }; +-allow pasta_t ifconfig_var_run_t:dir { add_name open rmdir write }; +-allow pasta_t container_var_run_t:file { create open write }; +-allow pasta_t ifconfig_var_run_t:file { create open write }; ++allow pasta_t container_var_run_t:dir { add_name open read rmdir write }; ++allow pasta_t ifconfig_var_run_t:dir { add_name open read rmdir write }; ++allow pasta_t container_var_run_t:file { create open read write }; ++allow pasta_t ifconfig_var_run_t:file { create open read write }; + allow systemd_logind_exec_t ifconfig_var_run_t:dir rmdir; + + # Allow pasta to bind to any port +-- +2.47.1 + diff --git a/SPECS/passt.spec b/SPECS/passt.spec index e4e2604..6d8ef8c 100644 --- a/SPECS/passt.spec +++ b/SPECS/passt.spec @@ -13,7 +13,7 @@ Name: passt Version: 0^20251210.gd04c480 -Release: 5%{?dist} +Release: 6%{?dist} Summary: User-mode networking daemons for virtual machines and namespaces License: GPL-2.0-or-later AND BSD-3-Clause Group: System Environment/Daemons @@ -40,6 +40,7 @@ Patch17: 0017-tcp-Send-TCP-keepalive-segments-after-a-period-of-ta.patch Patch18: 0018-tcp-Replace-send-buffer-boost-with-EPOLLOUT-monitori.patch Patch19: 0019-udp_vu-Discard-datagrams-when-RX-virtqueue-is-not-us.patch Patch20: 0020-conf-util-Disable-IPv6-if-explicit-IPv6-socket-probe.patch +Patch21: 0021-selinux-Access-to-netns-for-podman-build-read-access.patch BuildRequires: gcc, make, git, checkpolicy, selinux-policy-devel Requires: (%{name}-selinux = %{version}-%{release} if selinux-policy-%{selinuxtype}) @@ -154,6 +155,9 @@ fi %{_datadir}/selinux/packages/%{selinuxtype}/passt-repair.pp %changelog +* Sun Jul 26 2026 Stefano Brivio - 0^20251210.gd04c480-6 +- Resolves: RHEL-216654 + * Thu Jun 11 2026 Stefano Brivio - 0^20251210.gd04c480-5 - Resolves: RHEL-184106 RHEL-183990