Repository navigation
Apply capability changes in the hostnet test - #15331
Merged
1 commit merged intoOct 8, 2026
Merged
1 commit merged into
1 commit merged into
Conversation
EtiennePerot
requested changes
Oct 5, 2026
tamird
force-pushed
the
boot-test-capability-drop
branch
from
October 6, 2026 13:48
bac3c39 to
e206bb8
Compare
TestHostnetWithRawSockets, introduced in 6cc585c, passed EFFECTIVE rather than CAPS to Apply. The capability library only calls capset for the complete CAPS mask [1], so the test left CAP_NET_RAW enabled. On a privileged worker, loader.New passed the capability check and failed later when creating its control socket. Apply CAPS to the loaded snapshot, changing only effective CAP_NET_RAW. Keep the drop, check and restoration on one OS thread. The permitted capability remains set, so restore the effective bit before returning the thread to the runtime. If restoration fails, leave the thread locked so Go discards it. Reserve the initial thread for main, as in 962441d, so this failure path can terminate the test's thread safely. [1]: https://github.com/moby/sys/blob/50e999a77/capability/capability_linux.go#L365-L370 Assisted-by: Codex
tamird
force-pushed
the
boot-test-capability-drop
branch
from
October 6, 2026 14:22
e206bb8 to
443832c
Compare
kerumeto
approved these changes
Oct 7, 2026
copybara-service Bot
pushed a commit
that referenced
this pull request
Oct 7, 2026
TestHostnetWithRawSockets, introduced in 6cc585c, passed EFFECTIVE rather than CAPS to Apply. The capability library only calls capset for the complete CAPS mask [1], so the test left CAP_NET_RAW enabled. On a privileged worker, loader.New passed the capability check and failed later when creating its control socket. Apply CAPS to the loaded snapshot, changing only effective CAP_NET_RAW. Keep the drop, check and restoration on one OS thread. The permitted capability remains set, so restore the effective bit before returning the thread to the runtime. If restoration fails, leave the thread locked so Go discards it. Reserve the initial thread for main, as in 962441d, so this failure path can terminate the test's thread safely. [1]: https://github.com/moby/sys/blob/50e999a77/capability/capability_linux.go#L365-L370 Assisted-by: Codex <!-- codex-thread: 01a0680f-bbf5-7511-95f7-4414f4e10d2e --> FUTURE_COPYBARA_INTEGRATE_REVIEW=#15331 from tamird:boot-test-capability-drop 443832c PiperOrigin-RevId: 995193598
copybara-service Bot
pushed a commit
that referenced
this pull request
Oct 7, 2026
TestHostnetWithRawSockets, introduced in 6cc585c, passed EFFECTIVE rather than CAPS to Apply. The capability library only calls capset for the complete CAPS mask [1], so the test left CAP_NET_RAW enabled. On a privileged worker, loader.New passed the capability check and failed later when creating its control socket. Apply CAPS to the loaded snapshot, changing only effective CAP_NET_RAW. Keep the drop, check and restoration on one OS thread. The permitted capability remains set, so restore the effective bit before returning the thread to the runtime. If restoration fails, leave the thread locked so Go discards it. Reserve the initial thread for main, as in 962441d, so this failure path can terminate the test's thread safely. [1]: https://github.com/moby/sys/blob/50e999a77/capability/capability_linux.go#L365-L370 Assisted-by: Codex <!-- codex-thread: 01a0680f-bbf5-7511-95f7-4414f4e10d2e --> FUTURE_COPYBARA_INTEGRATE_REVIEW=#15331 from tamird:boot-test-capability-drop 443832c PiperOrigin-RevId: 995193598
copybara-service Bot
pushed a commit
that referenced
this pull request
Oct 7, 2026
TestHostnetWithRawSockets, introduced in 6cc585c, passed EFFECTIVE rather than CAPS to Apply. The capability library only calls capset for the complete CAPS mask [1], so the test left CAP_NET_RAW enabled. On a privileged worker, loader.New passed the capability check and failed later when creating its control socket. Apply CAPS to the loaded snapshot, changing only effective CAP_NET_RAW. Keep the drop, check and restoration on one OS thread. The permitted capability remains set, so restore the effective bit before returning the thread to the runtime. If restoration fails, leave the thread locked so Go discards it. Reserve the initial thread for main, as in 962441d, so this failure path can terminate the test's thread safely. [1]: https://github.com/moby/sys/blob/50e999a77/capability/capability_linux.go#L365-L370 Assisted-by: Codex <!-- codex-thread: 01a0680f-bbf5-7511-95f7-4414f4e10d2e --> FUTURE_COPYBARA_INTEGRATE_REVIEW=#15331 from tamird:boot-test-capability-drop 443832c PiperOrigin-RevId: 995193598
9c677de
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TestHostnetWithRawSockets, introduced in 6cc585c, passed EFFECTIVE
rather than CAPS to Apply. The capability library only calls capset for
the complete CAPS mask 1, so the test left CAP_NET_RAW enabled. On a
privileged worker, loader.New passed the capability check and failed
later when creating its control socket.
Apply CAPS to the loaded snapshot, changing only effective CAP_NET_RAW.
Keep the drop, check and restoration on one OS thread. The permitted
capability remains set, so restore the effective bit before returning
the thread to the runtime. If restoration fails, leave the thread locked
so Go discards it. Reserve the initial thread for main, as in 962441d,
so this failure path can terminate the test's thread safely.
Assisted-by: Codex