Skip to content

Apply capability changes in the hostnet test - #15331

Merged
1 commit merged into
google:masterfrom
tamird:boot-test-capability-drop
Oct 8, 2026
Merged

1 commit merged into
google:masterfrom
tamird:boot-test-capability-drop

Conversation

@tamird

@tamird tamird commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

TestHostnetWithRawSockets, introduced in 6cc585c, passed EFFECTIVE
rather than CAPS to Apply. The capability library only calls capset for
the complete CAPS mask 1, so the test left CAP_NET_RAW enabled. On a
privileged worker, loader.New passed the capability check and failed
later when creating its control socket.

Apply CAPS to the loaded snapshot, changing only effective CAP_NET_RAW.
Keep the drop, check and restoration on one OS thread. The permitted
capability remains set, so restore the effective bit before returning
the thread to the runtime. If restoration fails, leave the thread locked
so Go discards it. Reserve the initial thread for main, as in 962441d,
so this failure path can terminate the test's thread safely.

Assisted-by: Codex

Comment thread runsc/boot/loader_test.go
@tamird
tamird force-pushed the boot-test-capability-drop branch from bac3c39 to e206bb8 Compare October 6, 2026 13:48
@tamird
tamird requested a review from EtiennePerot October 6, 2026 13:52
TestHostnetWithRawSockets, introduced in 6cc585c, passed EFFECTIVE
rather than CAPS to Apply. The capability library only calls capset for
the complete CAPS mask [1], so the test left CAP_NET_RAW enabled. On a
privileged worker, loader.New passed the capability check and failed
later when creating its control socket.

Apply CAPS to the loaded snapshot, changing only effective CAP_NET_RAW.
Keep the drop, check and restoration on one OS thread. The permitted
capability remains set, so restore the effective bit before returning the
thread to the runtime. If restoration fails, leave the thread locked so
Go discards it. Reserve the initial thread for main, as in 962441d, so
this failure path can terminate the test's thread safely.

[1]: https://github.com/moby/sys/blob/50e999a77/capability/capability_linux.go#L365-L370

Assisted-by: Codex
@tamird
tamird force-pushed the boot-test-capability-drop branch from e206bb8 to 443832c Compare October 6, 2026 14:22
copybara-service Bot pushed a commit that referenced this pull request Oct 7, 2026
TestHostnetWithRawSockets, introduced in 6cc585c, passed EFFECTIVE rather than CAPS to Apply. The capability library only calls capset for the complete CAPS mask [1], so the test left CAP_NET_RAW enabled. On a privileged worker, loader.New passed the capability check and failed later when creating its control socket.

Apply CAPS to the loaded snapshot, changing only effective CAP_NET_RAW. Keep the drop, check and restoration on one OS thread. The permitted capability remains set, so restore the effective bit before returning the thread to the runtime. If restoration fails, leave the thread locked so Go discards it. Reserve the initial thread for main, as in 962441d, so this failure path can terminate the test's thread safely.

[1]: https://github.com/moby/sys/blob/50e999a77/capability/capability_linux.go#L365-L370

Assisted-by: Codex

<!-- codex-thread: 01a0680f-bbf5-7511-95f7-4414f4e10d2e -->

FUTURE_COPYBARA_INTEGRATE_REVIEW=#15331 from tamird:boot-test-capability-drop 443832c
PiperOrigin-RevId: 995193598
copybara-service Bot pushed a commit that referenced this pull request Oct 7, 2026
TestHostnetWithRawSockets, introduced in 6cc585c, passed EFFECTIVE rather than CAPS to Apply. The capability library only calls capset for the complete CAPS mask [1], so the test left CAP_NET_RAW enabled. On a privileged worker, loader.New passed the capability check and failed later when creating its control socket.

Apply CAPS to the loaded snapshot, changing only effective CAP_NET_RAW. Keep the drop, check and restoration on one OS thread. The permitted capability remains set, so restore the effective bit before returning the thread to the runtime. If restoration fails, leave the thread locked so Go discards it. Reserve the initial thread for main, as in 962441d, so this failure path can terminate the test's thread safely.

[1]: https://github.com/moby/sys/blob/50e999a77/capability/capability_linux.go#L365-L370

Assisted-by: Codex

<!-- codex-thread: 01a0680f-bbf5-7511-95f7-4414f4e10d2e -->

FUTURE_COPYBARA_INTEGRATE_REVIEW=#15331 from tamird:boot-test-capability-drop 443832c
PiperOrigin-RevId: 995193598
copybara-service Bot pushed a commit that referenced this pull request Oct 7, 2026
TestHostnetWithRawSockets, introduced in 6cc585c, passed EFFECTIVE rather than CAPS to Apply. The capability library only calls capset for the complete CAPS mask [1], so the test left CAP_NET_RAW enabled. On a privileged worker, loader.New passed the capability check and failed later when creating its control socket.

Apply CAPS to the loaded snapshot, changing only effective CAP_NET_RAW. Keep the drop, check and restoration on one OS thread. The permitted capability remains set, so restore the effective bit before returning the thread to the runtime. If restoration fails, leave the thread locked so Go discards it. Reserve the initial thread for main, as in 962441d, so this failure path can terminate the test's thread safely.

[1]: https://github.com/moby/sys/blob/50e999a77/capability/capability_linux.go#L365-L370

Assisted-by: Codex

<!-- codex-thread: 01a0680f-bbf5-7511-95f7-4414f4e10d2e -->

FUTURE_COPYBARA_INTEGRATE_REVIEW=#15331 from tamird:boot-test-capability-drop 443832c
PiperOrigin-RevId: 995193598
@copybara-service copybara-service Bot closed this pull request by merging all changes into google:master in 9c677de Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants