Skip to content

Apply capability changes in the hostnet test - #15452

Open
copybara-service[bot] wants to merge 1 commit into
masterfrom
test/cl995193598
Open

copybara-service[bot] wants to merge 1 commit into
masterfrom
test/cl995193598

Conversation

@copybara-service

Copy link
Copy Markdown

Apply capability changes in the hostnet test

TestHostnetWithRawSockets, introduced in 6cc585c, passed EFFECTIVE rather than CAPS to Apply. The capability library only calls capset for the complete CAPS mask 1, so the test left CAP_NET_RAW enabled. On a privileged worker, loader.New passed the capability check and failed later when creating its control socket.

Apply CAPS to the loaded snapshot, changing only effective CAP_NET_RAW. Keep the drop, check and restoration on one OS thread. The permitted capability remains set, so restore the effective bit before returning the thread to the runtime. If restoration fails, leave the thread locked so Go discards it. Reserve the initial thread for main, as in 962441d, so this failure path can terminate the test's thread safely.

Assisted-by: Codex

FUTURE_COPYBARA_INTEGRATE_REVIEW=#15331 from tamird:boot-test-capability-drop 443832c

@copybara-service copybara-service Bot added the exported Issue was exported automatically label Oct 7, 2026
@copybara-service
copybara-service Bot force-pushed the test/cl995193598 branch 2 times, most recently from 9bd425b to e0fbddb Compare October 7, 2026 21:24
@copybara-service
copybara-service Bot requested a review from relkochta as a code owner October 7, 2026 21:24
TestHostnetWithRawSockets, introduced in 6cc585c, passed EFFECTIVE rather than CAPS to Apply. The capability library only calls capset for the complete CAPS mask [1], so the test left CAP_NET_RAW enabled. On a privileged worker, loader.New passed the capability check and failed later when creating its control socket.

Apply CAPS to the loaded snapshot, changing only effective CAP_NET_RAW. Keep the drop, check and restoration on one OS thread. The permitted capability remains set, so restore the effective bit before returning the thread to the runtime. If restoration fails, leave the thread locked so Go discards it. Reserve the initial thread for main, as in 962441d, so this failure path can terminate the test's thread safely.

[1]: https://github.com/moby/sys/blob/50e999a77/capability/capability_linux.go#L365-L370

Assisted-by: Codex

<!-- codex-thread: 01a0680f-bbf5-7511-95f7-4414f4e10d2e -->

FUTURE_COPYBARA_INTEGRATE_REVIEW=#15331 from tamird:boot-test-capability-drop 443832c
PiperOrigin-RevId: 995193598
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

exported Issue was exported automatically

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant