From bf2b8a05a0b7bd07eb35ab73d4e6af50651a8625 Mon Sep 17 00:00:00 2001 From: Luboslav Pivarc Date: Wed, 10 May 2023 10:09:21 +0200 Subject: [PATCH] Do not drop effective&permitted set Currently moby drops ep sets before the entrypoint is executed. This does mean that with combination of no-new-privileges the file capabilities stops working with non-root containers. This is undesired as the usability of such containers is harmed comparing to running root containers. This commit therefore sets the effective/permitted set in order to allow use of file capabilities or libcap(3)/prctl(2) respectively with combination of no-new-privileges and without respectively. For no-new-privileges the container will be able to obtain capabilities that are requested. Signed-off-by: Luboslav Pivarc Signed-off-by: Bjorn Neergaard (cherry picked from commit 3aef732e61ec8ae0ea0bd8ad31116194e0fc21a6) Signed-off-by: Sebastiaan van Stijn --- oci/oci.go | 17 ++++------------- 1 file changed, 4 insertions(+), 13 deletions(-) diff --git a/oci/oci.go b/oci/oci.go index 864ccf5b60..45ed7979ee 100644 --- a/oci/oci.go +++ b/oci/oci.go @@ -23,19 +23,10 @@ func SetCapabilities(s *specs.Spec, caplist []string) error { if s.Process == nil { s.Process = &specs.Process{} } - // setUser has already been executed here - if s.Process.User.UID == 0 { - s.Process.Capabilities = &specs.LinuxCapabilities{ - Effective: caplist, - Bounding: caplist, - Permitted: caplist, - } - } else { - // Do not set Effective and Permitted capabilities for non-root users, - // to match what execve does. - s.Process.Capabilities = &specs.LinuxCapabilities{ - Bounding: caplist, - } + s.Process.Capabilities = &specs.LinuxCapabilities{ + Effective: caplist, + Bounding: caplist, + Permitted: caplist, } return nil }