Skip to content

auth: Honor file capabilities under no_new_privs - #14912

Merged
copybara-service[bot] merged 1 commit into
google:masterfrom
shailend-g:nnp-fcaps
Sep 26, 2026
Merged

copybara-service[bot] merged 1 commit into
google:masterfrom
shailend-g:nnp-fcaps

Conversation

@shailend-g

@shailend-g shailend-g commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Ambient capability support made execve ignore file capabilities when
no_new_privs is set. Linux does not do this. It skips setuid/setgid
bits under no_new_privs, but still applies file capabilities and only
stops them from adding to the permitted set. So capabilities the task
already holds are kept, and ambient capabilities are cleared as for
any file with capabilities.

This broke non-root containers that run setcap binaries with
allowPrivilegeEscalation: false: the binary started with no
capabilities at all.

Drop the special case. The existing no_new_privs downgrade already
matches Linux.

New exec tests (FileCaps*), Linux 6.12 vs runsc systrap:

Test                          Linux  runsc before  runsc after
FileCapsAlreadyHeldKept...    PASS   FAIL (1)      PASS
FileCapsClearAmbient          PASS   PASS          PASS
FileCapsClearAmbientWith...   PASS   FAIL (2)      PASS
FileCapsNotGained...          PASS   PASS          PASS

(1) permitted: got 0, want 400
(2) ambient kept: permitted got 400 (NET_BIND_SERVICE),
    want 1 (CHOWN)

FileCapsClearAmbient is the same as (2) without no_new_privs.

Fixes #14878

Ambient capability support made execve ignore file capabilities when
no_new_privs is set. Linux does not do this. It skips setuid/setgid
bits under no_new_privs, but still applies file capabilities and only
stops them from adding to the permitted set. So capabilities the task
already holds are kept, and ambient capabilities are cleared as for
any file with capabilities.

This broke non-root containers that run setcap binaries with
allowPrivilegeEscalation: false: the binary started with no
capabilities at all.

Drop the special case. The existing no_new_privs downgrade already
matches Linux.

New exec tests (FileCaps*), Linux 6.12 vs runsc systrap:

    Test                          Linux  runsc before  runsc after
    FileCapsAlreadyHeldKept...    PASS   FAIL (1)      PASS
    FileCapsClearAmbient          PASS   PASS          PASS
    FileCapsClearAmbientWith...   PASS   FAIL (2)      PASS
    FileCapsNotGained...          PASS   PASS          PASS

    (1) permitted: got 0, want 400
    (2) ambient kept: permitted got 400 (NET_BIND_SERVICE),
        want 1 (CHOWN)

FileCapsClearAmbient is the same as (2) without no_new_privs.

Fixes google#14878
@milantracy

Copy link
Copy Markdown
Collaborator

thanks, the behavior is in line with Linux with the change

copybara-service Bot pushed a commit that referenced this pull request Sep 25, 2026
Ambient capability support made execve ignore file capabilities when
no_new_privs is set. Linux does not do this. It skips setuid/setgid
bits under no_new_privs, but still applies file capabilities and only
stops them from adding to the permitted set. So capabilities the task
already holds are kept, and ambient capabilities are cleared as for
any file with capabilities.

This broke non-root containers that run setcap binaries with
allowPrivilegeEscalation: false: the binary started with no
capabilities at all.

Drop the special case. The existing no_new_privs downgrade already
matches Linux.

New exec tests (FileCaps*), Linux 6.12 vs runsc systrap:

    Test                          Linux  runsc before  runsc after
    FileCapsAlreadyHeldKept...    PASS   FAIL (1)      PASS
    FileCapsClearAmbient          PASS   PASS          PASS
    FileCapsClearAmbientWith...   PASS   FAIL (2)      PASS
    FileCapsNotGained...          PASS   PASS          PASS

    (1) permitted: got 0, want 400
    (2) ambient kept: permitted got 400 (NET_BIND_SERVICE),
        want 1 (CHOWN)

FileCapsClearAmbient is the same as (2) without no_new_privs.

Fixes #14878

FUTURE_COPYBARA_INTEGRATE_REVIEW=#14912 from shailend-g:nnp-fcaps aa481ad
PiperOrigin-RevId: 988018634
copybara-service Bot pushed a commit that referenced this pull request Sep 26, 2026
Ambient capability support made execve ignore file capabilities when
no_new_privs is set. Linux does not do this. It skips setuid/setgid
bits under no_new_privs, but still applies file capabilities and only
stops them from adding to the permitted set. So capabilities the task
already holds are kept, and ambient capabilities are cleared as for
any file with capabilities.

This broke non-root containers that run setcap binaries with
allowPrivilegeEscalation: false: the binary started with no
capabilities at all.

Drop the special case. The existing no_new_privs downgrade already
matches Linux.

New exec tests (FileCaps*), Linux 6.12 vs runsc systrap:

    Test                          Linux  runsc before  runsc after
    FileCapsAlreadyHeldKept...    PASS   FAIL (1)      PASS
    FileCapsClearAmbient          PASS   PASS          PASS
    FileCapsClearAmbientWith...   PASS   FAIL (2)      PASS
    FileCapsNotGained...          PASS   PASS          PASS

    (1) permitted: got 0, want 400
    (2) ambient kept: permitted got 400 (NET_BIND_SERVICE),
        want 1 (CHOWN)

FileCapsClearAmbient is the same as (2) without no_new_privs.

Fixes #14878

FUTURE_COPYBARA_INTEGRATE_REVIEW=#14912 from shailend-g:nnp-fcaps aa481ad
PiperOrigin-RevId: 988018634
copybara-service Bot pushed a commit that referenced this pull request Sep 26, 2026
Ambient capability support made execve ignore file capabilities when
no_new_privs is set. Linux does not do this. It skips setuid/setgid
bits under no_new_privs, but still applies file capabilities and only
stops them from adding to the permitted set. So capabilities the task
already holds are kept, and ambient capabilities are cleared as for
any file with capabilities.

This broke non-root containers that run setcap binaries with
allowPrivilegeEscalation: false: the binary started with no
capabilities at all.

Drop the special case. The existing no_new_privs downgrade already
matches Linux.

New exec tests (FileCaps*), Linux 6.12 vs runsc systrap:

    Test                          Linux  runsc before  runsc after
    FileCapsAlreadyHeldKept...    PASS   FAIL (1)      PASS
    FileCapsClearAmbient          PASS   PASS          PASS
    FileCapsClearAmbientWith...   PASS   FAIL (2)      PASS
    FileCapsNotGained...          PASS   PASS          PASS

    (1) permitted: got 0, want 400
    (2) ambient kept: permitted got 400 (NET_BIND_SERVICE),
        want 1 (CHOWN)

FileCapsClearAmbient is the same as (2) without no_new_privs.

Fixes #14878

FUTURE_COPYBARA_INTEGRATE_REVIEW=#14912 from shailend-g:nnp-fcaps aa481ad
PiperOrigin-RevId: 988018634
@copybara-service
copybara-service Bot merged commit cd7be38 into google:master Sep 26, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

execve discards file capabilities under no_new_privs even when they add nothing (stricter than Linux since 4886c6690 / release-20260727.0)

2 participants