auth: Honor file capabilities under no_new_privs - #14912
Merged
Merged
Conversation
Ambient capability support made execve ignore file capabilities when
no_new_privs is set. Linux does not do this. It skips setuid/setgid
bits under no_new_privs, but still applies file capabilities and only
stops them from adding to the permitted set. So capabilities the task
already holds are kept, and ambient capabilities are cleared as for
any file with capabilities.
This broke non-root containers that run setcap binaries with
allowPrivilegeEscalation: false: the binary started with no
capabilities at all.
Drop the special case. The existing no_new_privs downgrade already
matches Linux.
New exec tests (FileCaps*), Linux 6.12 vs runsc systrap:
Test Linux runsc before runsc after
FileCapsAlreadyHeldKept... PASS FAIL (1) PASS
FileCapsClearAmbient PASS PASS PASS
FileCapsClearAmbientWith... PASS FAIL (2) PASS
FileCapsNotGained... PASS PASS PASS
(1) permitted: got 0, want 400
(2) ambient kept: permitted got 400 (NET_BIND_SERVICE),
want 1 (CHOWN)
FileCapsClearAmbient is the same as (2) without no_new_privs.
Fixes google#14878
shailend-g
force-pushed
the
nnp-fcaps
branch
from
September 23, 2026 09:38
02ab181 to
aa481ad
Compare
Collaborator
|
thanks, the behavior is in line with Linux with the change |
milantracy
approved these changes
Sep 25, 2026
milantracy
approved these changes
Sep 25, 2026
copybara-service Bot
pushed a commit
that referenced
this pull request
Sep 25, 2026
Ambient capability support made execve ignore file capabilities when
no_new_privs is set. Linux does not do this. It skips setuid/setgid
bits under no_new_privs, but still applies file capabilities and only
stops them from adding to the permitted set. So capabilities the task
already holds are kept, and ambient capabilities are cleared as for
any file with capabilities.
This broke non-root containers that run setcap binaries with
allowPrivilegeEscalation: false: the binary started with no
capabilities at all.
Drop the special case. The existing no_new_privs downgrade already
matches Linux.
New exec tests (FileCaps*), Linux 6.12 vs runsc systrap:
Test Linux runsc before runsc after
FileCapsAlreadyHeldKept... PASS FAIL (1) PASS
FileCapsClearAmbient PASS PASS PASS
FileCapsClearAmbientWith... PASS FAIL (2) PASS
FileCapsNotGained... PASS PASS PASS
(1) permitted: got 0, want 400
(2) ambient kept: permitted got 400 (NET_BIND_SERVICE),
want 1 (CHOWN)
FileCapsClearAmbient is the same as (2) without no_new_privs.
Fixes #14878
FUTURE_COPYBARA_INTEGRATE_REVIEW=#14912 from shailend-g:nnp-fcaps aa481ad
PiperOrigin-RevId: 988018634
copybara-service Bot
pushed a commit
that referenced
this pull request
Sep 26, 2026
Ambient capability support made execve ignore file capabilities when
no_new_privs is set. Linux does not do this. It skips setuid/setgid
bits under no_new_privs, but still applies file capabilities and only
stops them from adding to the permitted set. So capabilities the task
already holds are kept, and ambient capabilities are cleared as for
any file with capabilities.
This broke non-root containers that run setcap binaries with
allowPrivilegeEscalation: false: the binary started with no
capabilities at all.
Drop the special case. The existing no_new_privs downgrade already
matches Linux.
New exec tests (FileCaps*), Linux 6.12 vs runsc systrap:
Test Linux runsc before runsc after
FileCapsAlreadyHeldKept... PASS FAIL (1) PASS
FileCapsClearAmbient PASS PASS PASS
FileCapsClearAmbientWith... PASS FAIL (2) PASS
FileCapsNotGained... PASS PASS PASS
(1) permitted: got 0, want 400
(2) ambient kept: permitted got 400 (NET_BIND_SERVICE),
want 1 (CHOWN)
FileCapsClearAmbient is the same as (2) without no_new_privs.
Fixes #14878
FUTURE_COPYBARA_INTEGRATE_REVIEW=#14912 from shailend-g:nnp-fcaps aa481ad
PiperOrigin-RevId: 988018634
copybara-service Bot
pushed a commit
that referenced
this pull request
Sep 26, 2026
Ambient capability support made execve ignore file capabilities when
no_new_privs is set. Linux does not do this. It skips setuid/setgid
bits under no_new_privs, but still applies file capabilities and only
stops them from adding to the permitted set. So capabilities the task
already holds are kept, and ambient capabilities are cleared as for
any file with capabilities.
This broke non-root containers that run setcap binaries with
allowPrivilegeEscalation: false: the binary started with no
capabilities at all.
Drop the special case. The existing no_new_privs downgrade already
matches Linux.
New exec tests (FileCaps*), Linux 6.12 vs runsc systrap:
Test Linux runsc before runsc after
FileCapsAlreadyHeldKept... PASS FAIL (1) PASS
FileCapsClearAmbient PASS PASS PASS
FileCapsClearAmbientWith... PASS FAIL (2) PASS
FileCapsNotGained... PASS PASS PASS
(1) permitted: got 0, want 400
(2) ambient kept: permitted got 400 (NET_BIND_SERVICE),
want 1 (CHOWN)
FileCapsClearAmbient is the same as (2) without no_new_privs.
Fixes #14878
FUTURE_COPYBARA_INTEGRATE_REVIEW=#14912 from shailend-g:nnp-fcaps aa481ad
PiperOrigin-RevId: 988018634
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ambient capability support made execve ignore file capabilities when
no_new_privs is set. Linux does not do this. It skips setuid/setgid
bits under no_new_privs, but still applies file capabilities and only
stops them from adding to the permitted set. So capabilities the task
already holds are kept, and ambient capabilities are cleared as for
any file with capabilities.
This broke non-root containers that run setcap binaries with
allowPrivilegeEscalation: false: the binary started with no
capabilities at all.
Drop the special case. The existing no_new_privs downgrade already
matches Linux.
New exec tests (FileCaps*), Linux 6.12 vs runsc systrap:
FileCapsClearAmbient is the same as (2) without no_new_privs.
Fixes #14878