Conversation
…write scripts/apparmor-userns.sh wrote the profile for whatever path it was given, including a porta under the home; a profile for a path its user can write grants userns to whatever that user puts there. It now refuses one that is not root's alone, and sudo porta setup copies porta to a root-owned /usr/local/bin/porta, writes the profile for that copy alone, loads it and checks the namespaces as the user who ran sudo. CI, the action and the runtime notice use it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…/bin The GitHub runner leaves /usr/local/bin writable by its user, and setup rightly refused to write a profile for a binary there. It now checks every directory up to /, uses /usr/local/bin where it is root's alone and otherwise /opt/porta/bin with a link from /usr/local/bin; the profile is for the file, so replacing the link grants nothing. The action does the same. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The runner leaves /opt writable by its user as well. /usr/libexec is the package manager's. A refusal now names the directory someone else can write. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
sudo porta setup: on Ubuntu 23.10+, copies porta to a directory only root can write (/usr/local/bin, else/usr/libexec/portalinked from it), writes the AppArmor profile for that copy alone, loads it and checks the namespaces as the user;--dry-run,--undo.scripts/apparmor-userns.shrefuses a binary on a path someone other than root can write: such a profile would grant userns to whatever that user puts there.🤖 Generated with Claude Code