[PATCH 0/2] pasta: Do not configure ID mappings when invoked with --netns-only
This is a narrow fix for bug 216 where `pasta` attempts to configure user and group ID mappings when invoked with `--netns-only`. A new `bool` argument `config_idmaps` was added to `pasta_start_ns()` that guards the logic to configure user and group ID mappings. It is set to `false` when `netns_only` is `true`. OpenAI Codex was used to explore and understand the codebase. Code written myself. Test written by Codex guided and reviewed by me. Dwayne B. Bent (2): pasta: Regression test for bug 216 pasta: Do not configure ID mappings when invoked with --netns-only conf.c | 2 +- pasta.c | 24 ++++++++++++++---------- pasta.h | 3 ++- test/pasta_options/netns_only | 19 +++++++++++++++++++ test/run | 1 + 5 files changed, 37 insertions(+), 12 deletions(-) create mode 100644 test/pasta_options/netns_only -- 2.55.0
Adds a test that asserts that when pasta is invoked via `unshare -r` in
standalone mode with `--netns-only` it does not print any warnings, and
the command executes successfully.
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Dwayne B. Bent
Add a `bool` argument `config_idmaps` to `pasta_start_ns()` that guards
the logic to configure user and group ID mappings. It is set to `false`
when `netns_only` is `true`. Fixes bug 216.
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Dwayne B. Bent
On Tue, Jul 21, 2026 at 11:37:26AM -0400, Dwayne B. Bent wrote:
Adds a test that asserts that when pasta is invoked via `unshare -r` in standalone mode with `--netns-only` it does not print any warnings, and the command executes successfully.
Assisted-by: Codex:gpt-5.6-sol Signed-off-by: Dwayne B. Bent
Content LGTM, however there's a detail in the packaging: Although having the test before the fix is obviously the right order while developing and testing it, for final merge we want the test either after the fix, or folded into the same patch: that way we don't risk breaking future bisects.
--- test/pasta_options/netns_only | 19 +++++++++++++++++++ test/run | 1 + 2 files changed, 20 insertions(+) create mode 100644 test/pasta_options/netns_only
diff --git a/test/pasta_options/netns_only b/test/pasta_options/netns_only new file mode 100644 index 0000000..197ed44 --- /dev/null +++ b/test/pasta_options/netns_only @@ -0,0 +1,19 @@ +# SPDX-License-Identifier: GPL-2.0-or-later +# +# PASST - Plug A Simple Socket Transport +# for qemu/UNIX domain socket mode +# +# PASTA - Pack A Subtle Tap Abstraction +# for network namespace/tap device mode +# +# test/pasta_options/netns_only - Check --netns-only handling + +htools unshare grep + +test --netns-only skips id mapping configuration +set OUT __STATEDIR__/netns-only.out +set ERR __STATEDIR__/netns-only.err + +passt unshare -r -- ./pasta -q --netns-only -- echo TEST > __OUT__ 2> __ERR__ +check grep -qx TEST __OUT__ +check [ ! -s __ERR__ ] diff --git a/test/run b/test/run index f858e55..c4073cc 100755 --- a/test/run +++ b/test/run @@ -85,6 +85,7 @@ run() {
setup pasta_options test pasta_options/log_to_file + test pasta_options/netns_only teardown pasta_options
setup build -- 2.55.0
-- David Gibson (he or they) | I'll have my music baroque, and my code david AT gibson.dropbear.id.au | minimalist, thank you, not the other way | around. http://www.ozlabs.org/~dgibson
On Tue, Jul 21, 2026 at 11:37:27AM -0400, Dwayne B. Bent wrote:
Add a `bool` argument `config_idmaps` to `pasta_start_ns()` that guards the logic to configure user and group ID mappings. It is set to `false` when `netns_only` is `true`. Fixes bug 216.
Assisted-by: Codex:gpt-5.6-sol Signed-off-by: Dwayne B. Bent
Needs a Link: https://bugs.passt.top/show_bug.cgi?id=216 line. Otherwise looks fine to me.
--- conf.c | 2 +- pasta.c | 24 ++++++++++++++---------- pasta.h | 3 ++- 3 files changed, 17 insertions(+), 12 deletions(-)
diff --git a/conf.c b/conf.c index 0fcba5c..2223604 100644 --- a/conf.c +++ b/conf.c @@ -1945,7 +1945,7 @@ void conf(struct ctx *c, int argc, char **argv) if (*netns) { pasta_open_ns(c, netns); } else { - pasta_start_ns(c, uid, gid, + pasta_start_ns(c, uid, gid, !netns_only, argc - optind, argv + optind); } } diff --git a/pasta.c b/pasta.c index 4e7ee54..5aa56b7 100644 --- a/pasta.c +++ b/pasta.c @@ -236,10 +236,11 @@ static int pasta_spawn_cmd(void *arg) * @c: Execution context * @uid: UID we're running as in the init namespace * @gid: GID we're running as in the init namespace + * @config_idmaps: Whether to configure user mappings * @argc: Number of arguments for spawned command * @argv: Command to spawn and arguments */ -void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, +void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, bool config_idmaps, int argc, char *argv[]) { char ns_fn_stack[NS_FN_STACK_SIZE] @@ -249,7 +250,6 @@ void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, .argv = argv, .c = c, }; - char uidmap[BUFSIZ], gidmap[BUFSIZ]; char *sh_argv[] = { NULL, NULL }; char sh_arg0[PATH_MAX + 1]; sigset_t set; @@ -259,16 +259,20 @@ void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, c->quiet = 1;
/* Configure user and group mappings */ - if (snprintf_check(uidmap, BUFSIZ, "0 %u 1", uid)) - die_perror("Can't build uidmap"); + if (config_idmaps) { + char uidmap[BUFSIZ], gidmap[BUFSIZ];
- if (snprintf_check(gidmap, BUFSIZ, "0 %u 1", gid)) - die_perror("Can't build gidmap"); + if (snprintf_check(uidmap, BUFSIZ, "0 %u 1", uid)) + die_perror("Can't build uidmap");
- if (write_file("/proc/self/uid_map", uidmap) || - write_file("/proc/self/setgroups", "deny") || - write_file("/proc/self/gid_map", gidmap)) { - warn("Couldn't configure user mappings"); + if (snprintf_check(gidmap, BUFSIZ, "0 %u 1", gid)) + die_perror("Can't build gidmap"); + + if (write_file("/proc/self/uid_map", uidmap) || + write_file("/proc/self/setgroups", "deny") || + write_file("/proc/self/gid_map", gidmap)) { + warn("Couldn't configure user mappings"); + } }
if (argc == 0) { diff --git a/pasta.h b/pasta.h index 07e04b3..edd7747 100644 --- a/pasta.h +++ b/pasta.h @@ -6,12 +6,13 @@ #ifndef PASTA_H #define PASTA_H
+#include
#include extern int pasta_child_pid;
void pasta_open_ns(struct ctx *c, const char *netns); -void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, +void pasta_start_ns(struct ctx *c, uid_t uid, gid_t gid, bool config_idmaps, int argc, char *argv[]); void pasta_ns_conf(struct ctx *c); void pasta_child_handler(int signal); -- 2.55.0
-- David Gibson (he or they) | I'll have my music baroque, and my code david AT gibson.dropbear.id.au | minimalist, thank you, not the other way | around. http://www.ozlabs.org/~dgibson
participants (2)
-
David Gibson
-
Dwayne B. Bent