From f665b58af742c5e95b1e33cc58443e1dd34acdd5 Mon Sep 17 00:00:00 2001
From: Daan De Meyer <daan.j.demeyer@gmail.com>
Date: Tue, 5 Dec 2023 10:24:13 +0100
Subject: [PATCH 0019/1160] nspawn: Check later whether to keep/drop
CAP_NET_BIND_SERVICE
Currently the check doesn't take any settings from nspawn settings
files into account, so let's delay the check until after we've
loaded any settings file.
(cherry picked from commit dd78141c530a141f170867b3fc5572b577168759)
src/nspawn/nspawn.c | 13 ++++++-------
1 file changed, 6 insertions(+), 7 deletions(-)
@@ -1632,13 +1632,6 @@ static int parse_argv(int argc, char *argv[]) {
arg_caps_retain |= plus;
arg_caps_retain |= arg_private_network ? UINT64_C(1) << CAP_NET_ADMIN : 0;
-
- /* If we're not unsharing the network namespace and are unsharing the user namespace, we won't have
- * permissions to bind ports in the container, so let's drop the CAP_NET_BIND_SERVICE capability to
- * indicate that. */
- if (!arg_private_network && arg_userns_mode != USER_NAMESPACE_NO && arg_uid_shift > 0)
- arg_caps_retain &= ~(UINT64_C(1) << CAP_NET_BIND_SERVICE);
-
arg_caps_retain &= ~minus;
/* Make sure to parse environment before we reset the settings mask below */
@@ -5420,6 +5413,12 @@ static int run(int argc, char *argv[]) {
if (r < 0)
goto finish;
+ /* If we're not unsharing the network namespace and are unsharing the user namespace, we won't have
+ * permissions to bind ports in the container, so let's drop the CAP_NET_BIND_SERVICE capability to
+ * indicate that. */
+ if (!arg_private_network && arg_userns_mode != USER_NAMESPACE_NO && arg_uid_shift > 0)
+ arg_caps_retain &= ~(UINT64_C(1) << CAP_NET_BIND_SERVICE);
+
r = cg_unified();
if (r < 0) {
log_error_errno(r, "Failed to determine whether the unified cgroups hierarchy is used: %m");
--
2.33.0