New issue
Advanced search Search tips

Issue 808196 link

Starred by 3 users

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Bug



Sign in to add a comment

crosvm: stop inheriting extra groups in wayland device

Project Member Reported by smbar...@chromium.org, Feb 1 2018

Issue description

The wayland virtio device should not have supplementary groups like daemon-store.
 
Components: OS>Systems>Containers
Labels: -Pri-3 Pri-2
Owner: za...@chromium.org
Status: Assigned (was: Untriaged)
Labels: Hotlist-Crostini-Platform

Comment 4 by za...@chromium.org, Jun 12 2018

After a few hours of collaborative investigation, the root of this issue is minijail, which should have dropped the supplementary gids (because crosvm never calls minijail_keep_supplementary_gids), but the call crosm does make to minijail_namespace_user_disable_setgroups sets a flag that prevents minijail from dropping the needed permissions with setgroups.
The fix should probably be to have minijal call setgroups after entering the user namespace, but before disallowing setgroups permanently.

Sign in to add a comment