Repository navigation
Fix legacy recursive mount restrictions without procfs - #352
Merged
robertswiecki merged 1 commit intoOct 2, 2026
Merged
robertswiecki merged 1 commit into
robertswiecki merged 1 commit into
Conversation
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
Collaborator
|
Thank you! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The legacy mount backend reapplies requested flags to nested mounts by scanning
/proc/self/mountinfoafter the jail root transition. If the final jail has no procfs,fopen()fails, the descendant scan is skipped, andremountPt()still reports success.For a recursive read-only bind, this can leave the top-level mount
rowhile a nested mount remainsrw. A jailed workload can write through that nested mount if its ordinary permissions allow it.Affected source revision tested:
f100fd917c6d3ed0fd15d868528b735cb5fb1a1.Impact
This bypasses an explicitly requested mount restriction. The reproduction writes only a marker to synthetic tmpfs mounts; it does not demonstrate authentication bypass, arbitrary host access, or code execution outside the jail.
Fix
Run the legacy remount pass after building the jail mount tree but before
pivot_root()/chroot(), while the original/proc/self/mountinfois accessible. Pass the temporary jail root toremountPt()and normalize destination paths before matching descendants. Fail jail setup if mountinfo is unavailable, a descendant remount fails, or any attached mount cannot receive its requested flags.Reproduction and validation
The attached
nsjail-pr-repro.zipcontains a Docker fixture and a static write probe. Its README gives the build and run commands. On the affected source, the--experimental_mnt old --disable_proccases write the marker, while the procfs-enabled controls fail withRead-only file system. The fixture covers both an explicit bind destination and the automatic chroot root bind.The final patch builds successfully. With
EXPECT_NO_PROC_WRITE=blocked, the fixture blocks writes for the default/mntdestination and/; withTEST_TRAILING_SLASH_DEST=1, it also blocks writes for/mnt/. The separate unreadable-mountinfo and failed-descendant-remount error branches were not forced in these runs.Related work
PR #311 handles escaped mountinfo path fields after the file is opened. Open PR #344 makes some mount-flag and final-remount failures fatal, but its current change does not address the legacy
fopen('/proc/self/mountinfo')failure path that skips descendant processing while returning success. This change addresses that missing-proc case. Issue #312 concerns ignoredmount_setattr()errors in the new mount API.Hi @robertswiecki — could you please review when convenient?
nsjail-pr-repro.zip