Skip to content

i/b/microceph-support: add user-identity-switching plug attribute - #17385

Open
UtkarshBhatthere wants to merge 1 commit into
canonical:masterfrom
UtkarshBhatthere:microceph-support-identity-switching
Open

i/b/microceph-support: add user-identity-switching plug attribute#17385
UtkarshBhatthere wants to merge 1 commit into
canonical:masterfrom
UtkarshBhatthere:microceph-support-identity-switching

Conversation

@UtkarshBhatthere

@UtkarshBhatthere UtkarshBhatthere commented Jul 20, 2026

Copy link
Copy Markdown

MicroCeph ships Samba inside its strictly confined snap to serve CephFS-backed SMB shares. smbd's per-session impersonation model requires switching process identity (setuid/setgid, and setgroups with a real supplementary group list) on every identity transition, and under strict confinement it hard-panics at startup (PANIC: sys_setgroups failed in init_guest_session_info), so the snap currently needs --devmode for SMB. Two things block it: the default seccomp template only allows the zero-length clear-groups form of setgroups, and no suitable interface grants CAP_SETUID/CAP_SETGID.

This PR extends microceph-support with an opt-in boolean plug attribute, user-identity-switching, following the privileged-containers pattern from docker-support. When true, the connected plug additionally gets AppArmor capability setuid/capability setgid and seccomp setgroups/setgroups32. Plugs without the attribute get exactly the previous policy, and connected-plug policy is applied per app binding the plug, so the microceph snap's existing daemon/osd/rbd apps are unaffected; only the smbd app, bound to a second attribute-carrying plug of this interface, gains the user-identity-switching policy.

Deliberately not granted: dac_override/dac_read_search (after impersonation smbd accesses files as the target user) and any file rules.

Verified on a MicroCeph test cluster: patching exactly these grants into a node's generated profiles made strict-mode smbd fully functional serving CephFS shares via vfs_ceph.

Forum discussion: https://forum.snapcraft.io/t/proposal-extend-the-existing-microceph-support-interface-with-an-user-identity-switching-plug-attribute/52389

🤖 Generated with Claude Code

https://claude.ai/code/session_01QTH2xQMoRkykWfnGqp6xKK

@UtkarshBhatthere
UtkarshBhatthere force-pushed the microceph-support-identity-switching branch from c0f2a4a to d075631 Compare July 20, 2026 10:22
@github-actions

github-actions Bot commented Jul 20, 2026

Copy link
Copy Markdown

Fri Jul 24 19:01:54 UTC 2026
The following results are from: https://github.com/canonical/snapd/actions/runs/30093467035

Failures:

Preparing:

  • openstack:opensuse-tumbleweed-64:
  • openstack:opensuse-tumbleweed-64:
  • openstack:opensuse-tumbleweed-64:
  • openstack:opensuse-tumbleweed-64:
  • openstack:opensuse-tumbleweed-64:
  • openstack:opensuse-tumbleweed-64:
  • openstack-arm:ubuntu-24.04-arm-64:tests/main/snap-seccomp-blocks-certain-mknod
  • openstack-arm:ubuntu-24.04-arm-64:tests/main/snap-seccomp-blocks-certain-creat
  • openstack:ubuntu-26.10-64:tests/main/lxd-postrm-purge
  • openstack:ubuntu-26.10-64:tests/main/interfaces-posix-mq

Executing:

  • openstack:ubuntu-26.10-64:tests/main/bad-interfaces-warn
  • openstack:ubuntu-26.10-64:tests/main/broken-seeding
  • openstack:ubuntu-26.10-64:tests/main/lxd
  • openstack:ubuntu-26.10-64:tests/main/xdg-settings
  • openstack:ubuntu-26.10-64:tests/main/apparmor-prompting-integration-tests:write_read_multiple_actioned_by_other_pid_deny_allow
  • openstack:ubuntu-26.10-64:tests/main/apparmor-prompting-integration-tests:write_read_multiple_actioned_by_other_pid_allow_deny

Restoring:

  • openstack:opensuse-tumbleweed-64:
  • openstack:opensuse-tumbleweed-64:
  • openstack:opensuse-tumbleweed-64:
  • openstack:opensuse-tumbleweed-64:
  • openstack:opensuse-tumbleweed-64:
  • openstack:opensuse-tumbleweed-64:
  • openstack:ubuntu-26.10-64:tests/main/apparmor-prompting-integration-tests:write_read_multiple_actioned_by_other_pid_deny_allow
  • openstack:ubuntu-26.10-64:tests/main/
  • openstack:ubuntu-26.10-64:
  • openstack:ubuntu-26.10-64:tests/main/apparmor-prompting-integration-tests:write_read_multiple_actioned_by_other_pid_allow_deny
  • openstack:ubuntu-26.10-64:tests/main/
  • openstack:ubuntu-26.10-64:

Skipped tests from snapd-testing-skip

If you wish to have any of the below tests run in your PR, in your PR description, add 'unskip:' followed by a copy-and-pasted list of the below tests you wish to run (unskip plus test list must be valid yaml)

  • openstack-arm:ubuntu-24.04-arm-64:tests/main/i18n
  • openstack-arm:ubuntu-core-24-arm-64:tests/main/i18n
  • openstack:debian-sid-64:tests/main/interfaces-network-status-classic
  • openstack:debian-sid-64:tests/main/interfaces-xdg-portal-permission-store
  • openstack:ubuntu-24.04-64:tests/main/apparmor-prompting-flag-restart
  • openstack:ubuntu-24.04-64:tests/main/apparmor-prompting-integration-tests
  • openstack:ubuntu-24.04-64:tests/main/apparmor-prompting-prompt-restoration
  • openstack:ubuntu-24.04-64:tests/main/apparmor-prompting-smoke
  • openstack:ubuntu-24.04-64:tests/main/apparmor-prompting-snapd-startup
  • openstack:ubuntu-24.04-64:tests/main/apparmor-prompting-support
  • openstack:ubuntu-24.04-64:tests/main/i18n
  • openstack:ubuntu-24.04-64:tests/main/interfaces-requests-activates-handlers
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-flag-restart
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-integration-tests
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-prompt-restoration
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-smoke
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-snapd-startup
  • openstack:ubuntu-26.04-64:tests/main/apparmor-prompting-support
  • openstack:ubuntu-26.04-64:tests/main/i18n
  • openstack:ubuntu-26.04-64:tests/main/interfaces-requests-activates-handlers

@codecov

codecov Bot commented Jul 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 79.23%. Comparing base (2984256) to head (7fde758).
⚠️ Report is 65 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master   #17385      +/-   ##
==========================================
+ Coverage   78.92%   79.23%   +0.31%     
==========================================
  Files        1397     1407      +10     
  Lines      195988   199867    +3879     
  Branches     2466     2561      +95     
==========================================
+ Hits       154688   158374    +3686     
- Misses      32013    32086      +73     
- Partials     9287     9407     +120     
Flag Coverage Δ
unittests 79.23% <100.00%> (+0.31%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@UtkarshBhatthere UtkarshBhatthere changed the title interfaces: add identity-switching attribute to microceph-support i/b/microceph-support: add identity-switching plug attribute Jul 20, 2026
@UtkarshBhatthere
UtkarshBhatthere force-pushed the microceph-support-identity-switching branch from d075631 to 20ae5ef Compare July 20, 2026 11:24
@bboozzoo
bboozzoo requested review from Copilot and jslarraz July 20, 2026 12:08
@bboozzoo bboozzoo added this to the 2.78 milestone Jul 20, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR extends the microceph-support interface to support strictly confined Samba (smbd) use cases that require per-session identity changes (setuid/setgid + non-zero-length setgroups), by adding an opt-in plug attribute that grants the minimal additional AppArmor/seccomp permissions only to apps that bind the attribute-carrying plug.

Changes:

  • Add a boolean plug attribute identity-switching to microceph-support.
  • When identity-switching: true, grant AppArmor capability setuid/capability setgid and seccomp setgroups/setgroups32 to the connected plug.
  • Add unit tests covering: default behavior unchanged, identity-switching: true grants added policy, identity-switching: false behaves like absent, and invalid values are rejected.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
interfaces/builtin/microceph_support.go Adds the identity-switching attribute handling, including AppArmor/seccomp conditional policy and plug attribute validation.
interfaces/builtin/microceph_support_test.go Adds tests verifying attribute sanitization and per-app policy application for both AppArmor and seccomp.

@pedronis pedronis added the Needs security review Can only be merged once security gave a :+1: label Jul 20, 2026

@bboozzoo bboozzoo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The change looks good to me. The interface is already superprivileged and the changes match the intended use case.

@pedronis pedronis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

naming consideration

Comment thread interfaces/builtin/microceph_support.go Outdated
MicroCeph ships Samba inside its strictly confined snap to serve
CephFS-backed SMB shares. smbd's per-session impersonation model
requires switching process identity (setuid/setgid and setgroups with
a real supplementary group list) on every identity transition, and
under strict confinement it hard-panics at startup
(PANIC: sys_setgroups failed in init_guest_session_info). The default
seccomp template only allows the zero-length clear-groups form of
setgroups, and no suitable interface grants CAP_SETUID/CAP_SETGID.

Extend microceph-support with an opt-in boolean plug attribute,
user-identity-switching, following the docker-support
privileged-containers pattern. When true, the connected plug
additionally gets AppArmor capability setuid/setgid and seccomp
setgroups/setgroups32. Plugs without the attribute (or with it set to
false) get exactly the previous policy, so the existing daemon/osd/rbd
apps of the microceph snap are unaffected; only the smbd app, bound to
a second attribute-carrying plug of this interface, gains the
user-identity-switching policy.

Verified on a MicroCeph test cluster: patching exactly these grants
into a node's generated profiles makes strict-mode smbd fully
functional serving CephFS shares via vfs_ceph.

Assisted-by: claude-code:claude-fable-5
Signed-off-by: Utkarsh Bhatt <utkarsh_bhatt@outlook.com>
@UtkarshBhatthere
UtkarshBhatthere force-pushed the microceph-support-identity-switching branch from 20ae5ef to 7fde758 Compare July 21, 2026 05:53
@UtkarshBhatthere UtkarshBhatthere changed the title i/b/microceph-support: add identity-switching plug attribute i/b/microceph-support: add user-identity-switching plug attribute Jul 21, 2026

@bboozzoo bboozzoo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks

@bboozzoo
bboozzoo requested a review from pedronis July 21, 2026 07:44

@pedronis pedronis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1

@github-actions github-actions Bot added the Auto rerun spread Auto reruns spread up to 4 times in non-draft PRs w/ >=1 approval and <20 fails in any fund. system label Jul 21, 2026
@bboozzoo bboozzoo closed this Jul 24, 2026
@bboozzoo bboozzoo reopened this Jul 24, 2026

@jslarraz jslarraz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jslarraz jslarraz removed the Needs security review Can only be merged once security gave a :+1: label Jul 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Auto rerun spread Auto reruns spread up to 4 times in non-draft PRs w/ >=1 approval and <20 fails in any fund. system

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants