canonical / canonical/core-base

core26 - coreutils symlink targets not covered by `defaultCoreRuntimeTemplateRules`

Open
#371 5 comments 0 reactions 0 assignees View on GitHub
Dominant language
Shell
Stars
37
Forks
53
Avg merge
1d 19h
Merged PRs (30d)
12

Description

The core26 snap appears to make use of the GNU coreutils, Ubuntu Questing is moving to a default of the uutils re-implementation of coreutils in Rust, and as a side effect the GNU coreutils binaries are now behind a layer of symlinks.

The snapd `defaultCoreRuntimeTemplateRules` does not cover this:
https://github.com/canonical/snapd/blob/44ef02278af92d3961fe6d8cedf8a4533f5aa53d/interfaces/apparmor/template.go#L507-L676

and as a consequence binaries/scripts with a core26 base are currently not able to execute coreutils tools such as `mkdir` and `readlink`.

Log excerpt:
```
apparmor="DENIED" operation="exec" class="file" profile="snap.microovn.switch" name="/usr/bin/gnumkdir" pid=1328 comm="switch.start" requested_mask="x" denied_mask="x" fsuid=0 ouid=0
apparmor="DENIED" operation="exec" class="file" profile="snap.microovn.switch" name="/usr/bin/gnumkdir" pid=1328 comm="switch.start" requested_mask="x" denied_mask="x" fsuid=0 ouid=0
apparmor="DENIED" operation="exec" class="file" profile="snap.microovn.switch" name="/usr/bin/gnumkdir" pid=1391 comm="switch.start" requested_mask="x" denied_mask="x" fsuid=0 ouid=0
apparmor="DENIED" operation="exec" class="file" profile="snap.microovn.switch" name="/usr/bin/gnumkdir" pid=1391 comm="switch.start" requested_mask="x" denied_mask="x" fsuid=0 ouid=0

apparmor="DENIED" operation="exec" class="file" profile="snap.microovn.ovn-ovsdb-server-nb" name="/usr/bin/gnureadlink" pid=1427 comm="ovn-ctl" requested_mask="x" denied_mask="x" fsuid=0 ouid=0
apparmor="DENIED" operation="exec" class="file" profile="snap.microovn.ovn-ovsdb-server-nb" name="/usr/bin/gnureadlink" pid=1427 comm="ovn-ctl" requested_mask="x" denied_mask="x" fsuid=0 ouid=0
```

```
# ls -l /snap/core26/current/bin/mkdir /snap/core26/current/bin/gnumkdir
-rwxr-xr-x 1 root root 68192 May 8 09:06 /snap/core26/current/bin/gnumkdir
lrwxrwxrwx 1 root root 8 Aug 26 11:28 /snap/core26/current/bin/mkdir -> gnumkdir
```

Contributor guide

No contributing guide indexed for this repository

Research direction

Start in snapd's apparmor/template.go at defaultCoreRuntimeTemplateRules, linked by the issue. Compare the existing runtime rule coverage with the core26 symlink targets and the denied gnumkdir and gnureadlink paths. Done means core26 binaries and scripts can execute these coreutils tools without the shown AppArmor denials.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux, shell
Domain
operating-systems, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.