Files
supervisor/tests/docker
Stefan AgnerandClaude Fable 5.1 a5d5c79a57 Add feature flag to drop MKNOD, AUDIT_WRITE and SETFCAP from apps (#7233)
containerd is introducing a "reduced" capability profile that removes
NET_RAW, MKNOD, AUDIT_WRITE and SETFCAP from the default set, matching what
Kubernetes' restricted profile has dropped for years. NET_RAW is handled by
the app_drop_net_raw flag since it has a security implication of its own and
known app fallout. This adds the remaining three under a separate flag.

Add AUDIT_WRITE, MKNOD and SETFCAP to the Capabilities enum so apps can
request them under privileged, and the app_reduced_capabilities development
feature flag. When enabled, app containers are created with these
capabilities in CapDrop unless the app explicitly declares them. The
security rating is unchanged for them.

None of the three has a consumer among the current core and community apps.
Apps receive the host /dev bind-mounted, so MKNOD is not needed to see
devices. The SSH apps and Debian's openssh-server are built without libaudit
and PAM, so AUDIT_WRITE is unused. SETFCAP only matters for packages
installed at runtime: Debian postinst scripts fall back to setuid with a
warning and apk logs a failed xattr write, both without failing the install.

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-17 10:21:41 +02:00
..