mirror of
https://github.com/home-assistant/supervisor.git
synced 2026-09-29 19:23:29 +01:00
containerd is introducing a "reduced" capability profile that removes NET_RAW, MKNOD, AUDIT_WRITE and SETFCAP from the default set, matching what Kubernetes' restricted profile has dropped for years. NET_RAW is handled by the app_drop_net_raw flag since it has a security implication of its own and known app fallout. This adds the remaining three under a separate flag. Add AUDIT_WRITE, MKNOD and SETFCAP to the Capabilities enum so apps can request them under privileged, and the app_reduced_capabilities development feature flag. When enabled, app containers are created with these capabilities in CapDrop unless the app explicitly declares them. The security rating is unchanged for them. None of the three has a consumer among the current core and community apps. Apps receive the host /dev bind-mounted, so MKNOD is not needed to see devices. The SSH apps and Debian's openssh-server are built without libaudit and PAM, so AUDIT_WRITE is unused. SETFCAP only matters for packages installed at runtime: Debian postinst scripts fall back to setuid with a warning and apk logs a failed xattr write, both without failing the install. Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>