Skip to content

contain: stop setup if PR_SET_NO_NEW_PRIVS fails#286

Open
srkyn wants to merge 1 commit into
google:masterfrom
srkyn:harden-no-new-privs-failure
Open

contain: stop setup if PR_SET_NO_NEW_PRIVS fails#286
srkyn wants to merge 1 commit into
google:masterfrom
srkyn:harden-no-new-privs-failure

Conversation

@srkyn

@srkyn srkyn commented Jul 20, 2026

Copy link
Copy Markdown

Summary

When nsjail is configured to set no_new_privs, a failed prctl(PR_SET_NO_NEW_PRIVS, 1) call currently produces a warning and lets the jailed command continue.

Treat the failed call as an error and stop setup before executing the command. This does not change the explicit --disable_no_new_privs path.

Testing

The full build passes on Ubuntu 24.04 under WSL. Basic true/false execution tests and the seccomp tests also pass.

I used strace syscall injection to force the PR_SET_NO_NEW_PRIVS call to return EPERM. nsjail stopped setup and did not execute the jailed command. The same command still ran when invoked with --disable_no_new_privs.

The remaining test suite reached the networking tests, then stopped because pasta is not installed.

@google-cla

google-cla Bot commented Jul 20, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@srkyn

srkyn commented Jul 20, 2026

Copy link
Copy Markdown
Author

@googlebot rescan

@srkyn
srkyn marked this pull request as ready for review July 20, 2026 19:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant