From nobody Tue Aug 25 02:50:50 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) client-ip=38.145.34.151; envelope-from=devel-bounces@lists.libvirt.org; helo=lists.libvirt.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass(p=reject dis=none) header.from=lists.libvirt.org ARC-Seal: i=1; a=rsa-sha256; t=1787090131; cv=none; d=zohomail.com; s=zohoarc; b=RnVnjcrHcO9GtfVlAtmOxG+FPNPYFv8uUhfGaSqcdEDcguy0UaWDtfFk/3dVh3KSFRnQYbCGcOsj9azm4tFhs1NgU42yzaXDsoSbAVzk5vwVlp1ZnHK39BcdNZsT/xr2/kQzI27ft8VFqOYS0gWL/DKsLG8DfxROl29rsallUuQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787090131; h=Content-Transfer-Encoding:Date:Date:From:From:List-Subscribe:List-Post:List-Owner:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:Reply-To:Subject:Subject:To:To:Message-Id:Cc; bh=sRzdd8AJLD5qSmdwfO7ncrOPk38ivff3OxdhN1GIqE4=; b=PbiMoG23oKGb+AoLv7T/xYGQCigttrOS1XN4YBh3qoH2dut0cYoYV/9h+k1D/RrLy4pq3h3RL2rLy6qAkcqSjXlc/GHTYFOuH3+z0skivYeMLDKbvl0A5IFXe2XNX2VyTfvcDICYV8UIzrgCDbyfCswghTdCrJr/MEcAv0C+AM4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.libvirt.org (lists.libvirt.org [38.145.34.151]) by mx.zohomail.com with SMTPS id 1787090131050449.22349047956277; Tue, 18 Aug 2026 14:55:31 -0700 (PDT) Received: by lists.libvirt.org (Postfix, from userid 993) id 66FCC418DA; Tue, 18 Aug 2026 17:55:29 -0400 (EDT) Received: from [172.19.199.13] (unknown [10.16.107.18]) by lists.libvirt.org (Postfix) with ESMTP id D009141A0E for ; Tue, 18 Aug 2026 17:54:33 -0400 (EDT) Received: by lists.libvirt.org (Postfix, from userid 993) id 6AE0B3F335; Tue, 18 Aug 2026 17:54:27 -0400 (EDT) Received: from mail-wm1-x329.google.com (mail-wm1-x329.google.com [IPv6:2a00:1450:4864:20::329]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (3072 bits) server-digest SHA256) (No client certificate requested) by lists.libvirt.org (Postfix) with ESMTPS id D1EE53F8ED for ; Tue, 18 Aug 2026 17:54:25 -0400 (EDT) Received: by mail-wm1-x329.google.com with SMTP id 5b1f17b1804b1-495437bb891so1426135e9.1 for ; Tue, 18 Aug 2026 14:54:25 -0700 (PDT) Received: from localhost ([69.51.117.130]) by smtp.gmail.com with UTF8SMTPSA id 5a478bee46e88-327bf143775sm45547eec.23.2026.08.18.14.54.23 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 18 Aug 2026 14:54:23 -0700 (PDT) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on lists.libvirt.org X-Spam-Level: X-Spam-Status: No, score=-2.7 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_NONE,SPF_HELO_NONE autolearn=unavailable autolearn_force=no version=4.0.1 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1787090064; x=1787694864; darn=lists.libvirt.org; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=sRzdd8AJLD5qSmdwfO7ncrOPk38ivff3OxdhN1GIqE4=; b=GJW3YozXAYCLumIF2SihNM0ajCYc4xWs+cowWcFb5WMmFu5QCqMnf9mt4l4ydUP7M/ rt+izeO7DM0DbIQhtxd2ARbpEoihrnFoaA0jS9AfU8mFo7SxuLoxybhs/Qz3tdKS5o5b fTKLP0ZS1e7b0zmi9DNDA1H2vaed0nXbSDgaA2KSDjBBapGnyxp0mt8pgT36r/fqbcea nM68PpY7VKcj4PUHELOiiEzN47bD9gWCBjIgThBwd0Pbw2a9AvZy8vYOW/vuDDFHfPy7 f61YFLTTxBMf3c/HrTOSBKwV4hOdz1HufeZ/PjDj67dBdrBeYTQ4BwxKOrVOD98qB4Bq mo2A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787090064; x=1787694864; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=sRzdd8AJLD5qSmdwfO7ncrOPk38ivff3OxdhN1GIqE4=; b=cRowzmi/QbVmtMXYw8Sg4rkd1P/AJVq4uJQOvMfjM2DzUCNfzkqsMQBp0pO1juBMmB LFkJ22vmh7Ci0b7juBhw2Ku5uUi70OC5I/KRgOvfwV5f7zr3raFm/1ktZzn92p3zVmWX gvOfj8Cz8ZkIQaB6rUHln8LQKRdYQ9Bfbyf4knNyCRBubv1RCEZQLiuNMtR2F1HsOB75 fRvwTzDl2+1FS9gmm50faAQkEKiWroLgjxYFAMMCCmboXFANe0L1zKyxVUQ2L2j59f2B bhvpiKE0IpcrHyIEW/l/UAPQpvAFNdBvl/aU4xgqJvu0hVfFCYxYZcpnGZ0KO37hR5uE TJ4Q== X-Gm-Message-State: AOJu0YxBYhPc67UlG/31ObjYbhBnVUL/Q2rqHylu+3T4qSrNl0UQZJuk YQ9ClnAWDZd3OYySAoPZj46I4axK4Zk/RWxBtEHotzgONfhiaG4qlOyqUrbVTqtK4EHjUGo+div ZNdJCIS4= X-Gm-Gg: AR+sD11mRrtO3WhAgQctqBfwkrXRxvRWheCyBnyq9k4arhrC/ui4pSkk9rSwFCTAFjX HxilC6btTqJVgtlI3lMR+7vLya5pFnVwcRypdQOslTbOJyfGDvcth1C9+sY5fSL1ii3jsM2Vapj lcRM70cau2xGergDEW+ZdHc4kc12edy8ruGNypW4586gapiG2chmsifBxXfglP1OX4IEYeZDMQ3 /2QBPMKMFyHwOxpgVxbBVJ2Ru3I2cND6PA7twzzIjYaVLHXZ99jRTpfjutvzb8J6sD/TCPmXHiS viFfluaIycVG0VKxufMX6ZGSY7Sodkm9/+sUY9k5fiqiZEb9Bd9T6WMhXFh1+y7Jz+JbeZkHTgY FffcUMEOqcpALHcryUd2cWSAt06rZB69gcE+zcTn3iu3UAAP3avXJwja3kYTffy5MPS+3R1xOIX ylrCtv/ZY79rirc9fsVyo35Iet2wDgoqIhhOQnkZqsV+zt4XpY2dA= X-Received: by 2002:a05:600c:4704:b0:499:5f81:8ca1 with SMTP id 5b1f17b1804b1-499aa0fd553mr3241455e9.6.1787090064426; Tue, 18 Aug 2026 14:54:24 -0700 (PDT) To: devel@lists.libvirt.org Subject: [PATCH] qemu: tpm: Avoid following symlinks when chown'ing log file Date: Tue, 18 Aug 2026 15:53:58 -0600 Message-ID: <20260818215421.731014-1-jfehlig@suse.com> X-Mailer: git-send-email 2.51.0 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Message-ID-Hash: F72UQKDT4QXB5R2YB5TTZOVVT5V4RFW2 X-Message-ID-Hash: F72UQKDT4QXB5R2YB5TTZOVVT5V4RFW2 X-MailFrom: jfehlig@suse.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.lists.libvirt.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Development discussions about the libvirt library & tools Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: From: Jim Fehlig via Devel Reply-To: Jim Fehlig X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZM-MESSAGEID: 1787090134050158500 Content-Type: text/plain; charset="utf-8" From: Jim Fehlig libvirt chown()s the swtpm log file to the swtpm user:group when starting a VM. The swtpm log directory is writable by swtmp user, who could replace the logfile with a symlink to a root-owned path. At next VM start, libvirt will chown() that path to the swtpm user:group, which breaks the intended separation between the confined swtpm account and root-owned files. Use fchown() on an fd opened with O_NOFOLLOW to avoid the potential symlink attack. Signed-off-by: Jim Fehlig Reviewed-by: Martin Kletzander --- src/qemu/qemu_tpm.c | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/src/qemu/qemu_tpm.c b/src/qemu/qemu_tpm.c index 660410bcba..34e11cc02f 100644 --- a/src/qemu/qemu_tpm.c +++ b/src/qemu/qemu_tpm.c @@ -1030,6 +1030,8 @@ qemuTPMEmulatorPrepareHost(virDomainTPMDef *tpm, uid_t qemu_user, const char *shortName) { + VIR_AUTOCLOSE logfd =3D -1; + /* create log dir ... allow 'tss' user to cd into it */ if (g_mkdir_with_parents(logDir, 0711) < 0) return -1; @@ -1039,13 +1041,20 @@ qemuTPMEmulatorPrepareHost(virDomainTPMDef *tpm, VIR_DIR_CREATE_ALLOW_EXIST) < 0) return -1; =20 - if (!virFileExists(tpm->data.emulator.logfile) && - virFileTouch(tpm->data.emulator.logfile, 0644) < 0) { + /* Open (creating if necessary) the logfile without following a + * symlink. The log directory is writable by swtpm_user, so we want + * to avoid chown'ing a symlink to an arbitrary path. + */ + if ((logfd =3D open(tpm->data.emulator.logfile, + O_WRONLY | O_CREAT | O_NOFOLLOW | O_CLOEXEC, 0644)) = < 0) { + virReportSystemError(errno, + _("Could not open swtpm logfile %1$s"), + tpm->data.emulator.logfile); return -1; } =20 /* ... and make sure it can be accessed by swtpm_user */ - if (chown(tpm->data.emulator.logfile, swtpm_user, swtpm_group) < 0) { + if (fchown(logfd, swtpm_user, swtpm_group) < 0) { virReportSystemError(errno, _("Could not chown on swtpm logfile %1$s"), tpm->data.emulator.logfile); --=20 2.51.0