Repository navigation
fix(webspaces): keep the capabilities package installs need when dropping capabilities - #11
Merged
NaysKutzu merged 1 commit intoOct 7, 2026
Conversation
…ping capabilities Since 3123204 every WebSpace container starts with CapDrop=ALL and no-new-privileges. That breaks plates whose startup installs packages before serving: the built-in PHP bootstrap (WebSpacePhpExtensions) runs `apt-get install $PHPIZE_DEPS ...` + `docker-php-ext-install` as root and then Apache. apt drops privileges to _apt and re-owns its list directories, so the container dies with E: setgroups 0 failed - setgroups (1: Operation not permitted) W: chown to _apt:root of directory /var/lib/apt/lists/partial failed E: The repository '... trixie-updates Release' no longer has a Release file. and restarts in a loop (exit code 100, the proxy answers 502). Every PHP WebSpace on the official php:8.3-apache image is affected - that is the shipped WordPress, Drupal, Joomla, Laravel and WHMCS plates - on every node, with no way to turn the hardening off. Keep the hardening, but drop down to the capabilities those startups actually need instead of everything, and make the whole thing configurable: docker: webspace_security: drop_capabilities: true # false = Docker's default capability set capabilities: [...] # capabilities kept; empty = drop all no_new_privileges: true The capability selection lives in a testable helper (WebSpaceRuntime.ApplyContainerSecurity) and is covered by unit tests. Measured on a live node with a throwaway container of the same image running the plate's startup script verbatim: with no capabilities apt fails and Apache never binds; with the default set the container serves after ~30 s with mysqli and pdo_mysql loaded.
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Member
|
Thank you for your contribution |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What breaks
3123204starts every WebSpace container withCapDrop = ["ALL"]andSecurityOpt = ["no-new-privileges:true"]. Plates whose startup installs packages before servingcan no longer start: the built-in PHP bootstrap (
Utils/WebSpaces/WebSpacePhpExtensions.cs) runsapt-get install $PHPIZE_DEPS …+docker-php-ext-installas root and thenapache2-foreground.apt drops privileges to
_aptand re-owns its list directories, so the container dies withand restarts in a loop (
Restarting (100)), while the reverse proxy answers502.Why this hits every node, not one installation
php:8.3-apacheimage, which does not shipmysqli,pdo_mysqloropcache, so theNEED_INSTALLbranch is always taken and apt is mandatory;Evidence
Live node, same image, the plate's startup script run verbatim in a throwaway container:
On the recreated PHP WebSpace after the change (defaults, no node-specific config):
The change
Hardening stays on, but the container only loses the capabilities that no plate startup needs:
The capability set is resolved in a testable helper,
WebSpaceRuntime.ApplyContainerSecurity,so the behaviour is pinned by unit tests instead of living inside the container-creation code.
Verification
dotnet test-> Failed: 0, Passed: 408, Skipped: 0 (8 new tests inFeatherQuilld.Tests/Docker/WebSpaceContainerSecurityTests.cs)every domain and backend port back at its pre-update baseline, the PHP WebSpace serves again
(
20001 -> 301), SFTP matrix 4/4 on password-only, publickey-listed and publickey-with-key,zero error lines in the daemon log.
Alternatives considered
CapDrop=["ALL"]and ship a prebuilt PHP image - works, but the daemon's own bootstrap andevery shipped PHP plate use the official image, so all of them would have to change, and the
image has to be rebuilt per PHP version.
shipped plates on other installations.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.