#745706 sysdig: Group-accessible /dev/sysdig0

Package:
sysdig
Source:
sysdig
Description:
system-level exploration and troubleshooting tool
Submitter:
Dima Kogan
Date:
2024-05-25 04:48:03 UTC
Severity:
wishlist
Tags:
#745706#5
Date:
2014-04-24 08:19:28 UTC
From:
To:
It would be nice if /dev/sysdig* was owned by a group that isn't root.
Then a properly-grouped non-root user can sysdig without sudo.

#745706#14
Date:
2014-05-13 06:17:49 UTC
From:
To:
Hi,

Upstream says [1] having access to /dev/sysdig is not enough, as you
need access to /proc too [2]. I am therefore tagging this bug as wontfix
for now as I do not want to implement halfworking things against
upstreams will.

Greets
Evgeni

[1] https://github.com/draios/sysdig/issues/156
[2] https://github.com/draios/sysdig/wiki/How%20to%20Install%20Sysdig%20for%20Linux#use-sysdig-as-non-root

#745706#21
Date:
2024-05-18 06:21:14 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
falcosecurity-libs, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 745706@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Dima Kogan <dkogan@debian.org> (supplier of updated falcosecurity-libs package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 17 May 2024 22:41:31 -0700
Source: falcosecurity-libs
Architecture: source
Version: 0.15.1-3
Distribution: unstable
Urgency: medium
Maintainer: Dima Kogan <dkogan@debian.org>
Changed-By: Dima Kogan <dkogan@debian.org>
Closes: 745706
Changes:
 falcosecurity-libs (0.15.1-3) unstable; urgency=medium
 .
   * scap driver now accessible as a non-root user, if they're in the
     "scap" group.
     Thanks to Gerald Combs <gerald@wireshark.org> (Closes: #745706)
   * debian/watch doesn't consider pre-release tags
Checksums-Sha1:
 764dc66ab4df7f3bff3f0fe297c58f1b38d5a7d1 2616 falcosecurity-libs_0.15.1-3.dsc
 d015e931d26247f6dd5a7fbb7ba221b99e9d8ac7 10180 falcosecurity-libs_0.15.1-3.debian.tar.xz
 389f8fe46ad800ad2ff9f2033f2e08ce991ffec8 14549 falcosecurity-libs_0.15.1-3_source.buildinfo
Checksums-Sha256:
 5518095b0bc4e440a7dc5e788b2a4932163681201296e539cf92d1af94b1e505 2616 falcosecurity-libs_0.15.1-3.dsc
 1ee043758b95595d7414909eafcc6e59fdd04494136caa31acc189ff95b82acc 10180 falcosecurity-libs_0.15.1-3.debian.tar.xz
 53a32daff1ce67c4ad391c66a08221f6e20d0fb18d38e04df116e5d636af4d3a 14549 falcosecurity-libs_0.15.1-3_source.buildinfo
Files:
 797c87a9ab368d86c588c115c3d2ccf0 2616 libdevel optional falcosecurity-libs_0.15.1-3.dsc
 4e3b8f9c9059cdc525f8e8a6c5b80938 10180 libdevel optional falcosecurity-libs_0.15.1-3.debian.tar.xz
 8b37fafd16e956a4bb7a9fcea27e023e 14549 libdevel optional falcosecurity-libs_0.15.1-3_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJGBAEBCgAwFiEEteL6GQ/fmv4hiInPrMfCzzCUEYgFAmZIQkUSHGRrb2dhbkBk
ZWJpYW4ub3JnAAoJEKzHws8wlBGIj7sP/iMCg91wveNHquSOL4viPv95vrZJMza5
y6cwBrptLvJHsFkDZwf1vt41y+1KmkWdmu0tC/FReUlaEXJSPpETPlYAuygXffW5
LBrERI4/NXxbmuxqPEJUzWCHGtTWHl+pxr+QYTJeYcn9m8bkin9Phm9l1GE9wUEI
n77qrHME7qMKcgeMZRlwD5IdjJM2BHxOGxQ1pbgKuPVJQ98A3ubw0aeAxZc9XzwK
A7W3ffkbHrYCJo4S50QyDEQGsbNcb/JbR8yGJqE8B/YsDi4dfqIJwRPOkrENluxb
BSoF34PdkUZb6bmrekiDAAf9eFWZZihfl2DsSmfq/4SmxfZ/1r/D3fCigB3H0Bqv
Gcz+RQPMown/uMm+QLTM0Kyj2JsGtQrVIw3u0CwOcmGq/tnFwFMcIsx2zKjlg1el
ln3v0niMzwYbYxqF0y53PE1VhICDkWiqodZLFG3c192NHk3tPvJaGkGpof2H9u+0
7Em7z5cM2ZrbNJ1l4F7F2JV7JnxFUSn4btLVaoI6O2ljIWCj7O0MI6QBw80/MpWJ
6v1U1deYdi9FI3brr1+7f7jDNPJ7JHPXFgtYPfZrFWT5ZyqhJnownd9TtpBldmyi
qYYHXQg9UqMfOcCauSy+I0vRBV+EObwA9feryMsAUnzOR4ZfIERguVHkyQ007nHI
JdcP1+0fCOPE
=Sibz
-----END PGP SIGNATURE-----

#745706#30
Date:
2024-05-25 04:45:25 UTC
From:
To:
I'm reopening this bug with the upload of falcosecurity-libs 0.15.1-4.

In 0.15.1-3 I added logic to add a "scap" group that has permissions to
talk to the scap driver. But the previous issues (this doesn't also
grant the required access to /proc) apparently weren't resolved yet. So
I reverted that logic, and the bug is back.

The relevant commit from git:

commit 793391d31ecd700a0913773c70591824c8e7d519
Author: Dima Kogan <dkogan@debian.org>
Date:   Fri May 24 21:18:18 2024 -0700

  Reverted the use-group-to-access-scap-device patches

  These patches:

    5682cde Dima Kogan   2024-05-24 Added missing Depends:adduser
    ea3ef71 Dima Kogan   2024-05-17 Tiny fixes to the use-group-to-access-scap-device
    b43bda3 Gerald Combs 2024-05-16 Add a udev rule and module config for falcosecurity-scap-dkms

  Reopens this bug:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=745706

  I did some testing earlier to confirm that this bug was actually fixed, and it
  seemed like it was. But apparently I didn't look thoroughly-enough, and this bug
  is still problematic. So I'm reverting the patches that effected this
  insufficient fix.

  Gerald Combs said:

    Hi Dima,

    I haven't had a chance to try out the new package, but I did ask around about
    the required capture permissions internally at Sysdig. It's possible to
    capture without root using the eBPF driver:

https://falco.org/docs/install-operate/running/#least-privileged

    However, the kmod driver requires root in order scan through /proc for process
    information other than your own. This matches my tests here; I see many more
    syscalls when I capture as root vs when I capture as an unprivileged user with
    read+write access to /dev/scap*.

    I'm going to update Logray's local Debian packaging to make falcodump setuid
    and accessible by the "scap" group:

https://gitlab.com/wireshark/wireshark/-/merge_requests/15673

    Hopefully at some point we can change that to a set of capabilities.