You are not logged in.

#1 2019-11-22 21:48:21

elkami
Member
Registered: 2016-05-11
Posts: 8

[SOLVED] run as root : Operation not permitted in openvpn script

Hi,

My goal is to set up a network namespace including openvpn and to bridge some connections outside of this namespace (port 9091, transmission web GUI).

What I did :

Create an openvpn systemd unit which starts the namespace. I don't remember where I found this but I think it is pretty neat to handle the namespace in the openvpn service: /usr/lib/systemd/system/openvpn-client@.service

[Unit]
Description=OpenVPN tunnel for %I
After=syslog.target network-online.target
Wants=network-online.target
Documentation=man:openvpn(8)
Documentation=https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage
Documentation=https://community.openvpn.net/openvpn/wiki/HOWTO

[Service]
Type=notify
PrivateTmp=true
WorkingDirectory=/etc/openvpn/client
ExecStart=/usr/bin/openvpn --script-security 2 --ifconfig-noexec --route-noexec --up /etc/openvpn/netns-script --route-up /etc/openvpn/netns-script --down /etc/openvpn/netns-script --suppress-timestamps --nobind --config %i.conf
CapabilityBoundingSet=CAP_IPC_LOCK CAP_NET_ADMIN CAP_NET_RAW CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_DAC_OVERRIDE
LimitNPROC=10
DeviceAllow=/dev/null rw
DeviceAllow=/dev/net/tun rw
ProtectSystem=true
ProtectHome=true
KillMode=process

[Install]
WantedBy=multi-user.target
EOF

This is the script called by openvpn and managing the namespace (with debug info):

#!/bin/sh

set -o xtrace

case $script_type in
        up)
                echo " this script is running as $(id -u -n)"
                ip netns add vpn
                ip netns exec vpn ip link set dev lo up
                ip link set dev "$1" up netns vpn mtu "$2"
                ip netns exec vpn ip addr add dev "$1" \
                        "$4/${ifconfig_netmask:-30}" \
                        ${ifconfig_broadcast:+broadcast "$ifconfig_broadcast"}
                if [ -n "$ifconfig_ipv6_local" ]; then
                        ip netns exec vpn ip addr add dev "$1" \
                                "$ifconfig_ipv6_local"/112
                fi
                ip link add name vethhost0 type veth peer name vethvpn0
                ip link set vethvpn0 netns vpn
                ip addr add 10.0.0.1/24 dev vethhost0
                ip netns exec vpn ip addr add 10.0.0.2/24 dev vethvpn0
                ip link set vethhost0 up
                ip netns exec vpn ip link set vethvpn0 up
                iptables -t nat -A PREROUTING ! -s 10.0.0.0/24 -p tcp -m tcp --dport 9091 -j DNAT --to-destination 10.0.0.2
                ip netns exec vpn ip route add default via 10.0.0.1
                iptables -t nat -A POSTROUTING -d 10.0.0.2/24 -j SNAT --to-source 10.0.0.1
                iptables -t nat -A OUTPUT -d 192.168.10.1 -p tcp -m tcp --dport 9091 -j DNAT --to-destination 10.0.0.2
                ;;
        route-up)
                ip netns exec vpn ip route add default via "$route_vpn_gateway"
                if [ -n "$ifconfig_ipv6_remote" ]; then
                        ip netns exec vpn ip route add default via \
                                "$ifconfig_ipv6_remote"
                fi
                ;;
        down)
                ip netns delete vpn
                ;;
esac

Make sure root is running it:

chmod 740 /etc/openvpn/netns-script
chmod u+s /etc/openvpn/netns-script

ls -l /etc/openvpn/netns-script
-rwsr----- 1 root root 1813 Nov 22 22:18 /etc/openvpn/netns-script

But when I start openvpn with sudo:

systemctl start openvpn-client@chire.service

The output of 'journalctl -eu openvpn-client@chire.service' tells me that some operations are not permitted :

Nov 22 22:18:44 rexthor openvpn[5958]: /etc/openvpn/netns-script tun0 1500 1552 10.8.0.18 10.8.0.17 init
Nov 22 22:18:44 rexthor openvpn[5958]: + case $script_type in
Nov 22 22:18:44 rexthor openvpn[5958]: ++ id -u -n
Nov 22 22:18:44 rexthor openvpn[5958]: + echo ' this script is running as root'
Nov 22 22:18:44 rexthor openvpn[5958]:  this script is running as root
Nov 22 22:18:44 rexthor openvpn[5958]: + ip netns add vpn
Nov 22 22:18:44 rexthor openvpn[5958]: mount --make-shared /var/run/netns failed: Operation not permitted
Nov 22 22:18:44 rexthor openvpn[5958]: + ip netns exec vpn ip link set dev lo up
Nov 22 22:18:44 rexthor openvpn[5958]: setting the network namespace "vpn" failed: Operation not permitted
Nov 22 22:18:44 rexthor openvpn[5958]: + ip link set dev tun0 up netns vpn mtu 1500
Nov 22 22:18:44 rexthor openvpn[5958]: + ip netns exec vpn ip addr add dev tun0 10.8.0.18/30
Nov 22 22:18:44 rexthor openvpn[5958]: setting the network namespace "vpn" failed: Operation not permitted
Nov 22 22:18:44 rexthor openvpn[5958]: + '[' -n '' ']'
Nov 22 22:18:44 rexthor openvpn[5958]: + ip link add name vethhost0 type veth peer name vethvpn0
Nov 22 22:18:44 rexthor openvpn[5958]: RTNETLINK answers: File exists
Nov 22 22:18:44 rexthor openvpn[5958]: + ip link set vethvpn0 netns vpn
Nov 22 22:18:44 rexthor openvpn[5958]: Cannot find device "vethvpn0"
Nov 22 22:18:44 rexthor openvpn[5958]: + ip addr add 10.0.0.1/24 dev vethhost0
Nov 22 22:18:44 rexthor openvpn[5958]: RTNETLINK answers: File exists
Nov 22 22:18:44 rexthor openvpn[5958]: + ip netns exec vpn ip addr add 10.0.0.2/24 dev vethvpn0
Nov 22 22:18:44 rexthor openvpn[5958]: setting the network namespace "vpn" failed: Operation not permitted
Nov 22 22:18:44 rexthor openvpn[5958]: + ip link set vethhost0 up
Nov 22 22:18:44 rexthor openvpn[5958]: + ip netns exec vpn ip link set vethvpn0 up
Nov 22 22:18:44 rexthor openvpn[5958]: setting the network namespace "vpn" failed: Operation not permitted
Nov 22 22:18:44 rexthor openvpn[5958]: + iptables -t nat -A PREROUTING '!' -s 10.0.0.0/24 -p tcp -m tcp --dport 9091 -j DNAT --to-destination 10.0.0.2
Nov 22 22:18:44 rexthor openvpn[5958]: + ip netns exec vpn ip route add default via 10.0.0.1
Nov 22 22:18:44 rexthor openvpn[5958]: setting the network namespace "vpn" failed: Operation not permitted
Nov 22 22:18:44 rexthor openvpn[5958]: + iptables -t nat -A POSTROUTING -d 10.0.0.2/24 -j SNAT --to-source 10.0.0.1
Nov 22 22:18:44 rexthor openvpn[5958]: + iptables -t nat -A OUTPUT -d 192.168.10.1 -p tcp -m tcp --dport 9091 -j DNAT --to-destination 10.0.0.2
Nov 22 22:18:44 rexthor openvpn[5958]: + case $script_type in
Nov 22 22:18:44 rexthor openvpn[5958]: + ip netns exec vpn ip route add default via 10.8.0.17
Nov 22 22:18:44 rexthor openvpn[5958]: setting the network namespace "vpn" failed: Operation not permitted
Nov 22 22:18:44 rexthor openvpn[5958]: + '[' -n '' ']'
Nov 22 22:18:44 rexthor openvpn[5958]: GID set to nobody
Nov 22 22:18:44 rexthor openvpn[5958]: UID set to nobody
Nov 22 22:18:44 rexthor openvpn[5958]: WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Nov 22 22:18:44 rexthor openvpn[5958]: Initialization Sequence Completed

Make sure the right openvpn service is running:

ystemctl status openvpn-client@chire.service                                                                                                                                                                                              22:35:19  ✔ 0 
● openvpn-client@chire.service - OpenVPN tunnel for chire
   Loaded: loaded (/usr/lib/systemd/system/openvpn-client@.service; disabled; vendor preset: disabled)
   Active: active (running) since Fri 2019-11-22 22:18:42 CET; 17min ago
     Docs: man:openvpn(8)
           https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage
           https://community.openvpn.net/openvpn/wiki/HOWTO
 Main PID: 5958 (openvpn)
   Status: "Initialization Sequence Completed"
    Tasks: 1 (limit: 4475)
   Memory: 2.6M
   CGroup: /system.slice/system-openvpn\x2dclient.slice/openvpn-client@chire.service
           └─5958 /usr/bin/openvpn --script-security 2 --ifconfig-noexec --route-noexec --up /etc/openvpn/netns-script --route-up /etc/openvpn/netns-script --down /etc/openvpn/netns-script --suppress-timestamps --nobind --config chire.conf

Why is root not permitted to do 'ip netns' ? It works when running these commands with sudo.
The second disturbing point is that 'ip link ...' does not complain, only 'ip netns'.

Thanks,

Last edited by elkami (2019-11-23 15:42:33)

Offline

#2 2019-11-22 22:01:21

loqs
Member
Registered: 2014-03-06
Posts: 19,097

Re: [SOLVED] run as root : Operation not permitted in openvpn script

Offline

#3 2019-11-23 00:12:14

elkami
Member
Registered: 2016-05-11
Posts: 8

Re: [SOLVED] run as root : Operation not permitted in openvpn script

Yes it does, thanks!

adding 'CAP_SYS_ADMIN' to the openvpn service file 'CapabilityBoundingSet'  property works.

I still don't understand how I didn't found this post ealrlier...

Offline

Board footer

Powered by FluxBB