Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1197670

Bug#1071234: sbuild --chroot-mode=unshare: exposes /sys/kernel; breaks apparmor detection; ftbfs lomiri-thumbnailer and mediascanner2

From Helmut Grohne <helmut@subdivi.de>
Newsgroups linux.debian.bugs.dist
Subject Bug#1071234: sbuild --chroot-mode=unshare: exposes /sys/kernel; breaks apparmor detection; ftbfs lomiri-thumbnailer and mediascanner2
Date 2024-05-16 23:30 +0200
Message-ID <IEQPL-dOA3-3@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Package: libsbuild-perl
Version: 0.85.8
Tags: ftbfs patch
Control: affects -1 + src:mediascanner2 src:lomiri-thumbnailer

Hi Johannes and Jochen,

Jochen asked me to look into why the affected packages FTBFS when using
unshare chroot-mode. I managed to reproduce the failure, run the failing
test in isolation, capture an strace, stare at the strace output,
codesearch for random strings such as
"com.canonical.MediaScanner2.Error.Unauthorized" and following it down
to "check_access", "does_client_have_access",
"get_client_apparmor_context" and finally "aa_is_enabled". That was a
clue to look into AppArmor, so I ran "aa-enabled" on various
configurations:
 * bookworm without apparmor -> Yes
 * Something with apparmor -> Yes
 * sbuild --chroot-mode=unshare -> Yes
 * sbuild --chroot-mode=schroot -> Maybe

I think you spot the difference. The tests believe that AppArmor is
working when it really is not and thus fail as the AppArmor context does
not come back in the expected way. That leaves the question of why
AppArmor looks like it was working. It's because
/sys/kernel/security/apparmor exists. The
https://systemd.io/CONTAINER_INTERFACE/  documents /sys/kernel to be
inaccessible. Once you do that (and sbuild makes it really hard to do
that), both packages can be built. I'm attaching a patch for your
convenience.

Helmut

Back to linux.debian.bugs.dist | Previous | Next | Find similar | Unroll thread


Thread

Bug#1071234: sbuild --chroot-mode=unshare: exposes /sys/kernel; breaks apparmor detection; ftbfs lomiri-thumbnailer and mediascanner2 Helmut Grohne <helmut@subdivi.de> - 2024-05-16 23:30 +0200

csiph-web