Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1197670
| From | Helmut Grohne <helmut@subdivi.de> |
|---|---|
| Newsgroups | linux.debian.bugs.dist |
| Subject | Bug#1071234: sbuild --chroot-mode=unshare: exposes /sys/kernel; breaks apparmor detection; ftbfs lomiri-thumbnailer and mediascanner2 |
| Date | 2024-05-16 23:30 +0200 |
| Message-ID | <IEQPL-dOA3-3@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
Package: libsbuild-perl Version: 0.85.8 Tags: ftbfs patch Control: affects -1 + src:mediascanner2 src:lomiri-thumbnailer Hi Johannes and Jochen, Jochen asked me to look into why the affected packages FTBFS when using unshare chroot-mode. I managed to reproduce the failure, run the failing test in isolation, capture an strace, stare at the strace output, codesearch for random strings such as "com.canonical.MediaScanner2.Error.Unauthorized" and following it down to "check_access", "does_client_have_access", "get_client_apparmor_context" and finally "aa_is_enabled". That was a clue to look into AppArmor, so I ran "aa-enabled" on various configurations: * bookworm without apparmor -> Yes * Something with apparmor -> Yes * sbuild --chroot-mode=unshare -> Yes * sbuild --chroot-mode=schroot -> Maybe I think you spot the difference. The tests believe that AppArmor is working when it really is not and thus fail as the AppArmor context does not come back in the expected way. That leaves the question of why AppArmor looks like it was working. It's because /sys/kernel/security/apparmor exists. The https://systemd.io/CONTAINER_INTERFACE/ documents /sys/kernel to be inaccessible. Once you do that (and sbuild makes it really hard to do that), both packages can be built. I'm attaching a patch for your convenience. Helmut
Back to linux.debian.bugs.dist | Previous | Next | Find similar | Unroll thread
Bug#1071234: sbuild --chroot-mode=unshare: exposes /sys/kernel; breaks apparmor detection; ftbfs lomiri-thumbnailer and mediascanner2 Helmut Grohne <helmut@subdivi.de> - 2024-05-16 23:30 +0200
csiph-web