Bug 12781

Summary: Not able to use losetup, cryptsetup, mount utilities under pseudo environment.
Product: [Yocto Project Subprojects] Pseudo Reporter: PRAKASH <prakashpks15>
Component: pseudoAssignee: Mark Hatle <mark.hatle>
Status: RESOLVED INVALID QA Contact:
Severity: enhancement    
Priority: Undecided CC: yp.pseudo.watcher, yp.watcher
Version: unspecified   
Target Milestone: ---   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Don't know

Description PRAKASH 2018-06-12 06:59:13 UTC
Hi Folks,

I am trying to do some encryption stuffs under pseudo environment but losetup, cryptsetup, mount these utilities are not able to run under pseudo.

I am getting permission denied errors.
Here below are the few steps i am trying to achieve under pseudo.

1. Creating Container file with specific size
dd if=/dev/zero of=/home/you/cryptfile bs=1M count=500
ex: dd if=/dev/zero of=a-sdcard bs=1M count=500

2. Associate with a loop device
sudo losetup /dev/loop0 image-file-name

3. Craete partitions
parted -s /dev/loop0 mklabel msdos
parted -s /dev/loop0 unit cyl mkpart primary fat32 -- 0 16
parted -s /dev/loop0 set 1 boot on
parted -s /dev/loop0 unit cyl mkpart primary ext2 -- 16 -2

4. Encrypt the RFS patition
cryptsetup -s 512 luksFormat /dev/loop0p2 enc.key
cryptsetup luksOpen -d enc.key /dev/loop0p2 example12
mkfs.ext4 /dev/mapper/example12
mount -t ext4 /dev/mapper/example12 /mnt/block3

All above steps are work perfectly fine with sudo. But we don't want run under sudo.

We want to run under pseudo.

Below is example to setup pseudo env
export PSEUDO="${FAKEROOTENV} PSEUDO_LOCALSTATEDIR=${STAGING_DIR_TARGET}${localstatedir}/pseudo ${STAGING_DIR_NATIVE}${bindir}/pseudo"

PLease let me know if you guys need more information on this.

Thanks!
Prakash
Comment 1 Mark Hatle 2018-06-12 14:17:34 UTC
Each of the items you mention require specific permissions (capabilities) from the system to execute.

'pseudo' does not elevate your permission, it just captures and emulates certain permission based components, specifically the ability to set and return 'fake' filesystem owners/groups/xattrs/modes.  These are not the actual owners/groups/xattrs/modes on the disk -- but in a side database.  All processes still run as the original user, and thus the kernel rejects the ability to run these tools as the user does not have adequate permissions.

To use those components, you need to actually run 'sudo', or execute them with a user who has the permissions (capabilities) to run the required syscalls.

Resolving as invalid, pseudo is working as designed.  System security precludes the extensions you are requesting.
Comment 2 PRAKASH 2018-06-12 17:06:29 UTC
Thanks for your response.

I understood your comment states that,  System security precludes the extensions you are requesting.

But still we we just wanted know
Is there any plan in near future to support/extends the pseudo functionality to elevate permissions for these utilities??