| Summary: | base-files do_package fatal error in subprocess | ||||||
|---|---|---|---|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] Meta-yocto | Reporter: | Christopher <jordan.denny5> | ||||
| Component: | meta-yocto | Assignee: | Christopher <jordan.denny5> | ||||
| Status: | RESOLVED WORKSFORME | QA Contact: | |||||
| Severity: | normal | ||||||
| Priority: | Medium+ | CC: | otavio, poky.bs.watcher, poky.watcher, randy.macleod | ||||
| Version: | 3.4 | ||||||
| Target Milestone: | 3.4 M4 | ||||||
| Hardware: | x86 | ||||||
| OS: | Multiple | ||||||
| Whiteboard: | |||||||
| OS type for building Yocto: | --- | Type of Regression: | --- | ||||
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |||||
| Attachments: |
|
||||||
|
Description
Christopher
2020-02-02 18:11:21 UTC
A proper fix would detect this problem then use a wrapper script but only if seccomp is present. Hey Randy, So I am not an expert by any means on seccomp, but it seems that detecting that the file program is compiled with this feature is difficult. I could read the audit log to determine that SIGSYS was indeed produced by an un-allowed system call like seen below [ 3613.158929] audit: type=1326 audit(1581812421.392:103): auid=1000 uid=1000 gid=1000 ses=2 subj==unconfined pid=6379 comm="file" exe="/usr/bin/file" sig=31 arch=c000003e syscall=39 compat=0 ip=0x7ff59f04a76b code=0x0 Through my research, it seems that I could check /proc/PID/status for the Seccomp flag, but this also doesn't seem viable. The file command also states for the "-S" option that "On systems where sandboxing is not available, this option has no effect" It seems like we can safely use this option. Christopher/Jordan, We think this is fixed for most users. What is you host system? Let us know if there's still a problem. |