Bug 14848

Summary: regression: sudo command in recipe not working anymore in kirkstone
Product: [Build System, Metadata & Runtime] BitBake Reporter: Marc Haesen <marc.haesen>
Component: bitbakeAssignee: Richard Purdie <richard.purdie>
Status: RESOLVED WONTFIX QA Contact:
Severity: major    
Priority: Undecided CC: marc.haesen, poky.bs.watcher, poky.watcher
Version: unspecified   
Target Milestone: ---   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Marc Haesen 2022-06-28 19:48:02 UTC
I have a recipe calling sudo which is working in yocto honister. When switched to kirkstone, the recipe gives errors executing the sudo command inside a task.
After some debugging, I found it is caused by the addition of calling the disable_network (bitbake/lib/bb/utils.py) function.

Applying the following patch solves the problem:

diff --git a/bitbake/lib/bb/utils.py b/bitbake/lib/bb/utils.py
index d11da978d7..7410e040bb 100644
--- a/bitbake/lib/bb/utils.py
+++ b/bitbake/lib/bb/utils.py
@@ -1608,8 +1608,6 @@ def disable_network(uid=None, gid=None):
     libc = ctypes.CDLL('libc.so.6')

     # From sched.h
-    # New user namespace
-    CLONE_NEWUSER = 0x10000000
     # New network namespace
     CLONE_NEWNET = 0x40000000

@@ -1618,7 +1616,7 @@ def disable_network(uid=None, gid=None):
     if gid is None:
         gid = os.getgid()

-    ret = libc.unshare(CLONE_NEWNET | CLONE_NEWUSER)
+    ret = libc.unshare(CLONE_NEWNET)
     if ret != 0:
         logger.debug("System doesn't suport disabling network without admin privs")
         return
Comment 1 Richard Purdie 2022-06-30 14:36:41 UTC
Firstly, using sudo in a recipe is horrible. I'd suggest you just disable the network isolation if you really want/have to do this with:

do_mytask[network] = "1"

See the migration notes for kirkstone for info on that:

https://docs.yoctoproject.org/migration-guides/migration-4.0.html#fetching-ch

From memory we need the namespace piece to have this work with normal user privileges so we can't/won't change this as mentioned.
Comment 2 Marc Haesen 2022-06-30 16:16:32 UTC
I agree that sudo should not be used in a recipe, but I am creating an encrypted disc-image with cryptsetup using a loop device. For this you need sudo rights.
If you known another way of creating an encrypted disc image without the need of root rights, I would be very glad.

But the workaround with do_mytask[network] = "1" works for me to.

Thanks anyhow.