| Summary: | Apparmor gives host contamination error with Dunfell 3.1.19 + Ubuntu 22.04 | ||
|---|---|---|---|
| Product: | [Yocto Project Subprojects] Pseudo | Reporter: | Ernst Persson <ernstp> |
| Component: | pseudo | Assignee: | Mark Hatle <mark.hatle> |
| Status: | RESOLVED INVALID | QA Contact: | |
| Severity: | normal | ||
| Priority: | Undecided | CC: | akuster, randy.macleod, steve, yp.pseudo.watcher, yp.watcher |
| Version: | 3.1.19 | ||
| Target Milestone: | --- | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
Interesting, the exact same thing happens on Kirkstone with apparmor-3.0.4-r0 actually! Ah, just found this workaround: https://git.yoctoproject.org/meta-security/commit/?id=b67b4cf5cafa5fb0c13dddc344ed286e7e6fcc72 But why is it needed?! :-) Armin, backport to dunfell and kirkstone in the meantime? Appears to be a meta-security bug. Please discuss with that community https://git.yoctoproject.org/meta-security/tree/README Looks like a broken Makefile but we're guessing (RP's guess.) -- YP Bug review |
With Dunfell as of today (3.1.19-ish), Ubuntu 22.04 and meta-security, building the Apparmor recipe gives the following error: ERROR: apparmor-2.13.6-r0 do_package: Error executing a python function in exec_func_python() autogenerated: ... File: '/home/ernst/code/upstream/poky/meta/lib/oe/sstatesig.py', lineno: 553, function: process 0549: add_perm(stat.S_IXOTH, 'x') 0550: 0551: if include_owners: 0552: try: *** 0553: update_hash(" %10s" % pwd.getpwuid(s.st_uid).pw_name) 0554: update_hash(" %10s" % grp.getgrgid(s.st_gid).gr_name) 0555: except KeyError as e: 0556: bb.warn("KeyError in %s" % path) 0557: msg = ("KeyError: %s\nPath %s is owned by uid %d, gid %d, which doesn't match " Exception: Exception: KeyError: 'getpwuid(): uid not found: 1000' Path ./package/etc/apparmor.d is owned by uid 1000, gid 1000, which doesn't match any user/group on target. This may be due to host contamination. This doesn't happen on older Ubuntu LTS's! From what I can tell etc/apparmor.d is created with a normal install -d command in apparmor profiles/Makefile . Is there a libc system call that pseudo fails to intercept with Ubuntu 22.04? To reproduce it's just setting up meta-security and meta-oe, everything dunfell, DISTRO_FEATURES:append = " apparmor", and then bitbake apparmor. With Yocto from master this doesn't happen but it has a newer version of Apparmor so it's hard to pinpoint the difference...