Bug 16320

Summary: Warnings in log about pam_lastlogs2.so and undefined symbol pam_syslog
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Pauli Heikkinen <pauli.a.t.heikkinen>
Component: coreAssignee: New Comer Bugs <newcomer>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium CC: ccasciato, meta.mr.watcher, meta.watcher, paul, pauli.a.t.heikkinen, randy.macleod, sivakumar.bs, yoann.congal
Version: 6.0   
Target Milestone: 6.1   
Hardware: x86   
OS: Multiple   
Whiteboard: NEWCOMER
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Don't know

Description Pauli Heikkinen 2026-06-17 10:45:30 UTC
I'm testing a Yocto 6.0 based x64 build that uses journald for logging; syslog is not used at all. It also uses lastlog2 from util-linux 2.41.3.

I'm seeing warnings like this in logs:

(weston)[693]: PAM unable to dlopen(/usr/lib/security/pam_lastlog2.so): /usr/lib/security/pam_lastlog2.so: undefined symbol: pam_syslog
(weston)[693]: PAM adding faulty module: /usr/lib/security/pam_lastlog2.so

This doesn't look right.

I took a quick look at the util-linux recipe and it doesn't look like it cares if syslog is used or not. I guess that's the root cause?
Comment 1 Pauli Heikkinen 2026-06-21 14:02:08 UTC
I guess the fix is here:

https://github.com/util-linux/util-linux/pull/4358

So nothing to do with building with syslog or no syslog actually.

This is pretty awful to have around, consider fix in 6.0.x too?
Comment 2 Pauli Heikkinen 2026-06-21 15:48:30 UTC
Fix is in 2.41.5:

https://www.kernel.org/pub/linux/utils/util-linux/v2.41/v2.41.5-ChangeLog

(I intend to verify that the linked patch fixes this, so far only strongly assuming based on smell and symptoms...)
Comment 3 Randy MacLeod 2026-06-21 16:40:57 UTC
Most of the changes are fine for a stable release:

util-linux.git on master
❯ gl v2.41.3..v2.41.5
230de59ff   2026-06-16   (tag: v2.41.5) build-sys: update release dates
63a366b31   2026-06-16   docs: update v2.41.5-ReleaseNotes
a9508d216   2026-05-27   libmount: add mount ID verification and man page TOCTOU note
4ca5d5c50   2026-05-27   libmount: use fd_target in hook_idmap for move_mount()
8b6454b84   2026-05-27   libmount: restrict X-mount.subdir for non-root
897a08c2b   2026-06-16   libmount: use fd-based fchownat/chmod in hook_owner
99bad5729   2026-05-27   libmount: ignore X-mount.nocanonicalize for restricted users
0b010025a   2026-06-16   libmount: add fd_target to context for TOCTOU prevention
b639bf5c4   2026-05-27   lib/fileutils: add ul_open_no_symlinks()
cc81bbcec   2026-06-16   libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path
132d9c8aa   2026-05-07   libblkid: fix use-after-free in nested partition probing
b8625310b   2026-06-09   libmount: fix subvolid buffer overflow in get_btrfs_fs_root
cc6cc7b0c   2026-02-18   pg: Fix compiler warning
3711d0ad8   2026-05-07   CI: replace ntp with ntpsec
1e4b0ec69   2026-03-30   liblastlog2: wait on busy SQLite connections
c8d0af042   2026-05-19   pam_lastlog2: fix libpam linking in autotools build
e147e16fa   2026-04-01   (tag: v2.41.4) build-sys: update release dates
153ab7556   2026-04-01   docs: update v2.41.4-ReleaseNotes
0bd8541bc   2026-04-01   tools: update git-version-next from master
75a23a2de   2026-03-25   libfdisk: dos: validate EBR link within extended partition bounds
05c2dbadf   2026-03-25   libblkid: dos: validate EBR data and links within extended partition
f55f9906b   2026-02-19   loopdev: add LOOPDEV_FL_NOFOLLOW to prevent symlink attacks
9ec69c31c   2026-01-24   Fix: Typo in disk-utils/fdisk.c
479133958   2025-11-26   blkid: Drop const from blkid_partitions_get_name()
718e4a76d   2026-01-06   build-sys: (gcc) ignore -Wunused-but-set-variable for bison
4c22d17cc   2025-05-01   bits: only build when cpu_set_t is available

but you might have to look at an explain the "add" commits
to the stable maintainer.

❯ gl v2.41.3..v2.41.5 | rg -i add
a9508d216   2026-05-27   libmount: add mount ID verification and man page TOCTOU note
0b010025a   2026-06-16   libmount: add fd_target to context for TOCTOU prevention
b639bf5c4   2026-05-27   lib/fileutils: add ul_open_no_symlinks()
f55f9906b   2026-02-19   loopdev: add LOOPDEV_FL_NOFOLLOW to prevent symlink attacks

Let us know how your testing goes and if you plan to send a util-linux upgrade
Comment 4 Pauli Heikkinen 2026-06-22 07:11:39 UTC
I just tested the patch and it works.

I have no immediate plans to submit updated recipe (commercial customer project so they're happy the minute the problem is solved for _them_ ). However here are some notes regarding the patch I linked to:

- The patch contained changes on two lines, removing an option from another line and adding it on another. However, the removed text is not yet there in 2.41.3 so actually only one line needs changing.
- If patching instead of updating all of util-linux, don't forget to add upstream status:

Upstream-Status: Backport [2.41.5]
Comment 5 Randy MacLeod 2026-06-23 00:52:14 UTC
Pauli, Thanks for the bug report and explainations.
It's a shame that your customer won't pay to have you send the patch
but we'll see if we can find someone to pick up where you left off.
Comment 6 Siva Balasubramanian 2026-06-25 11:35:12 UTC
I've picked this up and sent a patch to the openembedded-core list backporting
the upstream fix:

util-linux: backport pam_lastlog2 libpam linking fix

https://lists.openembedded.org/g/openembedded-core/topic/patch_v1_util_linux/119970715

Details:

- Backports upstream commit c8d0af0421f6491ab1cb2301d2e197315289d34c
  ("pam_lastlog2: fix libpam linking in autotools build", released in
  util-linux 2.41.5; master commit 5683ed6320e0, PR #4358).

- As Pauli noted in comment 4, only one line changes against 2.41.3:
  the upstream commit also drops -lpam from LDFLAGS, but that LDFLAGS
  reference was added after 2.41.3 and isn't present in our source, so
  the net backport is the single LIBADD hunk
  (pam_lastlog2_la_LIBADD = liblastlog2.la -lpam). Carrying the LDFLAGS
  hunk would just fail to apply.

- Upstream-Status: Backport [.../commit/c8d0af04...] is set on the patch.

Tested: built util-linux with pam in DISTRO_FEATURES (qemux86-64). Before
the patch the resulting pam_lastlog2.so has no libpam entry; after the
patch "readelf -d" shows libpam.so.0 in NEEDED, which resolves the
dlopen() "undefined symbol: pam_syslog" failure from the report.

This is also a candidate for the 6.0.x stable branch (same util-linux
2.41.3, same single-hunk backport), as suggested in comments 1-2.
Comment 7 Siva Balasubramanian 2026-06-25 15:05:03 UTC
Update: the master patch isn't needed there - master already has a
pending upgrade to util-linux 2.42.2 which includes this fix natively
(per Mathieu Dubois-Briand).

Resent targeting the wrynose (6.0 LTS) branch instead, which is still
on 2.41.3:

https://patchwork.yoctoproject.org/project/oe-core/patch/20260625150015.2832246-1-sivakumar.bs@gmail.com/

Same single-line fix and verification as before (readelf -d / dlopen
test), just retargeted.
Comment 8 Paul Barker 2026-08-20 15:33:14 UTC
The update to util-linux 2.41.5 has landed in wrynose:

https://git.openembedded.org/openembedded-core/commit/?h=wrynose&id=e561916058483df7fabcbe929882e2ae2c79479b