Bug 14848 - regression: sudo command in recipe not working anymore in kirkstone
Summary: regression: sudo command in recipe not working anymore in kirkstone
Status: RESOLVED WONTFIX
Alias: None
Product: BitBake
Classification: Build System, Metadata & Runtime
Component: bitbake (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Undecided major
Target Milestone: ---
Assignee: Richard Purdie
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2022-06-28 19:48 UTC by Marc Haesen
Modified: 2022-06-30 16:16 UTC (History)
3 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marc Haesen 2022-06-28 19:48:02 UTC
I have a recipe calling sudo which is working in yocto honister. When switched to kirkstone, the recipe gives errors executing the sudo command inside a task.
After some debugging, I found it is caused by the addition of calling the disable_network (bitbake/lib/bb/utils.py) function.

Applying the following patch solves the problem:

diff --git a/bitbake/lib/bb/utils.py b/bitbake/lib/bb/utils.py
index d11da978d7..7410e040bb 100644
--- a/bitbake/lib/bb/utils.py
+++ b/bitbake/lib/bb/utils.py
@@ -1608,8 +1608,6 @@ def disable_network(uid=None, gid=None):
     libc = ctypes.CDLL('libc.so.6')

     # From sched.h
-    # New user namespace
-    CLONE_NEWUSER = 0x10000000
     # New network namespace
     CLONE_NEWNET = 0x40000000

@@ -1618,7 +1616,7 @@ def disable_network(uid=None, gid=None):
     if gid is None:
         gid = os.getgid()

-    ret = libc.unshare(CLONE_NEWNET | CLONE_NEWUSER)
+    ret = libc.unshare(CLONE_NEWNET)
     if ret != 0:
         logger.debug("System doesn't suport disabling network without admin privs")
         return
Comment 1 Richard Purdie 2022-06-30 14:36:41 UTC
Firstly, using sudo in a recipe is horrible. I'd suggest you just disable the network isolation if you really want/have to do this with:

do_mytask[network] = "1"

See the migration notes for kirkstone for info on that:

https://docs.yoctoproject.org/migration-guides/migration-4.0.html#fetching-ch

From memory we need the namespace piece to have this work with normal user privileges so we can't/won't change this as mentioned.
Comment 2 Marc Haesen 2022-06-30 16:16:32 UTC
I agree that sudo should not be used in a recipe, but I am creating an encrypted disc-image with cryptsetup using a loop device. For this you need sudo rights.
If you known another way of creating an encrypted disc image without the need of root rights, I would be very glad.

But the workaround with do_mytask[network] = "1" works for me to.

Thanks anyhow.