Bug 14900 - Apparmor gives host contamination error with Dunfell 3.1.19 + Ubuntu 22.04
Summary: Apparmor gives host contamination error with Dunfell 3.1.19 + Ubuntu 22.04
Status: RESOLVED INVALID
Alias: None
Product: Pseudo
Classification: Yocto Project Subprojects
Component: pseudo (show other bugs)
Version: 3.1.19
Hardware: x86 Multiple
: Undecided normal
Target Milestone: ---
Assignee: Mark Hatle
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2022-08-19 07:43 UTC by Ernst Persson
Modified: 2022-08-25 14:42 UTC (History)
5 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ernst Persson 2022-08-19 07:43:14 UTC
With Dunfell as of today (3.1.19-ish), Ubuntu 22.04 and meta-security,
building the Apparmor recipe gives the following error:

ERROR: apparmor-2.13.6-r0 do_package: Error executing a python function in exec_func_python() autogenerated:
...
File: '/home/ernst/code/upstream/poky/meta/lib/oe/sstatesig.py', lineno: 553, function: process
     0549:                    add_perm(stat.S_IXOTH, 'x')
     0550:
     0551:                if include_owners:
     0552:                    try:
 *** 0553:                        update_hash(" %10s" % pwd.getpwuid(s.st_uid).pw_name)
     0554:                        update_hash(" %10s" % grp.getgrgid(s.st_gid).gr_name)
     0555:                    except KeyError as e:
     0556:                        bb.warn("KeyError in %s" % path)
     0557:                        msg = ("KeyError: %s\nPath %s is owned by uid %d, gid %d, which doesn't match "
Exception: Exception: KeyError: 'getpwuid(): uid not found: 1000'
Path ./package/etc/apparmor.d is owned by uid 1000, gid 1000, which doesn't match any user/group on target. This may be due to host contamination.

This doesn't happen on older Ubuntu LTS's!

From what I can tell etc/apparmor.d is created with a normal install -d command in apparmor profiles/Makefile .

Is there a libc system call that pseudo fails to intercept with Ubuntu 22.04?

To reproduce it's just setting up meta-security and meta-oe, everything dunfell, DISTRO_FEATURES:append = " apparmor",
and then bitbake apparmor.

With Yocto from master this doesn't happen but it has a newer version of Apparmor so it's hard to pinpoint the difference...
Comment 1 Ernst Persson 2022-08-19 08:22:29 UTC
Interesting, the exact same thing happens on Kirkstone with apparmor-3.0.4-r0 actually!
Comment 2 Ernst Persson 2022-08-19 08:46:51 UTC
Ah, just found this workaround: https://git.yoctoproject.org/meta-security/commit/?id=b67b4cf5cafa5fb0c13dddc344ed286e7e6fcc72

But why is it needed?! :-)

Armin, backport to dunfell and kirkstone in the meantime?
Comment 3 Randy MacLeod 2022-08-25 14:42:19 UTC
Appears to be a meta-security bug. Please discuss with that community 
https://git.yoctoproject.org/meta-security/tree/README

Looks like a broken Makefile but we're guessing (RP's guess.) -- YP Bug review