Structured the bug description with the canonical SRU template.

The debdiff for stonking (systemd 261.2-1ubuntu3) is attached to the bug
and ready for review: it gracefully handles EPERM privilege errors on
character/block device nodes in systemd-tmpfiles and marks static-nodes-
permissions.conf entries as z- so sbuild unshare environments complete
udev setup without failing.

** Description changed:

+ [ Impact ]
+ 
+ When running sbuild with the unshare backend (e.g. sbuild --run-
+ autopkgtest with /dev/kvm bind-mounted) or inside unprivileged user
+ namespaces and containers with bind-mounted device nodes, package
+ installation fails during udev configuration:
+ 
+   Setting up udev (261~rc4-1) ...
+   Creating group 'input' with GID 995.
+   Creating group 'sgx' with GID 994.
+   Creating group 'clock' with GID 993.
+   Creating group 'kvm' with GID 992.
+   Creating group 'render' with GID 991.
+   fchownat() of /dev/kvm failed: Operation not permitted
+   dpkg: error processing package udev (--configure):
+    installed udev package postinst maintainer script subprocess failed with 
exit status 73
+ 
+ Exit status 73 corresponds to EX_CANTCREAT from <sysexits.h>. This
+ failure completely breaks package building in sbuild unshare
+ environments.
+ 
+ The issue was unmasked by debhelper 14 (dh_installtmpfiles), which removed 
the trailing '|| true' fallback from the generated udev.postinst snippet:
+   systemd-tmpfiles ${DPKG_ROOT:+--root="$DPKG_ROOT"} --create 
static-nodes-permissions.conf
+ 
+ In unprivileged user namespaces, device nodes bind-mounted from the host
+ are owned by IDs outside the namespace mapping or lack write privileges
+ to inode metadata in the underlying VFS, causing fchownat() and fchmod()
+ to return EPERM. Previously, systemd-tmpfiles had always returned exit
+ code 73 on these nodes, but '|| true' masked the failure. With the
+ fallback removed, udev configuration aborts.
+ 
+ [ Fix ]
+ 
+ 1. In src/tmpfiles/tmpfiles.c (fd_set_perms):
+    When fchmod_opath() or fchownat() returns a privilege error 
(ERRNO_IS_PRIVILEGE) on a character or block device node (S_ISCHR / S_ISBLK), 
log the failure at debug level and do not abort. Additionally, respect 
i->allow_failure (the '-' prefix in tmpfiles.d).
+ 
+ 2. In debian/extra/static-nodes-permissions.conf:
+    Mark static device node entries with the 'z-' action prefix instead of 
'z', explicitly allowing systemd-tmpfiles to tolerate permission setting 
failures if running in restricted or unprivileged environments.
+ 
+ [ Test Plan ]
+ 
+ 1. Reproduction:
+    - Configure sbuild with unshare backend and /dev/kvm bind mount:
+      $autopkgtest_opts = ['--', 'unshare', '--release', '%r', '--arch', '%a', 
'-b', '/dev/kvm', '/dev/kvm'];
+    - Trigger a build or install udev within the unshare environment.
+    - Without fix: udev.postinst fails on fchownat() of /dev/kvm with exit 
code 73.
+ 2. Verification:
+    - Build systemd source package with systemd_261.2-1ubuntu3.debdiff and 
install udev in the test container.
+    - Run sbuild --run-autopkgtest with unshare and /dev/kvm bind mount.
+    - udev.postinst completes with exit code 0, unprivileged device nodes are 
gracefully skipped, and package configuration succeeds.
+    - On a standard host with full root privileges, verify that static device 
node ownership (root:kvm, root:render) continues to be applied correctly.
+ 
+ [ Where problems could occur ]
+ 
+ The change is scoped to systemd-tmpfiles device node permission handling
+ and Debian/Ubuntu static-nodes-permissions.conf.
+ 
+ Privilege errors (EPERM, EACCES) are only tolerated on character/block
+ device nodes or when lines are explicitly prefixed with 'z-'. Regular
+ files and directories will continue to fail loudly if ownership cannot
+ be established.
+ 
+ On privileged systems, systemd-tmpfiles will continue to set ownership
+ normally. Regression risk is very low.
+ 
+ [ Other Info ]
+ 
+ - Debian counterpart: Debian Bug #1140336 (reported by Benjamin Drung).
+ - Target series: Ubuntu 26.10 (stonking development series).
+ - Package: systemd (261.2-1ubuntu3).
+ - Debdiff: Attached to bug as systemd_261.2-1ubuntu3.debdiff (type: patch). 
Closes LP: #2160036 and Debian: #1140336.
+ 
+ --- [ Original Report ]
  Imported from Debian bug http://bugs.debian.org/1140336:
+ 
+ Package: udev
+ Version: 261~rc4-1
+ Severity: normal
+ X-Debbugs-Cc: <email address hidden>
+ 
+ Dear Maintainer,
  
  I am using sbuild with the unshare backend and this config for
  autopkgtest:
  
  $autopkgtest_opts = ['--', 'unshare', '--release', '%r', '--arch', '%a',
  '-b', '/dev/kvm', '/dev/kvm'];
  
  Running sbuild --run-autopkgtest on the dracut source code started to
  fail during package installation:
  
  Setting up udev (261~rc4-1) ...
  Creating group 'input' with GID 995.
  Creating group 'sgx' with GID 994.
  Creating group 'clock' with GID 993.
  Creating group 'kvm' with GID 992.
  Creating group 'render' with GID 991.
  fchownat() of /dev/kvm failed: Operation not permitted
  dpkg: error processing package udev (--configure):
-  old udev package postinst maintainer script subprocess failed with exit 
status 73
- 
- Affected package: systemd 261.1-2ubuntu1
+  installed udev package postinst maintainer script subprocess failed with 
exit status 73

** Tags added: autopkgtest sbuild stonking tmpfiles udev unshare

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160036

Title:
  udev: fchownat() of /dev/kvm failed: Operation not permitted

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/2160036/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to