test-seccomp fails test_restrict_suid_sgid on arm64 on Bionic
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
| systemd (Ubuntu) |
Undecided
|
Unassigned | ||
| Bionic |
Medium
|
Dan Streetman |
Bug Description
[impact]
RestrictSUIDSGID (backported to Bionic in security CVE) fails 100% of the time on arm64, and testcase failure indicates this as well.
[test case]
check autopkgtest logs, e.g.
https:/
/* test_restrict_
Failed to add suid/sgid rule for architecture arm64, skipping: Numerical argument out of domain
Assertion 'chmod(path, 0775 | S_ISUID) < 0 && errno == EPERM' failed at ../src/
suidsgidseccomp terminated by signal ABRT.
Assertion 'wait_for_
FAIL: test-seccomp (code: 134)
Aborted (core dumped)
[regression potential]
this improves the function that (tries to) install seccomp suid/sgid filters, so and regression would involve failure to restrict suid/sgid with seccomp filters; however on arm64, the this functionality already fails 100% of the time (which is what the failed test case was pointing out).
[scope]
this fails only in Bionic, and this specific feature and testcase was backported in patches for CVE-2019-384x. It does not appear that the backported feature, or its testcase, ever passed in Bionic on arm64.
[other info]
systemd bionic arm64 autopkgtests have failed forever, but we should fix that.
Changed in systemd (Ubuntu): | |
status: | New → Fix Released |
Changed in systemd (Ubuntu Bionic): | |
assignee: | nobody → Dan Streetman (ddstreet) |
importance: | Undecided → Low |
status: | New → In Progress |
description: | updated |
description: | updated |
Changed in systemd (Ubuntu Bionic): | |
importance: | Low → Medium |
Changed in systemd (Ubuntu Bionic): | |
status: | In Progress → Fix Committed |
tags: | added: verification-needed verification-needed-bionic |
All autopkgtests for the newly accepted systemd (237-3ubuntu10.40) for bionic have finished running.
The following regressions have been reported in tests triggered by the package:
gvfs/1.
prometheus-
systemd/
umockdev/0.11.1-1 (armhf)
linux-hwe-
kde4libs/
util-linux/unknown (armhf)
nftables/unknown (armhf)
linux-raspi2-
netplan.
openssh/
Please visit the excuses page listed below and investigate the failures, proceeding afterwards as per the StableReleaseUp
https:/
[1] https:/
Thank you!
Dan Streetman (ddstreet) wrote : | #3 |
tags: |
added: verification-done verification-done-bionic removed: verification-needed verification-needed-bionic |
Launchpad Janitor (janitor) wrote : | #4 |
This bug was fixed in the package systemd - 237-3ubuntu10.40
---------------
systemd (237-3ubuntu10.40) bionic; urgency=medium
* d/t/logind: skip if nonexistent /sys/power/state (LP: #1862657)
* d/p/lp1839290-
- when restarting service after failure, replace existing queued jobs
(LP: #1839290)
* d/p/lp1867421-
- fix resolution of IntelliMouse (LP: #1867421)
* d/p/lp1858412-
- allow vacuuming journal 'root' dir (LP: #1858412)
* d/p/lp1862232/
d/p/
d/p/
d/p/
d/p/
d/p/
d/p/
- do not fail network setup if hostname is not valid (LP: #1862232)
* d/t/systemd-fsckd: Skip test on arm64 (LP: #1870194)
* d/p/lp1870589-
- fix test-seccomp failure (LP: #1870589)
* d/rules: use meson --print-errorlogs instead of cat testlog
- (LP: #1870811)
* d/p/lp1776654-
- sync journal before reading from it (LP: #1776654)
* d/p/lp1837914-
- do not crash if NULL passted to journal destructor (LP: #1837914)
* d/e/initramfs-
- Follow symlinks when finding link files to copy into initramfs
(LP: #1868892)
-- Dan Streetman <email address hidden> Mon, 20 Apr 2020 10:12:49 -0400
Changed in systemd (Ubuntu Bionic): | |
status: | Fix Committed → Fix Released |
The verification of the Stable Release Update for systemd has completed successfully and the package is now being released to -updates. Subsequently, the Ubuntu Stable Release Updates Team is being unsubscribed and will not receive messages about this bug report. In the event that you encounter a regression using the package from -updates please report a new bug using ubuntu-bug and tag the bug report regression-update so we can easily find any regressions.
Hello Dan, or anyone else affected,
Accepted systemd into bionic-proposed. The package will build now and be available at https:/ /launchpad. net/ubuntu/ +source/ systemd/ 237-3ubuntu10. 40 in a few hours, and then in the -proposed repository.
Please help us by testing this new package. See https:/ /wiki.ubuntu. com/Testing/ EnableProposed for documentation on how to enable and use -proposed. Your feedback will aid us getting this update out to other Ubuntu users.
If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested, what testing has been performed on the package and change the tag from verification- needed- bionic to verification- done-bionic. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification- failed- bionic. In either case, without details of your testing we will not be able to proceed.
Further information regarding the verification process can be found at https:/ /wiki.ubuntu. com/QATeam/ PerformingSRUVe rification . Thank you in advance for helping!
N.B. The updated package will be released to -updates after the bug(s) fixed by this package have been verified and the package has been in -proposed for a minimum of 7 days.