On Pi desktop, numerous reports of lack of landlock supported ABI
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| linux-raspi (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
| Noble |
Fix Released
|
Undecided
|
Unassigned | ||
| Oracular |
Fix Released
|
Undecided
|
Unassigned | ||
| tracker-miners (Ubuntu) |
Invalid
|
Undecided
|
Pragyansh Chaturvedi | ||
Bug Description
[Impact]
On the Ubuntu noble desktop for Raspberry Pi, the system journal has numerous of the following entries:
May 23 10:30:29 kermit tracker-
May 23 10:30:29 kermit tracker-
These appear to be written every time a file in my home directory is modified. The kernel is the stock noble kernel from linux-raspi, 6.8.0-1004-raspi.
[Test Case]
Ubuntu desktop image with tracker-miner should produce any log entries like the ones above.
$ sudo dmesg | grep landl
[ 0.002208] LSM: initializing lsm=lockdown,
[ 0.002531] landlock: Up and running.
[Where Problems Could Occur]
Kernel issues (crashes, stack traces) at boot and/or when userspace invokes the LSM ABI.
CVE References
- 2024-42284
- 2024-42301
- 2024-44987
- 2024-44998
- 2024-46713
- 2024-46722
- 2024-46723
- 2024-46724
- 2024-46725
- 2024-46735
- 2024-46737
- 2024-46738
- 2024-46739
- 2024-46740
- 2024-46741
- 2024-46743
- 2024-46744
- 2024-46745
- 2024-46746
- 2024-46747
- 2024-46749
- 2024-46750
- 2024-46751
- 2024-46752
- 2024-46753
- 2024-46754
- 2024-46755
- 2024-46756
- 2024-46757
- 2024-46758
- 2024-46759
- 2024-46760
- 2024-46761
- 2024-46762
- 2024-46763
- 2024-46765
- 2024-46766
- 2024-46767
- 2024-46768
- 2024-46770
- 2024-46771
- 2024-46772
- 2024-46773
- 2024-46774
- 2024-46775
- 2024-46776
- 2024-46777
- 2024-46778
- 2024-46779
- 2024-46780
- 2024-46781
- 2024-46782
- 2024-46783
- 2024-46784
- 2024-46785
- 2024-46786
- 2024-46787
- 2024-46788
- 2024-46791
- 2024-46792
- 2024-46793
- 2024-46794
- 2024-46795
- 2024-46797
- 2024-46798
- 2024-46822
- 2024-46823
- 2024-46824
- 2024-46825
- 2024-46826
- 2024-46827
- 2024-46828
- 2024-46829
- 2024-46830
- 2024-46831
- 2024-46832
- 2024-46834
- 2024-46835
- 2024-46836
- 2024-46838
- 2024-46840
- 2024-46841
- 2024-46842
- 2024-46843
- 2024-46844
- 2024-46845
- 2024-46846
- 2024-46847
- 2024-46848
- 2024-47663
- 2024-47664
- 2024-47665
- 2024-47666
- 2024-47667
- 2024-47668
- 2024-47669
| tags: | added: kern-11631 |
| description: | updated |
| description: | updated |
| Changed in linux-raspi (Ubuntu): | |
| status: | New → Invalid |
| no longer affects: | tracker-miners (Ubuntu Noble) |
| no longer affects: | tracker-miners (Ubuntu Oracular) |
| Changed in tracker-miners (Ubuntu): | |
| status: | New → Invalid |
| Changed in linux-raspi (Ubuntu Noble): | |
| status: | New → Confirmed |
| Changed in linux-raspi (Ubuntu Oracular): | |
| status: | New → Confirmed |
| Changed in linux-raspi (Ubuntu): | |
| milestone: | none → ubuntu-25.04-beta |
| Changed in tracker-miners (Ubuntu): | |
| milestone: | none → ubuntu-25.04-beta |
| Changed in linux-raspi (Ubuntu Noble): | |
| status: | Confirmed → Fix Committed |
| Changed in linux-raspi (Ubuntu Oracular): | |
| status: | Confirmed → Fix Committed |
| tags: | added: kernel-daily-bug |

I checked https:/ /man7.org/ linux/man- pages/man2/ landlock_ create_ ruleset. 2.html /gitlab. gnome.org/ GNOME/localsear ch/-/blob/ master/ src/libtracker- miners- common/ tracker- landlock. c#L36, introduced in https:/ /gitlab. gnome.org/ GNOME/localsear ch/-/commit/ 38f0bed52b412a8 9ae6669a478805c 8f91af0ff9
The macro which fails is https:/
Running dmesg | grep landlock || journalctl -kb -g landlock, I get:
[ 42.661148] landlock: Disabled but requested by user space. You should enable Landlock at boot time: https:/ /docs.kernel. org/userspace- api/landlock. html#boot- time-configurat ion
The fix would be to enable the Landlock LSM during boot