I couldn't find this reported anywhere else so just adding this here for
future travelers:

This change breaks scripts which use the `#!/usr/bin/env bash` (or
similar) shebangs when building multi-arch containers. In multi-arch
container container builds, Docker makes use of binfmt extensions to run
non-native code through qemu. The change this ticket describes breaks
this because the running executable is a qemu binary.

```
#277 [linux/arm64 container 28/30] RUN <<'EOF' (#!/usr/bin/env bash...)
#277 8.845 Security violation: Requested utility `env` does not match 
executable name:
#277 8.845   /dev/pipes/EOF
#277 ERROR: process "/dev/.buildkit_qemu_emulator /bin/sh -c /dev/pipes/EOF" 
did not complete successfully: exit code: 1
```

In this case we have a RUN statement that looks like this:

```dockerfile
RUN <<'EOF'
#!/usr/bin/env bash

# Some bash script
EOF
```

That succeeds on the native architecture, but fails when multi-arch
Docker builds are run with the setup documented on
https://docs.docker.com/build/building/multi-platform/.

To work around this in our builds we replaced the rust-coreutils with
GNU core utils, which do not have this additional verification:

```
apt-get remove coreutils-from-uutils --allow-remove-essential --yes
```

To be clear I am not asking for this validation to be removed, but this
was the best search result when I was trying to debug this so I am
leaving my findings here for other people who find the same issue.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2137745

Title:
  Ubuntu patch prevents custom argv[0]

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/rust-coreutils/+bug/2137745/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to