Rebased the debdiff onto current stonking archive version 261.3-0ubuntu3
(published on 2026-10-04).

Target version: systemd 261.3-0ubuntu4 for stonking.

Changes:
- fd_set_perms: treat ERRNO_IS_PRIVILEGE on character/block device nodes as 
non-fatal debug, preventing exit status 73 in unprivileged namespaces.
- static-nodes-permissions.conf.in: change action prefix from 'z' to 'z-' to 
tolerate permission errors on static device nodes.
- Forwarded patch to Debian BTS #1140336.
- Closes LP: #2160036 and Debian: #1140336.


** Description changed:

- [ Impact ]
+ In unprivileged user namespaces (e.g. sbuild with unshare backend,
+ rootless containers, Apptainer), static device nodes bind-mounted from
+ the host (/dev/kvm, /dev/fuse, etc.) are owned by IDs outside the
+ namespace mapping or lack write permissions to inode metadata in the
+ underlying VFS. As a result, fchownat() and fchmod() return EPERM (exit
+ code 73).
  
- When running sbuild with the unshare backend (e.g. sbuild --run-
- autopkgtest with /dev/kvm bind-mounted) or inside unprivileged user
- namespaces and containers with bind-mounted device nodes, package
- installation fails during udev configuration:
+ Previously, systemd-tmpfiles failures were masked by a trailing '|| true' 
fallback in the maintainer script. Starting with debhelper 14 
(dh_installtmpfiles), the fallback was dropped from udev.postinst:
+   systemd-tmpfiles ${DPKG_ROOT:+--root="$DPKG_ROOT"} --create 
static-nodes-permissions.conf
+ With the fallback gone, udev configuration aborts with exit code 73 during 
sbuild or container builds.
  
-   Setting up udev (261~rc4-1) ...
-   Creating group 'input' with GID 995.
-   Creating group 'sgx' with GID 994.
-   Creating group 'clock' with GID 993.
-   Creating group 'kvm' with GID 992.
-   Creating group 'render' with GID 991.
-   fchownat() of /dev/kvm failed: Operation not permitted
-   dpkg: error processing package udev (--configure):
-    installed udev package postinst maintainer script subprocess failed with 
exit status 73
+ Root Cause:
+ fd_set_perms() in src/tmpfiles/tmpfiles.c treats any failure from fchownat() 
or fchmod_opath() as fatal and returns EX_CANTCREAT (73), failing to 
distinguish privilege errors on device nodes from file creation errors. 
Additionally, static-nodes-permissions.conf uses the 'z' prefix without 
tolerating unprivileged execution.
  
- Exit status 73 corresponds to EX_CANTCREAT from <sysexits.h>. This
- failure completely breaks package building in sbuild unshare
- environments.
+ Fix:
+ 1. In src/tmpfiles/tmpfiles.c (fd_set_perms):
+    Treat privilege errors (ERRNO_IS_PRIVILEGE: EPERM, EACCES) on character 
and block devices (S_ISCHR, S_ISBLK) as non-fatal, logging them at debug level. 
Additionally, respect Item.allow_failure if set.
+ 2. In tmpfiles.d/static-nodes-permissions.conf.in:
+    Mark static device node entries with the 'z-' action prefix instead of 
'z', explicitly allowing systemd-tmpfiles to tolerate permission setting 
failures in unprivileged environments.
  
- The issue was unmasked by debhelper 14 (dh_installtmpfiles), which removed 
the trailing '|| true' fallback from the generated udev.postinst snippet:
-   systemd-tmpfiles ${DPKG_ROOT:+--root="$DPKG_ROOT"} --create 
static-nodes-permissions.conf
- 
- In unprivileged user namespaces, device nodes bind-mounted from the host
- are owned by IDs outside the namespace mapping or lack write privileges
- to inode metadata in the underlying VFS, causing fchownat() and fchmod()
- to return EPERM. Previously, systemd-tmpfiles had always returned exit
- code 73 on these nodes, but '|| true' masked the failure. With the
- fallback removed, udev configuration aborts.
- 
- [ Fix ]
- 
- 1. In src/tmpfiles/tmpfiles.c (fd_set_perms):
-    When fchmod_opath() or fchownat() returns a privilege error 
(ERRNO_IS_PRIVILEGE) on a character or block device node (S_ISCHR / S_ISBLK), 
log the failure at debug level and do not abort. Additionally, respect 
i->allow_failure (the '-' prefix in tmpfiles.d).
- 
- 2. In debian/extra/static-nodes-permissions.conf:
-    Mark static device node entries with the 'z-' action prefix instead of 
'z', explicitly allowing systemd-tmpfiles to tolerate permission setting 
failures if running in restricted or unprivileged environments.
- 
- [ Test Plan ]
- 
- 1. Reproduction:
-    - Configure sbuild with unshare backend and /dev/kvm bind mount:
-      $autopkgtest_opts = ['--', 'unshare', '--release', '%r', '--arch', '%a', 
'-b', '/dev/kvm', '/dev/kvm'];
-    - Trigger a build or install udev within the unshare environment.
-    - Without fix: udev.postinst fails on fchownat() of /dev/kvm with exit 
code 73.
- 2. Verification:
-    - Build systemd source package with systemd_261.3-0ubuntu3.debdiff and 
install udev in the test container.
-    - Run sbuild --run-autopkgtest with unshare and /dev/kvm bind mount.
-    - udev.postinst completes with exit code 0, unprivileged device nodes are 
gracefully skipped, and package configuration succeeds.
-    - On a standard host with full root privileges, verify that static device 
node ownership (root:kvm, root:render) continues to be applied correctly.
- 
- [ Where problems could occur ]
- 
- The change is scoped to systemd-tmpfiles device node permission handling
- and Debian/Ubuntu static-nodes-permissions.conf.
- 
- Privilege errors (EPERM, EACCES) are only tolerated on character/block
- device nodes or when lines are explicitly prefixed with 'z-'. Regular
- files and directories will continue to fail loudly if ownership cannot
- be established.
- 
- On privileged systems, systemd-tmpfiles will continue to set ownership
- normally. Regression risk is very low.
- 
- [ Other Info ]
- 
- - Debian counterpart: Debian Bug #1140336 (reported by Benjamin Drung).
- - Target series: Ubuntu 26.10 (stonking development series).
- - Package: systemd (261.3-0ubuntu3).
- - Debdiff: Attached to bug as systemd_261.3-0ubuntu3.debdiff (type: patch). 
Closes LP: #2160036 and Debian: #1140336.
- - Rebase: Rebased on top of systemd 261.3-0ubuntu2 from stonking-proposed.
+ Upstream & Debian Status:
+ - Debian BTS: #1140336 
(https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140336)
+ - Target: Ubuntu 26.10 (stonking development series)
+ - Proposed Package: systemd 261.3-0ubuntu4
  
  --- [ Original Report ]
  Imported from Debian bug http://bugs.debian.org/1140336:
  
  Package: udev
  Version: 261~rc4-1
  Severity: normal
- X-Debbugs-Cc: <email address hidden>
+ X-Debbugs-Cc: [email protected]
  
  Dear Maintainer,
  
  I am using sbuild with the unshare backend and this config for
  autopkgtest:
  
  $autopkgtest_opts = ['--', 'unshare', '--release', '%r', '--arch', '%a',
  '-b', '/dev/kvm', '/dev/kvm'];
  
  Running sbuild --run-autopkgtest on the dracut source code started to
  fail during package installation:
  
  Setting up udev (261~rc4-1) ...
  Creating group 'input' with GID 995.
  Creating group 'sgx' with GID 994.
  Creating group 'clock' with GID 993.
  Creating group 'kvm' with GID 992.
  Creating group 'render' with GID 991.
  fchownat() of /dev/kvm failed: Operation not permitted
  dpkg: error processing package udev (--configure):
   old udev package postinst maintainer script subprocess failed with exit 
status 73
+ 
+ -- 
+ Benjamin Drung
+ Debian & Ubuntu Developer

** Changed in: systemd (Ubuntu)
       Status: New => Confirmed

** Tags added: systemd

** Patch added: "systemd 261.3-0ubuntu4 debdiff for stonking"
   
https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/2160036/+attachment/6006720/+files/systemd_261.3-0ubuntu4_stonking.debdiff

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160036

Title:
  udev: fchownat() of /dev/kvm failed: Operation not permitted

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/2160036/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to