Page MenuHomeFreeBSD

sysutils/buildah: Add a patch to correctly preserve setuid/setgid bits
Needs ReviewPublic

Authored by dtxdf on Tue, Sep 29, 4:41 PM.

Details

Reviewers
dfr
Summary

This is basically the same patch as in sysutils/podman, but for buildah.

To reproduce the issue:

console
# pkg install -f buildah-1.43.2_4
Updating FreeBSD-ports repository catalogue...
FreeBSD-ports repository is up to date.
Updating FreeBSD-ports-kmods repository catalogue...
FreeBSD-ports-kmods repository is up to date.
Updating FreeBSD-base repository catalogue...
FreeBSD-base repository is up to date.
Updating Custom repository catalogue...
Custom repository is up to date.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

Installed packages to be DOWNGRADED:
	buildah: 1.43.2_5 -> 1.43.2_4 [FreeBSD-ports]

Number of packages to be downgraded: 1

21 MiB to be downloaded.

Proceed with this action? [y/N]: y
[1/1] Fetching buildah-1.43.2_4: 100%    21 MiB  96.3 kB/s    03:48
Checking integrity... done (0 conflicting)
[1/1] Downgrading buildah from 1.43.2_5 to 1.43.2_4...
[1/1] Extracting buildah-1.43.2_4: 100%
# buildah images
REPOSITORY                          TAG      IMAGE ID       CREATED        SIZE
ghcr.io/appjail-makejails/dyndnsd   latest   b2c4be73f168   10 hours ago   906 MB
ghcr.io/appjail-makejails/puck      latest   dc8050efd8f8   3 weeks ago    5.37 GB
<none>                              <none>   da8bac961c22   6 weeks ago    432 MB
# buildah build --network=host -t my-doas .
STEP 1/2: FROM ghcr.io/appjail-makejails/core
Trying to pull ghcr.io/appjail-makejails/core:latest...
Getting image source signatures
Copying blob bd9ddc54bea9 skipped: already exists
Copying blob bd9ddc54bea9 skipped: already exists
Copying blob 4c3830b1ac52 skipped: already exists
Copying blob 41aee0059163 skipped: already exists
Copying blob 78f5966825d4 skipped: already exists
Copying blob 78d645ce98ae skipped: already exists
Copying config bff0378f63 done   |
Writing manifest to image destination
STEP 2/2: RUN pkg install doas
Updating FreeBSD-base repository catalogue...
[d58d3424546e] Fetching meta.conf: . done
[d58d3424546e] Fetching data: .......... done
Processing entries: .......... done
FreeBSD-base repository update completed. 509 packages processed.
Updating FreeBSD-ports repository catalogue...
[d58d3424546e] Fetching meta.conf: . done
[d58d3424546e] Fetching data: .......... done
Processing entries: .......... done
FreeBSD-ports repository update completed. 38380 packages processed.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	doas: 6.4 [FreeBSD-ports]

Number of packages to be installed: 1

25 KiB to be downloaded.
[d58d3424546e] [1/1] Fetching doas-6.4: .... done
Checking integrity... done (0 conflicting)
[d58d3424546e] [1/1] Installing doas-6.4...
[d58d3424546e] [1/1] Extracting doas-6.4: .......... done
=====
Message from doas-6.4:

--
To use doas,

/usr/local/etc/doas.conf

must be created. Refer to doas.conf(5) for further details and/or follow
/usr/local/etc/doas.conf.sample as an example.

Note: In order to be able to run most desktop (GUI) applications, the user
needs to have the keepenv keyword specified. If keepenv is not specified then
key elements, like the user's $HOME variable, will be reset and cause the GUI
application to crash.

Users who only need to run command line applications can usually get away
without keepenv.

When in doubt, try to avoid using keepenv as it is less secure to have
environment variables passed to privileged users.
COMMIT my-doas
Getting image source signatures
Copying blob d8ef77f70a0e skipped: already exists
Copying blob 28c5f6166e10 skipped: already exists
Copying blob 5f70bf18a086 skipped: already exists
Copying blob 7fd083ca5838 skipped: already exists
Copying blob 80c64af2e62f skipped: already exists
Copying blob 5f70bf18a086 skipped: already exists
Copying blob a852269d7f80 done   |
Copying config 52509110f3 done   |
Writing manifest to image destination
--> 52509110f3c4
Successfully tagged localhost/my-doas:latest
52509110f3c46d16a1b79eec57038f35c75ca490b8751b6519efc59715506b8a
# buildah images
REPOSITORY                          TAG      IMAGE ID       CREATED        SIZE
localhost/my-doas                   latest   52509110f3c4   10 hours ago   275 MB
ghcr.io/appjail-makejails/dyndnsd   latest   b2c4be73f168   20 hours ago   906 MB
ghcr.io/appjail-makejails/core      latest   bff0378f63f1   3 weeks ago    192 MB
ghcr.io/appjail-makejails/puck      latest   dc8050efd8f8   3 weeks ago    5.37 GB
<none>                              <none>   da8bac961c22   6 weeks ago    432 MB
# buildah from 52509110f3c4
my-doas-working-container
# buildah mount my-doas-working-container
/var/db/containers/storage/zfs/graph/e87638349343e1950f5d7d8af7759e30b40716a196860ff36c2da24932012404
# chroot /var/db/containers/storage/zfs/graph/e87638349343e1950f5d7d8af7759e30b40716a196860ff36c2da24932012404 ls -l /usr/local/bin/doas
-rwxr-xr-x  1 root wheel 27384 28 ago.  07:58 /usr/local/bin/doas
# buildah umount my-doas-working-container
eadb39dd1798a6670540f2c484b0d0b748a96eb735a6d31f62c3e003fb2cf5bb
# buildah rm my-doas-working-container
eadb39dd1798a6670540f2c484b0d0b748a96eb735a6d31f62c3e003fb2cf5bb
# buildah rmi 52509110f3c4
untagged: localhost/my-doas:latest
52509110f3c46d16a1b79eec57038f35c75ca490b8751b6519efc59715506b8a
# pkg search buildah
buildah-1.43.2_5               Manage Pods, Containers and Container Images
buildah-1.43.2_4               Manage Pods, Containers and Container Images
# pkg install -f buildah-1.43.2_5
Updating FreeBSD-ports repository catalogue...
FreeBSD-ports repository is up to date.
Updating FreeBSD-ports-kmods repository catalogue...
Fetching data: 100%    44 KiB  45.4 kB/s    00:01
The provides database is up-to-date.
Processing entries: 100%
FreeBSD-ports-kmods repository update completed. 286 packages processed.
Updating FreeBSD-base repository catalogue...
Fetching data: 100%    83 KiB  85.5 kB/s    00:01
The provides database is up-to-date.
Processing entries: 100%
FreeBSD-base repository update completed. 512 packages processed.
Updating Custom repository catalogue...
Custom repository is up to date.
All repositories are up to date.
Checking integrity... done (0 conflicting)
The following 1 package(s) will be affected (of 0 checked):

Installed packages to be UPGRADED:
	buildah: 1.43.2_4 -> 1.43.2_5 [Custom]

Number of packages to be upgraded: 1

Proceed with this action? [y/N]: y
[1/1] Upgrading buildah from 1.43.2_4 to 1.43.2_5...
[1/1] Extracting buildah-1.43.2_5: 100%
# buildah build --network=host -t my-doas .
STEP 1/2: FROM ghcr.io/appjail-makejails/core
STEP 2/2: RUN pkg install doas
Updating FreeBSD-base repository catalogue...
[fc196f25e90a] Fetching meta.conf: . done
[fc196f25e90a] Fetching data: .......... done
Processing entries: .......... done
FreeBSD-base repository update completed. 509 packages processed.
Updating FreeBSD-ports repository catalogue...
[fc196f25e90a] Fetching meta.conf: . done
[fc196f25e90a] Fetching data: .......... done
Processing entries: .......... done
FreeBSD-ports repository update completed. 38380 packages processed.
All repositories are up to date.
The following 1 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
	doas: 6.4 [FreeBSD-ports]

Number of packages to be installed: 1

25 KiB to be downloaded.
[fc196f25e90a] [1/1] Fetching doas-6.4: .... done
Checking integrity... done (0 conflicting)
[fc196f25e90a] [1/1] Installing doas-6.4...
[fc196f25e90a] [1/1] Extracting doas-6.4: .......... done
=====
Message from doas-6.4:

--
To use doas,

/usr/local/etc/doas.conf

must be created. Refer to doas.conf(5) for further details and/or follow
/usr/local/etc/doas.conf.sample as an example.

Note: In order to be able to run most desktop (GUI) applications, the user
needs to have the keepenv keyword specified. If keepenv is not specified then
key elements, like the user's $HOME variable, will be reset and cause the GUI
application to crash.

Users who only need to run command line applications can usually get away
without keepenv.

When in doubt, try to avoid using keepenv as it is less secure to have
environment variables passed to privileged users.
COMMIT my-doas
Getting image source signatures
Copying blob d8ef77f70a0e skipped: already exists
Copying blob 28c5f6166e10 skipped: already exists
Copying blob 5f70bf18a086 skipped: already exists
Copying blob 7fd083ca5838 skipped: already exists
Copying blob 80c64af2e62f skipped: already exists
Copying blob 5f70bf18a086 skipped: already exists
Copying blob bd543f326c26 done   |
Copying config 7c7c1f781f done   |
Writing manifest to image destination
--> 7c7c1f781f28
Successfully tagged localhost/my-doas:latest
7c7c1f781f28ddd4ec67f2f25ac9fbe5dc05b2fb4757f6b3afaacc0e5c17fbf3
# buildah images
REPOSITORY                          TAG      IMAGE ID       CREATED         SIZE
localhost/my-doas                   latest   7c7c1f781f28   8 minutes ago   275 MB
ghcr.io/appjail-makejails/dyndnsd   latest   b2c4be73f168   20 hours ago    906 MB
ghcr.io/appjail-makejails/core      latest   bff0378f63f1   3 weeks ago     192 MB
ghcr.io/appjail-makejails/puck      latest   dc8050efd8f8   3 weeks ago     5.37 GB
<none>                              <none>   da8bac961c22   6 weeks ago     432 MB
# buildah from 7c7c1f781f28
my-doas-working-container
# buildah mount my-doas-working-container
/var/db/containers/storage/zfs/graph/06781bca8bdc3ee45d52883f3e47c75ddfd15156844fab4c7b188bb1a6a06055
# chroot /var/db/containers/storage/zfs/graph/06781bca8bdc3ee45d52883f3e47c75ddfd15156844fab4c7b188bb1a6a06055 ls -l /usr/local/bin/doas
-rwsr-xr-x  1 root wheel 27384 28 ago.  07:58 /usr/local/bin/doas

Containerfile:

containerfile
FROM ghcr.io/appjail-makejails/core

RUN pkg install doas

Diff Detail

Repository
R11 FreeBSD ports repository
Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

dtxdf requested review of this revision.Tue, Sep 29, 4:41 PM
dtxdf created this revision.