Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 742503 - sys-boot/grub-2.04-r1: USE="libzfs" causes sandbox violation in /etc/exports.d
Summary: sys-boot/grub-2.04-r1: USE="libzfs" causes sandbox violation in /etc/exports.d
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: AMD64 Linux
: Normal normal (vote)
Assignee: Richard Yao (RETIRED)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-09-14 15:03 UTC by Jacob Godserv
Modified: 2020-09-25 20:28 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
tail-build.log.txt (tail-build.log.txt,16.72 KB, text/plain)
2020-09-14 15:04 UTC, Jacob Godserv
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Jacob Godserv 2020-09-14 15:03:07 UTC
Attempting to merge sys-boot/grub-2.04-r1 with USE libzfs turned on results in multiple sandbox violations, all mkdir in /etc/exports.d but with a different grub-* command, like the following:

F: mkdir
S: deny
P: /etc/exports.d
A: /etc/exports.d
R: /etc/exports.d
C: grub-mkrelpath --help 

F: mkdir
S: deny
P: /etc/exports.d
A: /etc/exports.d
R: /etc/exports.d
C: grub-mkrelpath --version 


Without this USE, GRUB merges fine.

Reproducible: Always

Steps to Reproduce:
1. USE="libzfs" emerge =sys-boot/grub-2.04-r1



# emerge --info
Portage 3.0.4 (python 3.7.8-final-0, default/linux/amd64/17.1/systemd, gcc-9.3.0, glibc-2.31-r6, 5.4.54-1-lts x86_64)
=================================================================
System uname: Linux-5.4.54-1-lts-x86_64-AMD_Ryzen_9_3900X_12-Core_Processor-with-gentoo-2.7
KiB Mem:     2627560 total,    173188 free
KiB Swap:          0 total,         0 free
Timestamp of repository gentoo: Sun, 13 Sep 2020 21:00:01 +0000
Head commit of repository gentoo: 2d90a48683dfa35eed2beb9bd54b21e2b8aa6236
sh bash 5.0_p18
ld GNU ld (Gentoo 2.33.1 p2) 2.33.1
app-shells/bash:          5.0_p18::gentoo
dev-lang/perl:            5.30.3::gentoo
dev-lang/python:          2.7.18-r1::gentoo, 3.7.8-r2::gentoo, 3.8.5::gentoo
dev-util/cmake:           3.16.5::gentoo
sys-apps/baselayout:      2.7::gentoo
sys-apps/sandbox:         2.18::gentoo
sys-devel/autoconf:       2.69-r5::gentoo
sys-devel/automake:       1.16.1-r1::gentoo
sys-devel/binutils:       2.33.1-r1::gentoo
sys-devel/gcc:            9.3.0-r1::gentoo
sys-devel/gcc-config:     2.3.1::gentoo
sys-devel/libtool:        2.4.6-r6::gentoo
sys-devel/make:           4.2.1-r4::gentoo
sys-kernel/linux-headers: 5.4-r1::gentoo (virtual/os-headers)
sys-libs/glibc:           2.31-r6::gentoo
Repositories:

gentoo
    location: /var/db/repos/gentoo
    sync-type: rsync
    sync-uri: rsync://rsync.gentoo.org/gentoo-portage
    priority: -1000
    sync-rsync-verify-jobs: 1
    sync-rsync-verify-max-age: 24
    sync-rsync-extra-opts: 
    sync-rsync-verify-metamanifest: yes

ACCEPT_KEYWORDS="amd64"
ACCEPT_LICENSE="@FREE"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-O2 -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/gnupg/qualified.txt"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/gconf /etc/gentoo-release /etc/sandbox.d /etc/terminfo"
CXXFLAGS="-O2 -pipe"
DISTDIR="/var/cache/distfiles"
ENV_UNSET="CARGO_HOME DBUS_SESSION_BUS_ADDRESS DISPLAY GOBIN GOPATH PERL5LIB PERL5OPT PERLPREFIX PERL_CORE PERL_MB_OPT PERL_MM_OPT XAUTHORITY XDG_CACHE_HOME XDG_CONFIG_HOME XDG_DATA_HOME XDG_RUNTIME_DIR"
FCFLAGS="-O2 -pipe"
FEATURES="assume-digests binpkg-docompress binpkg-dostrip binpkg-logs config-protect-if-modified distlocks ebuild-locks fixlafiles ipc-sandbox merge-sync multilib-strict network-sandbox news parallel-fetch pid-sandbox preserve-libs protect-owned qa-unresolved-soname-deps sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync xattr"
FFLAGS="-O2 -pipe"
GENTOO_MIRRORS="http://distfiles.gentoo.org"
LANG="C.UTF8"
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
MAKEOPTS="-j2"
PKGDIR="/var/cache/binpkgs"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --omit-dir-times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages --exclude=/.git"
PORTAGE_TMPDIR="/var/tmp"
USE="acl amd64 berkdb bzip2 cli crypt dri fortran gdbm iconv ipv6 libglvnd libtirpc multilib ncurses nls nptl openmp pam pcre readline seccomp split-usr ssl systemd tcpd udev unicode xattr zlib" ABI_X86="64" ADA_TARGET="gnat_2018" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" APACHE2_MODULES="authn_core authz_core socache_shmcb unixd actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" CALLIGRA_FEATURES="karbon sheets words" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" CPU_FLAGS_X86="mmx mmxext sse sse2" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock greis isync itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf skytraq superstar2 timing tsip tripmate tnt ublox ubx" GRUB_PLATFORMS="efi-64" INPUT_DEVICES="libinput" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LIBREOFFICE_EXTENSIONS="presenter-console presenter-minimizer" OFFICE_IMPLEMENTATION="libreoffice" PHP_TARGETS="php7-2 php7-3 php7-4" POSTGRES_TARGETS="postgres10 postgres11" PYTHON_SINGLE_TARGET="python3_7" PYTHON_TARGETS="python2_7 python3_7" RUBY_TARGETS="ruby25" USERLAND="GNU" VIDEO_CARDS="amdgpu fbdev intel nouveau radeon radeonsi vesa dummy v4l" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account"
Unset:  CC, CPPFLAGS, CTARGET, CXX, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LC_ALL, LINGUAS, PORTAGE_BINHOST, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS
Comment 1 Jacob Godserv 2020-09-14 15:04:23 UTC
Created attachment 660138 [details]
tail-build.log.txt

Here's the end of the build.log where the error happens.
Comment 2 Jacob Godserv 2020-09-14 23:22:41 UTC
Adding /etc/exports.d to the allowed sandbox list obviously allowed this to work, but I neither had a prior /etc/exports.d, nor did the merge create one. Very odd.
Comment 3 Jacob Godserv 2020-09-14 23:23:34 UTC
It's quite possible that ZFS itself is trying to do this:
https://github.com/openzfs/zfs/issues/10785
Comment 4 Mike Gilbert gentoo-dev 2020-09-17 01:11:31 UTC
Seems like an issue that should be addressed in libzfs.
Comment 5 Georgy Yakovlev archtester gentoo-dev 2020-09-17 09:13:48 UTC
I guess zfs version is 2.0.0-rc1?

there's a PR fixing it https://github.com/openzfs/zfs/pull/10934
I can add it after it's reviewed/merged.

workaround is simple enough, just creating /etc/exports.d

we could add addpredict to grub, but it's not the correct solution.
Comment 6 Larry the Git Cow gentoo-dev 2020-09-25 20:28:35 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c10c708ba999cd9aa08aae373d4103522ad7d358

commit c10c708ba999cd9aa08aae373d4103522ad7d358
Author:     Georgy Yakovlev <gyakovlev@gentoo.org>
AuthorDate: 2020-09-25 20:24:26 +0000
Commit:     Georgy Yakovlev <gyakovlev@gentoo.org>
CommitDate: 2020-09-25 20:28:20 +0000

    sys-fs/zfs: add exports.d patch
    
    Closes: https://bugs.gentoo.org/742503
    Package-Manager: Portage-3.0.8, Repoman-3.0.1
    Signed-off-by: Georgy Yakovlev <gyakovlev@gentoo.org>

 .../files/2.0.0_rc2-exports-d-permissions.patch    | 189 +++++++++++++++++++++
 ...fs-2.0.0_rc2.ebuild => zfs-2.0.0_rc2-r1.ebuild} |   5 +-
 2 files changed, 193 insertions(+), 1 deletion(-)