Hi Alex,
On Thu, Feb 15, 2024 at 4:01 AM Alexandre Rossi <
niol@zincube.net> wrote:
What is the result of the following line in a LXC container?
(lxc)$ systemd-run --property=DynamicUser=yes /usr/bin/true
# systemd-run --property=DynamicUser=yes /usr/bin/true
Running as unit: run-rd2fa855982314217b00729153ec6dd8b.service
Nothing else displayed but that line.
Are there any kernel messages (i.e. journalctl -t kernel) when the failure
happens? We're looking for some permission denied stuff.
# journalctl -t kernel
-- No entries --
However, there were permission denied messages in the journal when I ran
the above command:
# journalctl -xe
...
Feb 15 07:41:23 davmail systemd[1]: Bus private-bus-connection: changing
state UNSET → OPENING
Feb 15 07:41:23 davmail systemd[1]: sd-bus: starting bus
private-bus-connection on fds 12/12 (socket:[140468349],
socket:[140468349])...
Feb 15 07:41:23 davmail systemd[1]: Bus private-bus-connection: changing
state OPENING → AUTHENTICATING
Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/systemd1 iface=org.freedesktop.systemd1.Manager
Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/systemd1/job iface=org.freedesktop.systemd1.Job
Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/systemd1/unit iface=org.freedesktop.systemd1.Unit
Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/systemd1/unit iface=org.freedesktop.systemd1.Automount
Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/systemd1/unit
iface=org.freedesktop.systemd1.Device
Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/systemd1/unit iface=org.freedesktop.systemd1.Mount Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/systemd1/unit iface=org.freedesktop.systemd1.Path
Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/systemd1/unit iface=org.freedesktop.systemd1.Scope Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/systemd1/unit
iface=org.freedesktop.systemd1.Service
Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/systemd1/unit iface=org.freedesktop.systemd1.Slice Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/systemd1/unit
iface=org.freedesktop.systemd1.Socket
Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/systemd1/unit iface=org.freedesktop.systemd1.Swap
Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/systemd1/unit
iface=org.freedesktop.systemd1.Target
Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/systemd1/unit iface=org.freedesktop.systemd1.Timer Feb 15 07:41:23 davmail systemd[1]: Registering bus object implementation
for path=/org/freedesktop/LogControl1 iface=org.freedesktop.LogControl1
Feb 15 07:41:23 davmail systemd[1]: Accepted new private connection.
Feb 15 07:41:23 davmail systemd[1]: Bus private-bus-connection: changing
state AUTHENTICATING → RUNNING
Feb 15 07:41:23 davmail systemd[1]: Got message type=method_call sender=n/a destination=org.freedesktop.systemd1 path=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager member=StartTransientUnit
cookie=1 reply_cookie=0 signature=ssa(sv)a(sa(sv)) error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: run-rd2fa855982314217b00729153ec6dd8b.service: Failed to load
configuration: No such file or directory
Feb 15 07:41:23 davmail systemd[1]: var.mount: Failed to load
configuration: No such file or directory
Feb 15 07:41:23 davmail systemd[1]: var-tmp.mount: Failed to load configuration: No such file or directory
Feb 15 07:41:23 davmail systemd[1]: run-rd2fa855982314217b00729153ec6dd8b.service: Trying to enqueue job run-rd2fa855982314217b00729153ec6dd8b.service/start/fail
Feb 15 07:41:23 davmail systemd[1]: tmp.mount: Cannot add dependency job, ignoring: Unit tmp.mount not found.
Feb 15 07:41:23 davmail systemd[1]: systemd-modules-load.service: Cannot
add dependency job, ignoring: Unit systemd-modules-load.service is masked.
Feb 15 07:41:23 davmail systemd[1]: systemd-firstboot.service: Cannot add dependency job, ignoring: Unit systemd-firstboot.service is masked.
Feb 15 07:41:23 davmail systemd[1]: systemd-journald-audit.socket: Cannot
add dependency job, ignoring: Unit systemd-journald-audit.socket is masked.
Feb 15 07:41:23 davmail systemd[1]: systemd-pstore.service: Cannot add dependency job, ignoring: Unit systemd-pstore.service is masked.
Feb 15 07:41:23 davmail systemd[1]: dev-hugepages.mount: Cannot add
dependency job, ignoring: Unit dev-hugepages.mount is masked.
Feb 15 07:41:23 davmail systemd[1]: systemd-binfmt.service: Cannot add dependency job, ignoring: Unit systemd-binfmt.service is masked.
Feb 15 07:41:23 davmail systemd[1]: tmp.mount: Cannot add dependency job, ignoring: Unit tmp.mount not found.
Feb 15 07:41:23 davmail systemd[1]: run-rd2fa855982314217b00729153ec6dd8b.service: Installed new job run-rd2fa855982314217b00729153ec6dd8b.service/start as 2812
Feb 15 07:41:23 davmail systemd[1]: run-rd2fa855982314217b00729153ec6dd8b.service: Enqueued job run-rd2fa855982314217b00729153ec6dd8b.service/start as 2812
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a
path=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager member=UnitNew cookie=1 reply_cookie=0 signature=so error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager member=UnitNew cookie=6111 reply_cookie=0 signature=so error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a
path=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager member=JobNew cookie=2 reply_cookie=0 signature=uos error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager member=JobNew cookie=6112 reply_cookie=0 signature=uos error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=method_return sender=org.freedesktop.systemd1 destination=n/a path=n/a interface=n/a member=n/a cookie=3 reply_cookie=1 signature=o error-name=n/a
error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: var.mount: Collecting.
Feb 15 07:41:23 davmail systemd[1]: var-tmp.mount: Collecting.
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a
path=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager member=UnitNew cookie=4 reply_cookie=0 signature=so error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager member=UnitNew cookie=6113 reply_cookie=0 signature=so error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a
path=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager member=UnitRemoved cookie=5 reply_cookie=0 signature=so error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager member=UnitRemoved cookie=6114 reply_cookie=0 signature=so error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a
path=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager member=UnitNew cookie=6 reply_cookie=0 signature=so error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager member=UnitNew cookie=6115 reply_cookie=0 signature=so error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a
path=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager member=UnitRemoved cookie=7 reply_cookie=0 signature=so error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager member=UnitRemoved cookie=6116 reply_cookie=0 signature=so error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a path=/org/freedesktop/systemd1/unit/_2d_2emount interface=org.freedesktop.DBus.Properties member=PropertiesChanged cookie=8 reply_cookie=0 signature=sa{sv}as error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a path=/org/freedesktop/systemd1/unit/_2d_2emount interface=org.freedesktop.DBus.Properties member=PropertiesChanged cookie=9 reply_cookie=0 signature=sa{sv}as error-name=n/a error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1/unit/_2d_2emount interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=6117 reply_cookie=0 signature=sa{sv}as error-name=n/a
error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1/unit/_2d_2emount interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=6118 reply_cookie=0 signature=sa{sv}as error-name=n/a
error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a path=/org/freedesktop/systemd1/unit/shutdown_2etarget interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=10 reply_cookie=0 signature=sa{sv}as error-name=n/a error-message=n/a Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1/unit/shutdown_2etarget interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=6119 reply_cookie=0 signature=sa{sv}as error-name=n/a
error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a path=/org/freedesktop/systemd1/unit/basic_2etarget interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=11 reply_cookie=0 signature=sa{sv}as error-name=n/a error-message=n/a Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1/unit/basic_2etarget interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=6120 reply_cookie=0 signature=sa{sv}as error-name=n/a
error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a path=/org/freedesktop/systemd1/unit/sysinit_2etarget interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=12 reply_cookie=0 signature=sa{sv}as error-name=n/a error-message=n/a Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1/unit/sysinit_2etarget interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=6121 reply_cookie=0 signature=sa{sv}as error-name=n/a
error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a path=/org/freedesktop/systemd1/unit/system_2eslice interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=13 reply_cookie=0 signature=sa{sv}as error-name=n/a error-message=n/a Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1/unit/system_2eslice interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=6122 reply_cookie=0 signature=sa{sv}as error-name=n/a
error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a path=/org/freedesktop/systemd1/unit/systemd_2djournald_2esocket interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=14 reply_cookie=0 signature=sa{sv}as error-name=n/a error-message=n/a Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a path=/org/freedesktop/systemd1/unit/systemd_2djournald_2esocket interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=15 reply_cookie=0 signature=sa{sv}as error-name=n/a error-message=n/a Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a
path=/org/freedesktop/systemd1/unit/systemd_2djournald_2esocket interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=6123 reply_cookie=0 signature=sa{sv}as error-name=n/a
error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a
path=/org/freedesktop/systemd1/unit/systemd_2djournald_2esocket interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=6124 reply_cookie=0 signature=sa{sv}as error-name=n/a
error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a path=/org/freedesktop/systemd1/unit/systemd_2dtmpfiles_2dsetup_2eservice interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=16 reply_cookie=0 signature=sa{sv}as error-name=n/a error-message=n/a Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a path=/org/freedesktop/systemd1/unit/systemd_2dtmpfiles_2dsetup_2eservice interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=17 reply_cookie=0 signature=sa{sv}as error-name=n/a error-message=n/a Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1/unit/systemd_2dtmpfiles_2dsetup_2eservice interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=6125 reply_cookie=0 signature=sa{sv}as error-name=n/a
error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1/unit/systemd_2dtmpfiles_2dsetup_2eservice interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=6126 reply_cookie=0 signature=sa{sv}as error-name=n/a
error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a path=/org/freedesktop/systemd1/unit/tmp_2emount interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=18 reply_cookie=0 signature=sa{sv}as error-name=n/a error-message=n/a Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a path=/org/freedesktop/systemd1/unit/tmp_2emount interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=19 reply_cookie=0 signature=sa{sv}as error-name=n/a error-message=n/a Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1/unit/tmp_2emount interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=6127 reply_cookie=0 signature=sa{sv}as error-name=n/a
error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1/unit/tmp_2emount interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=6128 reply_cookie=0 signature=sa{sv}as error-name=n/a
error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: run-rd2fa855982314217b00729153ec6dd8b.service: Will spawn child (service_enter_start): /usr/bin/true
Feb 15 07:41:23 davmail systemd[1]: run-rd2fa855982314217b00729153ec6dd8b.service: Failed to set 'trusted.invocation_id' xattr on control group /system.slice/run-rd2fa855982314217b00729153ec6dd8b.service, ignoring: Operation not permitted
Feb 15 07:41:23 davmail systemd[1]: run-rd2fa855982314217b00729153ec6dd8b.service: Failed to remove 'trusted.delegate' xattr flag on control group /system.slice/run-rd2fa855982314217b00729153ec6dd8b.service, ignoring: Operation not permitted
Feb 15 07:41:23 davmail systemd[1]: run-rd2fa855982314217b00729153ec6dd8b.service: Passing 0 fds to service
Feb 15 07:41:23 davmail systemd[1]: run-rd2fa855982314217b00729153ec6dd8b.service: About to execute
/usr/bin/true
Feb 15 07:41:23 davmail systemd[1]: run-rd2fa855982314217b00729153ec6dd8b.service: Forked /usr/bin/true as 4719
Feb 15 07:41:23 davmail (true)[4719]: PR_SET_MM_ARG_START failed: Operation
not permitted
Feb 15 07:41:23 davmail (true)[4719]: run-rd2fa855982314217b00729153ec6dd8b.service: Failed to update dynamic
user credentials: Permission denied
Feb 15 07:41:23 davmail (true)[4719]: run-rd2fa855982314217b00729153ec6dd8b.service: Failed at step USER spawning /usr/bin/true: Permission denied
░░ Subject: Process /usr/bin/true could not be executed
░░ Defined-By: systemd
░░ Support:
https://www.debian.org/support
░░
░░ The process /usr/bin/true could not be executed and failed.
░░
░░ The error number returned by this process is ERRNO.
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a path=/org/freedesktop/systemd1/unit/run_2drd2fa855982314217b00729153ec6dd8b_2eservice
interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=20 reply_cookie=0 signature=sa{sv}as error-name=n/a error-message=n/a Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=org.freedesktop.systemd1 destination=n/a path=/org/freedesktop/systemd1/unit/run_2drd2fa855982314217b00729153ec6dd8b_2eservice
interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=21 reply_cookie=0 signature=sa{sv}as error-name=n/a error-message=n/a Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1/unit/run_2drd2fa855982314217b00729153ec6dd8b_2eservice
interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=6129 reply_cookie=0 signature=sa{sv}as error-name=n/a
error-message=n/a
Feb 15 07:41:23 davmail systemd[1]: Sent message type=signal sender=n/a destination=n/a path=/org/freedesktop/systemd1/unit/run_2drd2fa855982314217b00729153ec6dd8b_2eservice
interface=org.freedesktop.DBus.Properties member=PropertiesChanged
cookie=6130 reply_cookie=0 signature=sa{sv}as error-name=n/a
error-message=n/a
Mark
--
Mark Gardner
--
<div dir="ltr"><div dir="ltr"><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">Hi Alex,</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Feb 15, 2024 at 4:01 AM Alexandre Rossi <<a href=
"mailto:
niol@zincube.net">
niol@zincube.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">What is the result of the following line in a LXC container?<br>
(lxc)$ systemd-run --property=DynamicUser=yes /usr/bin/true<br></blockquote><div><br></div><div> # systemd-run --property=DynamicUser=yes /usr/bin/true</div>Running as unit: run-rd2fa855982314217b00729153ec6dd8b.service</div><div class="gmail_quote"><br>
</div><div class="gmail_quote"><div class="gmail_default" style="font-family:arial,sans-serif;font-size:small">Nothing else displayed but that line.</div></div><div class="gmail_quote"><br><blockquote class="gmail_quote" styl