security_SandboxedServices test failure on stout due to root run dbus-monitor in rf-led-handler.conf |
||||||||||
Issue descriptionChrome OS version: 10525.0.0, 67.0.3381.0 dev channel stout Test name: security_SandboxedServices/security_SandboxedServices Failure reason: One or more processes failed sandboxing Stainless logs: https://stainless.corp.google.com/search?view=list&first_date=2018-03-23&last_date=2018-03-29&test=security_SandboxedServices&board=stout&status=FAIL&status=ERROR&status=ABORT&exclude_cts=true&exclude_not_run=false&exclude_non_release=false&exclude_au=true&exclude_acts=true&exclude_retried=true&exclude_non_production=true
,
Apr 12 2018
Still happening today on cros-goldeneye/chromeos/healthmonitoring/buildDetails?builderName=stout-release&buildNumber=&id=&buildbucketId=&token=AIQH9qMAseiN4OyOBc0Qu8lccDXh%3A1523569989573 04/10 15:02:05.292 WARNI|security_Sandboxed:0323| New services: set(['btdispatch', 'dbus-monitor']) 04/10 15:02:05.296 ERROR|security_Sandboxed:0334| New services are not allowed to run as root, but these are: ['dbus-monitor'] 04/10 15:02:05.300 ERROR|security_Sandboxed:0338| Failed sandboxing: ['dbus-monitor'] https://00e9e64bac88ed6f60d2e076da52b5fdf99d7883cdb706263b-apidata.googleusercontent.com/download/storage/v1/b/chromeos-autotest-results/o/191067824-chromeos-test%2Fchromeos6-row2-rack5-host13%2Fdebug%2Fclient.0.DEBUG?qk=AD5uMEvOR_MLCH1TP4gcfznj5c1DBj__eDZvmbSinWpAhY4kJjx_iTMwQ9NAbTUdK6_lHIkJxJkRJ35kZxO7r3PMde5ErQwfWkUQL84DeeANQmcuwSwYekZh-5qwzM3Aw9GLCQIDyfHkg71Kl9-AEk3yb4snIi8eN8A7YBXWsujYoNx4z3UqUhuwnrlTRg06P8R4N7_cQU_I3aN9Y2xFuxHPDwjJmt5arvlUtGat373vLl5fWztEJ-LkiupOb_1KQcN9RCp0PsNacb0VynPPp1I9JZpk5XUBgcKVsnJoQ7PnfXLPif9USym6u5pnF74hbZNSHw8zKJsV-vV2aO5GdRWBcxM6ls4i6O-WTzDHCxOOn6p3dMmXBH-PC-VfTcjwg8mEksvp4J7kilH2ojyOg_K3cAqHxjhw4U-rDP8KYEqVngNKdQ9TbfcYwr8pCWlSQd9qnhRZ4bcQ-04TNovDgEq5gDpbVNv0tqb4_ngY2XDSJlBeJ7FgYr-jDp1H3TRFy4wb8RJ2fzybsazLyVb-PUAibG6DoFoz2y8n1dRZx662LcWfLf9fzCxxA2HeQG-_eyF3zC_TJwrJYxiWINqsY7Ud69S2LFhjuGyrHcoTJDlRA9pXjPzRTMcM4ag96SAJMDkimWPFRxBgpRERjt-pkHRCr8Xja9nD2gjGRfJQFZXbKX7odDzHOF1kKhZsqqfkxOVFmJ-a0BlcclxsDW8BzaZ7pbE6ylp1rjeF6IUN_P6opB9qg6gfMW7L9gjgK5Q-FlnQ63ei1heoOWezCXC2V1kBHtZbBgpgH-TKih_WiRPs3TBKKJsqt2DRUbZvCwTKUA_vle44Tvr4tycyrr-wob9pRjZ2a1ox7A
,
Apr 12 2018
Nigel, looking at GE, isn't this device supposed to be EOL now? I'll mark build as experimental for now.
,
Apr 16 2018
,
Apr 24 2018
no, stout is not yet EOL. it's ivybridge, not sandybridge. please do not mark it experimental.
,
Apr 24 2018
Stout started out on Sandbridge but got rev'd to Ivybridge. Official AUE date for stout is June 2018
,
Apr 24 2018
On the actual issue, Stout had/has an LED on the b-panel which was supposed to be on when the device was online i think. As mentioned, this is very old, what is the lowest effort path to closing this?
,
Apr 25 2018
find a user that can talk to the bluez/shill dbus endpoints (prob those respective users?) and change to that account before running dbus-send/dbus-monitor. we do this in a few conf files already like authpolicyd.conf via minijail.
,
Apr 25 2018
Passing to current deputy.
,
May 4 2018
Whom is the right owner for this? We still have this error showing up on the 68 release.
,
May 7 2018
tragedy of the commons
,
May 22 2018
If we keep punting this out, the device will be AUEd before fixing it, maybe that is the most reasonable path for now. It does not seem like it would really impact users and is more of an annoyance on the test dashboards.
,
May 23 2018
Not sure if this is relevant but there's about 100K 28-day active users of Stout, but i was never convinced that the LED feature was useful...
,
May 30 2018
Nigel, this is assigned to you; can you find a product eng owner?
,
May 30 2018
,
Jun 1 2018
Adding Nick, anyone on you team that could take a look based on Mikes comments in #8?
,
Jun 1 2018
This sounds like maybe some old services were caught up in an upstart security thing? See: https://groups.google.com/a/google.com/forum/?utm_medium=email&utm_source=footer#!msg/chromeos-chatty-eng/ChDd3cvy-AE/SkXS3d-PAQAJ;context-place=forum/chromeos-chatty-eng Assign to vapier@ to check if this is the case as he +2d the change referenced above and is familiar with upstart, so seems likely to be the right owner.
,
Jun 1 2018
Reading further, it sounds like vapier@ may already have a fix in mind re #8 so he should just implement that if so.
,
Jun 1 2018
this issue has nothing to do with upstart/env exporting. plus, that has only landed recently. the security test has long been failing, it just hasn't failed on every build, so people have ignored it. it's probably been failing ever since the conf file in question was added to the stout build.
,
Jun 1 2018
Not sure. From the bug traffic above, vapier@ clearly seems to know the most about the issue.
,
Jun 1 2018
it needs someone who has actual hardware, knows what this led script is supposed to do, and knows how to make sure it's still working knowing why it's broken (which I explained above) doesn't help with the rest
,
Jun 2 2018
Nobody has any of that. You have 1/4 which is the closest.
,
Jun 7 2018
,
Jul 3
This error was observed on stout-release (see https://uberchromegw.corp.google.com/i/chromeos/builders/stout-release/builds/5131) at HWTest stage. security_SandboxedServices [ FAILED ] security_SandboxedServices FAIL: One or more processes failed sandboxing: defaultdict(<type 'list'>, {'dbus-monitor': ['missing euser']}) security_SandboxedServices retry_count: 2
,
Jul 19
This test failing on stout for M68 beta build (10718.58.0, 68.0.3440.70): https://stainless.corp.google.com/search?exclude_retried=false&first_date=2018-07-11&master_builder_name=&builder_name_number=&shard=&exclude_acts=true&builder_name=&master_builder_name_number=&owner=chromeos-test&retry=&exclude_cts=false&exclude_non_production=false&hostname=&board=stout&test=%5Esecurity_SandboxedServices%24&suite=&build=%5ER68%5C-10718%5C.58%5C.0%24&status=FAIL&status=ERROR&status=ABORT&reason=&waterfall=chromeos(_release%7C)&exclude_not_run=false&last_date=2018-07-25&exclude_non_release=true&exclude_au=false&model=&view=list |
||||||||||
►
Sign in to add a comment |
||||||||||
Comment 1 by vapier@chromium.org
, Mar 29 2018Labels: -M-66 Proj-stout
Status: Available (was: Untriaged)
Summary: security_SandboxedServices test failure on stout due to root run dbus-monitor in rf-led-handler.conf (was: security_SandboxedServices test failure on stout)