Regression in latest SLR betas and steamrt3c Steam Client if using pam_tmpdir or pam_mktemp
Una pull request collegata è già stata integrata.
- #807 di @smcv — integrata
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 40/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- linux, shell
- Ambito
- cli, devops, operating-systems
Direzione di ricerca
The issue is about bubblewrap (bwrap) 0.12.0 failing when PAM modules like pam_tmpdir set TMPDIR to a directory with unusual permissions. Start by examining the steam-runtime's srt-bwrap integration and the linked bubblewrap issue #806. Reproduce the failure with the given shell commands, then look at bwrap's source code around directory creation and permission handling. The fix likely involves modifying bwrap's handling of bind mounts for directories with restricted parent traversal permissions.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
After updating the Steam Runtime's internal copy of bubblewrap (srt-bwrap) to 0.12.0, launching its containers no longer works on a system with Debian's pam_tmpdir, or with OpenWall's pam_mktemp as packaged by Gentoo. Despite being unrelated codebases, these two are basically equivalent: they're implementations of the same idea.
These PAM modules create a restricted parent directory that ordinary users can traverse through, but not list (this is unusual!), and then a per-user private temp directory inside that, and set TMPDIR (among other environment variables) to that per-user directory. The same effect can be reproduced on a test system with something like this:
sudo mkdir -m711 /tmp/private
sudo install -d -o$(id -nu) -g$(id -ng) -m1770 /tmp/private/$(id -nu)
# the PAM module would do the equivalent of: export TMPDIR=/tmp/private/$(id -nu)
bwrap --ro-bind / / --bind "/tmp/private/$(id -nu)" "/tmp/private/$(id -nu) -- true
With older bwrap builds, this worked. With a newer bwrap build, it fails with bwrap: Can't mkdir parents for /tmp/private/user: Permission denied. This is tracked as https://github.com/containers/bubblewrap/issues/806 in bwrap.
Affected versions
Steam Linux Runtime betas dated x.0.20260914.y are affected.
The experimental steamrt3c Steam Client is not currently affected, but its next beta probably will be.
Workarounds
- Don't use
pam_tmpdirorpam_mktemp - Or set all of the environment variables
TMP,TMPDIR,TEMPandTEMPDIRto an existing directory whose parent directories are all readable (for example$HOME/tmp,/tmpor/var/tmp) before starting Steam
- Lingua principale
- Shell
- Stelle
- 1.5k
- Fork
- 97
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di ValveSoftware/steam-runtime
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 58/100
ValveSoftware/steam-runtime#857 · 2 commenti ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
ValveSoftware/steam-runtime#856 · 6 commenti ·
-
Need Retest Pressure Vessel
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
ValveSoftware/steam-runtime#854 · 4 commenti ·
-
Need Retest
Difficoltà 4/5 3-5 giorni Idoneità per principianti 55/100
ValveSoftware/steam-runtime#853 · 6 commenti ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
ValveSoftware/steam-runtime#851 · 3 commenti ·
Tutte le issue di ValveSoftware/steam-runtime
Issue simili
-
Erreur dans le documentationApertabug
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 82/100
stephrobert/pavois#390 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
enhancement
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
-
Update to 8.1.3Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 84/100
-
feat(plugin): /context-guru:status --stats writes the JSON to a temp file and shows only the pathApertaenhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
rossoctl/context-guru#411 ·
I maintainer di solito rispondono entro 1 giorno