Skip to content

systemd 257.13-6: fix render/systemd-journal group regressions and repair the STIG build variant - #1671

Open
dcasota wants to merge 1 commit into
vmware:5.0from
dcasota:fix/systemd-groups-and-stig-variant
Open

dcasota wants to merge 1 commit into
vmware:5.0from
dcasota:fix/systemd-groups-and-stig-variant

Conversation

@dcasota

@dcasota dcasota commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Problem

SPECS/systemd (257.13, subrelease 91 and later) has five defects:

Defect Affected builds Symptom
dangling accel udev rule every install 50-udev-default.rules:56 Unknown group 'render', ignoring. on each boot
emptied systemd-journal sysusers snippet every install five Failed to resolve group 'systemd-journal' from inside the initrd on each boot
unpinned journal GID any build once the snippet is restored systemd-sysusers would allocate an arbitrary GID in the initrd
missing harden-tmpfs-mount-options.patch STIG_HARDEN=1 build fails on a missing source
duplicate Patch4: STIG_HARDEN=1 error: patch 4 defined multiple times, no %prep

The last two go unnoticed because %define STIG_HARDEN 0 in the spec body wins over rpmbuild -D, so the STIG variant is never parsed, built or tested.

render. 0004-Remove-unused-default-groups-rules-and-tmpfiles.patch deletes the render group from sysusers.d/basic.conf.in and the drm/kfd rules, but keeps SUBSYSTEM=="accel", GROUP="render", ... as a context line.

systemd-journal. The group exists on the installed system (GID 23, from filesystem's group file) but not in the initrd. dracut 109 builds the initrd's /etc/group by running systemd-sysusers against the shipped snippets (11systemd-journald installs systemd-journal.conf, 78systemd-sysusers runs systemd-sysusers --root=$initdir). Patch 0004 empties that snippet, while 11systemd-tmpfiles still installs tmpfiles.d/systemd.conf, whose five /run/log/journal and /var/log/journal lines reference the group.

tmp.mount. harden-tmpfs-mount-options.patch (adds noexec to units/tmp.mount) is referenced by the STIG conditional but exists only in SPECS/90/systemd/. tmp.mount is owned by this package and not marked as a config file, which is why photon-os-installer skips the equivalent ansible control PHTN-50-000245 (stigenable.py): an install-time edit would show as permanent rpm -V drift and be reverted by the next systemd upgrade. With the spec side unreachable, neither side delivers the control; /tmp is mounted rw,nosuid,nodev without noexec on an installed 5.0 guest.

Change

SPECS/systemd/systemd.spec 257.13-5 -> 257.13-6:

  • 0004 patch: the deletion hunk also removes the accel/render rule, and the hunk that emptied sysusers.d/systemd-journal.conf.in is dropped, so g systemd-journal {{SYSTEMD_JOURNAL_GID}} - is shipped.
  • -Dsystemd-journal-gid=23: required with the restored snippet. meson_options.txt:320 defaults the option to 0 and meson.build:964 is conf.set(name, val > 0 ? val : '-'), so without the pin the GID would be dynamic and /run/log/journal mis-owned across switch-root. 23 matches filesystem.
  • STIG_HARDEN: %define STIG_HARDEN 0 -> %{!?STIG_HARDEN: %global STIG_HARDEN 0}, so the flag can be set from pkg_build_options.json / -D. Default stays off.
  • harden-tmpfs-mount-options.patch is added to this directory (same patch as in SPECS/90/systemd/), with a spec comment explaining why the control belongs here and not in the installer.
  • Patch list is unnumbered Patch:, so rpm assigns indices in order and a conditional patch cannot collide with an unconditional one.

One %changelog entry.

Testing

  • rpmspec -P at subrelease 91 and 92, STIG_HARDEN unset / 0 / 1: all parse without warnings; Source2 is 50-security-hardening.conf for unset/0 and 50-security-hardening.stig.conf for 1, and the tmpfs patch is listed only for 1. The unchanged base spec with STIG_HARDEN set to 1 in its body fails with error: patch 4 defined multiple times.
  • Non-STIG builds are unchanged: the expanded %prep at subrelease 91 and 92 is identical to the base spec's (apart from the source directory path).
  • Against systemd-257.13.tar.gz (sha512 matches config.yaml), all six patches apply in rpm's order with patch -p1 --fuzz=0. Result: no GROUP="render" left in rules.d/50-udev-default.rules.in, the systemd-journal sysusers entry present, and units/tmp.mount has Options=mode=1777,strictatime,nosuid,noexec,nodev,....
  • check_spec.py --mainline 93 exits 0 at subrelease 91 and 92.

🤖 Generated with Claude Code

@aabusair aabusair closed this Sep 2, 2026
@aabusair aabusair reopened this Sep 2, 2026
@dcasota
dcasota force-pushed the fix/systemd-groups-and-stig-variant branch from ccafa05 to b5f56d0 Compare September 16, 2026 18:06
@dcasota dcasota changed the title systemd 257.13-7: fix render/systemd-journal group regressions and repair the STIG build variant systemd 257.13-6: fix render/systemd-journal group regressions and repair the STIG build variant Sep 16, 2026
@dcasota
dcasota force-pushed the fix/systemd-groups-and-stig-variant branch from b5f56d0 to 4f8c7c7 Compare September 17, 2026 06:02
… variant

Five defects, each invisible in some constellations and fatal in others.

Group regressions (affect EVERY constellation)

  0004: also drop the SUBSYSTEM=="accel" rule from 50-udev-default.rules.in.
  The same patch removes the "render" group from sysusers.d/basic.conf.in but
  left the accel rule referencing it, so systemd-udevd logs
  "50-udev-default.rules:56 Unknown group 'render', ignoring." on every boot
  of every install. systemd 253 had no accel rule; the regression arrived with
  the 253->257 rebase. The dev branch (255.10) already deletes this line.

  0004: stop emptying sysusers.d/systemd-journal.conf.in. dracut 109 builds
  the initrd's /etc/group by running systemd-sysusers against the shipped
  snippets; with the entry removed the snippet is a no-op, so the initrd has
  no systemd-journal group while 11systemd-tmpfiles still installs
  tmpfiles.d/systemd.conf, which references it on five lines. Every boot logs
  five "Failed to resolve group 'systemd-journal'" from inside the initrd.
  Harmless under dracut 059, which copied the group in explicitly; a real gap
  since the 109 bump on 5.0.

  Pin -Dsystemd-journal-gid=23 to match filesystem's static group file. The
  meson default is 0, which meson.build maps to "-" (dynamic allocation), so
  restoring the sysusers entry without this would let systemd-sysusers pick an
  arbitrary GID in the initrd and mis-own /run/log/journal across switch-root.

STIG build variant (affects only STIG_HARDEN=1)

  Ship harden-tmpfs-mount-options.patch. It was referenced by the STIG
  conditional but existed only under SPECS/90/systemd; it was dropped from
  this directory in 17c9365 "systemd: upgrade to v257.13".

  Replace the plain define of STIG_HARDEN with a define-if-unset so the flag
  can be set from pkg_build_options.json or rpmbuild -D. A plain define in the
  spec body beats -D, which made every STIG conditional unreachable and thus
  never parsed, built or tested.

  Switch to unnumbered "Patch:" so rpm assigns indices. The conditional STIG
  patch and 0005-default-conf-modifications.patch had both been given index 4;
  once STIG_HARDEN is reachable that is a hard
  "error: patch 4 defined multiple times" with no prep section emitted.

Non-STIG builds are unchanged: the expanded %prep is byte-identical before
and after at subrelease 91 and 92.

Change-Id: I430c22804c50d5a9cae83043139f4de787ef2864
Signed-off-by: Daniel Casota <dcasota@gmail.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dcasota
dcasota force-pushed the fix/systemd-groups-and-stig-variant branch from 4f8c7c7 to 36cc56e Compare October 9, 2026 07:23

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants