Repository navigation
systemd 257.13-6: fix render/systemd-journal group regressions and repair the STIG build variant - #1671
Open
dcasota wants to merge 1 commit into
Open
systemd 257.13-6: fix render/systemd-journal group regressions and repair the STIG build variant#1671dcasota wants to merge 1 commit into
dcasota wants to merge 1 commit into
Conversation
This was referenced Sep 9, 2026
dcasota
force-pushed
the
fix/systemd-groups-and-stig-variant
branch
from
September 16, 2026 18:06
ccafa05 to
b5f56d0
Compare
dcasota
force-pushed
the
fix/systemd-groups-and-stig-variant
branch
from
September 17, 2026 06:02
b5f56d0 to
4f8c7c7
Compare
… variant Five defects, each invisible in some constellations and fatal in others. Group regressions (affect EVERY constellation) 0004: also drop the SUBSYSTEM=="accel" rule from 50-udev-default.rules.in. The same patch removes the "render" group from sysusers.d/basic.conf.in but left the accel rule referencing it, so systemd-udevd logs "50-udev-default.rules:56 Unknown group 'render', ignoring." on every boot of every install. systemd 253 had no accel rule; the regression arrived with the 253->257 rebase. The dev branch (255.10) already deletes this line. 0004: stop emptying sysusers.d/systemd-journal.conf.in. dracut 109 builds the initrd's /etc/group by running systemd-sysusers against the shipped snippets; with the entry removed the snippet is a no-op, so the initrd has no systemd-journal group while 11systemd-tmpfiles still installs tmpfiles.d/systemd.conf, which references it on five lines. Every boot logs five "Failed to resolve group 'systemd-journal'" from inside the initrd. Harmless under dracut 059, which copied the group in explicitly; a real gap since the 109 bump on 5.0. Pin -Dsystemd-journal-gid=23 to match filesystem's static group file. The meson default is 0, which meson.build maps to "-" (dynamic allocation), so restoring the sysusers entry without this would let systemd-sysusers pick an arbitrary GID in the initrd and mis-own /run/log/journal across switch-root. STIG build variant (affects only STIG_HARDEN=1) Ship harden-tmpfs-mount-options.patch. It was referenced by the STIG conditional but existed only under SPECS/90/systemd; it was dropped from this directory in 17c9365 "systemd: upgrade to v257.13". Replace the plain define of STIG_HARDEN with a define-if-unset so the flag can be set from pkg_build_options.json or rpmbuild -D. A plain define in the spec body beats -D, which made every STIG conditional unreachable and thus never parsed, built or tested. Switch to unnumbered "Patch:" so rpm assigns indices. The conditional STIG patch and 0005-default-conf-modifications.patch had both been given index 4; once STIG_HARDEN is reachable that is a hard "error: patch 4 defined multiple times" with no prep section emitted. Non-STIG builds are unchanged: the expanded %prep is byte-identical before and after at subrelease 91 and 92. Change-Id: I430c22804c50d5a9cae83043139f4de787ef2864 Signed-off-by: Daniel Casota <dcasota@gmail.com> Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
dcasota
force-pushed
the
fix/systemd-groups-and-stig-variant
branch
from
October 9, 2026 07:23
4f8c7c7 to
36cc56e
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
SPECS/systemd(257.13, subrelease 91 and later) has five defects:acceludev rule50-udev-default.rules:56 Unknown group 'render', ignoring.on each bootsystemd-journalsysusers snippetFailed to resolve group 'systemd-journal'from inside the initrd on each bootsystemd-sysuserswould allocate an arbitrary GID in the initrdharden-tmpfs-mount-options.patchSTIG_HARDEN=1Patch4:STIG_HARDEN=1error: patch 4 defined multiple times, no%prepThe last two go unnoticed because
%define STIG_HARDEN 0in the spec body wins overrpmbuild -D, so the STIG variant is never parsed, built or tested.render.0004-Remove-unused-default-groups-rules-and-tmpfiles.patchdeletes therendergroup fromsysusers.d/basic.conf.inand thedrm/kfdrules, but keepsSUBSYSTEM=="accel", GROUP="render", ...as a context line.systemd-journal. The group exists on the installed system (GID 23, fromfilesystem's group file) but not in the initrd. dracut 109 builds the initrd's/etc/groupby runningsystemd-sysusersagainst the shipped snippets (11systemd-journaldinstallssystemd-journal.conf,78systemd-sysusersrunssystemd-sysusers --root=$initdir). Patch 0004 empties that snippet, while11systemd-tmpfilesstill installstmpfiles.d/systemd.conf, whose five/run/log/journaland/var/log/journallines reference the group.tmp.mount.
harden-tmpfs-mount-options.patch(addsnoexectounits/tmp.mount) is referenced by the STIG conditional but exists only inSPECS/90/systemd/.tmp.mountis owned by this package and not marked as a config file, which is why photon-os-installer skips the equivalent ansible controlPHTN-50-000245(stigenable.py): an install-time edit would show as permanentrpm -Vdrift and be reverted by the next systemd upgrade. With the spec side unreachable, neither side delivers the control;/tmpis mountedrw,nosuid,nodevwithoutnoexecon an installed 5.0 guest.Change
SPECS/systemd/systemd.spec257.13-5 -> 257.13-6:accel/renderrule, and the hunk that emptiedsysusers.d/systemd-journal.conf.inis dropped, sog systemd-journal {{SYSTEMD_JOURNAL_GID}} -is shipped.-Dsystemd-journal-gid=23: required with the restored snippet.meson_options.txt:320defaults the option to0andmeson.build:964isconf.set(name, val > 0 ? val : '-'), so without the pin the GID would be dynamic and/run/log/journalmis-owned across switch-root. 23 matchesfilesystem.STIG_HARDEN:%define STIG_HARDEN 0->%{!?STIG_HARDEN: %global STIG_HARDEN 0}, so the flag can be set frompkg_build_options.json/-D. Default stays off.harden-tmpfs-mount-options.patchis added to this directory (same patch as inSPECS/90/systemd/), with a spec comment explaining why the control belongs here and not in the installer.Patch:, so rpm assigns indices in order and a conditional patch cannot collide with an unconditional one.One
%changelogentry.Testing
rpmspec -Pat subrelease 91 and 92,STIG_HARDENunset / 0 / 1: all parse without warnings; Source2 is50-security-hardening.conffor unset/0 and50-security-hardening.stig.conffor 1, and the tmpfs patch is listed only for 1. The unchanged base spec withSTIG_HARDENset to 1 in its body fails witherror: patch 4 defined multiple times.%prepat subrelease 91 and 92 is identical to the base spec's (apart from the source directory path).systemd-257.13.tar.gz(sha512 matchesconfig.yaml), all six patches apply in rpm's order withpatch -p1 --fuzz=0. Result: noGROUP="render"left inrules.d/50-udev-default.rules.in, thesystemd-journalsysusers entry present, andunits/tmp.mounthasOptions=mode=1777,strictatime,nosuid,noexec,nodev,....check_spec.py --mainline 93exits 0 at subrelease 91 and 92.🤖 Generated with Claude Code