Saturday, September 24, 2022

snap store error ubuntu

sudo snap --refresh

[sudo] password for xxxx: 

panic: runtime error: invalid memory address or nil pointer dereference [recovered]

panic: runtime error: invalid memory address or nil pointer dereference

[signal SIGSEGV: segmentation violation code=0x1 addr=0x10 pc=0x55d2d3e4c645]


goroutine 1 [running]:

main.main.func1()

/build/snapd/parts/snapd-deb/build/cmd/snap/main.go:492 +0x95

panic(0x55d2d44ef040, 0x55d2d4b658f0)

/usr/lib/go-1.13/src/runtime/panic.go:679 +0x1b6

main.run(0xc000393db8, 0xe)

/build/snapd/parts/snapd-deb/build/cmd/snap/main.go:559 +0x375

main.main()

/build/snapd/parts/snapd-deb/build/cmd/snap/main.go:497 +0x371

Sep 24 16:17:01 chrx CRON[5822]: pam_unix(cron:session): session opened for user root(uid=0) by (uid=0)

Sep 24 16:17:01 chterx CRON[5823]: (root) CMD (   cd / && run-parts --report /etc/cron.hourly)

Sep 24 16:17:01 chx CRON[5822]: pam_unix(cron:session): session closed for user root

Sep 24 16:17:33 chx sudo[5839]: cohter : TTY=pts/0 ; PWD=/home/chuter ; USER=root ; COMMAND=/usr/bin/snap --refresh

Sep 24 16:17:33 chrx sudo[5839]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=1000)

Sep 24 16:17:33 cherx sudo[5839]: pam_unix(sudo:session): session closed for user root

Sep 24 16:19:56 hrx polkitd(authority=local)[817]: Registered Authentication Agent for unix-process:5993:113025 (system bus name :1.99 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object >

Sep 24 16:20:00 chrx polkitd(authority=local)[817]: Operator of unix-session:1 successfully authenticated as unix-user:chr to gain TEMPORARY authorization for action org.freedesktop.syst>

Sep 24 16:20:00 chx polkitd(authority=local)[817]: Unregistered Authentication Agent for unix-process:5993:113025 (system bus name :1.99, object path /org/freedesktop/PolicyKit1/Authenticati>





Monday, September 19, 2022

dmesg: read kernel buffer failed: Operation not permitted

Don’t worry, it still works, it has just become a privileged operation, and it works fine with sudo dmesg. But why the change?

Well, I happen to be the one who proposed for this change to be made, and followed up on getting the configuration changes made. This blog post will describe how it slightly improves the security of Ubuntu, and the journey to getting the changes landed in a release.

Matthew Ruffell

Sustaining Engineer @ Canonical.

https://ruffell.nz/programming/writeups/2020/10/24/getting-dmesg-restrict-enabled-in-ubuntu-groovy.html

https://www.phoronix.com/news/Ubuntu-20.10-Restrict-dmesg



Why should users have access to dmesg if they can't access /var/log/kern.log?

https://lists.ubuntu.com/archives/ubuntu-devel/2020-June/041063.html


For those interested this new default restriction can be turned off with


sudo sysctl kernel.dmesg_restrict=0

https://archived.forum.manjaro.org/t/why-did-dmesg-become-a-priveleged-operation-suddenly/86468/2



sysctl kernel.dmesg_restrict

kernel.dmesg_restrict = 1


 ls -l /var/log/dmesg*

-rw-r----- 1 root adm 83674 Sep 20 07:56 /var/log/dmesg

-rw-r----- 1 root adm 85387 Sep 20 07:06 /var/log/dmesg.0

-rw-r----- 1 root adm 20186 Sep 19 20:55 /var/log/dmesg.1.gz

-rw-r----- 1 root adm 20637 Sep 19 20:50 /var/log/dmesg.2.gz

-rw-r----- 1 root adm 20154 Sep 19 09:40 /var/log/dmesg.3.gz

-rw-r----- 1 root adm 20840 Sep 19 04:57 /var/log/dmesg.4.gz



message during bootup (mtd device must be supplied)

 MTD subsystem (stands for Memory Technology Devices) provides an abstraction layer for raw flash devices. It makes it possible to use the same API when working with different flash types and technologies, e.g. NAND, OneNAND, NOR, AG-AND, ECC'd NOR, etc.

http://www.linux-mtd.infradead.org/doc/general.html



sudo dmesg | grep mtd

[    2.910229] systemd[1]: Starting Load Kernel Module mtdpstore...

[    2.946037] mtd device must be supplied (device name is empty)

[    2.979483] systemd[1]: modprobe@mtdpstore.service: Deactivated successfully.

[    2.979714] systemd[1]: Finished Load Kernel Module mtdpstore.

systemd-pstore.service - Platform Persistent Storage Archival
     Loaded: loaded (/lib/systemd/system/systemd-pstore.service; enabled; vendo>
     Active: inactive (dead)
  Condition: start condition failed at Tue 2022-09-20 07:06:20 IST; 14min ago
             └─ ConditionDirectoryNotEmpty=/sys/fs/pstore was not met
       Docs: man:systemd-pstore(8)

Systemd has a systemd-pstore component that scans the pstore on boot and if non-empty, takes all previously created dumps, transfers them into its journal and removes the pstore elements. This is very important on UEFI systems, which only have a limited amount of space for variables.

https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1978079

This problem affects (at least) Ubuntu 20.04 and 22.04. A quick fix would be to configure CONFIG_EFI_VARS_PSTORE=y so that it's always available. A long term fix would make systemd rescan the directory after all module probing settled.


computer@computer:~$ uname -r
5.15.0-47-generic
computer@computer:~$ ls /boot
config-5.15.0-46-generic  initrd.img                    memtest86+.bin                System.map-5.15.0-47-generic  vmlinuz.old
config-5.15.0-47-generic  initrd.img-5.15.0-46-generic  memtest86+.elf                vmlinuz
efi                       initrd.img-5.15.0-47-generic  memtest86+_multiboot.bin      vmlinuz-5.15.0-46-generic
grub                      initrd.img.old                System.map-5.15.0-46-generic  vmlinuz-5.15.0-47-generic


journalctl -xn
Sep 20 07:30:01 computerx CRON[5108]: pam_unix(cron:session): session opened for user root(uid=0) by (uid=0)
Sep 20 07:30:01 computerx CRON[5109]: (root) CMD ([ -x /etc/init.d/anacron ] && if [ ! -d /run/systemd/system ]; then /usr/sbin/invoke-r>
Sep 20 07:30:01 computerx CRON[5108]: pam_unix(cron:session): session closed for user root
Sep 20 07:30:08 computerx sudo[5112]: computer : TTY=pts/0 ; PWD=/home/computer ; USER=root ; COMMAND=/usr/bin/sh -c echo 1 > /proc/sys/>
Sep 20 07:30:08 computerx sudo[5112]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=1000)
Sep 20 07:30:08 computerx sudo[5112]: pam_unix(sudo:session): session closed for user root
Sep 20 07:31:09 computerx anacron[5176]: Anacron 2.3 started on 2022-09-20
Sep 20 07:31:09 computerx systemd[1]: Started Run anacron jobs.
░░ Subject: A start job for unit anacron.service has finished successfully
░░ Defined-By: systemd
░░ Support: http://www.ubuntu.com/support
░░ 
░░ A start job for unit anacron.service has finished successfully.
░░ 
░░ The job identifier is 2557.
Sep 20 07:31:09 computerx anacron[5176]: Normal exit (0 jobs run)
Sep 20 07:31:09 computerx systemd[1]: anacron.service: Deactivated successfully.
░░ Subject: Unit succeeded
░░ Defined-By: systemd
░░ Support: http://www.ubuntu.com/support
░░ 
░░ The unit anacron.service has successfully entered the 'dead' state.

ls -lrt /var/spool/anacron
total 12
-rw------- 1 root root 9 Sep  2 16:28 cron.monthly
-rw------- 1 root root 9 Sep 16 11:18 cron.weekly
-rw------- 1 root root 9 Sep 20 07:11 cron.daily

cat /etc/anacrontab
# /etc/anacrontab: configuration file for anacron

# See anacron(8) and anacrontab(5) for details.

SHELL=/bin/sh
HOME=/root
LOGNAME=root

# These replace cron's entries
1 5 cron.daily run-parts --report /etc/cron.daily
7 10 cron.weekly run-parts --report /etc/cron.weekly
@monthly 15 cron.monthly run-parts --report /etc/cron.monthly
https://www.thegeekdiary.com/linux-os-service-anacron/

https://launchpad.net/~mustafakemalgilor


https://linuxconfig.org/how-to-enable-all-sysrq-functions-on-linux