Package: clevis-systemd
Version: 15-4
Severity: important

The clevis-luks-askpass script is shipped without execute permissions:

-rw-r--r-- root/root      2343 2021-01-04 22:50 
./usr/libexec/clevis-luks-askpass

This breaks the clevis-luks-askpass.service systemd unit, and by
extension automatic unlocking of an encrypted root filesystem in the
initrd:

Jan 10 14:53:56 simula systemd[677]: clevis-luks-askpass.service: Failed to 
locate executable /usr/libexec/clevis-luks-askpass: Permission denied
Jan 10 14:53:56 simula systemd[677]: clevis-luks-askpass.service: Failed at 
step EXEC spawning /usr/libexec/clevis-luks-askpass: Permission denied
Jan 10 14:53:56 simula systemd[1]: clevis-luks-askpass.service: Main process 
exited, code=exited, status=203/EXEC
Jan 10 14:53:56 simula systemd[1]: clevis-luks-askpass.service: Failed with 
result 'exit-code'.


After manually running

 sudo chmod +x /usr/libexec/clevis-luks-askpass

it's working.


-- System Information:
Debian Release: bullseye/sid
  APT prefers testing-debug
  APT policy: (500, 'testing-debug'), (500, 'testing'), (500, 'stable'), (103, 
'unstable-debug'), (103, 'unstable'), (102, 'experimental-debug'), (102, 
'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 5.10.5+ (SMP w/12 CPU threads; PREEMPT)
Kernel taint flags: TAINT_UNSIGNED_MODULE
Locale: LANG=en_CA.UTF-8, LC_CTYPE=en_CA.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_CA:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages clevis-systemd depends on:
ii  clevis-luks  15-4
ii  systemd      247.2-4

clevis-systemd recommends no packages.

clevis-systemd suggests no packages.

-- no debconf information

Reply via email to