Bug#1148926: udev: static_node parsing logic accidentally drops folder execution bit (0660) on /dev/snd
root
noj.unk at hotmail.com
Fri Sep 25 10:10:11 BST 2026
Package: systemd
Version: 257.13-1~deb13u1
Severity: normal
-- Package-specific info:
Dear Maintainers,
I have encountered an environment boundary bug where unprivileged daemon system users (specifically those belonging to the 'audio' group, such as '_snapserver') are entirely blocked from initializing standard ALSA hardware handles because the parent path /dev/snd/ is deployed missing its execution permissions bit (drw-rw----).
*** Steps to reproduce:
1. Attempt to execute an audio trace from a standard nologin daemon system account that relies on the 'audio' group:
root at pbsx:~ # cd /tmp
root at pbsx:/tmp # runuser -u _snapserver -- arecord -D hw:0,0 --duration=1 /dev/null
*** Actual Results:
ALSA lib confmisc.c:165:(snd_config_get_card) Cannot get card index for 0
arecord: main:850: audio open error: No such file or directory
*** Diagnosed Cause:
Checking the parent tree metrics reveals that the device mapping framework drops the folder execution permission gate:
root at pbsx:/tmp # ls -ld /dev/snd/
drw-rw---- 3 root root 280 /dev/snd/
Because the directory lacks execute ('x') permissions, the kernel throws an immediate EACCES (Permission denied) whenever an unprivileged process profile triggers an internal 'openat' lookups for downstream hardware handles like /dev/snd/controlC0—even if that user has explicit group ownership over the file itself.
This relates directly to the static allocation parser routines linked to /lib/udev/rules.d/50-udev-default.rules:
SUBSYSTEM=="sound", GROUP="audio", OPTIONS+="static_node=snd/seq", OPTIONS+="static_node=snd/timer"
When the udev template initializes the parent structures to stage 'snd/seq' and 'snd/timer' placeholders, its internal fallback mechanism defaults the directory node layout to a file boundary mask of 0660 instead of preserving standard directory traversal privileges (0755).
*** Suggested Structural Correction:
Please ensure that the template generation script or the target static-nodes-permissions.conf output configuration natively enforces standard directory traversal privileges ('d /dev/snd 0755 root root -') so daemon threads are not locked away from utilizing their designated group credentials.
-- System Information:
Debian Release: 13.7
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 7.0.14-19-pve (SMP w/8 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
Versions of packages systemd depends on:
ii libacl1 2.3.2-2+b1
ii libapparmor1 4.1.1-pmx1
ii libc6 2.41-12+deb13u4
ii libmount1 2.41.5-0+deb13u1
ii libpam0g 1.7.0-5
ii libseccomp2 2.6.0-2
ii libselinux1 3.8.1-1
ii libssl3t64 3.5.7-1~deb13u2
ii libsystemd-shared 257.13-1~deb13u1
ii libsystemd0 257.13-1~deb13u1
ii mount 2.41.5-0+deb13u1
Versions of packages systemd recommends:
ii chrony [time-daemon] 4.8-4~bpo13+2
ii dbus [default-dbus-system-bus] 1.16.2-2
ii linux-sysctl-defaults 4.12.1
ii systemd-cryptsetup 257.13-1~deb13u1
Versions of packages systemd suggests:
pn libtss2-tcti-device0 <none>
pn polkitd <none>
pn systemd-boot <none>
pn systemd-container <none>
pn systemd-homed <none>
pn systemd-repart <none>
pn systemd-resolved <none>
pn systemd-userdbd <none>
Versions of packages systemd is related to:
pn dbus-user-session <none>
pn dracut <none>
ii initramfs-tools 0.148.4
ii libnss-systemd 257.13-1~deb13u1
ii libpam-systemd 257.13-1~deb13u1
ii udev 257.13-1~deb13u1
-- no debconf information
More information about the Pkg-systemd-maintainers
mailing list