[Bug 281995] IDS errors after upgrading from 14.0 to 14.1-RELEASE amd64

From: <bugzilla-noreply_at_freebsd.org>
Date: Thu, 10 Oct 2024 17:46:36 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281995

            Bug ID: 281995
           Summary: IDS errors after upgrading from 14.0 to 14.1-RELEASE
                    amd64
           Product: Base System
           Version: 14.1-RELEASE
          Hardware: amd64
                OS: Any
            Status: New
          Severity: Affects Only Me
          Priority: ---
         Component: bin
          Assignee: bugs@FreeBSD.org
          Reporter: zldrobit@gmail.com

Created attachment 254141
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=254141&action=edit
IDS from AWS lightsail

I am upgrading two FreeBSD amd64 servers from 14.0-RELEASE-p11 to
14.1-RELEASE-p5, and one FreeBSD amd64 AWS lightsail VPS from 14.1-RELEASE to
14.1-RELEASE-p5. All succeeded after running 'freebsd-update upgrade/install'
and some reboots. However, all the IDS check didn't passed, e.g. the output of
'freebsd-update IDS > outfile.ids; grep zfs outfile.ids' is

/boot/kernel/zfs.ko has 0555 permissions, but should have 0444
permissions./boot/kernel/zfs.ko has 0555 permissions, but should have 0444
permissions./boot/kernel/zfs.ko has SHA256 hash
4e944f4cdd86d0ad0d1ac5f6c7eaf98f7e63db4c65c43a3f31e022c967162546, but should
have SHA256 hash
96738b0cc44a1e09a00073a41e26e77a4608c07e392edbf43c3d8c0ce7d0fa20./usr/lib/debug/boot/kernel/zfs.ko.debug
has 0555 permissions, but should have 0444
permissions./usr/lib/debug/boot/kernel/zfs.ko.debug has 0555 permissions, but
should have 0444 permissions./usr/lib/debug/boot/kernel/zfs.ko.debug has SHA256
hash a353a4d17ce825b700c910a71ad7c852fcb1769b90593894a5be89a553ab16b4, but
should have SHA256 hash
b184c113c8fc85be36c55eb806c6837b3d3c20a7535cd2e8ee0906cb725cfc6d.

The full IDS output file from the AWS VPS and a FreeBSD desktop are attached.
PS: I cannot reproduce this situation by updating FreeBSD aarch64 from 14.1 to
14.1-RELEASE-p5.

-- 
You are receiving this mail because:
You are the assignee for the bug.