Native ffmpeg fails inside the media boundary: missing libblas.so.3 #993

Open
opened 2026-10-03 07:36:54 +00:00 by kayg · 4 comments
Owner

Found during the read-only #988 runtime checks. On both the production container (10.69.69.83) and staging container (10.69.69.192), running the installed media wrapper in encoder-probe mode with its outer nproc cap removed passes namespace setup but fails before ffmpeg starts:

ffmpeg: error while loading shared libraries: libblas.so.3: cannot open shared object file: No such file or directory

No live files or configuration were changed. This is separate from #988's launcher EAGAIN: the fixed JPEG decode succeeds in production after changing only the outer nproc allowance (392-byte WebP). Check Debian alternatives symlinks for BLAS/LAPACK: the media boundary intentionally does not mount host /etc/alternatives. Resolve required public runtime libraries into /opt/calternal/lib at image build time rather than widening the host /etc mount. Add an image-level ffmpeg probe regression and check video thumbnails.

Found during the read-only #988 runtime checks. On both the production container (10.69.69.83) and staging container (10.69.69.192), running the installed media wrapper in `encoder-probe` mode with its outer nproc cap removed passes namespace setup but fails before ffmpeg starts: ``` ffmpeg: error while loading shared libraries: libblas.so.3: cannot open shared object file: No such file or directory ``` No live files or configuration were changed. This is separate from #988's launcher EAGAIN: the fixed JPEG decode succeeds in production after changing only the outer nproc allowance (392-byte WebP). Check Debian alternatives symlinks for BLAS/LAPACK: the media boundary intentionally does not mount host `/etc/alternatives`. Resolve required public runtime libraries into `/opt/calternal/lib` at image build time rather than widening the host `/etc` mount. Add an image-level ffmpeg probe regression and check video thumbnails.
Author
Owner

Read-only production check confirms the library exists outside the boundary but the link crosses an unmounted directory:

/usr/lib/x86_64-linux-gnu/libblas.so.3 -> /etc/alternatives/libblas.so.3-x86_64-linux-gnu
resolved target: /usr/lib/x86_64-linux-gnu/blas/libblas.so.3.12.1

Resolve this public runtime library at image build time; do not expose host /etc to decoders.

Read-only production check confirms the library exists outside the boundary but the link crosses an unmounted directory: ``` /usr/lib/x86_64-linux-gnu/libblas.so.3 -> /etc/alternatives/libblas.so.3-x86_64-linux-gnu resolved target: /usr/lib/x86_64-linux-gnu/blas/libblas.so.3.12.1 ``` Resolve this public runtime library at image build time; do not expose host `/etc` to decoders.
Author
Owner

Starting #993 on job/ffmpegblas-993, based on origin/dev at d4e7188810.

Starting #993 on `job/ffmpegblas-993`, based on origin/dev at d4e7188810a89fb0e8e6b162279917f7e23989f9.
Author
Owner

Reproduced #993 on the cached runtime image with the same outer SYS_ADMIN capability and /proc/* unmask used by deployment: calternal-media-sandbox encoder-probe -- ffmpeg -hide_banner -encoders exits 127 with ffmpeg: error while loading shared libraries: libblas.so.3. ldd /usr/bin/ffmpeg lists both libblas.so.3 and liblapack.so.3; both /usr/lib/x86_64-linux-gnu soname links resolve through /etc/alternatives. I am copying their selected public libraries into /opt/calternal/lib and adding a smoke check that runs the encoder probe and the Files video-thumbnail command against the checked-in MP4 fixture.

Reproduced #993 on the cached runtime image with the same outer `SYS_ADMIN` capability and `/proc/*` unmask used by deployment: `calternal-media-sandbox encoder-probe -- ffmpeg -hide_banner -encoders` exits 127 with `ffmpeg: error while loading shared libraries: libblas.so.3`. `ldd /usr/bin/ffmpeg` lists both `libblas.so.3` and `liblapack.so.3`; both `/usr/lib/x86_64-linux-gnu` soname links resolve through `/etc/alternatives`. I am copying their selected public libraries into `/opt/calternal/lib` and adding a smoke check that runs the encoder probe and the Files video-thumbnail command against the checked-in MP4 fixture.
Author
Owner

Completed #993 on job/ffmpegblas-993.

Built: The runtime image now installs libblas3 and liblapack3, resolves their selected public shared objects into /opt/calternal/lib, and keeps /etc/alternatives outside the media boundary. The deployment build runs an image smoke check for the ffmpeg encoder probe and the Files video-thumbnail command. DESIGN §39 records the library invariant.

Files: deploy/Containerfile.runtime, deploy/deploy-cloud.sh, docs/DESIGN.md, tests/adversarial/test-media-runtime-image.sh.

Head: 0a1aa90bf92373881f4b4f84c79ee89356cd79cd (fix(media): resolve ffmpeg libraries in sandbox).

Gate output:

  • podman build ...: Successfully tagged localhost/calternal-cloud:ffmpegblas-993 (exit 0).
  • tests/adversarial/test-media-runtime-image.sh localhost/calternal-cloud:ffmpegblas-993: exit 0; no output. It found libx264 through encoder-probe and produced a WebP thumbnail from source-generated.mp4 inside the media boundary.
  • Before the fix, the same smoke script against localhost/calternal-cloud:main exited 127 with: ffmpeg: error while loading shared libraries: libblas.so.3: cannot open shared object file: No such file or directory.
  • cargo fmt --check: exit 0; no output.
  • bash -n tests/adversarial/test-media-runtime-image.sh deploy/deploy-cloud.sh and git diff --check: exit 0; no output.
  • Rust clippy and tests were not run because no Rust crate changed.
  • cargo clean: Removed 1 file, 356B total.

Known gaps: The image smoke ran locally on amd64. I did not deploy or run the check on production/staging, and I did not build an arm64 image.

Decisions: DESIGN §39 did not state how to keep Debian's alternatives-selected BLAS/LAPACK libraries available while /etc/alternatives stays hidden. I copy both selected libraries into /opt/calternal/lib, because ldd /usr/bin/ffmpeg showed both dependencies use alternatives symlinks. The smoke container uses the same SYS_ADMIN capability and /proc/* unmask as the deployed runtime.

Completed #993 on `job/ffmpegblas-993`. **Built:** The runtime image now installs `libblas3` and `liblapack3`, resolves their selected public shared objects into `/opt/calternal/lib`, and keeps `/etc/alternatives` outside the media boundary. The deployment build runs an image smoke check for the ffmpeg encoder probe and the Files video-thumbnail command. DESIGN §39 records the library invariant. **Files:** `deploy/Containerfile.runtime`, `deploy/deploy-cloud.sh`, `docs/DESIGN.md`, `tests/adversarial/test-media-runtime-image.sh`. **Head:** `0a1aa90bf92373881f4b4f84c79ee89356cd79cd` (`fix(media): resolve ffmpeg libraries in sandbox`). **Gate output:** - `podman build ...`: `Successfully tagged localhost/calternal-cloud:ffmpegblas-993` (exit 0). - `tests/adversarial/test-media-runtime-image.sh localhost/calternal-cloud:ffmpegblas-993`: exit 0; no output. It found `libx264` through `encoder-probe` and produced a WebP thumbnail from `source-generated.mp4` inside the media boundary. - Before the fix, the same smoke script against `localhost/calternal-cloud:main` exited 127 with: `ffmpeg: error while loading shared libraries: libblas.so.3: cannot open shared object file: No such file or directory`. - `cargo fmt --check`: exit 0; no output. - `bash -n tests/adversarial/test-media-runtime-image.sh deploy/deploy-cloud.sh` and `git diff --check`: exit 0; no output. - Rust clippy and tests were not run because no Rust crate changed. - `cargo clean`: `Removed 1 file, 356B total`. **Known gaps:** The image smoke ran locally on amd64. I did not deploy or run the check on production/staging, and I did not build an arm64 image. **Decisions:** DESIGN §39 did not state how to keep Debian's alternatives-selected BLAS/LAPACK libraries available while `/etc/alternatives` stays hidden. I copy both selected libraries into `/opt/calternal/lib`, because `ldd /usr/bin/ffmpeg` showed both dependencies use alternatives symlinks. The smoke container uses the same `SYS_ADMIN` capability and `/proc/*` unmask as the deployed runtime.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#993
No description provided.