Package builds need to act as root without being root, and faked-sysv is the quiet daemon behind fakeroot that makes the pretence stick. This guide runs a harmless ownership test inside fakeroot, confirms the real file stays unchanged, and shows where faked-sysv fits. The installed package here is fakeroot 1.33-1. Its faked-sysv program is the SysV IPC daemon that remembers fake ownership and permission metadata for a fakeroot process.
Allow about ten minutes. You need a shell, the fakeroot package, and a writable temporary directory. The test does not need sudo. It changes only a temporary file's in-process view of its metadata, not the file's real ownership.
Check the wrapper, the daemon selected by this installation, and the package version. These are ordinary read-only commands:
$ command -v fakeroot
/usr/bin/fakeroot
$ command -v faked-sysv
/usr/bin/faked-sysv
$ dpkg-query -W -f='${Package} ${Version}\n' fakeroot
fakeroot 1.33-1
$ fakeroot --version
fakeroot version 1.33
The local package provides faked-sysv; it does not provide a command named simply faked in PATH. The manual page uses faked as the daemon's generic name and is also installed under the canonical faked-sysv(1) name.
Checkpoint: if fakeroot --version fails, stop here and repair the package installation. Do not download a replacement daemon or copy one from another host.
Make a directory under /tmp and record the file's real numeric owner and group. Use a path you own, rather than placing test files in a package or service directory:
$ test_dir=$(mktemp -d /tmp/fakeroot-guide.XXXXXX)
$ touch "$test_dir/sample"
$ printf 'real before: '
$ stat -c '%u:%g %n' "$test_dir/sample"
real before: 1004:1004 /tmp/fakeroot-guide.XXXXXX/sample
Your user and directory suffix will differ. The useful part is the numeric pair. Keep the path in test_dir for the remaining commands. This test creates state in /tmp; remove that directory yourself after checking the result, once you are certain it contains nothing you need.
Run a shell through fakeroot and ask it to assign an obviously synthetic owner. The command uses no elevated privileges:
$ fakeroot sh -c 'chown 1234:2345 "$1"; printf "fake inside: "; stat -c "%u:%g %n" "$1"' sh "$test_dir/sample"
fake inside: 1234:2345 /tmp/fakeroot-guide.XXXXXX/sample
The first sh is the shell's $0 value. The pathname is passed separately as $1, so spaces or shell metacharacters in the path are not accidentally interpreted. The synthetic IDs do not need to exist in /etc/passwd or /etc/group.
During this command, the wrapped stat asks the daemon for the fake metadata. The daemon remembers the requested owner for that fakeroot session; it does not grant the shell real root powers and it does not write a new owner to the filesystem.
Inspect the same file outside fakeroot:
$ printf 'real after: '
$ stat -c '%u:%g %n' "$test_dir/sample"
real after: 1004:1004 /tmp/fakeroot-guide.XXXXXX/sample
The output should match the real owner recorded in step 2, not 1234:2345. This is the key boundary: fakeroot makes selected programs report fake metadata, while the kernel still enforces your actual permissions.
If the real owner changed, stop using the test recipe and investigate. A correctly functioning unprivileged fakeroot run should not be able to perform a real arbitrary chown. Do not try to correct the file with sudo until you have established what changed and why.
Normally you do not start faked-sysv by hand. The fakeroot wrapper creates or selects the communication channel and starts the appropriate backend for the session. faked-sysv then remembers fake ownership, permissions and related metadata when the wrapped process asks for them.
The daemon's own options are for session plumbing and diagnostics:
--foreground keeps it in the foreground instead of forking.--debug writes diagnostic information to standard error.--key selects a SysV communication key, creating the channel if it does not exist.--cleanup cleans up semaphores and accepts a number.--save-file, --load and --port alter how session state is saved, loaded or transported.These options are not a normal service configuration. A manually launched daemon can collide with an existing session, leave IPC resources behind, or expose a communication endpoint more widely than intended. Use the wrapper's documented interface unless you are debugging fakeroot itself and have an explicit recovery plan.
Fakeroot's wrapper exposes -s to save session state and -i to load it. That is separate from saving a daemon environment directly with faked-sysv --save-file. If a build genuinely needs ownership state across commands, keep the state file private and in a temporary or controlled build directory:
$ state_file="$test_dir/fakeroot.state"
$ fakeroot -s "$state_file" sh -c 'chown 1234:2345 "$1"' sh "$test_dir/sample"
$ test -s "$state_file" && echo 'state file created'
state file created
Do not load a state file from an untrusted checkout. It is session data, not a harmless text configuration file. Do not put it in a shared directory or make it world-readable. If you do not need persistence, omit -s and -i; the simplest session has the smallest amount of state to retain.
A fake owner is not a privilege escalation. Programs can still fail when they need real access to a file, bind a restricted port, use a capability, or perform an operation that fakeroot does not wrap. Run the build as the intended unprivileged account and treat errors from the real kernel as real errors.
Do not compare a stat run inside and outside fakeroot without checking which shell launched it. The fake view exists only in the wrapped process tree and its daemon session. A separate ordinary stat sees the filesystem's actual metadata.
Finally, do not assume the SysV backend is interchangeable with a TCP backend. This guide covers the installed faked-sysv implementation. If a script selects another daemon explicitly, read that daemon's manual and check its transport and cleanup behaviour before reusing these examples.
fakeroot 1.33 and faked-sysv were found in the installed package.sudo, and no service or system configuration was changed.