Home / Alt manpages / fakeroot-tcp(1)

  • fakeroot-tcp(1)
  • User command
  • linux

Test Root-Owned Archive Metadata Safely with fakeroot-tcp

Packaging scripts love to demand root, and fakeroot-tcp is how you satisfy them without actually handing over the keys. It makes an unprivileged shell see simulated root ownership, so you can build a package or archive with root-looking metadata while your real files stay exactly as owned as before. This is the TCP-backed variant, useful when the SysV IPC build is unavailable.

Allow about fifteen minutes. You need a shell, the fakeroot package, and a writable working directory. The examples use fakeroot 1.33-1, installed here on Ubuntu. They do not need sudo or any elevated privilege.

Safety boundary

Fakeroot does not grant real privileges. It intercepts selected file operations and keeps a fake view for processes using its library. It cannot let you read protected files, change another user's real files, or bypass the kernel's permission checks.

1. Check the installed command

Confirm the executable and package version before relying on an option in a script. This is read-only:

$ command -v fakeroot-tcp
/usr/bin/fakeroot-tcp
$ dpkg-query -W -f='${Package} ${Version}\n' fakeroot
fakeroot 1.33-1
$ fakeroot-tcp --version
fakeroot version 1.33

The installed manpage documents the command as fakeroot, while this executable selects the TCP implementation. Its option syntax is the same for the workflow here. Ask for help if you are working on another host:

$ fakeroot-tcp --help
fakeroot, create a fake root environment.
   usage: fakeroot [-l|--lib fakerootlib] [-f|--faked fakedbin]
                   [-i file] [-s file] [-u|--unknown-is-real]
                   [-b|--fd-base fd] [-h|--help] [-v|--version]
                   [--] [command]

Checkpoint: if the version or help output is missing, stop here and inspect the package installation. Do not copy options from a different fakeroot release without checking its local manual.

2. Create an isolated test directory

Make a temporary directory and keep the path in a shell variable. This avoids mixing fake metadata with a real source tree:

$ work=$(mktemp -d)
$ printf 'package input\n' > "$work/readme.txt"
$ printf 'working directory: %s\n' "$work"
working directory: /tmp/tmp.example

Your temporary path will differ. The redirection creates an ordinary file before fakeroot starts. Check its real owner and mode:

$ stat -c 'before: %u:%g %a %n' "$work/readme.txt"
before: 1004:1004 644 /tmp/tmp.example/readme.txt

The numeric owner is host-specific. The useful check is that it is your account, not a simulated root identity.

3. Observe a fake ownership change

Run one shell inside fakeroot and change the test file's apparent owner. The numeric IDs are deliberately obvious test values. They do not identify a real user or group:

$ fakeroot-tcp -- sh -c 'p=$1
> chown 1234:2345 "$p"
> chmod 600 "$p"
> stat -c "inside: %u:%g %a %n" "$p"' sh "$work/readme.txt"
inside: 1234:2345 600 /tmp/tmp.example/readme.txt
$ stat -c 'after: %u:%g %a %n' "$work/readme.txt"
after: 1004:1004 600 /tmp/tmp.example/readme.txt

The mode change is real because chmod is allowed for the file owner. The ownership shown inside the session is fake. After the session exits, fakeroot's ownership record is gone, so a new ordinary stat sees the real owner again.

Checkpoint: the two owner fields should differ, while the mode remains 600. If your account cannot change the file mode, check that the temporary directory and file belong to you.

4. Build an archive with simulated root metadata

Archive creation is the practical use case. Create a tar archive inside a fresh fakeroot session, after assigning the files the metadata you want the archive to carry:

$ fakeroot-tcp -- sh -c 'chown 0:0 "$1"; chmod 644 "$1"; tar -cf "$2" -C "$(dirname "$1")" "$(basename "$1")"' sh "$work/readme.txt" "$work/package-input.tar"
$ tar -tvf "$work/package-input.tar"
-rw-r--r-- root/root         14 <timestamp> readme.txt

The timestamp will vary, and this example's byte count comes from the sample text. The important fields are root/root and the requested mode. tar reads the fake metadata while it is inside the fakeroot process tree, so the archive can contain root ownership without the source file becoming root-owned on disk.

Do not use this to conceal an unsafe build. Archive metadata is not proof that the package contents are trustworthy, and fakeroot does not sandbox the command. Review the files and build process separately.

5. Verify the real source and the archive separately

Check the source file after the fakeroot process has ended, then inspect the archive contents. These are two different claims:

$ stat -c 'source: %u:%g %a %n' "$work/readme.txt"
source: 1004:1004 644 /tmp/tmp.example/readme.txt
$ tar --numeric-owner -tvf "$work/package-input.tar"
-rw-r--r-- 0/0             14 <timestamp> readme.txt

Use the second command when you want numeric IDs rather than the names in the local account database. A successful exit status from fakeroot-tcp only means that the child command completed successfully. It does not validate every archive member or permission, so inspect the result you intend to distribute.

6. Keep the fake session's boundaries clear

Put the complete operation under one invocation. Starting a second fakeroot-tcp command does not automatically inherit the first command's fake ownership database. If you need a longer workflow, run a shell or build command as the child and keep all metadata-sensitive operations in that process tree.

Options before the command belong to fakeroot. Arguments after the command belong to the child. Use -- when the child command begins with options that could confuse option parsing:

$ fakeroot-tcp -- sh -c 'id; stat -c "%u:%g %a %n" "$1"' sh "$work/readme.txt"
uid=1004(user) gid=1004(user) groups=1004(user)
1004:1004 644 /tmp/tmp.example/readme.txt

The exact id output is host-specific. Seeing your real UID there is expected: fakeroot changes selected file-operation results, not the process's kernel identity.

7. Avoid the common traps

  • Do not run the compiler or configure stage inside fakeroot unless the build documentation specifically requires it. The manual warns that system-probing programs can become confused when file behaviour is simulated. Build first, then package with fakeroot where appropriate.
  • Do not test access control by assuming a fake root shell can read a protected path. It cannot provide real access, and trying it against sensitive files adds no useful evidence.
  • Remember that fakeroot does not wrap every operation. In particular, a file created outside the session can be treated as unknown when inspected inside it. Create and inspect metadata-sensitive files within the same session.
  • Do not treat fake ownership as persistent state. If a later command must see the same metadata, use one invocation or the documented -s and -i save and load options. Saved state files need careful handling and should not be shared casually.

8. Clean up the test files

The test directory contains no system files, but remove it when you have checked the archive. This is the only destructive command in the guide:

$ rm -- "$work/readme.txt" "$work/package-input.tar"
$ rmdir -- "$work"
$ test ! -e "$work" && echo 'temporary test directory removed'
temporary test directory removed

If you need to examine the archive again, do not run the cleanup yet. If a removal command fails, inspect the directory with find "$work" -maxdepth 1 -type f -print and remove only the files you recognise.

Done means

  • You verified the installed fakeroot package and TCP executable version.
  • You observed fake ownership inside a session and real ownership afterwards.
  • You created an archive whose metadata says root/root without using root privileges.
  • You checked archive contents independently of the command's exit status.
  • You kept builds, protected files and persistent system configuration outside the test.