Skip to content

Fix: GLIBC version incompatibility causes orbit agent failure on Ubuntu 20.04 during fleet-desktop update - #38648

Merged
nulmete merged 3 commits into
mainfrom
nulmete/glibc-fleet-desktop-incompatibility-fix
Jan 23, 2026
Merged

Fix: GLIBC version incompatibility causes orbit agent failure on Ubuntu 20.04 during fleet-desktop update#38648
nulmete merged 3 commits into
mainfrom
nulmete/glibc-fleet-desktop-incompatibility-fix

Conversation

@nulmete

@nulmete nulmete commented Jan 22, 2026

Copy link
Copy Markdown
Member

Related issue: Resolves #35413

Applied the same fix as in https://github.com/fleetdm/fleet/pull/29186/files:

  • Added musl-tools to the container image. This provides musl-gcc, a compiler that links against musl libc instead of glibc. We use it for static linking as explained below.
  • Added static linking flags (CGO_ENABLED=1 CC=musl-gcc -linkmode external -extldflags "-static"). This produces a self-contained binary with all C library code embedded, eliminating runtime dependencies on the host system's glibc version.

Checklist for submitter

  • Changes file added for user-visible changes in changes/, orbit/changes/ or ee/fleetd-chrome/changes.
    See Changes files for more information.

Testing

Steps:

  • Started TUF server for the first time. Generated a Linux x86_64 image.
SYSTEMS="linux" \                                      
DEB_FLEET_URL=https://nicofleet.ngrok.io \
DEB_TUF_URL=http://nicotuf.ngrok.io \
GENERATE_DEB=1 \
ENROLL_SECRET=tm2CHBEF1I5BVuM1+4hzRRtpC5ZYV8vb \
FLEET_DESKTOP=1 \
DEBUG=1 \
./tools/tuf/test/main.sh
  • Installed fleet-osquery_26.1.46030_amd64.deb generated by the previous command on a Kubuntu 20.04 x86_64 VM.
  • Ran sudo journalctl -u orbit to debug logs and verified that the GLIBC incompatibility error was raised:
tammi 22 15:36:53 nicolas-Standard-PC-i440FX-PIIX-1996 sudo[125623]: pam_unix(sudo:session): session opened for user nicolas by (uid=0)

tammi 22 15:36:53 nicolas-Standard-PC-i440FX-PIIX-1996 orbit[125624]: /opt/orbit/bin/desktop/linux/stable/fleet-desktop/fleet-desktop: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.32' not found (required by /opt/orbit/bin/desktop/linux/stable/fleet-desktop/fleet-desktop)

tammi 22 15:36:53 nicolas-Standard-PC-i440FX-PIIX-1996 orbit[125624]: /opt/orbit/bin/desktop/linux/stable/fleet-desktop/fleet-desktop: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by /opt/orbit/bin/desktop/linux/stable/fleet-desktop/fleet-desktop)

tammi 22 15:36:53 nicolas-Standard-PC-i440FX-PIIX-1996 sudo[125623]: pam_unix(sudo:session): session closed for user nicolas

tammi 22 15:37:08 nicolas-Standard-PC-i440FX-PIIX-1996 orbit[125199]: 2026-01-22T15:37:08+02:00 INF killing any pre-existing fleet-desktop instances

tammi 22 15:37:09 nicolas-Standard-PC-i440FX-PIIX-1996 orbit[125199]: 2026-01-22T15:37:09+02:00 INF attempting to get user session type and display id=1000 user=nicolas

tammi 22 15:37:09 nicolas-Standard-PC-i440FX-PIIX-1996 orbit[125199]: 2026-01-22T15:37:09+02:00 ERR failed to get X11 display, using default :0 error="display not found on who output"
  • Built a new version of the agent after applying the fixes on this PR and pushed it to the TUF server:
# 1. Hardcode orbit to a higher version
export ORBIT_VERSION=26.1.46099

#2. Generate new package
FLEET_DESKTOP_VERSION=$ORBIT_VERSION make desktop-linux

#3. Update to TUF server
./tools/tuf/test/push_target.sh linux desktop desktop.tar.gz $ORBIT_VERSION
Screenshot 2026-01-22 at 5 18 25 PM
  • In the VM, verified that an update for fleet desktop was detected by running sudo journalctl -u orbit -g "update detected":
tammi 22 20:33:32 nicolas-Standard-PC-i440FX-PIIX-1996 orbit[4114]: 2026-01-22T20:33:32+02:00 INF update detected target=desktop
  • Verified the new version is shown both on the desktop icon and the Fleet UI:
Screenshot 2026-01-22 at 5 22 17 PM Screenshot 2026-01-22 at 5 22 46 PM

fleetd/orbit/Fleet Desktop

  • Verified compatibility with the latest released version of Fleet (see Must rule)
  • If the change applies to only one platform, confirmed that runtime.GOOS is used as needed to isolate changes
  • Verified that fleetd runs on macOS, Linux and Windows
  • Verified auto-update works from the released version of component to the new version (see tools/tuf/test)

@nulmete
nulmete marked this pull request as ready for review January 22, 2026 20:28
@nulmete
nulmete requested a review from a team as a code owner January 22, 2026 20:28

@lucasmrod lucasmrod left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

When moving to "Awaiting QA" let's document that we will need to smoke test fleetd on all supported distributions/versions of Linux.

@nulmete
nulmete merged commit 2a23fe1 into main Jan 23, 2026
11 of 12 checks passed
@nulmete
nulmete deleted the nulmete/glibc-fleet-desktop-incompatibility-fix branch January 23, 2026 15:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

GLIBC version incompatibility causes orbit agent failure on Ubuntu 20.04 during fleet-desktop update

2 participants