Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 282021 - sys-apps/groff failes to merge because of sandbox access violations
Summary: sys-apps/groff failes to merge because of sandbox access violations
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: x86 Linux
: High normal (vote)
Assignee: Gentoo's Team for Core System packages
URL:
Whiteboard:
Keywords:
: 282034 (view as bug list)
Depends on:
Blocks:
 
Reported: 2009-08-19 13:40 UTC by Steffen Hau
Modified: 2009-08-28 12:13 UTC (History)
6 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Solves the issue with sandbox access violations (groff-sandbox-ebuild.patch,397 bytes, patch)
2009-08-19 14:23 UTC, Steffen Hau
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Steffen Hau 2009-08-19 13:40:43 UTC
I tried to recompile @system after gcc upgrade and when it comes to emerge sys-apps/groff-1.20.1-r1 it failes with a sandbox access violation.

>>> Source compiled.
--------------------------- ACCESS VIOLATION SUMMARY ---------------------------
LOG FILE "/var/log/sandbox/sandbox-14024.log"

VERSION 1.0
FORMAT: F - Function called
FORMAT: S - Access Status
FORMAT: P - Path as passed to function
FORMAT: A - Absolute Path (not canonical)
FORMAT: R - Canonical Path
FORMAT: C - Command Line

F: chmod
S: deny
P: /var/cache/fontconfig
A: /var/cache/fontconfig
R: /var/cache/fontconfig
C: gs -q -dBATCH -dSAFER -dDEVICEHEIGHTPOINTS=792 -dDEVICEWIDTHPOINTS=700 -dFIXEDMEDIA=true -sDEVICE=pnmraw -r100 -dTextAlphaBits=4 -dGraphicsAlphaBits=4 -sOutputFile=/var/tmp/portage/sys-apps/groff-1.20.1-r1/temp/groff-page-0lm5ci /var/tmp/portage/sys-apps/groff-1.20.1-r1/temp/groff-ps-nIzmif - 

F: chmod
S: deny
P: /var/cache/fontconfig
A: /var/cache/fontconfig
R: /var/cache/fontconfig
C: gs -q -dBATCH -dSAFER -dDEVICEHEIGHTPOINTS=792 -dDEVICEWIDTHPOINTS=700 -dFIXEDMEDIA=true -sDEVICE=pnmraw -r100 -dTextAlphaBits=4 -dGraphicsAlphaBits=4 -sOutputFile=/var/tmp/portage/sys-apps/groff-1.20.1-r1/temp/groff-page-0lm5ci /var/tmp/portage/sys-apps/groff-1.20.1-r1/temp/groff-ps-nIzmif - 

F: chmod
S: deny
P: /var/cache/fontconfig
A: /var/cache/fontconfig
R: /var/cache/fontconfig
C: gs -q -dBATCH -dSAFER -dDEVICEHEIGHTPOINTS=792 -dDEVICEWIDTHPOINTS=700 -dFIXEDMEDIA=true -sDEVICE=pnmraw -r100 -dTextAlphaBits=4 -dGraphicsAlphaBits=4 -sOutputFile=/var/tmp/portage/sys-apps/groff-1.20.1-r1/temp/groff-page-0lm5ci /var/tmp/portage/sys-apps/groff-1.20.1-r1/temp/groff-ps-nIzmif - 
--------------------------------------------------------------------------------


Reproducible: Always

Steps to Reproduce:
1. emerge sys-apps/groff-1.20.1-r1 with FEATURES="sandbox"
2.
3.

Actual Results:  
Failes to merge


Portage 2.2_rc38 (default/linux/x86/10.0, gcc-4.4.1, glibc-2.10.1-r0, 2.6.31-rc6-HAUIHAU i686)
=================================================================
System uname: Linux-2.6.31-rc6-HAUIHAU-i686-Intel-R-_Core-TM-2_CPU_T7200_@_2.00GHz-with-gentoo-2.0.1
Timestamp of tree: Tue, 18 Aug 2009 09:30:20 +0000
ccache version 2.4 [enabled]
app-shells/bash:     4.0_p28
dev-java/java-config: 2.1.8-r1
dev-lang/python:     2.6.2-r1, 3.1.1
dev-util/ccache:     2.4-r8
dev-util/cmake:      2.6.4-r2
sys-apps/baselayout: 2.0.1
sys-apps/openrc:     0.4.3-r3
sys-apps/sandbox:    2.0
sys-devel/autoconf:  2.13, 2.63-r1
sys-devel/automake:  1.9.6-r2, 1.10.2, 1.11
sys-devel/binutils:  2.19.1-r1
sys-devel/gcc-config: 1.4.1
sys-devel/libtool:   2.2.6a
virtual/os-headers:  2.6.30-r1
ACCEPT_KEYWORDS="x86 ~x86"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-march=core2 -O2 -pipe -fomit-frame-pointer -mfpmath=sse -msse3"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/config /var/lib/hsqldb"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/env.d/java/ /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/php/apache2-php5/ext-active/ /etc/php/cgi-php5/ext-active/ /etc/php/cli-php5/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo /etc/texmf/language.dat.d /etc/texmf/language.def.d /etc/texmf/updmap.d /etc/texmf/web2c /etc/udev/rules.d"
CXXFLAGS="-march=core2 -O2 -pipe -fomit-frame-pointer -mfpmath=sse -msse3"
DISTDIR="/usr/portage/distfiles"
FEATURES="assume-digests ccache distlocks fakeroot fixpackages metadata-transfer parallel-fetch preserve-libs protect-owned sandbox sfperms strict unmerge-logs unmerge-orphans userfetch userpriv usersandbox"
GENTOO_MIRRORS="http://mirrors.sec.informatik.tu-darmstadt.de/gentoo/ ftp://sunsite.informatik.rwth-aachen.de/pub/Linux/gentoo/ "
LANG="de_DE.utf8"
LC_ALL="de_DE.utf8"
LDFLAGS="-Wl,-O1 -Wl,--as-needed -Wl,-znow -Wl,--sort-common -s"
LINGUAS="de"
MAKEOPTS="-j4"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage/layman/sectools /usr/local/portage/layman/gnome /usr/local/portage/layman/hauihau"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="X aac aalib accessibility acl acpi alsa apache2 bash-completion berkdb bidi bluetooth branding bzip2 cairo cdb cdda cddb cdparanoia cdr cli cracklib crypt ctype cups curl dbus dedicated dga directfb doc dri dts dv dvd dvdr dvdread encode examples exif ffmpeg firefox flac fontconfig foomaticdb fortran ftp gdbm gif glitz glut gmp gnome gnome-keyring gnutls gphoto2 gstreamer gtk gtk2 hal htmlhandbook iconv ieee1394 imagemagick imap imlib innodb ipod ipv6 isdnlog java java5 java6 javascript jpeg jpeg2k lame lcms ldap libcaca libnotify libsamplerate lua mad mikmod mmap mmx mng mono mp3 mpeg mplayer mudflap musepack musicbrainz mysql ncurses nls noseamonkey nptl nptlonly nsplugin offensive ogg openal opengl openmp oscar pam pcmcia pcre pdf perl php plasma png policykit posix ppds pppd python qt4 quicktime readline reflection rss rtc ruby samba sasl sdl session sndfile snmp sockets spell spl sqlite sse sse2 ssl startup-notification subversion svg sysfs tcl tcpd theora threads tiff tk truetype unicode usb userlocales v4l2 vcd vim-syntax visualization vorbis win32codecs x264 x86 xattr xcb xcomposite xine xinerama xml xorg xosd xpm xscreensaver xulrunner xv xvid yahoo zlib" ALSA_CARDS="hda-intel" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="actions alias auth_basic auth_digest authn_anon authn_dbd authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache dav dav_fs dav_lock dbd deflate dir disk_cache env expires ext_filter file_cache filter headers ident imagemap include info log_config logio mem_cache mime mime_magic negotiation proxy proxy_ajp proxy_balancer proxy_connect proxy_ftp proxy_http rewrite setenvif so speling status substitute unique_id userdir usertrack version vhost_alias" APACHE2_MPMS="worker" CAMERAS="canon casio_qv fuji kodak konica minolta mustek panasonic samsung sonydscf1 sonydscf55 toshiba" ELIBC="glibc" INPUT_DEVICES="evdev keyboard mouse synaptics" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LINGUAS="de" USERLAND="GNU" VIDEO_CARDS="radeon radeonhd"
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, FFLAGS, INSTALL_MASK, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS
Comment 1 Steffen Hau 2009-08-19 14:23:06 UTC
Created attachment 201710 [details, diff]
Solves the issue with sandbox access violations

I tried to dig this issue a bit down. This violation occurs, when gs is called from pre-grohtml in the compile phase of groff. I found another bug (http://bugs.gentoo.org/show_bug.cgi?id=278221), where fontconfig is the cause of the problem. According to this bug, they added an addpredict foer /var/cache/fontconfig and resolved the sandbox violations. The appended patch for the ebuild solves this issue for me.
Comment 2 Patrick Lauer gentoo-dev 2009-08-19 17:21:59 UTC
*** Bug 282034 has been marked as a duplicate of this bug. ***
Comment 3 Samuli Suominen (RETIRED) gentoo-dev 2009-08-19 17:23:40 UTC
dirtyepic, related to recent fontconfig bump?
Comment 4 Krzysztof Magusiak 2009-08-19 18:32:37 UTC
(In reply to comment #1)
> Created an attachment (id=201710) [edit]
> Solves the issue with sandbox access violations
> 
> I tried to dig this issue a bit down. This violation occurs, when gs is called
> from pre-grohtml in the compile phase of groff. I found another bug
> (http://bugs.gentoo.org/show_bug.cgi?id=278221), where fontconfig is the cause
> of the problem. According to this bug, they added an addpredict foer
> /var/cache/fontconfig and resolved the sandbox violations. The appended patch
> for the ebuild solves this issue for me.
> 

Solves the issue for me too.
Comment 5 Ryan Hill (RETIRED) gentoo-dev 2009-08-20 02:11:01 UTC
yes.  i was actually going to file this bug yesterday but then it mysteriously started working again for me. :P

so, why is gs chmoding /var/cache/fontconfig, and why is groff using gs when ghostscript isn't a dependency?
Comment 6 Gregg Casillo 2009-08-21 23:11:14 UTC
Steffan's patch worked for me. Thanks!
Comment 7 Andrew Savchenko gentoo-dev 2009-08-22 20:20:47 UTC
Thanks, patch helps me to on ~x86.
Comment 8 Ryan Hill (RETIRED) gentoo-dev 2009-08-23 22:50:26 UTC
fixed in fontconfig-2.7.1-r1.
Comment 9 Martin Mokrejš 2009-08-28 12:13:03 UTC
Yes, current tree is fixed (am on ~x86):

# emerge -pv groff fontconfig

These are the packages that would be merged, in order:

Calculating dependencies... done!
[ebuild   R   ] sys-apps/groff-1.20.1-r1  USE="X -examples" LINGUAS="-ja" 0 kB
[ebuild   R   ] media-libs/fontconfig-2.7.1-r1  USE="-doc" 0 kB