I tried to recompile @system after gcc upgrade and when it comes to emerge sys-apps/groff-1.20.1-r1 it failes with a sandbox access violation. >>> Source compiled. --------------------------- ACCESS VIOLATION SUMMARY --------------------------- LOG FILE "/var/log/sandbox/sandbox-14024.log" VERSION 1.0 FORMAT: F - Function called FORMAT: S - Access Status FORMAT: P - Path as passed to function FORMAT: A - Absolute Path (not canonical) FORMAT: R - Canonical Path FORMAT: C - Command Line F: chmod S: deny P: /var/cache/fontconfig A: /var/cache/fontconfig R: /var/cache/fontconfig C: gs -q -dBATCH -dSAFER -dDEVICEHEIGHTPOINTS=792 -dDEVICEWIDTHPOINTS=700 -dFIXEDMEDIA=true -sDEVICE=pnmraw -r100 -dTextAlphaBits=4 -dGraphicsAlphaBits=4 -sOutputFile=/var/tmp/portage/sys-apps/groff-1.20.1-r1/temp/groff-page-0lm5ci /var/tmp/portage/sys-apps/groff-1.20.1-r1/temp/groff-ps-nIzmif - F: chmod S: deny P: /var/cache/fontconfig A: /var/cache/fontconfig R: /var/cache/fontconfig C: gs -q -dBATCH -dSAFER -dDEVICEHEIGHTPOINTS=792 -dDEVICEWIDTHPOINTS=700 -dFIXEDMEDIA=true -sDEVICE=pnmraw -r100 -dTextAlphaBits=4 -dGraphicsAlphaBits=4 -sOutputFile=/var/tmp/portage/sys-apps/groff-1.20.1-r1/temp/groff-page-0lm5ci /var/tmp/portage/sys-apps/groff-1.20.1-r1/temp/groff-ps-nIzmif - F: chmod S: deny P: /var/cache/fontconfig A: /var/cache/fontconfig R: /var/cache/fontconfig C: gs -q -dBATCH -dSAFER -dDEVICEHEIGHTPOINTS=792 -dDEVICEWIDTHPOINTS=700 -dFIXEDMEDIA=true -sDEVICE=pnmraw -r100 -dTextAlphaBits=4 -dGraphicsAlphaBits=4 -sOutputFile=/var/tmp/portage/sys-apps/groff-1.20.1-r1/temp/groff-page-0lm5ci /var/tmp/portage/sys-apps/groff-1.20.1-r1/temp/groff-ps-nIzmif - -------------------------------------------------------------------------------- Reproducible: Always Steps to Reproduce: 1. emerge sys-apps/groff-1.20.1-r1 with FEATURES="sandbox" 2. 3. Actual Results: Failes to merge Portage 2.2_rc38 (default/linux/x86/10.0, gcc-4.4.1, glibc-2.10.1-r0, 2.6.31-rc6-HAUIHAU i686) ================================================================= System uname: Linux-2.6.31-rc6-HAUIHAU-i686-Intel-R-_Core-TM-2_CPU_T7200_@_2.00GHz-with-gentoo-2.0.1 Timestamp of tree: Tue, 18 Aug 2009 09:30:20 +0000 ccache version 2.4 [enabled] app-shells/bash: 4.0_p28 dev-java/java-config: 2.1.8-r1 dev-lang/python: 2.6.2-r1, 3.1.1 dev-util/ccache: 2.4-r8 dev-util/cmake: 2.6.4-r2 sys-apps/baselayout: 2.0.1 sys-apps/openrc: 0.4.3-r3 sys-apps/sandbox: 2.0 sys-devel/autoconf: 2.13, 2.63-r1 sys-devel/automake: 1.9.6-r2, 1.10.2, 1.11 sys-devel/binutils: 2.19.1-r1 sys-devel/gcc-config: 1.4.1 sys-devel/libtool: 2.2.6a virtual/os-headers: 2.6.30-r1 ACCEPT_KEYWORDS="x86 ~x86" CBUILD="i686-pc-linux-gnu" CFLAGS="-march=core2 -O2 -pipe -fomit-frame-pointer -mfpmath=sse -msse3" CHOST="i686-pc-linux-gnu" CONFIG_PROTECT="/etc /usr/share/config /var/lib/hsqldb" CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/env.d/java/ /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/php/apache2-php5/ext-active/ /etc/php/cgi-php5/ext-active/ /etc/php/cli-php5/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo /etc/texmf/language.dat.d /etc/texmf/language.def.d /etc/texmf/updmap.d /etc/texmf/web2c /etc/udev/rules.d" CXXFLAGS="-march=core2 -O2 -pipe -fomit-frame-pointer -mfpmath=sse -msse3" DISTDIR="/usr/portage/distfiles" FEATURES="assume-digests ccache distlocks fakeroot fixpackages metadata-transfer parallel-fetch preserve-libs protect-owned sandbox sfperms strict unmerge-logs unmerge-orphans userfetch userpriv usersandbox" GENTOO_MIRRORS="http://mirrors.sec.informatik.tu-darmstadt.de/gentoo/ ftp://sunsite.informatik.rwth-aachen.de/pub/Linux/gentoo/ " LANG="de_DE.utf8" LC_ALL="de_DE.utf8" LDFLAGS="-Wl,-O1 -Wl,--as-needed -Wl,-znow -Wl,--sort-common -s" LINGUAS="de" MAKEOPTS="-j4" PKGDIR="/usr/portage/packages" PORTAGE_CONFIGROOT="/" PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages" PORTAGE_TMPDIR="/var/tmp" PORTDIR="/usr/portage" PORTDIR_OVERLAY="/usr/local/portage/layman/sectools /usr/local/portage/layman/gnome /usr/local/portage/layman/hauihau" SYNC="rsync://rsync.gentoo.org/gentoo-portage" USE="X aac aalib accessibility acl acpi alsa apache2 bash-completion berkdb bidi bluetooth branding bzip2 cairo cdb cdda cddb cdparanoia cdr cli cracklib crypt ctype cups curl dbus dedicated dga directfb doc dri dts dv dvd dvdr dvdread encode examples exif ffmpeg firefox flac fontconfig foomaticdb fortran ftp gdbm gif glitz glut gmp gnome gnome-keyring gnutls gphoto2 gstreamer gtk gtk2 hal htmlhandbook iconv ieee1394 imagemagick imap imlib innodb ipod ipv6 isdnlog java java5 java6 javascript jpeg jpeg2k lame lcms ldap libcaca libnotify libsamplerate lua mad mikmod mmap mmx mng mono mp3 mpeg mplayer mudflap musepack musicbrainz mysql ncurses nls noseamonkey nptl nptlonly nsplugin offensive ogg openal opengl openmp oscar pam pcmcia pcre pdf perl php plasma png policykit posix ppds pppd python qt4 quicktime readline reflection rss rtc ruby samba sasl sdl session sndfile snmp sockets spell spl sqlite sse sse2 ssl startup-notification subversion svg sysfs tcl tcpd theora threads tiff tk truetype unicode usb userlocales v4l2 vcd vim-syntax visualization vorbis win32codecs x264 x86 xattr xcb xcomposite xine xinerama xml xorg xosd xpm xscreensaver xulrunner xv xvid yahoo zlib" ALSA_CARDS="hda-intel" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="actions alias auth_basic auth_digest authn_anon authn_dbd authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache dav dav_fs dav_lock dbd deflate dir disk_cache env expires ext_filter file_cache filter headers ident imagemap include info log_config logio mem_cache mime mime_magic negotiation proxy proxy_ajp proxy_balancer proxy_connect proxy_ftp proxy_http rewrite setenvif so speling status substitute unique_id userdir usertrack version vhost_alias" APACHE2_MPMS="worker" CAMERAS="canon casio_qv fuji kodak konica minolta mustek panasonic samsung sonydscf1 sonydscf55 toshiba" ELIBC="glibc" INPUT_DEVICES="evdev keyboard mouse synaptics" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LINGUAS="de" USERLAND="GNU" VIDEO_CARDS="radeon radeonhd" Unset: CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, FFLAGS, INSTALL_MASK, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS
Created attachment 201710 [details, diff] Solves the issue with sandbox access violations I tried to dig this issue a bit down. This violation occurs, when gs is called from pre-grohtml in the compile phase of groff. I found another bug (http://bugs.gentoo.org/show_bug.cgi?id=278221), where fontconfig is the cause of the problem. According to this bug, they added an addpredict foer /var/cache/fontconfig and resolved the sandbox violations. The appended patch for the ebuild solves this issue for me.
*** Bug 282034 has been marked as a duplicate of this bug. ***
dirtyepic, related to recent fontconfig bump?
(In reply to comment #1) > Created an attachment (id=201710) [edit] > Solves the issue with sandbox access violations > > I tried to dig this issue a bit down. This violation occurs, when gs is called > from pre-grohtml in the compile phase of groff. I found another bug > (http://bugs.gentoo.org/show_bug.cgi?id=278221), where fontconfig is the cause > of the problem. According to this bug, they added an addpredict foer > /var/cache/fontconfig and resolved the sandbox violations. The appended patch > for the ebuild solves this issue for me. > Solves the issue for me too.
yes. i was actually going to file this bug yesterday but then it mysteriously started working again for me. :P so, why is gs chmoding /var/cache/fontconfig, and why is groff using gs when ghostscript isn't a dependency?
Steffan's patch worked for me. Thanks!
Thanks, patch helps me to on ~x86.
fixed in fontconfig-2.7.1-r1.
Yes, current tree is fixed (am on ~x86): # emerge -pv groff fontconfig These are the packages that would be merged, in order: Calculating dependencies... done! [ebuild R ] sys-apps/groff-1.20.1-r1 USE="X -examples" LINGUAS="-ja" 0 kB [ebuild R ] media-libs/fontconfig-2.7.1-r1 USE="-doc" 0 kB