<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>95292</bug_id>
          
          <creation_ts>2005-06-06 20:57 0000</creation_ts>
          <short_desc>nullmailer-1.00 ebuild gets sandbox violation doing chmod on mailq symlink</short_desc>
          <delta_ts>2005-11-29 12:30:00 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Unspecified</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <keywords>Inclusion</keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>sllewbj@blueyonder.co.uk</reporter>
          <assigned_to>net-mail@gentoo.org</assigned_to>
          <cc>dragonheart@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>sllewbj@blueyonder.co.uk</who>
            <bug_when>2005-06-06 20:57:48 0000</bug_when>
            <thetext>The nullmailer-1.00 ebuild gets a sandbox violation when it tries to do chmod on
the /usr/bin/mailq symlink in the build area.  This symlink properly points to
/usr/sbin/sendmail (i.e., a real absolute path outside of the sandbox), as it
should when the mailwrapper USE flag is on.  Doing chmod on a symlink is a bit
odd, but it seems that this line in the ebuild is intended for the case when
/usr/bin/mailq is a real file.

Reproducible: Always
Steps to Reproduce:
1.emerge nullmailer


Actual Results:  
The ebuild failed with a sandbox violation.

Expected Results:  
Nullmailer should have been successfully emerged.

Here are the error lines from the emerge output (the first and 4th line are the
surrounding context, lines 2 and 3 are the error):

---------------------------------------------------------
make[1]: Leaving directory
`/extra/var/tmp/portage/nullmailer-1.00/work/nullmailer-1.00&apos;
ACCESS DENIED   chmod:    
/extra/var/tmp/portage/nullmailer-1.00/image/usr/bin/mailq
chmod: changing permissions of
`/extra/var/tmp/portage/nullmailer-1.00/image//usr/bin/mailq&apos;: Permission denied
 * Please ensure you have selected nullmailer in your /etc/mailer.conf
---------------------------------------------------------

Here is the emerge failure message that gets appended at the end:

--------------------------- ACCESS VIOLATION SUMMARY ---------------------------
LOG FILE = &quot;/tmp/sandbox-mail-mta_-_nullmailer-1.00-1471.log&quot;

chmod:     /extra/var/tmp/portage/nullmailer-1.00/image/usr/bin/mailq (symlink
to /usr/sbin/sendmail)
--------------------------------------------------------------------------------

Finally, here is the &quot;emerge info&quot; output for my system:

---------------------------------------------------------
Gentoo Base System version 1.6.12
Portage 2.0.51.22-r1 (default-linux/x86/2005.0, gcc-3.4.4, glibc-2.3.5-r0,
2.6.8.1-co-0.6.2-pre1 i686)
=================================================================
System uname: 2.6.8.1-co-0.6.2-pre1 i686 Intel(R) Pentium(R) M processor 1100MHz
dev-lang/python:     2.2.3-r1, 2.3.5
sys-apps/sandbox:    1.2.8
sys-devel/autoconf:  2.13, 2.59-r6
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.5
sys-devel/binutils:  2.16-r1
sys-devel/libtool:   1.5.18
virtual/os-headers:  2.6.11-r1
ACCEPT_KEYWORDS=&quot;x86 ~x86&quot;
AUTOCLEAN=&quot;yes&quot;
CBUILD=&quot;i686-pc-linux-gnu&quot;
CFLAGS=&quot;-march=pentium4 -O2 -pipe&quot;
CHOST=&quot;i686-pc-linux-gnu&quot;
CONFIG_PROTECT=&quot;/etc /usr/kde/2/share/config /usr/kde/3/share/config
/usr/lib/X11/xkb /usr/share/config /var/qmail/control&quot;
CONFIG_PROTECT_MASK=&quot;/etc/gconf /etc/terminfo /etc/texmf/web2c /etc/env.d&quot;
CXXFLAGS=&quot;-march=pentium4 -O2 -pipe&quot;
DISTDIR=&quot;/usr/portage/distfiles&quot;
FEATURES=&quot;autoconfig candy distlocks moo sandbox sfperms strict&quot;
GENTOO_MIRRORS=&quot;http://gentoo.blueyonder.co.uk
ftp://gentoo.blueyonder.co.uk/mirrors/gentoo&quot;
MAKEOPTS=&quot;&quot;
PKGDIR=&quot;/usr/portage/packages&quot;
PORTAGE_TMPDIR=&quot;/extra/var/tmp&quot;
PORTDIR=&quot;/usr/portage&quot;
PORTDIR_OVERLAY=&quot;/usr/local/portage&quot;
SYNC=&quot;rsync://rsync.gentoo.org/gentoo-portage&quot;
USE=&quot;x86 X Xaw3d acl apache2 bitmap-fonts bonobo crypt emacs emacs-w3 emboss
escreen esd etwin fam fortran fpx gcj gd gd-external gif glitz graphviz gtk gtk2
guile imagemagick imlib ipv6 java jbig jpeg latex lcms leim libg++ libwww lua
lzw-tiff mad mailwrapper md5sum mmx motif mozdevelop mozilla mozsvg mozxmlterm
mp3 mpeg ncurses nodrm nptl objc ogg oggvorbis opengl pam pam_chroot pam_console
pam_timestamp perl php png python readline samba sdk slang snmp socks5 spell sse
ssl tcltk tcpd tetex tiff truetype truetype-fonts type1-fonts unicode vorbis wmf
xinerama xml2 xmms xprint xv zlib userland_GNU kernel_linux elibc_glibc&quot;
Unset:  ASFLAGS, CTARGET, LANG, LC_ALL, LDFLAGS, LINGUAS</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>azarah@gentoo.org</who>
            <bug_when>2005-06-09 08:52:10 0000</bug_when>
            <thetext>This is because chmod follows the symlink, and tries to chmod the actual
/usr/bin/sendmail.  The Makefile should be patched to not do this.  If you need
more info, add me to CC.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>sllewbj@blueyonder.co.uk</who>
            <bug_when>2005-06-09 09:12:52 0000</bug_when>
            <thetext>There is indeed a line in the Makefile that could do the chmod, but I think it
is not being invoked.  I suspect the guilty chmod is the one in the ebuild script.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>soulse@gmail.com</who>
            <bug_when>2005-07-16 23:13:17 0000</bug_when>
            <thetext>Created an attachment (id=63591)
nullmailer-1.00.ebuild.diff

well i couldnt reproduce the problem but i think this patch could help you...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dragonheart@gentoo.org</who>
            <bug_when>2005-07-20 15:35:07 0000</bug_when>
            <thetext>I did produce this problem and Marco&apos;s patch works. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>robbat2@gentoo.org</who>
            <bug_when>2005-11-29 12:30:00 0000</bug_when>
            <thetext>fixed in cvs.</thetext>
          </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>63591</attachid>
            <date>2005-07-16 23:13 0000</date>
            <desc>nullmailer-1.00.ebuild.diff</desc>
            <filename>nullmailer-1.00.ebuild.diff</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tIG51bGxtYWlsZXItMS4wMC5lYnVpbGQub3JpZwkyMDA1LTA3LTE3IDAwOjQ2OjU2LjI0MTcx
NzE3NiArMDAwMAorKysgbnVsbG1haWxlci0xLjAwLmVidWlsZAkyMDA1LTA3LTE3IDAwOjU0OjI1
LjA3MzQ4NDM3NiArMDAwMApAQCAtNjUsNyArNjUsNiBAQAogCWlmIHVzZSBtYWlsd3JhcHBlcjsg
dGhlbgogCQltdiAke0R9L3Vzci9zYmluL3NlbmRtYWlsICR7RH0vdXNyL3NiaW4vc2VuZG1haWwu
bnVsbG1haWxlcgogCQltdiAke0R9L3Vzci9iaW4vbWFpbHEgJHtEfS91c3IvYmluL21haWxxLm51
bGxtYWlsZXIKLQkJZG9zeW0gL3Vzci9zYmluL3NlbmRtYWlsIC91c3IvYmluL21haWxxCiAJCWlu
c2ludG8gL2V0Yy9tYWlsCiAJCWRvaW5zICR7RklMRVNESVJ9L21haWxlci5jb25mCiAJZmkKQEAg
LTEyMCw2ICsxMTksMTAgQEAKIAljaG1vZCA3NzAgL3Zhci9sb2cvbnVsbG1haWxlciAvdmFyL251
bGxtYWlsZXIve3RtcCxxdWV1ZX0KIAljaG1vZCA2NjAgL3Zhci9udWxsbWFpbGVyL3RyaWdnZXIK
IAorCWlmIHVzZSBtYWlsd3JhcHBlcjsgdGhlbgorCQlkb3N5bSAvdXNyL3NiaW4vc2VuZG1haWwg
L3Vzci9iaW4vbWFpbHEKKwlmaQorCiAJZWluZm8gIlRvIGNyZWF0ZSBhbiBpbml0aWFsIHNldHVw
LCBwbGVhc2UgZG86IgogCWVpbmZvICJlYnVpbGQgL3Zhci9kYi9wa2cvJHtDQVRFR09SWX0vJHtQ
Rn0vJHtQRn0uZWJ1aWxkIGNvbmZpZyIKIAltc2dfc3ZzY2FuCg==
</data>        

          </attachment>
    </bug>

</bugzilla>