Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 252618 - app-misc/ca-certificates-20080809: wrongly reports broken links
Summary: app-misc/ca-certificates-20080809: wrongly reports broken links
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo's Team for Core System packages
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-12-26 16:59 UTC by Toralf Förster
Modified: 2008-12-27 22:48 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Toralf Förster gentoo-dev 2008-12-26 16:59:38 UTC
I got this :

WARN: postinst
Broken symlink for a certificate at /etc/ssl/certs/878cf4c6.0
Broken symlink for a certificate at /etc/ssl/certs/2fb1850a.0
Broken symlink for a certificate at /etc/ssl/certs/a3c60019.0
Broken symlink for a certificate at /etc/ssl/certs/aad3d04d.0
Broken symlink for a certificate at /etc/ssl/certs/cdd7aee7.0
Broken symlink for a certificate at /etc/ssl/certs/1e49180d.0
Broken symlink for a certificate at /etc/ssl/certs/56e607f4.0
Broken symlink for a certificate at /etc/ssl/certs/d4e39186.0
Broken symlink for a certificate at /etc/ssl/certs/843b6c51.0
Broken symlink for a certificate at /etc/ssl/certs/7a9820c1.0
Broken symlink for a certificate at /etc/ssl/certs/2edf7016.1
You MUST remove the above broken symlinks
Otherwise any SSL validation that use the directory may fail!
To batch-remove them, run:
find -L /etc/ssl/certs/ -type l -exec rm {} +


but the find command returns nothing and the mentioned links do not exist :


Reproducible: Always
Comment 1 Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2008-12-27 04:29:44 UTC
(In reply to comment #0)

> but the find command returns nothing and the mentioned links do not exist :

The find command is not suppose to return anything. It is merely suppose to remove the broken links. Re-open the bug if the message is still present after running this command & remerging ca-certs. Thanks.
Comment 2 Toralf Förster gentoo-dev 2008-12-27 10:41:27 UTC
I reopened this report b/c independend from the output of the find command (I did not run it with -exec rm , only with -print) the mentioned links do not exist during upgrade of that package from app-misc/ca-certificates-20080514-r2 to app-misc/ca-certificates-20080809.

OTOH re-emerging the package did not show that issue again - but that is not a bug fix, isn't it ?
Comment 3 Toralf Förster gentoo-dev 2008-12-27 13:08:57 UTC
Furthermore chrooting into my user mode linux image file and trying to upgrade that package I get :

>>> Emerging (1 of 3) app-misc/ca-certificates-20080809 to /
 * ca-certificates_20080809_all.deb RMD160 SHA1 SHA256 size ;-) ...                                                  [ ok ]
 * checking ebuild checksums ;-) ...                                                                                 [ ok ]
 * checking auxfile checksums ;-) ...                                                                                [ ok ]
 * checking miscfile checksums ;-) ...                                                                               [ ok ]
 * checking ca-certificates_20080809_all.deb ;-) ...                                                                 [ ok ]
>>> Unpacking source...
>>> Unpacking ca-certificates_20080809_all.deb to /var/tmp/portage/app-misc/ca-certificates-20080809/work
>>> Unpacking ./data.tar.gz to /var/tmp/portage/app-misc/ca-certificates-20080809/work
 * Applying ca-certificates-20080514-warn-on-bad-symlinks.patch ...                                                  [ ok ]
>>> Source unpacked.
 * The ebuild phase 'unpack' has exited unexpectedly. This type of behavior
 * is known to be triggered by things such as failed variable assignments
 * (bug #190128) or bad substitution errors (bug #200313).

The UML image is a stable Gentoo system :

n22 / # emerge --info
Portage 2.1.4.5 (default/linux/x86/2008.0, gcc-4.1.2, glibc-2.6.1-r0, 2.6.27-gentoo-r7 i686)
=================================================================
System uname: 2.6.27-gentoo-r7 i686 Intel(R) Pentium(R) M processor 1700MHz
Timestamp of tree: Sat, 27 Dec 2008 10:45:02 +0000
ccache version 2.4 [enabled]
app-shells/bash:     3.2_p33
dev-lang/python:     2.5.2-r7
dev-python/pycrypto: 2.0.1-r6
dev-util/ccache:     2.4-r7
sys-apps/baselayout: 1.12.11.1
sys-apps/sandbox:    1.2.18.1-r2
sys-devel/autoconf:  2.13, 2.61-r2
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10.1-r1
sys-devel/binutils:  2.18-r3
sys-devel/gcc-config: 1.4.0-r4
sys-devel/libtool:   1.5.26
virtual/os-headers:  2.6.23-r3
ACCEPT_KEYWORDS="x86"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O2 -march=pentium-m -fomit-frame-pointer -pipe"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/3.5/env /usr/kde/3.5/share/config /usr/kde/3.5/shutdown /usr/share/config"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/php/apache2-php5/ext-active/ /etc/php/cgi-php5/ext-active/ /etc/php/cli-php5/ext-active/ /etc/revdep-rebuild /etc/terminfo /etc/udev/rules.d"
CXXFLAGS="-O2 -march=pentium-m -fomit-frame-pointer -pipe"
DISTDIR="/usr/portage/distfiles"
FEATURES="ccache distlocks metadata-transfer parallel-fetch sandbox sfperms strict unmerge-orphans userfetch"
GENTOO_MIRRORS="http://distfiles.gentoo.org http://distro.ibiblio.org/pub/linux/distributions/gentoo"
LDFLAGS="-Wl,-O1"
LINGUAS="de en"
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="acl apache2 berkdb bzip2 cli cracklib crypt cups dri fam fastbuild fortran gdbm gpm iconv ipv6 isdnlog javascript logrotate midi mmx mmxext mudflap mysql ncurses nls nptl nptlonly openmp pam pcre perl ppds pppd python readline reflection session spl sse sse2 ssl sysfs tcpd unicode userlocales x86 xml xorg zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1 emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="actions alias auth_basic auth_digest authn_anon authn_dbd authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache dav dav_fs dav_lock dbd deflate dir disk_cache env expires ext_filter file_cache filter headers ident imagemap include info log_config logio mem_cache mime mime_magic negotiation proxy proxy_ajp proxy_balancer proxy_connect proxy_http rewrite setenvif so speling status unique_id userdir usertrack vhost_alias" ELIBC="glibc" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LINGUAS="de en" USERLAND="GNU"
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, FFLAGS, INSTALL_MASK, LANG, LC_ALL, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS
Comment 4 Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2008-12-27 16:25:02 UTC
(In reply to comment #2)
> I reopened this report b/c independend from the output of the find command (I
> did not run it with -exec rm , only with -print) the mentioned links do not
> exist during upgrade of that package from app-misc/ca-certificates-20080514-r2
> to app-misc/ca-certificates-20080809.
> 
> OTOH re-emerging the package did not show that issue again - but that is not a
> bug fix, isn't it ?
> 

Ok, well. I saw this warning myself and then ran the find command and all is well so I really do not think that there is a bug here. Regardless, assigning to maintainers for review.
Comment 6 Toralf Förster gentoo-dev 2008-12-27 22:48:03 UTC
(In reply to comment #5)
> probably fixed in cvs now
yep, now the installation was succesful within the chrooted UML.