Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 463380 - app-doc/devmanual-0_pre20130309 - sandbox violation in $HOME/.config/inkscape
Summary: app-doc/devmanual-0_pre20130309 - sandbox violation in $HOME/.config/inkscape
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Development (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Markos Chandras (RETIRED)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-03-26 17:08 UTC by Helmut Jarausch
Modified: 2013-03-29 19:44 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
build log (build.log,17.31 KB, text/plain)
2013-03-26 17:08 UTC, Helmut Jarausch
Details
build environment (environment,81.31 KB, text/plain)
2013-03-27 08:44 UTC, Helmut Jarausch
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Helmut Jarausch 2013-03-26 17:08:50 UTC
Created attachment 343322 [details]
build log

Emerging devmanual fails due to a strange sandbox violation, it tries to write to 
/home/jarausch/.config/inkscape/extension-errors.log

On another machine it tries to write to
/root/.config/inkscape


I've attached the build log.

Thanks for looking into it,
Helmut.


emerge --info app-doc/devmanual
Portage 2.2.0_alpha169_p6 (default/linux/amd64/13.0/desktop, gcc-4.7.2, glibc-2.16.0, 3.9.0-rc4 x86_64)
=================================================================
                        System Settings
=================================================================
System uname: Linux-3.9.0-rc4-x86_64-AMD_Phenom-tm-_II_X4_940_Processor-with-gentoo-2.2
KiB Mem:     7908152 total,    465728 free
KiB Swap:    1048572 total,   1048572 free
Timestamp of tree: Tue, 26 Mar 2013 14:15:01 +0000
ld GNU ld (GNU Binutils) 2.23.1
ccache version 3.1.9 [disabled]
app-shells/bash:          4.2_p45
dev-java/java-config:     2.1.12-r1
dev-lang/python:          2.7.4_pre20130317::progress, 3.3.1_pre20130317::progress
dev-util/ccache:          3.1.9
dev-util/cmake:           2.8.10.2-r1
dev-util/pkgconfig:       0.28
sys-apps/baselayout:      2.2
sys-apps/openrc:          0.11.8
sys-apps/sandbox:         2.6-r1
sys-devel/autoconf:       2.13, 2.69
sys-devel/automake:       1.8.5-r4, 1.9.6-r3, 1.10.3, 1.11.6, 1.12.6, 1.13.1
sys-devel/binutils:       2.23.1
sys-devel/gcc:            4.5.4, 4.6.3, 4.7.2-r1, 4.8.0_pre9999::local
sys-devel/gcc-config:     1.8
sys-devel/libtool:        2.4.2
sys-devel/make:           3.82-r4
sys-kernel/linux-headers: 3.8 (virtual/os-headers)
sys-libs/glibc:           2.16.0
Repositories: gentoo local sunrise
ACCEPT_KEYWORDS="amd64 ~amd64"
ACCEPT_LICENSE="*"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-mtune=native -O2 -msse3 -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/config /usr/share/gnupg/qualified.txt /usr/share/polkit-1/actions /var/lib/hsqldb /var/lib/neatx/home"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/dconf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/php/apache2-php5.4/ext-active/ /etc/php/apache2-php5.5/ext-active/ /etc/php/cgi-php5.4/ext-active/ /etc/php/cgi-php5.5/ext-active/ /etc/php/cli-php5.4/ext-active/ /etc/php/cli-php5.5/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo /etc/texmf/language.dat.d /etc/texmf/language.def.d /etc/texmf/updmap.d /etc/texmf/web2c"
CXXFLAGS="-mtune=native -O2 -msse3 -pipe"
DISTDIR="/usr/portage/distfiles"
FCFLAGS="-O2 -pipe"
FEATURES="assume-digests binpkg-logs buildpkg config-protect-if-modified distlocks ebuild-locks fixlafiles merge-sync news parallel-fetch preserve-libs protect-owned sandbox sfperms splitdebug strict unknown-features-warn unmerge-logs unmerge-orphans userfetch"
FFLAGS="-O2 -pipe"
GENTOO_MIRRORS="ftp://sunsite.informatik.rwth-aachen.de/pub/Linux/gentoo "
LANG="en_US.iso88591"
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
MAKEOPTS="-j4"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage /usr/local/portage/layman/sunrise"
SYNC="rsync://rsync.informatik.RWTH-Aachen.de/gentoo-portage"
USE="3dnow 3dnowext 3dnowprefetch X a52 aac acl acpi alsa amd64 avahi berkdb branding bzip2 cairo cdda cdr cli consolekit cracklib crypt cups cxx dbus dri dts dvd dvdr emboss encode exif fam ffmpeg fftw firefox flac fortran fuse gdbm gfortran gif gimp gnome gpm gtk gtk3 iconv ipv6 jpeg kde lapack lcms libnotify mad mmx mmxext mng modules mp3 mp4 mpeg mudflap multilib ncurses nls nptl nptlonly ogg opengl openmp pam pango pcre pdf png policykit ppds qt qt3support qt4 readline sdl session smp spell sqlite sqlite3 sse sse2 sse3 sse4a ssl startup-notification svg tcl tcpd threads tiff tk truetype udev udisks unicode upower usb vorbis wxwidgets x264 xcb xml xulrunner xv xvid zlib" ABI_X86="64" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="authn_core authz_core socache_shmcb unixd actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" CALLIGRA_FEATURES="kexi words flow plan sheets stage tables krita karbon braindump" CAMERAS="ptp2" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ubx" GRUB_PLATFORMS="pc multiboot" INPUT_DEVICES="keyboard mouse evdev wacom" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LIBREOFFICE_EXTENSIONS="presenter-console presenter-minimizer" LINGUAS="en de" OFFICE_IMPLEMENTATION="libreoffice" PHP_TARGETS="php5-3" PYTHON_SINGLE_TARGET="python2_7" PYTHON_TARGETS="python2_7 python3_3" RUBY_TARGETS="ruby18 ruby19" USERLAND="GNU" VIDEO_CARDS="ati radeon fglrx" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account"
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LC_ALL, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, USE_PYTHON

=================================================================
                        Package Settings
=================================================================

app-doc/devmanual-0_pre20130309 was built with the following:
USE=""
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2013-03-26 18:41:03 UTC
Please attach the environment file mentioned in the build log.
Comment 2 Helmut Jarausch 2013-03-27 08:44:54 UTC
Created attachment 343388 [details]
build environment
Comment 3 Jeroen Roovers (RETIRED) gentoo-dev 2013-03-27 17:12:55 UTC
./general-concepts/mirrors/diagram.svg:   xmlns:sodipodi="http://inkscape.sourceforge.net/DTD/sodipodi-0.dtd"
./general-concepts/mirrors/diagram.svg:   xmlns:inkscape="http://www.inkscape.org/namespaces/inkscape"

It looks like xsltproc happens to know where to find inkscape.
Comment 4 Markos Chandras (RETIRED) gentoo-dev 2013-03-27 17:48:09 UTC
(In reply to comment #3)
> ./general-concepts/mirrors/diagram.svg:  
> xmlns:sodipodi="http://inkscape.sourceforge.net/DTD/sodipodi-0.dtd"
> ./general-concepts/mirrors/diagram.svg:  
> xmlns:inkscape="http://www.inkscape.org/namespaces/inkscape"
> 
> It looks like xsltproc happens to know where to find inkscape.

I don't understand what you are saying here and frankly I don't quite understand this  problem at all. Why can't I reproduce it myself? (I don't have inkscape installed).
Comment 5 Jeroen Roovers (RETIRED) gentoo-dev 2013-03-27 17:50:59 UTC
I can't reproduce it either, but it is apparent that inkscape is somehow called, so having inkscape installed is one of the requirements to reproducing the problem.

Both URLs are dead, by the way, so maybe Helmut has a local copy?
Comment 6 Markos Chandras (RETIRED) gentoo-dev 2013-03-27 18:07:00 UTC
(In reply to comment #5)
> I can't reproduce it either, but it is apparent that inkscape is somehow
> called, so having inkscape installed is one of the requirements to
> reproducing the problem.
> 
> Both URLs are dead, by the way, so maybe Helmut has a local copy?

Hmm i think that the "convert" command in the makefile calls inkscape and then for some reason it tries to write to $HOME. I need to setup my env with inkscape to see what's going on.
Comment 7 Jeroen Roovers (RETIRED) gentoo-dev 2013-03-27 18:22:33 UTC
PATH="/usr/lib64/portage/bin/ebuild-helpers:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/opt/bin:/usr/x86_64-pc-linux-gnu/gcc-bin/4.7.2"

Maybe some old leftover in PATH (RESOLVED -> INVALID)?
Comment 8 Helmut Jarausch 2013-03-28 09:22:59 UTC
(In reply to comment #5)
> I can't reproduce it either, but it is apparent that inkscape is somehow
> called, so having inkscape installed is one of the requirements to
> reproducing the problem.
> 
> Both URLs are dead, by the way, so maybe Helmut has a local copy?

A local copy of what?

whence -a convert  only shows /usr/bin/convert  (from imagemagick)
whence -a inkscape only shows /usr/bin/inkscape (from inkscape)
whence -a xsltproc only shows /usr/bin/xsltproc (from libxslt)

and simlarly

locate -b '\convert' doesn't find any other versions which are in any paths.

What can I do to find the culprit?
Comment 9 Jeroen Roovers (RETIRED) gentoo-dev 2013-03-28 15:36:10 UTC
(In reply to comment #8)
> (In reply to comment #5)
> > I can't reproduce it either, but it is apparent that inkscape is somehow
> > called, so having inkscape installed is one of the requirements to
> > reproducing the problem.
> > 
> > Both URLs are dead, by the way, so maybe Helmut has a local copy?
> 
> A local copy of what?

Both DTDs mentioned in comment #3.
Comment 10 Markos Chandras (RETIRED) gentoo-dev 2013-03-28 22:34:27 UTC
(In reply to comment #8)
> (In reply to comment #5)
> > I can't reproduce it either, but it is apparent that inkscape is somehow
> > called, so having inkscape installed is one of the requirements to
> > reproducing the problem.
> > 
> > Both URLs are dead, by the way, so maybe Helmut has a local copy?
> 
> A local copy of what?
> 
> whence -a convert  only shows /usr/bin/convert  (from imagemagick)
> whence -a inkscape only shows /usr/bin/inkscape (from inkscape)
> whence -a xsltproc only shows /usr/bin/xsltproc (from libxslt)
> 
> and simlarly
> 
> locate -b '\convert' doesn't find any other versions which are in any paths.
> 
> What can I do to find the culprit?

Have you configured inkscape in a special way or something? However, I have no idea why inkscape is called...
Comment 11 Markos Chandras (RETIRED) gentoo-dev 2013-03-28 22:49:05 UTC
(In reply to comment #10)
> (In reply to comment #8)
> > (In reply to comment #5)
> > > I can't reproduce it either, but it is apparent that inkscape is somehow
> > > called, so having inkscape installed is one of the requirements to
> > > reproducing the problem.
> > > 
> > > Both URLs are dead, by the way, so maybe Helmut has a local copy?
> > 
> > A local copy of what?
> > 
> > whence -a convert  only shows /usr/bin/convert  (from imagemagick)
> > whence -a inkscape only shows /usr/bin/inkscape (from inkscape)
> > whence -a xsltproc only shows /usr/bin/xsltproc (from libxslt)
> > 
> > and simlarly
> > 
> > locate -b '\convert' doesn't find any other versions which are in any paths.
> > 
> > What can I do to find the culprit?
> 
> Have you configured inkscape in a special way or something? However, I have
> no idea why inkscape is called...

Ok I did some googling and it seems that imagemagick can use inkscape if it is present and in your $PATH. So I need to find out how to override that
Comment 12 Markos Chandras (RETIRED) gentoo-dev 2013-03-28 23:08:52 UTC
CC'ing imagemagick maintainers.

Guys, it seems imagemagick calls "inkscape" if it is present (see [1]). I can't find a way to disable this. Do you know if it possible? Otherwise I need to block inkscape in the devmanual ebuild.

[1]http://www.imagemagick.org/script/changelog.php
Comment 13 Markos Chandras (RETIRED) gentoo-dev 2013-03-29 00:01:44 UTC
Fixed in a different way. Sync in a couple of hours to get it

+  29 Mar 2013; Markos Chandras <hwoarang@gentoo.org>
+  devmanual-0_pre20130309.ebuild, devmanual-9999.ebuild:
+  export XDG_CONFIG_HOME to workaround sandbox problems. Bug #463380
+
Comment 14 Helmut Jarausch 2013-03-29 19:44:00 UTC
(In reply to comment #13)
> Fixed in a different way. Sync in a couple of hours to get it
> 
> +  29 Mar 2013; Markos Chandras <hwoarang@gentoo.org>
> +  devmanual-0_pre20130309.ebuild, devmanual-9999.ebuild:
> +  export XDG_CONFIG_HOME to workaround sandbox problems. Bug #463380
> +

Thanks, it works just fine.
Helmut.