Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 502280 - dev-java/icedtea-bin - sandbox violation in /proc/self/coredump_filter by java[c] ...
Summary: dev-java/icedtea-bin - sandbox violation in /proc/self/coredump_filter by jav...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Java (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Java team
URL:
Whiteboard:
Keywords:
: 512758 512784 512816 512824 512836 512840 512894 512950 512954 512988 512990 513306 513696 513722 513880 (view as bug list)
Depends on:
Blocks:
 
Reported: 2014-02-23 20:34 UTC by consumer21
Modified: 2014-06-28 08:08 UTC (History)
22 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
build.log (build.log,282.73 KB, text/plain)
2014-02-23 20:34 UTC, consumer21
Details
/var/log/sandbox/sandbox-6749.log (sandbox-6749.log,1.97 KB, text/x-log)
2014-06-09 11:05 UTC, Kai Wüstermann
Details
/var/tmp/portage/net-dns/libidn-1.28/temp/build.log (build.log,120.66 KB, text/x-log)
2014-06-09 11:14 UTC, Kai Wüstermann
Details
buildlog of libbluray-0.5.0 (libbluray-build.log,73.97 KB, text/x-log)
2014-06-11 09:00 UTC, Stephan Karacson
Details
libreoffice 4.2.3.3-r1 buildlog (libreoffice-build.log,31.07 KB, text/x-log)
2014-06-11 17:57 UTC, Stephan Karacson
Details

Note You need to log in before you can comment on or make changes to this bug.
Description consumer21 2014-02-23 20:34:17 UTC
Created attachment 371138 [details]
build.log

emerge dev-lang/R yields a

 * ------------------- ACCESS VIOLATION SUMMARY --------------------
 * LOG FILE: "/var/log/sandbox/sandbox-29865.log"
 *
 ... (see attached file)


# emerge -info
Portage 2.2.7 (default/linux/amd64/13.0, gcc-4.7.3, glibc-2.17, 3.10.25-gentoo x86_64)
=================================================================
System uname: Linux-3.10.25-gentoo-x86_64-Intel-R-_Atom-TM-_CPU_C2750_@_2.40GHz-with-gentoo-2.2
KiB Mem:    16427564 total,  13723172 free
KiB Swap:   20971516 total,  20971516 free
Timestamp of tree: Sat, 22 Feb 2014 14:15:01 +0000
ld GNU ld (GNU Binutils) 2.23.2
app-shells/bash:          4.2_p45
dev-lang/python:          2.7.5-r3, 3.3.2-r2
dev-util/cmake:           2.8.11.2
dev-util/pkgconfig:       0.28
sys-apps/baselayout:      2.2
sys-apps/openrc:          0.12.4
sys-apps/sandbox:         2.6-r1
sys-devel/autoconf:       2.69
sys-devel/automake:       1.12.6, 1.13.4
sys-devel/binutils:       2.23.2
sys-devel/gcc:            4.7.3-r1
sys-devel/gcc-config:     1.7.3
sys-devel/libtool:        2.4.2
sys-devel/make:           3.82-r4
sys-kernel/linux-headers: 3.9 (virtual/os-headers)
sys-libs/glibc:           2.17
Repositories: gentoo
ACCEPT_KEYWORDS="amd64"
ACCEPT_LICENSE="* -@EULA"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-march=native -O2 -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/gnupg/qualified.txt /var/bind"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo"
CXXFLAGS="-march=native -O2 -pipe"
DISTDIR="/usr/portage/distfiles"
FCFLAGS="-O2 -pipe"
FEATURES="assume-digests binpkg-logs config-protect-if-modified distlocks ebuild-locks fixlafiles merge-sync news parallel-fetch preserve-libs protect-owned sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync"
FFLAGS="-O2 -pipe"
GENTOO_MIRRORS="rsync://de-mirror.org/gentoo/ http://linux.rz.ruhr-uni-bochum.de/download/gentoo-mirror/ rsync://ftp.halifax.rwth-aachen.de/gentoo/ ftp://ftp.halifax.rwth-aachen.de/gentoo/ http://ftp.halifax.rwth-aachen.de/gentoo/ ftp://sunsite.informatik.rwth-aachen.de/pub/Linux/gentoo"
LANG="en_US.utf8"
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
MAKEOPTS="-j9"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --omit-dir-times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY=""
SYNC="rsync://rsync.de.gentoo.org/gentoo-portage"
USE="acl acpi alsa amd64 bzip2 cdb cli cracklib crypt cxx dbm fortran gdbm git gzip hddtemp iconv idn imap ipv6 lzma maildir mmap mmx modules multilib ncurses nls nptl nptlonly openmp pam pcre readline sasl session sse sse2 sse3 sse4_1 ssl ssse3 tcpd unicode usb zlib" ABI_X86="64" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" APACHE2_MODULES="authn_core authz_core socache_shmcb unixd actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" CALLIGRA_FEATURES="kexi words flow plan sheets stage tables krita karbon braindump author" CAMERAS="ptp2" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ublox ubx" INPUT_DEVICES="keyboard mouse evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LIBREOFFICE_EXTENSIONS="presenter-console presenter-minimizer" OFFICE_IMPLEMENTATION="libreoffice" PHP_TARGETS="php5-5" PYTHON_SINGLE_TARGET="python2_7" PYTHON_TARGETS="python2_7 python3_3" RUBY_TARGETS="ruby19 ruby18" USERLAND="GNU" VIDEO_CARDS="fbdev glint intel mach64 mga nouveau nv r128 radeon savage sis tdfx trident vesa via vmware dummy v4l" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account"
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LC_ALL, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, USE_PYTHON
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-08 23:11:03 UTC
*** Bug 512784 has been marked as a duplicate of this bug. ***
Comment 2 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-08 23:11:17 UTC
*** Bug 512758 has been marked as a duplicate of this bug. ***
Comment 3 Kai Wüstermann 2014-06-09 11:05:52 UTC
Created attachment 378580 [details]
/var/log/sandbox/sandbox-6749.log
Comment 4 Kai Wüstermann 2014-06-09 11:07:02 UTC
I can confirm this bug for net-dns/libidn-1.28 here.


The end of emerge output:
(null)*(null) --------------------------- ACCESS VIOLATION SUMMARY ---------------------------
 (null)*(null) LOG FILE: "/var/log/sandbox/sandbox-6749.log"
 (null)*(null) 
VERSION 1.0
FORMAT: F - Function called
FORMAT: S - Access Status
FORMAT: P - Path as passed to function
FORMAT: A - Absolute Path (not canonical)
FORMAT: R - Canonical Path
FORMAT: C - Command Line

F: open_wr
S: deny
P: /proc/self/coredump_filter
A: /proc/self/coredump_filter
R: /proc/8090/coredump_filter
C: javac -d ../../../../../../../java/src/main/java -source 1.5 -target 1.5 CombiningClass.java Composition.java DecompositionKeys.java DecompositionMappings.java IDNA.java IDNAException.java NFKC.java Punycode.java PunycodeException.java RangeSet.java RFC3454.java Stringprep.java StringprepException.java 

F: open_wr
S: deny
P: /proc/self/coredump_filter
A: /proc/self/coredump_filter
R: /proc/8130/coredump_filter
C: javac -d ../../../../java/src/util/java -classpath ../../../../java/src/main/java -source 1.5 -target 1.5 GenerateRFC3454.java GenerateNFKC.java TestIDNA.java TestNFKC.java 

F: open_wr
S: deny
P: /proc/self/coredump_filter
A: /proc/self/coredump_filter
R: /proc/8150/coredump_filter
C: jar cf libidn-1.28.jar -C ./src/main/java gnu/inet/encoding/CombiningClass.class -C ./src/main/java gnu/inet/encoding/Composition.class -C ./src/main/java gnu/inet/encoding/DecompositionKeys.class -C ./src/main/java gnu/inet/encoding/DecompositionMappings.class -C ./src/main/java gnu/inet/encoding/IDNA.class -C ./src/main/java gnu/inet/encoding/IDNAException.class -C ./src/main/java gnu/inet/encoding/NFKC.class -C ./src/main/java gnu/inet/encoding/Punycode.class -C ./src/main/java gnu/inet/encoding/PunycodeException.class -C ./src/main/java gnu/inet/encoding/RangeSet$1.class -C ./src/main/java gnu/inet/encoding/RangeSet$Builder.class -C ./src/main/java gnu/inet/encoding/RangeSet.class -C ./src/main/java gnu/inet/encoding/RangeSet$Range.class -C ./src/main/java gnu/inet/encoding/RangeSet$RangeContainsComparator.class -C ./src/main/java gnu/inet/encoding/RFC3454.class -C ./src/main/java gnu/inet/encoding/Stringprep.class -C ./src/main/java gnu/inet/encoding/StringprepException.class 
 (null)*(null) --------------------------------------------------------------------------------
!!! When you file a bug report, please include the following information:
GENTOO_VM=icedtea-bin-6  CLASSPATH="" JAVA_HOME="/opt/icedtea-bin-6.1.13.3"
JAVACFLAGS="-source 1.5 -target 1.5" COMPILER=""
and of course, the output of emerge --info =libidn-1.28


emerge --info =libidn-1.28
Portage 2.2.8-r1 (default/linux/amd64/13.0/desktop, gcc-4.7.3, glibc-2.17, 3.12.21-gentoo-r1 x86_64)
=================================================================
                        System Settings
=================================================================
System uname: Linux-3.12.21-gentoo-r1-x86_64-Intel-R-_Core-TM-2_Quad_CPU_Q8200_@_2.33GHz-with-gentoo-2.2
KiB Mem:     4047692 total,    940676 free
KiB Swap:    4192928 total,   4192928 free
Timestamp of tree: Mon, 09 Jun 2014 10:15:01 +0000
ld GNU ld (GNU Binutils) 2.23.2
ccache version 3.1.9 [disabled]
app-shells/bash:          4.2_p45
dev-java/java-config:     2.2.0
dev-lang/python:          2.7.6, 3.3.3
dev-util/ccache:          3.1.9-r3
dev-util/cmake:           2.8.12.2
dev-util/pkgconfig:       0.28
sys-apps/baselayout:      2.2
sys-apps/openrc:          0.12.4
sys-apps/sandbox:         2.6-r1
sys-devel/autoconf:       2.13, 2.69
sys-devel/automake:       1.10.3, 1.11.6, 1.12.6, 1.13.4
sys-devel/binutils:       2.23.2
sys-devel/gcc:            4.7.3-r1
sys-devel/gcc-config:     1.7.3
sys-devel/libtool:        2.4.2
sys-devel/make:           3.82-r4
sys-kernel/linux-headers: 3.13 (virtual/os-headers)
sys-libs/glibc:           2.17
Repositories: gentoo science
ACCEPT_KEYWORDS="amd64"
ACCEPT_LICENSE="* -@EULA Oracle-BCLA-JavaSE PUEL dlj-1.1 AdobeFlash-11.x"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-march=native -O2 -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/lib/latex2html /usr/share/gnupg/qualified.txt /usr/share/texmf-site/tex/latex/html /var/lib/hsqldb"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo /etc/texmf/language.dat.d /etc/texmf/language.def.d /etc/texmf/updmap.d /etc/texmf/web2c"
CXXFLAGS="-march=native -O2 -pipe"
DISTDIR="/usr/portage/distfiles"
EMERGE_DEFAULT_OPTS=" -j3  --load-average 4"
FCFLAGS="-O2 -pipe"
FEATURES="assume-digests binpkg-logs config-protect-if-modified distlocks ebuild-locks fixlafiles merge-sync news parallel-fetch preserve-libs protect-owned sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync"
FFLAGS="-O2 -pipe"
GENTOO_MIRRORS="http://de-mirror.org/gentoo/ ftp://ftp.wh2.tu-dresden.de/pub/mirrors/gentoo"
LANG="de_DE.UTF-8"
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
MAKEOPTS="-j4"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --omit-dir-times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/var/lib/layman/science"
SYNC="rsync://rsync.de.gentoo.org/gentoo-portage"
USE="X a52 aac acl acpi alsa amd64 amr berkdb branding bzip2 cairo cdda cdr cli consolekit cracklib crypt cups cupsddk cxx dbus dri dts dvd dvdr dvi emboss encode exif fam firefox flac fortran g3dvl gdbm gif gimp gnutls gpm gstreamer gtk gtk3 hddtemp hpijs hunspell iconv ipv6 java jpeg jpg latex lcms libnotify lm_sensors lyx mad midi mime mmx mng modules mono mp3 mp4 mpeg mtp multilib ncurses nls nptl nsplugin nvidia odbc odf ogg opencl opengl openmp pam pango pcre pdf pmu png policykit ppds python qt3support raw readline scanner sdl session smp spell sse sse2 ssl startup-notification svg symlink system-cairo system-icu system-jpeg system-sqlite tcpd theora thunar thunderbird tiff truetype udev udisks unicode upower usb vorbis win32codecs wmf wxwidgets x264 xcb xinerama xml xpm xscreensaver xv xvid xvmc zlib" ABI_X86="64" ALSA_CARDS="hda-intel" APACHE2_MODULES="authn_core authz_core socache_shmcb unixd actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" CALLIGRA_FEATURES="kexi words flow plan sheets stage tables krita karbon braindump author" CAMERAS="ptp2" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ublox ubx" INPUT_DEVICES="evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LIBREOFFICE_EXTENSIONS="presenter-console presenter-minimizer" LINGUAS="de en" OFFICE_IMPLEMENTATION="libreoffice" PHP_TARGETS="php5-5" PYTHON_SINGLE_TARGET="python2_7" PYTHON_TARGETS="python2_7 python3_3" RUBY_TARGETS="ruby19 ruby20" SANE_BACKENDS="epson2 net" USERLAND="GNU" VIDEO_CARDS="nvidia" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account"
Unset:  CPPFLAGS, CTARGET, INSTALL_MASK, LC_ALL, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, USE_PYTHON
Comment 5 Kai Wüstermann 2014-06-09 11:14:32 UTC
Created attachment 378582 [details]
/var/tmp/portage/net-dns/libidn-1.28/temp/build.log
Comment 6 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-09 13:44:42 UTC
*** Bug 512816 has been marked as a duplicate of this bug. ***
Comment 7 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-09 13:45:18 UTC
*** Bug 512824 has been marked as a duplicate of this bug. ***
Comment 8 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-09 17:43:00 UTC
*** Bug 512836 has been marked as a duplicate of this bug. ***
Comment 9 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-09 18:08:04 UTC
I can't readily find what may have recently changed. Was it a virtual/jdk provider that got bumped, maybe?
Comment 10 Stephan Karacson 2014-06-09 18:25:28 UTC
my change was upgrade
icedtea-bin-6.1.12.7 to dev-java/icedtea-bin-6.1.13.3
media-video/ffmpeg-1.0.8 to media-video/ffmpeg-1.2.6
net-libs/libpcap-1.3.0-r1 to net-libs/libpcap-1.5.3
media-video/vlc-2.0.7 to media-video/vlc-2.1.2

then a emerge  @preserved-rebuild of seven ebuilds
app-cdr/k3b-2.0.2-r4
media-sound/sox-14.4.1
kde-base/ffmpegthumbs-4.12.5
media-libs/phonon-vlc-0.6.2
app-misc/strigi-0.7.8
kde-base/nepomuk-core-4.12.5
media-libs/opencv-2.4.5
where last one fails with java use, see bug 512816
Comment 11 Alexander Miller 2014-06-09 19:13:15 UTC
In reply to Comment 9:
The problem seems to be the upgrade to dev-java/icedtea-bin-6.1.13.3.
Note that dev-java/icedtea got added a sandbox control file in 6.1.13.1 (see bug #499746) to fix a similar issue, while icedtea-bin-6.1.13.3 has none. So when the latter is the only java provider a sandbox violation will occur.
Comment 12 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-09 19:22:50 UTC
I can't find a good reason why sandbox should disallow programs to write to /proc/self/coredump_filter. Maybe it ought to be exempted somehow.
Comment 13 Bob Johnson 2014-06-09 19:31:19 UTC
Confirmed with https://bugs.gentoo.org/show_bug.cgi?id=512836 - masking dev-java/icedtea-bin-6.1.13.3 and downgrading to dev-java/icedtea-bin-6.1.12.7 allows the virtualbox upgrade to succeed.
Comment 14 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-09 19:46:25 UTC
*** Bug 512840 has been marked as a duplicate of this bug. ***
Comment 15 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-09 19:47:05 UTC
(In reply to Bob Johnson from comment #13)
> Confirmed with https://bugs.gentoo.org/show_bug.cgi?id=512836 - masking
> dev-java/icedtea-bin-6.1.13.3 and downgrading to
> dev-java/icedtea-bin-6.1.12.7 allows the virtualbox upgrade to succeed.

FEATURES=-sandbox is probably the easiest workaround.
Comment 16 Alexander Miller 2014-06-09 21:15:04 UTC
In reply to Comment 12:
Isn't sandbox supposed to disallow writes to random files? I'm no expert here, but let's look what other java implementations do: There is "java-vm_sandbox-predict /proc/self/coredump_filter" or similar in the ebuilds for icedtea-7.*, icedtea-6.1.13.*, icedtea-bin-7.*, also for oracle-jdk-bin, some versions of ibm-jdk-bin, didn't check all the other ones. It is not needed for icedtea-6.1.12.* and icedtea-bin-6.1.12.*. Now, icedtea-bin-6.1.13.* fails without it.

In the bug I mentioned above, icedtea-6.1.13.* was fixed with the following commit: <http://sources.gentoo.org/cgi-bin/viewvc.cgi/gentoo-x86/dev-java/icedtea/icedtea-6.1.13.1.ebuild?r1=1.1&r2=1.2>

Here's what adding such a line would do:
echo 'SANDBOX_PREDICT="/proc/self/coredump_filter"' > /etc/sandbox.d/20icedtea-bin-6
Comment 17 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-09 22:14:45 UTC
(In reply to Alexander Miller from comment #16)
> Isn't sandbox supposed to disallow writes to random files?

I wouldn't think /proc/self/* is random for any definition of "random".

> In the bug I mentioned above, icedtea-6.1.13.* was fixed with the following
> commit:
> <http://sources.gentoo.org/cgi-bin/viewvc.cgi/gentoo-x86/dev-java/icedtea/
> icedtea-6.1.13.1.ebuild?r1=1.1&r2=1.2>
> 
> Here's what adding such a line would do:
> echo 'SANDBOX_PREDICT="/proc/self/coredump_filter"' >
> /etc/sandbox.d/20icedtea-bin-6

That would work, too.
Comment 18 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-10 15:30:14 UTC
*** Bug 512894 has been marked as a duplicate of this bug. ***
Comment 19 Kai Wüstermann 2014-06-10 15:39:49 UTC
> 
> Here's what adding such a line would do:
> echo 'SANDBOX_PREDICT="/proc/self/coredump_filter"' >
> /etc/sandbox.d/20icedtea-bin-6

This works for me.
Comment 20 Stayka 2014-06-10 18:33:06 UTC
(In reply to Kai Wüstermann from comment #19)
> > 
> > Here's what adding such a line would do:
> > echo 'SANDBOX_PREDICT="/proc/self/coredump_filter"' >
> > /etc/sandbox.d/20icedtea-bin-6
> 
> This works for me.
same here
Comment 21 Stephan Karacson 2014-06-11 09:00:31 UTC
Created attachment 378676 [details]
buildlog of libbluray-0.5.0

Access violation of libblueray 0.5.0
Comment 22 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-11 12:02:45 UTC
*** Bug 512950 has been marked as a duplicate of this bug. ***
Comment 23 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-11 12:03:03 UTC
*** Bug 512954 has been marked as a duplicate of this bug. ***
Comment 24 Stephan Karacson 2014-06-11 17:57:13 UTC
Created attachment 378716 [details]
libreoffice 4.2.3.3-r1 buildlog

libreoffice 4.2.3.3-r1 affected too, I'll stop posting error, but this bug seems to affect many ebuilds using java.
Comment 25 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-12 11:10:44 UTC
*** Bug 512988 has been marked as a duplicate of this bug. ***
Comment 26 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-12 11:10:59 UTC
*** Bug 512990 has been marked as a duplicate of this bug. ***
Comment 27 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-12 19:40:38 UTC
+  12 Jun 2014; Jeroen Roovers <jer@gentoo.org> icedtea-bin-6.1.13.3.ebuild,
+  icedtea-bin-6.1.13.3-r1.ebuild:
+  Add java-vm_sandbox-predict /proc/self/coredump_filter (bug #502280).
Comment 28 Stephan Karacson 2014-06-13 17:04:20 UTC
works for me (libreoffice, libbluray)
thank you!
Comment 29 spam-mails-here 2014-06-13 23:08:32 UTC
after manually

# emerge -1v icedtea-bin

it works for me, too (libidn, libbluray)
Comment 30 gsra99 2014-06-14 12:39:48 UTC
(In reply to spam-mails-here from comment #29)
> after manually
> 
> # emerge -1v icedtea-bin
> 
> it works for me, too (libidn, libbluray)

The above solution worked for me (app-emulation/virtualbox)
Comment 31 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-15 14:02:43 UTC
*** Bug 513306 has been marked as a duplicate of this bug. ***
Comment 32 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-18 15:20:19 UTC
*** Bug 513696 has been marked as a duplicate of this bug. ***
Comment 33 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-19 01:19:37 UTC
*** Bug 513722 has been marked as a duplicate of this bug. ***
Comment 34 Mark Knecht 2014-06-19 15:31:52 UTC
Worked fine for me. Thanks.
Comment 35 Jeroen Roovers (RETIRED) gentoo-dev 2014-06-19 19:52:01 UTC
*** Bug 513880 has been marked as a duplicate of this bug. ***
Comment 36 Pacho Ramos gentoo-dev 2014-06-25 20:01:53 UTC
  12 Jun 2014; Jeroen Roovers <jer@gentoo.org> icedtea-bin-6.1.13.3.ebuild,
  icedtea-bin-6.1.13.3-r1.ebuild:
  Add java-vm_sandbox-predict /proc/self/coredump_filter (bug #502280).

Can we have a revbump for this change directly to stable? Otherwise people need to figure they need to rebuild icedtea-bin themselves :/
Comment 37 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2014-06-27 14:34:50 UTC
(In reply to Pacho Ramos from comment #36)
>   12 Jun 2014; Jeroen Roovers <jer@gentoo.org> icedtea-bin-6.1.13.3.ebuild,
>   icedtea-bin-6.1.13.3-r1.ebuild:
>   Add java-vm_sandbox-predict /proc/self/coredump_filter (bug #502280).
> 
> Can we have a revbump for this change directly to stable? Otherwise people
> need to figure they need to rebuild icedtea-bin themselves :/

Done.
Comment 38 Pacho Ramos gentoo-dev 2014-06-28 08:08:40 UTC
Thanks :)