Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 574262 - net-libs/nodejs-5.5.0 sandbox violation during emerge
Summary: net-libs/nodejs-5.5.0 sandbox violation during emerge
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Development (show other bugs)
Hardware: AMD64 Linux
: Normal normal (vote)
Assignee: Patrick Lauer
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-02-09 14:21 UTC by cyshei
Modified: 2016-02-11 12:09 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Full build log (build.log,324.70 KB, text/x-log)
2016-02-09 14:21 UTC, cyshei
Details
just change make to emake on src_install() (nodejs-5.5.0.ebuild,5.59 KB, text/plain)
2016-02-10 23:55 UTC, Luca Tiburzio
Details

Note You need to log in before you can comment on or make changes to this bug.
Description cyshei 2016-02-09 14:21:44 UTC
Created attachment 425076 [details]
Full build log

>>> Install nodejs-5.5.0 into /var/tmp/portage/net-libs/nodejs-5.5.0/image/ category net-libs
make -C out BUILDTYPE=Release V=1
make[1]: Entering directory '/var/tmp/portage/net-libs/nodejs-5.5.0/work/node-v5.5.0/out'
make[1]: Nothing to be done for 'all'.
make[1]: Leaving directory '/var/tmp/portage/net-libs/nodejs-5.5.0/work/node-v5.5.0/out'
ln -fs out/Release/node node
/usr/bin/python2.7 tools/install.py install '/var/tmp/portage/net-libs/nodejs-5.5.0/image/' '/usr'
 * PT_PAX marking -m /var/tmp/portage/net-libs/nodejs-5.5.0/image/usr/bin/node with paxctl
 * XATTR_PAX marking -me /var/tmp/portage/net-libs/nodejs-5.5.0/image/usr/bin/node with setfattr
 * ACCESS DENIED:  mkdir:        /usr/etc
/var/tmp/portage/net-libs/nodejs-5.5.0/image//usr/lib64/node_modules/npm/node_modules/archy/examples
/var/tmp/portage/net-libs/nodejs-5.5.0/image//usr/lib64/node_modules/npm/node_modules/fstream/examples
/var/tmp/portage/net-libs/nodejs-5.5.0/image//usr/lib64/node_modules/npm/node_modules/mkdirp/examples
/var/tmp/portage/net-libs/nodejs-5.5.0/image//usr/lib64/node_modules/npm/node_modules/node-gyp/node_modules/tar/examples
/var/tmp/portage/net-libs/nodejs-5.5.0/image//usr/lib64/node_modules/npm/node_modules/nopt/examples
/var/tmp/portage/net-libs/nodejs-5.5.0/image//usr/lib64/node_modules/npm/node_modules/npmlog/node_modules/ansi/examples
/var/tmp/portage/net-libs/nodejs-5.5.0/image//usr/lib64/node_modules/npm/node_modules/request/node_modules/hawk/node_modules/sntp/examples
/var/tmp/portage/net-libs/nodejs-5.5.0/image//usr/lib64/node_modules/npm/node_modules/tar/examples                             [ ok ]
>>> Completed installing nodejs-5.5.0 into /var/tmp/portage/net-libs/nodejs-5.5.0/image/

 * Final size of build directory: 227292 KiB
 * Final size of installed tree: 26328 KiB

 * --------------------------- ACCESS VIOLATION SUMMARY ---------------------------
 * LOG FILE: "/var/log/sandbox/sandbox-18392.log"
 * 
VERSION 1.0
FORMAT: F - Function called
FORMAT: S - Access Status
FORMAT: P - Path as passed to function
FORMAT: A - Absolute Path (not canonical)
FORMAT: R - Canonical Path
FORMAT: C - Command Line

F: mkdir
S: deny
P: /usr/etc
A: /usr/etc
R: /usr/etc
C: npm                                                                                
 * --------------------------------------------------------------------------------


% emerge --info
Portage 2.2.27 (python 3.4.3-final-0, default/linux/amd64/13.0/desktop/gnome/systemd, gcc-5.3.0, glibc-2.22-r1, 4.1.15-gentoo-r1 x86_64)
=================================================================
System uname: Linux-4.1.15-gentoo-r1-x86_64-Intel-R-_Xeon-R-_CPU_E3-1245_V2_@_3.40GHz-with-gentoo-2.2
KiB Mem:    12306356 total,   1621884 free
KiB Swap:    2097148 total,   2082868 free
Timestamp of repository gentoo: Tue, 09 Feb 2016 14:02:55 +0000
sh bash 4.3_p42-r2
ld GNU ld (Gentoo 2.25.1 p1.1) 2.25.1
distcc 3.2rc1 x86_64-pc-linux-gnu [enabled]
app-shells/bash:          4.3_p42-r2::gentoo
dev-lang/perl:            5.22.1::gentoo
dev-lang/python:          2.7.11-r2::gentoo, 3.4.3-r7::gentoo, 3.5.1-r2::gentoo
dev-util/cmake:           3.4.3::gentoo
dev-util/pkgconfig:       0.29::gentoo
sys-apps/baselayout:      2.2::gentoo
sys-apps/openrc:          0.20.4::gentoo
sys-apps/sandbox:         2.10-r1::gentoo
sys-devel/autoconf:       2.13::gentoo, 2.69-r1::gentoo
sys-devel/automake:       1.10.3-r2::gentoo, 1.11.6-r2::gentoo, 1.12.6-r1::gentoo, 1.13.4-r1::gentoo, 1.14.1-r1::gentoo, 1.15-r1::gentoo
sys-devel/binutils:       2.25.1-r1::gentoo
sys-devel/gcc:            4.9.3::gentoo, 5.3.0::gentoo
sys-devel/gcc-config:     1.8-r1::gentoo
sys-devel/libtool:        2.4.6-r1::gentoo
sys-devel/make:           4.1-r1::gentoo
sys-kernel/linux-headers: 4.4::gentoo (virtual/os-headers)
sys-libs/glibc:           2.22-r1::gentoo
Repositories:

gentoo
    location: /usr/portage
    sync-type: git
    sync-uri: https://github.com/gentoo-mirror/gentoo
    priority: -1000

ACCEPT_KEYWORDS="amd64 ~amd64"
ACCEPT_LICENSE="*"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-O2 -pipe -march=sandybridge"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/config /usr/share/gnupg/qualified.txt"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/dconf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo /etc/texmf/language.dat.d /etc/texmf/language.def.d /etc/texmf/updmap.d /etc/texmf/web2c"
CXXFLAGS="-O2 -pipe -march=sandybridge"
DISTDIR="/usr/portage/distfiles"
FCFLAGS="-O2 -pipe"
FEATURES="assume-digests binpkg-logs buildpkg config-protect-if-modified distcc distlocks ebuild-locks fixlafiles merge-sync news parallel-fetch preserve-libs protect-owned sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync xattr"
FFLAGS="-O2 -pipe"
GENTOO_MIRRORS="http://gentoo.ussg.indiana.edu/ http://distfiles.gentoo.org http://distro.ibiblio.org/pub/linux/distributions/gentoo"
LANG="en_US.utf8"
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
MAKEOPTS="-j33 -l8"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --omit-dir-times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages --exclude=/.git"
PORTAGE_TMPDIR="/var/tmp"
USE="X a52 aac acl acpi alsa amd64 ao berkdb bluetooth bluray branding bzip2 cairo cdda cdr cjk cli colord cracklib crypt cups cxx dbus dri dts dvd dvdr eds emacs emboss encode evo exif fam ffmpeg firefox flac fortran fuse gdbm gif glamor gnome gnome-keyring gnome-online-accounts gpm gstreamer gtk gtk3 iconv introspection ipv6 jpeg kde lcms ldap libnotify libsecret mad mmx mmxext mng modules mp3 mp4 mpeg multilib musepack nautilus ncurses networkmanager nls nptl ogg opengl openmp pam pango pcre pdf png policykit ppds pulseaudio qt3support qt4 readline sdl seccomp session smp spell sse sse2 ssl startup-notification svg systemd tcpd threads tiff tracker truetype udev udisks unicode upower usb vaapi vdpau vorbis wifi wxwidgets x264 xattr xcb xft xinerama xml xv xvid zlib zsh-completion" ABI_X86="64" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" APACHE2_MODULES="authn_core authz_core socache_shmcb unixd actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" CALLIGRA_FEATURES="kexi words flow plan sheets stage tables krita karbon braindump author" CAMERAS="ptp2" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" CPU_FLAGS_X86="aes avx mmx mmxext popcnt sse sse2 sse3 sse4_1 sse4_2 ssse3" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ublox ubx" GRUB_PLATFORMS="efi-64 pc" INPUT_DEVICES="keyboard mouse evdev vmmouse" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LIBREOFFICE_EXTENSIONS="presenter-console presenter-minimizer" LINGUAS="en" OFFICE_IMPLEMENTATION="libreoffice" PHP_TARGETS="php5-5" PYTHON_SINGLE_TARGET="python2_7" PYTHON_TARGETS="python2_7 python3_4" RUBY_TARGETS="ruby20 ruby21" USERLAND="GNU" VIDEO_CARDS="intel i965 vesa vmware nvidia" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account"
Unset:  CC, CPPFLAGS, CTARGET, CXX, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LC_ALL, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, USE_PYTHON
Comment 1 Aric Belsito 2016-02-10 01:20:49 UTC
Same issue here.
Comment 2 Johan Bergström 2016-02-10 05:38:15 UTC
The ebuild landed slightly prematurely. There's a 5.6.0 ebuild in progress here: https://github.com/gentoo/gentoo/compare/master...jbergstroem:verbump/net-libs/nodejs-5.4.1#diff-868008c4e457f3114cff385db27acddbL169

let me know if that works better!
Comment 3 Johan Bergström 2016-02-10 05:39:01 UTC
(In reply to Johan Bergström from comment #2)
> The ebuild landed slightly prematurely. There's a 5.6.0 ebuild in progress
> here:
> https://github.com/gentoo/gentoo/compare/master...jbergstroem:verbump/net-
> libs/nodejs-5.4.1#diff-868008c4e457f3114cff385db27acddbL169
> 
> let me know if that works better!

(note: the branch requires a bump of http-parser yet to land in gentoo-x86)
Comment 4 Ivan Iraci 2016-02-10 10:52:38 UTC
Same problem here.
Comment 5 Luca Tiburzio 2016-02-10 23:55:11 UTC
Created attachment 425176 [details]
just change make to emake on src_install()

on src_install() make tries to create standard paths.
it is correct to use emake instead.
Comment 6 Johan Bergström 2016-02-10 23:58:23 UTC
As far as I know, using `emake` over `make` is the correct way. The issue might have been using `make` all along then?

Also, here's the latest 5.6.0 ebuild with all known fixes; you might run into a sandbox issue writing to /usr/etc based on new behaviour in npm:
https://github.com/gentoo/gentoo/pull/781

@patrick (or someone from proxy-maint) -- is `emake` or `make` the correct way?
Comment 7 Patrice Clement gentoo-dev 2016-02-11 07:10:41 UTC
emake :)
Comment 8 Johan Bergström 2016-02-11 07:12:28 UTC
(In reply to Patrice Clement from comment #7)
> emake :)

Great. The ebuild linked to above should be seen as final (from my hands at least). I've tried building with/without npm,snapshots,icu and debug. Feel free to review/land at will.
Comment 9 Patrick Lauer gentoo-dev 2016-02-11 12:09:46 UTC
Fixed in 5.6.0