Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 631038 - net-analyzer/nagstamon-3.0: sandbox ACCESS VIOLATION in /proc/self/oom_score_adj
Summary: net-analyzer/nagstamon-3.0: sandbox ACCESS VIOLATION in /proc/self/oom_score_adj
Status: RESOLVED TEST-REQUEST
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Deadline: 2020-09-21
Assignee: Christian Ruppert (idl0r)
URL:
Whiteboard:
Keywords: PMASKED
Depends on:
Blocks:
 
Reported: 2017-09-15 07:03 UTC by Marcin Mirosław
Modified: 2021-04-07 06:14 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
build.log (build.log,35.69 KB, text/plain)
2017-09-15 07:05 UTC, Marcin Mirosław
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Marcin Mirosław 2017-09-15 07:03:46 UTC
[...]>>> Install nagstamon-3.0 into /var/tmp/portage/net-analyzer/nagstamon-3.0/image/ category net-analyzer
 * python3_4: running distutils-r1_run_phase distutils-r1_python_install
/usr/bin/python3.4 setup.py install --root=/var/tmp/portage/net-analyzer/nagstamon-3.0/image/_python3.4
 * ACCESS DENIED:  open_wr:      /proc/self/oom_score_adj
 * ACCESS DENIED:  open_wr:      /proc/self/oom_score_adj
 * ACCESS DENIED:  open_wr:      /proc/self/oom_score_adj
 * ACCESS DENIED:  open_wr:      /proc/self/oom_score_adj
running install
 * ACCESS DENIED:  open_wr:      /proc/self/oom_score_adj
 * ACCESS DENIED:  open_wr:      /proc/self/oom_score_adj
running build
running build_py
running build_scripts
running install_lib
[...]


Reproducible: Always




# emerge --info
Portage 2.3.8 (python 3.4.6-final-0, default/linux/amd64/13.0/desktop/plasma, gcc-6.4.0, glibc-2.25-r5, 4.11.0-bcache+ x86_64)
=================================================================
System uname: Linux-4.11.0-bcache+-x86_64-Intel-R-_Core-TM-2_Quad_CPU_Q6600_@_2.40GHz-with-gentoo-2.4.1
Timestamp of repository gentoo: Fri, 15 Sep 2017 06:00:01 +0000
Head commit of repository gentoo: 0509241143b517572f289a2955d2d06e2b4b2304
sh bash 4.4_p12
ld GNU gold (Gentoo 2.28.1 p1.0 2.28.1) 1.14
ccache version 3.3.4 [enabled]
app-shells/bash:          4.4_p12::gentoo
dev-java/java-config:     2.2.0-r3::gentoo
dev-lang/perl:            5.24.2::gentoo
dev-lang/python:          2.7.13::gentoo, 3.4.6::gentoo
dev-util/ccache:          3.3.4-r1::gentoo
dev-util/cmake:           3.9.2::gentoo
dev-util/pkgconfig:       0.29.2::gentoo
sys-apps/baselayout:      2.4.1-r2::gentoo
sys-apps/openrc:          0.30::gentoo
sys-apps/sandbox:         2.10-r4::gentoo
sys-devel/autoconf:       2.13::gentoo, 2.69-r4::gentoo
sys-devel/automake:       1.15.1-r1::gentoo
sys-devel/binutils:       2.28.1::gentoo, 2.29::gentoo
sys-devel/gcc:            6.4.0::gentoo
sys-devel/gcc-config:     1.8-r1::gentoo
sys-devel/libtool:        2.4.6-r4::gentoo
sys-devel/make:           4.2.1-r1::gentoo
sys-kernel/linux-headers: 4.13::gentoo (virtual/os-headers)
sys-libs/glibc:           2.25-r5::gentoo
Repositories:

gentoo
    location: /usr/portage
    sync-type: rsync
    sync-uri: rsync://192.168.138.254/gentoo-portage
    priority: -1000

ACCEPT_KEYWORDS="amd64 ~amd64"
ACCEPT_LICENSE="*"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-O2 -march=native -pipe -fpeel-loops              -fuse-linker-plugin -fuse-ld=bfd -fvar-tracking-assignments -g"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/lib64/libreoffice/program/sofficerc /usr/share/config /usr/share/gnupg/qualified.txt"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/dconf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo"
CXXFLAGS="-O2 -march=native -pipe -fpeel-loops              -fuse-linker-plugin -fuse-ld=bfd -fvar-tracking-assignments -g"
DISTDIR="/usr/portage/distfiles"
FCFLAGS="-O2 -march=native -pipe -fpeel-loops              -fuse-linker-plugin -fuse-ld=bfd -fvar-tracking-assignments -g"
FEATURES="assume-digests binpkg-logs ccache cgroup collision-protect compressdebug config-protect-if-modified distlocks downgrade-backup ebuild-locks fixlafiles multilib-strict news parallel-fetch parallel-install preserve-libs protect-owned sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync xattr"
FFLAGS="-O2 -march=native -pipe -fpeel-loops              -fuse-linker-plugin -fuse-ld=bfd -fvar-tracking-assignments -g"
GENTOO_MIRRORS="http://distfiles.gentoo.org"
LDFLAGS="-Wl,-O1 -Wl,--as-needed -z relro -Wl,--sort-common -O2 -march=native -pipe -fpeel-loops              -fuse-linker-plugin -fuse-ld=bfd -fvar-tracking-assignments -g"
MAKEOPTS="-j3 -l4"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --omit-dir-times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages --exclude=/.git"
PORTAGE_TMPDIR="/var/tmp"
USE="X a52 aac acl acpi activities aio alsa amd64 apm async bash-completion bittorrent branding bzip2 cairo caps cdda cdr chroot cli consolekit crypt cups cxx dbus declarative dmx dri dvd dvdr emboss encode exif fam firefox ftp gif glamor glibc-omitfp gpl gpm iconv idn iproute2 ipv6 ithreads jit jpeg kde kipi kwallet laptop lcms libnotify lightning logrotate mad mmap mng modules mp3 mp4 mpeg multilib ncurses network-cron nls nptl nsplugin nspluginwrapper objc ogg opengl openmp openssl optimization optimized-qmake pam pango pcre pdf phonon plasma png policykit ppds python3 qml qt3support qt4 qt5 readline samba sdl seccomp semantic-desktop session sharedmem smp spell ssl startup-notification svg threads threadsafe tiff tools truetype udev udisks unicode unwind upower urandom usb vim vim-pager vim-syntax vorbis widgets wxwidgets x264 xattr xcb xcomposite xinerama xml xscreensaver xv xvid zip zlib" ABI_X86="32 64" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" APACHE2_MODULES="actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cgid dav dbd deflate dir env expires ext_filter filter headers include info log_config logio mime mime_magic negotiation rewrite setenvif speling status unique_id usertrack vhost_alias" APACHE2_MPMS="worker" CALLIGRA_FEATURES="kexi words flow plan sheets stage tables krita karbon braindump author" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" CPU_FLAGS_X86="mmx mmxext sse sse2 sse3 ssse3" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock isync itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf skytraq superstar2 timing tsip tripmate tnt ublox ubx" INPUT_DEVICES="evdev" KERNEL="linux" L10N="pl en" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LIBREOFFICE_EXTENSIONS="presenter-console presenter-minimizer" LINGUAS="pl en" OFFICE_IMPLEMENTATION="libreoffice" PHP_TARGETS="php5-6" POSTGRES_TARGETS="postgres9_5" PYTHON_SINGLE_TARGET="python3_4" PYTHON_TARGETS="python2_7 python3_4" RUBY_TARGETS="ruby24" USERLAND="GNU" VIDEO_CARDS="nvidia fbdev nouveau" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account"
Unset:  CC, CPPFLAGS, CTARGET, CXX, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LANG, LC_ALL, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS
Comment 1 Marcin Mirosław 2017-09-15 07:05:06 UTC
Created attachment 494578 [details]
build.log
Comment 2 Martin Samek 2017-09-19 21:14:35 UTC
I have this problem too.
Comment 3 Zentoo 2018-05-25 07:08:58 UTC
I confirm the problem on ~amd64 too.

------------------------------------------------------------------------------
>>> Source compiled.
>>> Test phase [not enabled]: net-analyzer/nagstamon-3.0.2

>>> Install nagstamon-3.0.2 into /gentoo/tmp/portage/net-analyzer/nagstamon-3.0.2/image/ category net-analyzer
 * python3_6: running distutils-r1_run_phase distutils-r1_python_install
python3.6 setup.py install --root=/gentoo/tmp/portage/net-analyzer/nagstamon-3.0.2/image/_python3.6
 * ACCESS DENIED:  open_wr:      /proc/self/oom_score_adj
 * ACCESS DENIED:  open_wr:      /proc/self/oom_score_adj
running install
running build
running build_py
running build_scripts
running install_lib
------------------------------------------------------------------------------
...
 * --------------------------- ACCESS VIOLATION SUMMARY ---------------------------
 * LOG FILE: "/var/log/sandbox/sandbox-1920.log"
 * 
VERSION 1.0
FORMAT: F - Function called
FORMAT: S - Access Status
FORMAT: P - Path as passed to function
FORMAT: A - Absolute Path (not canonical)
FORMAT: R - Canonical Path
FORMAT: C - Command Line

F: open_wr
S: deny
P: /proc/self/oom_score_adj
A: /proc/self/oom_score_adj
R: /proc/2011/oom_score_adj
C: /usr/bin/dbus-daemon --syslog-only --fork --print-pid 5 --print-address 7 --session 

F: open_wr
S: deny
P: /proc/self/oom_score_adj
A: /proc/self/oom_score_adj
R: /proc/2011/oom_score_adj
C: /usr/bin/dbus-daemon --syslog-only --fork --print-pid 5 --print-address 7 --session 
------------------------------------------------------------------------------
Comment 4 Zentoo 2018-06-27 08:30:18 UTC
The problem seems to be related to tty environment since the emerge is sucessfull from a VT console.

It seems that in X environment ebuild install phase try to launch a dbus session inside the sandbox. I suppose that it try to send a notification to the desktop via dbus.

It seems to be really similar to this forefox bug: https://bugs.gentoo.org/604394

I've try to add this in the ebuild but the sandbox violation is still here:


pkg_setup() {
    unset DBUS_SESSION_BUS_ADDRESS \
        DISPLAY \
        XSESSION \
        ORBIT_SOCKETDIR \
        SESSION_MANAGER \
        XDG_SESSION_COOKIE \
        XAUTHORITY
}
Comment 5 Martin Samek 2018-10-05 07:28:00 UTC
I have this problem too with nagstamon-3.0.2
Comment 6 Zentoo 2018-10-05 13:58:33 UTC
(In reply to Martin Samek from comment #5)
> I have this problem too with nagstamon-3.0.2

It's definitively a problem with your environment since I don't have the problem anymore here on a ~amd64 system compiled for python:3.6.

Are you on 32/64 bits ? stable/unstable ? And wich python target ?
Comment 7 Hans de Graaff gentoo-dev Security 2021-04-07 06:14:17 UTC
I'm closing this since I can't reproduce it with nagstamon 3.6.0. Please reopen if this is still an issue for you with newer versions.