Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 928516 - media-libs/opencv-4.9.0 Sandbox Access Violation
Summary: media-libs/opencv-4.9.0 Sandbox Access Violation
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal with 1 vote (vote)
Assignee: Paul Zander
URL:
Whiteboard:
Keywords: PullRequest
Depends on:
Blocks:
 
Reported: 2024-04-03 14:29 UTC by Andrea Postiglione
Modified: 2024-04-21 12:51 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andrea Postiglione 2024-04-03 14:29:38 UTC
thunderdome ~ # emerge --info opencv
Portage 3.0.63 (python 3.11.8-final-0, default/linux/amd64/17.1/desktop/plasma/systemd/merged-usr, gcc-12, glibc-2.39-r2, 6.8.2-gentoo x86_64)
=================================================================
                         System Settings
=================================================================
System uname: Linux-6.8.2-gentoo-x86_64-Intel-R-_Core-TM-_i9-10900K_CPU_@_3.70GHz-with-glibc2.39
KiB Mem:   131687600 total, 117531060 free
KiB Swap:    8388604 total,   8388604 free
Timestamp of repository 4nykey: Mon, 01 Apr 2024 09:52:39 +0000
Head commit of repository 4nykey: 86e1fa9f5bfbcc255222885acea671b1e739a693

Timestamp of repository guru: Tue, 02 Apr 2024 23:18:30 +0000
Head commit of repository guru: e1f103135d4cf26dde825f9fdab707d54331e1fc

Timestamp of repository gentoo: Wed, 03 Apr 2024 09:45:00 +0000
Head commit of repository gentoo: 01542f71c722abee914b93f4f363b228464b7965
sh bash 5.2_p26
ld GNU ld (Gentoo 2.41 p5) 2.41.0
distcc[55696] (dcc_trace_version) distcc 3.4 x86_64-pc-linux-gnu; built Mar  4 2024 18:32:02 [disabled]
app-misc/pax-utils:        1.3.7::gentoo
app-shells/bash:           5.2_p26::gentoo
dev-build/autoconf:        2.13-r8::gentoo, 2.72-r1::gentoo
dev-build/automake:        1.16.5-r2::gentoo
dev-build/cmake:           3.29.0::gentoo
dev-build/libtool:         2.4.7-r4::gentoo
dev-build/make:            4.4.1-r1::gentoo
dev-build/meson:           1.4.0-r1::gentoo
dev-java/java-config:      2.3.3-r1::gentoo
dev-lang/perl:             5.38.2-r2::gentoo
dev-lang/python:           3.11.8_p1::gentoo
dev-lang/rust:             1.76.0-r1::gentoo
sec-policy/selinux-base:   2.20240226-r1::gentoo
sys-apps/baselayout:       2.15::gentoo
sys-apps/sandbox:          2.38::gentoo
sys-apps/systemd:          255.4::gentoo
sys-devel/binutils:        2.41-r5::gentoo, 2.42-r1::gentoo
sys-devel/binutils-config: 5.5::gentoo
sys-devel/clang:           17.0.6::gentoo, 18.1.2::gentoo
sys-devel/gcc:             12.3.1_p20240209::gentoo
sys-devel/gcc-config:      2.11::gentoo
sys-devel/lld:             17.0.6::gentoo, 18.1.2::gentoo
sys-devel/llvm:            17.0.6::gentoo, 18.1.2::gentoo
sys-kernel/linux-headers:  6.8-r1::gentoo (virtual/os-headers)
sys-libs/glibc:            2.39-r2::gentoo
sys-libs/libselinux:       3.6-r1::gentoo
Repositories:

4nykey
    location: /var/db/repos/4nykey
    sync-type: git
    sync-uri: https://github.com/gentoo-mirror/4nykey.git
    masters: gentoo
    volatile: False

guru
    location: /var/db/repos/guru
    sync-type: git
    sync-uri: https://github.com/gentoo-mirror/guru.git
    masters: gentoo
    volatile: False

gentoo
    location: /var/db/repos/gentoo
    sync-type: rsync
    sync-uri: rsync://rsync7.de.gentoo.org/gentoo-portage/
    priority: 10
    volatile: True
    sync-rsync-verify-max-age: 24
    sync-rsync-verify-jobs: 1
    sync-rsync-extra-opts: 
    sync-rsync-verify-metamanifest: no

local
    location: /var/db/repos/local
    masters: gentoo
    priority: 100
    volatile: True

Binary Repositories:

gentoobinhost
    priority: 1
    sync-uri: https://gentoo.osuosl.org/releases/amd64/binpackages/17.1/x86-64

ACCEPT_KEYWORDS="amd64 ~amd64"
ACCEPT_LICENSE="*"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-march=native -mtune=native -O3 -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/lib64/libreoffice/program/sofficerc /usr/share/config /usr/share/gnupg/qualified.txt"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/dconf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/revdep-rebuild /etc/sandbox.d"
CXXFLAGS="-march=native -mtune=native -O3 -pipe"
DISTDIR="/var/cache/distfiles"
ENV_UNSET="CARGO_HOME DBUS_SESSION_BUS_ADDRESS DISPLAY GDK_PIXBUF_MODULE_FILE GOBIN GOPATH PERL5LIB PERL5OPT PERLPREFIX PERL_CORE PERL_MB_OPT PERL_MM_OPT XAUTHORITY XDG_CACHE_HOME XDG_CONFIG_HOME XDG_DATA_HOME XDG_RUNTIME_DIR XDG_STATE_HOME"
FCFLAGS="-march=native -mtune=native -O3 -pipe"
FEATURES="assume-digests binpkg-docompress binpkg-dostrip binpkg-logs binpkg-multi-instance buildpkg buildpkg-live config-protect-if-modified distlocks ebuild-locks fixlafiles ipc-sandbox merge-sync merge-wait metadata-transfer multilib-strict network-sandbox news parallel-fetch pid-sandbox pkgdir-index-trusted preserve-libs protect-owned qa-unresolved-soname-deps sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync xattr"
FFLAGS="-march=native -mtune=native -O3 -pipe"
GENTOO_MIRRORS="http://distfiles.gentoo.org/"
LANG="it_IT.UTF-8"
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
LEX="flex"
MAKEOPTS="-j20"
PKGDIR="/var/cache/binpkgs"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --omit-dir-times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages --exclude=/.git"
PORTAGE_TMPDIR="/var/tmp"
SHELL="/bin/bash"
USE="X a52 aac acl acpi activities alsa amd64 bluetooth branding bzip2 cairo cdda cdr cli crypt cups dbus declarative dri dts dvd dvdr encode exif flac fortran gdbm gif gpm gtk gui iconv icu ipv6 jpeg kde kwallet lcms libnotify libtirpc mad mng mp3 mp4 mpeg multilib ncurses networkmanager nls ogg opengl openmp pam pango pcre pdf pipewire plasma png policykit ppds pulseaudio qml qt5 readline screencast sdl seccomp selinux semantic-desktop sound spell ssl startup-notification svg systemd test-rust tiff truetype udev udisks unicode upower usb vorbis vulkan wayland widgets wxwidgets x264 xattr xcb xft xml xv xvid zlib" ABI_X86="64" ADA_TARGET="gcc_12" APACHE2_MODULES="authn_core authz_core socache_shmcb unixd actions alias auth_basic authn_anon authn_dbm authn_file authz_dbm authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir env expires ext_filter file_cache filter headers include info log_config logio mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" CALLIGRA_FEATURES="karbon sheets words" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" CPU_FLAGS_X86="fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush dts acpi mmx mmxext fxsr sse sse2 ss ht tm pbe syscall nx pdpe1gb rdtscp lm constant_tsc art arch_perfmon pebs bts rep_good nopl xtopology nonstop_tsc cpuid aperfmperf pni pclmulqdq dtes64 monitor ds_cpl vmx smx est tm2 ssse3 sse3 sdbg fma cx16 xtpr pdcm pcid sse4_1 sse4_2 x2apic movbe popcnt tsc_deadline_timer aes xsave avx f16c rdrand lahf_lm abm 3dnowprefetch cpuid_fault epb invpcid_single ssbd ibrs ibpb stibp ibrs_enhanced tpr_shadow vnmi flexpriority ept vpid ept_ad fsgsbase tsc_adjust sgx bmi1 avx2 smep bmi2 erms invpcid mpx rdseed adx smap clflushopt intel_pt xsaveopt xsavec xgetbv1 xsaves dtherm ida arat pln pts hwp hwp_notify hwp_act_window hwp_epp pku ospke sgx_lc md_clear flush_l1d arch_capabilities" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock greis isync itrax mtk3301 ntrip navcom oceanserver oncore rtcm104v2 rtcm104v3 sirf skytraq superstar2 tsip tripmate tnt ublox" GRUB_PLATFORMS="efi-64" INPUT_DEVICES="libinput evdev mouse synaptics" KERNEL="linux" L10N="it" LCD_DEVICES="bayrad cfontz glk hd44780 lb216 lcdm001 mtxorb text" LLVM_TARGETS="NVPTX" LUA_SINGLE_TARGET="lua5-4" LUA_TARGETS="lua5-4" OFFICE_IMPLEMENTATION="libreoffice" PHP_TARGETS="php8-1" POSTGRES_TARGETS="postgres15" PYTHON_SINGLE_TARGET="python3_11" PYTHON_TARGETS="python3_11" QEMU_SOFTMMU_TARGETS="x86_64 hppa i386 arm sparc64" RUBY_TARGETS="ruby32" VIDEO_CARDS="nvidia" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipp2p iface geoip fuzzy condition tarpit sysrq proto logmark ipmark dhcpmac delude chaos account"
Unset:  ADDR2LINE, AR, ARFLAGS, AS, ASFLAGS, CC, CCLD, CONFIG_SHELL, CPP, CPPFLAGS, CTARGET, CXX, CXXFILT, ELFEDIT, EMERGE_DEFAULT_OPTS, EXTRA_ECONF, F77FLAGS, FC, GCOV, GPROF, INSTALL_MASK, LC_ALL, LD, LFLAGS, LIBTOOL, LINGUAS, MAKE, MAKEFLAGS, NM, OBJCOPY, OBJDUMP, PORTAGE_BINHOST, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, PYTHONPATH, RANLIB, READELF, RUSTFLAGS, SIZE, STRINGS, STRIP, YACC, YFLAGS

=================================================================
                        Package Settings
=================================================================

media-libs/opencv-4.8.1-r1::gentoo was built with the following:
USE="contrib contribdnn cuda cudnn eigen features2d ffmpeg gstreamer java jpeg opencl opengl openmp png python qt5 tiff v4l vaapi webp xine -contribcvv -contribfreetype -contribhdf (-contribovis) -contribsfm -contribxfeatures2d -debug -dnnsamples -examples -gdal -gflags -glog -gphoto2 -gtk3 -ieee1394 -jpeg2k -lapack -non-free -opencvapps -openexr -qt6 -tbb -tesseract -testprograms -vtk" ABI_X86="(64) -32 (-x32)" CPU_FLAGS_X86="avx avx2 f16c popcnt sse sse2 sse3 sse4_1 sse4_2 ssse3 -avx512f -fma3" PYTHON_TARGETS="python3_11 -python3_10 -python3_12" VIDEO_CARDS="-intel"




 * ----------------------- SANDBOX ACCESS VIOLATION SUMMARY -----------------------
 * LOG FILE: "/var/tmp/portage/media-libs/opencv-4.9.0/temp/sandbox.log"
 * 
VERSION 1.0
FORMAT: F - Function called
FORMAT: S - Access Status
FORMAT: P - Path as passed to function
FORMAT: A - Absolute Path (not canonical)
FORMAT: R - Canonical Path
FORMAT: C - Command Line

F: fopen_wr
S: deny
P: /proc/self/task/195/comm
A: /proc/self/task/195/comm
R: /proc/194/task/195/comm
C: __nvcc_device_query 

F: fopen_wr
S: deny
P: /proc/self/task/1764/comm
A: /proc/self/task/1764/comm
R: /proc/1763/task/1764/comm
C: /var/tmp/portage/media-libs/opencv-4.9.0/work/opencv-4.9.0_build-abi_x86_64.amd64-python3_11/CMakeFiles/CheckCUDA/CMakeFiles/3.29.0/CMakeDetermineCompilerABI_CUDA.bin 

F: fopen_wr
S: deny
P: /proc/self/task/1831/comm
A: /proc/self/task/1831/comm
R: /proc/1830/task/1831/comm
C: /var/tmp/portage/media-libs/opencv-4.9.0/work/opencv-4.9.0_build-abi_x86_64.amd64-python3_11/CMakeFiles/3.29.0/CMakeDetermineCompilerABI_CUDA.bin
Comment 1 Paul Zander 2024-04-05 08:57:09 UTC
Can you tell me you versions of:
- dev-util/nvidia-cuda-toolkit
- x11-drivers/nvidia-drivers

and what GPUs you use?

The easiest solutions is to follow the instructions in the pkg_pretend einfo, e.g. set CUDA_GENERATION or CUDA_ARCH_BIN. That will avoid the auto detection.

Or you add "/proc/self/task/" to SANDBOX_PREDICT in /etc/sandbox.d/. 
> echo 'SANDBOX_PREDICT="/proc/self/task"' >> /etc/sandbox.d/20nvidia
Comment 2 Andrea Postiglione 2024-04-05 10:57:40 UTC
(In reply to Paul Zander from comment #1)
> Can you tell me you versions of:
> - dev-util/nvidia-cuda-toolkit
> - x11-drivers/nvidia-drivers
> 
> and what GPUs you use?
> 
> The easiest solutions is to follow the instructions in the pkg_pretend
> einfo, e.g. set CUDA_GENERATION or CUDA_ARCH_BIN. That will avoid the auto
> detection.
> 
> Or you add "/proc/self/task/" to SANDBOX_PREDICT in /etc/sandbox.d/. 
> > echo 'SANDBOX_PREDICT="/proc/self/task"' >> /etc/sandbox.d/20nvidia

thunderdome ~ # equery list nvidia-cuda-toolkit
 * Searching for nvidia-cuda-toolkit ...
[IP-] [  ] dev-util/nvidia-cuda-toolkit-12.3.2:0/12.3.2
thunderdome ~ # equery list nvidia-drivers
 * Searching for nvidia-drivers ...
[IP-] [  ] x11-drivers/nvidia-drivers-550.67:0/550

thunderdome ~ # lspci | grep VGA
01:00.0 VGA compatible controller: NVIDIA Corporation TU104BM [GeForce RTX 2080 SUPER Mobile / Max-Q] (rev a1)
Comment 3 Paul Zander 2024-04-08 15:01:45 UTC
Have you tried either solution? If not, the SANDBOX_PREDICT is now in dev-util/nvidia-cuda-toolkit-12.3.2, so try reinstalling that.
Comment 4 Larry the Git Cow gentoo-dev 2024-04-21 12:51:18 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=cebb6e2fdce12a8c5f81f1b19bd494469ace2786

commit cebb6e2fdce12a8c5f81f1b19bd494469ace2786
Author:     Paul Zander <negril.nx+gentoo@gmail.com>
AuthorDate: 2024-04-12 13:08:34 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2024-04-21 12:49:40 +0000

    media-libs/opencv: bugfixes
    
    Closes: https://bugs.gentoo.org/929972
    Closes: https://bugs.gentoo.org/928516
    Closes: https://bugs.gentoo.org/928747
    Closes: https://bugs.gentoo.org/927992
    Closes: https://bugs.gentoo.org/927917
    Signed-off-by: Paul Zander <negril.nx+gentoo@gmail.com>
    Closes: https://github.com/gentoo/gentoo/pull/36248
    Signed-off-by: Sam James <sam@gentoo.org>

 .../opencv/files/opencv-4.9.0-cuda-12.4.patch      | 70 ++++++++++++++++++++++
 media-libs/opencv/opencv-4.8.1-r1.ebuild           |  1 +
 media-libs/opencv/opencv-4.9.0.ebuild              |  5 +-
 profiles/arch/amd64/use.mask                       |  4 ++
 profiles/arch/arm64/package.use.force              |  4 ++
 profiles/arch/arm64/package.use.mask               |  4 ++
 profiles/arch/base/use.mask                        |  4 ++
 profiles/arch/x86/use.mask                         |  4 ++
 8 files changed, 95 insertions(+), 1 deletion(-)