Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 950648 - app-crypt/tpm2-tss-4.1.3-r1: Fails to configure with slibtool - ACCESS DENIED: open_wr: /usr/share/slibtool/ax_add_fortify_sourc
Summary: app-crypt/tpm2-tss-4.1.3-r1: Fails to configure with slibtool - ACCESS DENIED...
Status: UNCONFIRMED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Christopher Byrne
URL:
Whiteboard:
Keywords: PullRequest
: 951829 (view as bug list)
Depends on:
Blocks: slibtool
  Show dependency tree
 
Reported: 2025-03-05 13:46 UTC by zyxhere
Modified: 2025-03-23 00:31 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
aclocal.out (aclocal.out,494 bytes, text/plain)
2025-03-05 13:46 UTC, zyxhere
Details
build.log (build.log,3.85 KB, text/x-log)
2025-03-05 13:46 UTC, zyxhere
Details
sandbox.log (sandbox.log,459 bytes, text/x-log)
2025-03-05 13:47 UTC, zyxhere
Details

Note You need to log in before you can comment on or make changes to this bug.
Description zyxhere 2025-03-05 13:46:29 UTC
Created attachment 920262 [details]
aclocal.out

----------------------- SANDBOX ACCESS VIOLATION SUMMARY -----------------------
 * LOG FILE: "/var/tmp/portage/app-crypt/tpm2-tss-4.1.3-r1/temp/sandbox.log"

Portage 3.0.66.1 (python 3.12.9-final-0, default/linux/amd64/23.0/no-multilib/hardened, gcc-15, glibc-2.40-r8, 6.13.5-gentoo-dist-hardened x86_64)
=================================================================
System uname: Linux-6.13.5-gentoo-dist-hardened-x86_64-12th_Gen_Intel-R-_Core-TM-_i5-1235U-with-glibc2.40
KiB Mem:    11961304 total,   1967776 free
KiB Swap:    8388604 total,   8125436 free
Head commit of repository gentoo: c87872700e8951a13c426d9a61c7df1350e2567c

Head commit of repository guru: b826b71086fee111344c0fedae38f56bcbaaa76c

sh bash 5.2_p37
ld GNU ld (Gentoo 2.44 p1) 2.44.0
app-misc/pax-utils:        1.3.8::gentoo
app-shells/bash:           5.2_p37::gentoo
dev-build/autoconf:        2.13-r8::gentoo, 2.72-r1::gentoo
dev-build/automake:        1.17-r1::gentoo
dev-build/cmake:           3.31.5::gentoo
dev-build/libtool:         2.5.4::gentoo
dev-build/make:            4.4.1-r100::gentoo
dev-build/meson:           1.6.1::gentoo
dev-lang/perl:             5.40.0-r1::gentoo
dev-lang/python:           3.12.9::gentoo, 3.13.2::gentoo
dev-lang/rust:             1.85.0-r1::gentoo
llvm-core/clang:           19.1.7::gentoo
llvm-core/lld:             19.1.7::gentoo
llvm-core/llvm:            19.1.7::gentoo
sys-apps/baselayout:       2.17::gentoo
sys-apps/openrc:           0.56::gentoo
sys-apps/sandbox:          2.39::gentoo
sys-devel/binutils:        2.44::gentoo
sys-devel/binutils-config: 5.5.2::gentoo
sys-devel/gcc:             15.0.1_pre20250302-r1::gentoo
sys-devel/gcc-config:      2.12.1::gentoo
sys-kernel/linux-headers:  6.12::gentoo (virtual/os-headers)
sys-libs/glibc:            2.40-r8::gentoo
Repositories:

gentoo
    location: /var/db/repos/gentoo
    sync-type: git
    sync-uri: https://anongit.gentoo.org/git/repo/gentoo.git
    priority: -1000
    volatile: False

guru
    location: /var/db/repos/guru
    sync-type: git
    sync-uri: https://anongit.gentoo.org/git/repo/proj/guru.git
    masters: gentoo
    volatile: False

local
    location: /var/db/repos/local
    masters: gentoo
    volatile: False

Binary Repositories:

gentoobinhost
    priority: 1
    sync-uri: https://distfiles.gentoo.org/releases/amd64/binpackages/23.0/x86-64-v3

Installed sets: @base, @extra, @gnomie, @utils
ACCEPT_KEYWORDS="amd64"
ACCEPT_LICENSE="@FREE"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-march=native -O2 -pipe -flto=auto -Werror=odr -Werror=lto-type-mismatch -Werror=strict-aliasing -fdiagnostics-color=always"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/gnupg/qualified.txt"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/dconf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/sandbox.d"
CXXFLAGS="-march=native -O2 -pipe -flto=auto -Werror=odr -Werror=lto-type-mismatch -Werror=strict-aliasing -fdiagnostics-color=always"
DISTDIR="/var/cache/distfiles"
ENV_UNSET="CARGO_HOME DBUS_SESSION_BUS_ADDRESS DISPLAY GDK_PIXBUF_MODULE_FILE GOBIN GOPATH PERL5LIB PERL5OPT PERLPREFIX PERL_CORE PERL_MB_OPT PERL_MM_OPT XAUTHORITY XDG_CACHE_HOME XDG_CONFIG_HOME XDG_DATA_HOME XDG_RUNTIME_DIR XDG_STATE_HOME"
FCFLAGS="-march=native -O2 -pipe -flto=auto -Werror=odr -Werror=lto-type-mismatch -Werror=strict-aliasing -fdiagnostics-color=always"
FEATURES="assume-digests binpkg-docompress binpkg-dostrip binpkg-logs binpkg-multi-instance buildpkg-live config-protect-if-modified distlocks ebuild-locks fixlafiles ipc-sandbox merge-sync merge-wait multilib-strict network-sandbox news parallel-fetch pid-sandbox pkgdir-index-trusted preserve-libs protect-owned qa-unresolved-soname-deps sandbox sfperms strict strict-keepdir unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync warn-on-large-env xattr"
FFLAGS="-march=native -O2 -pipe -flto=auto -Werror=odr -Werror=lto-type-mismatch -Werror=strict-aliasing -fdiagnostics-color=always"
GENTOO_MIRRORS="http://distfiles.gentoo.org"
LANG="C.UTF8"
LD="ld.mold"
LDFLAGS="-Wl,-O1 -Wl,--as-needed -Wl,-z,pack-relative-relocs -flto=auto -fuse-ld=mold -Wl,--color-diagnostics"
LEX="flex"
LIBTOOL="rlibtool"
MAKE="make LIBTOOL=rlibtool"
MAKEFLAGS="LIBTOOL=rlibtool"
MAKEOPTS="-j6 -l8"
PKGDIR="/var/cache/binpkgs"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --omit-dir-times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages --exclude=/.git"
PORTAGE_TMPDIR="/var/tmp"
RUSTFLAGS="-C target-cpu=native"
SHELL="/bin/bash"
USE="acl amd64 aom avif bluetooth bzip2 cet clang crypt cups dbus dist-kernel elogind flac fontconfig gdbm gdk-pixbuf gif gnome gnome-keyring gstreamer gtk gtk4 hardened harfbuzz iconv icu io-uring io_uring ipv6 jpeg jpegxl keyring lcms libtirpc lto lz4 lzma lzo modemmanager ncurses networkmanager nls openmp opus orc pam pcre pdf pgo pic pie pipewire png policykit profile readline screencast seccomp sound spell ssl ssp svg test-rust tiff tpm udev udisks unicode upower usb vaapi vpx vulkan wayland webp xattr xml xtpax zlib zstd" ABI_X86="64" ADA_TARGET="gcc_14" APACHE2_MODULES="authn_core authz_core socache_shmcb unixd actions alias auth_basic authn_anon authn_dbm authn_file authz_dbm authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir env expires ext_filter file_cache filter headers include info log_config logio mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" CALLIGRA_FEATURES="karbon sheets words" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" CPU_FLAGS_X86="aes avx avx2 f16c fma3 mmx mmxext pclmul popcnt rdrand sha sse sse2 sse3 sse4_1 sse4_2 ssse3 vpclmulqdq" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock greis isync itrax navcom oceanserver oncore rtcm104v2 rtcm104v3 sirf skytraq superstar2 tsip tripmate tnt ublox" GUILE_SINGLE_TARGET="3-0" GUILE_TARGETS="3-0" INPUT_DEVICES="libinput" KERNEL="linux" LCD_DEVICES="bayrad cfontz glk hd44780 lb216 lcdm001 mtxorb text" LLVM_TARGETS="x86 AMDGPU WebAssembly" LUA_SINGLE_TARGET="lua5-1" LUA_TARGETS="lua5-1" OFFICE_IMPLEMENTATION="libreoffice" PHP_TARGETS="php8-2" POSTGRES_TARGETS="postgres16" PYTHON_SINGLE_TARGET="python3_12" PYTHON_TARGETS="python3_12" RUBY_TARGETS="ruby32" VIDEO_CARDS="intel" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipp2p iface geoip fuzzy condition tarpit sysrq proto logmark ipmark dhcpmac delude chaos account"
Unset:  ADDR2LINE, AR, ARFLAGS, AS, ASFLAGS, CC, CCLD, CONFIG_SHELL, CPP, CPPFLAGS, CTARGET, CXX, CXXFILT, ELFEDIT, EMERGE_DEFAULT_OPTS, EXTRA_ECONF, F77FLAGS, FC, GCOV, GPROF, INSTALL_MASK, LC_ALL, LFLAGS, LINGUAS, NM, OBJCOPY, OBJDUMP, PORTAGE_BINHOST, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, PYTHONPATH, RANLIB, READELF, SIZE, STRINGS, STRIP, YACC, YFLAGS
Comment 1 zyxhere 2025-03-05 13:46:52 UTC
Created attachment 920263 [details]
build.log
Comment 2 zyxhere 2025-03-05 13:47:13 UTC
Created attachment 920264 [details]
sandbox.log
Comment 3 Christopher Byrne 2025-03-05 16:36:48 UTC
The problem here is AT_M4DIR="/usr/share/slibtool" added to the environment. 

This causes autotools.eclass to run:

aclocal -I /usr/share/slibtool -I m4 --install --system-acdir=/var/tmp/portage/app-crypt/tpm2-tss-4.1.3-r1/temp/aclocal

And info guide for aclocal states this about the --install option:

    Install system-wide third-party macros into the first directory specified with ‘-I dir’ instead of copying them into the output file. This is also done if dir is an absolute path. 

However, autotools.eclass handles this, not app-crypt/tpm2-tss.
Comment 4 Christopher Byrne 2025-03-05 20:52:17 UTC
autotools.eclass is choking on this in Makefile.am:

ACLOCAL_AMFLAGS = -I m4 --install

By itself, its not a problem, but combined with AT_M4DIR it fails because AT_M4DIR comes first. See eaclocal_amflags in autotools.eclass.
Comment 6 Christopher Byrne 2025-03-06 03:03:57 UTC
Still doesn't work even with above change. 

The problem is in autotools.eclass. It will fail or any package that has "AT_M4DIR" set in the environment and "ACLOCAL_AMFLAGS" with "--install" in Makefile.am. This was once recommended, so its likely other package will hit the issue with slibtool if they are following the wiki. 

Note ACLOCAL_AMFLAGS is deprecated in Automake (since 1.13) in favor of AC_CONFIG_MACRO_DIRS in Autoconf (since 2.70).
Comment 7 orbea 2025-03-11 15:02:29 UTC
They already have 'AC_CONFIG_MACRO_DIR([m4])' in configure.ac and I'm not sure what adding '--install' to ACLOCAL_AMFLAGS is supposed to solve? Maybe '--install' can just be removed or the entire ACLOCAL_AMFLAGS removed?

This is not a common problem at least.
Comment 8 Christopher Byrne 2025-03-11 16:33:22 UTC
I sent a PR upstream to remove the deprecated construction
Comment 9 orbea 2025-03-11 17:47:47 UTC
There is no reason to change 'AC_CONFIG_MACRO_DIR' to 'AC_CONFIG_MACRO_DIRS', both are valid and there is only one directory.

https://www.gnu.org/software/autoconf/manual/autoconf-2.70/html_node/Input.html
Comment 10 Christopher Byrne 2025-03-11 18:36:17 UTC
Ok, it was my understanding they worked slightly differently, but I tested it out and they do in fact do the same thing as long as there's only one directory.
Comment 11 orbea 2025-03-12 16:30:15 UTC
I also wonder if there is a better way for slibtoolize to inject /usr/share/slibtool/slibtool.m4 into the autoreconf process?
Comment 12 orbea 2025-03-13 16:31:10 UTC
I sent a patch to the Gentoo ML (And created a PR) that should solve this. To test this it requires commenting or otherwise removing AT_SYS_M4DIR from make.conf.

It may still be a good idea for tpm2-tss to not use a deprecated macro though.
Comment 13 zyxhere 2025-03-22 14:50:37 UTC
Same thing with app-crypt/tpm2-tools and app-crypt/tpm2-abrmd
I guess the entire tpm2-software suite is affected
Comment 14 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2025-03-23 00:31:08 UTC
*** Bug 951829 has been marked as a duplicate of this bug. ***