Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 165275 - www-servers/yaws removal request (outdated, vulnerable, broken)
Summary: www-servers/yaws removal request (outdated, vulnerable, broken)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Server (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo TreeCleaner Project
URL: http://sourceforge.net/mailarchive/fo...
Whiteboard:
Keywords:
Depends on: 159602
Blocks:
  Show dependency tree
 
Reported: 2007-02-04 13:57 UTC by Christopher Covington
Modified: 2008-06-02 21:01 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
/etc/yaws.conf (yaws.conf,3.53 KB, text/plain)
2007-02-04 13:59 UTC, Christopher Covington
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Christopher Covington 2007-02-04 13:57:49 UTC
Yaws is unable to access .beam binaries and I'm pretty sure it isn't because of poor configuration. The files are readable as user nobody and are in my path. Also, when I install ErlyWeb from the Erlay overlay and try to compile a new application, I get a massive dump of the same kind of errors.

Error that I get all the time in /var/log/yaws/report.log:
=ERROR REPORT==== 4-Feb-2007::10:26:10 ===
File operation error: eacces. Target: ./random.beam. Function: get_file. Process: code_server.

Snippets from /var/log/yaws/report.log when trying to compile a new ErlyWeb app:
=ERROR REPORT==== 4-Feb-2007::10:27:36 ===
File operation error: eacces. Target: ./otp_internal.beam. Function: get_file. Process: code_server.

=ERROR REPORT==== 4-Feb-2007::10:27:36 ===
File operation error: eacces. Target: ./erl_internal.beam. Function: get_file. Process: code_server.

=ERROR REPORT==== 4-Feb-2007::10:27:36 ===
File operation error: eacces. Target: ./erlyweb.beam. Function: get_file. Process: code_server.

=ERROR REPORT==== 4-Feb-2007::10:27:36 ===
File operation error: eacces. Target: ./erlyweb_util.beam. Function: get_file. Process: code_server.

=ERROR REPORT==== 4-Feb-2007::10:27:36 ===
File operation error: eacces. Target: ./filelib.beam. Function: get_file. Process: code_server.

# eix yaws
[I] www-servers/yaws
     Available versions:  (~)1.56 (~)1.58
     Installed versions:  1.58(09:34:31 PM 12/30/2006)
     Homepage:            http://yaws.hyber.org/
     Description:         Yaws is a high performance HTTP 1.1 web server.

# emerge --info
Portage 2.1.2-r5 (default-linux/x86/vserver, gcc-4.1.1, glibc-2.5-r0, 2.6.18-vs2.1.1-gentoo-r1 i686)
=================================================================
System uname: 2.6.18-vs2.1.1-gentoo-r1 i686 Intel(R) Pentium(R) D  CPU 2.66GHz
Gentoo Base System version 1.12.6
Timestamp of tree: Fri, 02 Feb 2007 13:50:01 +0000
dev-java/java-config: 1.3.7, 2.0.31-r3
dev-lang/python:     2.4.4
dev-python/pycrypto: 2.0.1-r5
sys-apps/sandbox:    1.2.18.1
sys-devel/autoconf:  2.13, 2.61
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.17
sys-devel/gcc-config: 1.3.14
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.19.2-r2
ACCEPT_KEYWORDS="x86 ~x86"
AUTOCLEAN="yes"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-march=prescott -O2 -pipe -fomit-frame-pointer"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /var/qmail/alias /var/qmail/control"
CONFIG_PROTECT_MASK="/etc/env.d /etc/env.d/java/ /etc/gconf /etc/java-config/vms/ /etc/revdep-rebuild /etc/terminfo"
CXXFLAGS="-march=prescott -O2 -pipe -fomit-frame-pointer"
DISTDIR="/usr/portage/distfiles"
FEATURES="autoconfig confcache distlocks metadata-transfer parallel-fetch sandbox sfperms strict userpriv usersandbox"
GENTOO_MIRRORS="http://distfiles.gentoo.org http://distro.ibiblio.org/pub/linux/distributions/gentoo"
LANG="en_US.utf8"
LC_ALL="en_US.utf8"
MAKEOPTS="-j3"
PKGDIR="/usr/portage/packages"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage/layman/erlay /usr/local/portage"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="berkdb bitmap-fonts bzip2 cgi cli cracklib crypt dlloader dri exif fastcgi fortran ftp gmp gnutls iconv ipv6 isdnlog jpeg memlimit midi ming ncurses nptl nptlonly pam pcre png postgres pppd python readline reflection session socks5 spell spl sse sse2 sse3 ssl tcpd threads tidy truetype truetype-fonts type1-fonts unicode x86 xml xorg xsl zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mulaw multi null plug rate route share shm softvol" ELIBC="glibc" INPUT_DEVICES="keyboard mouse evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" USERLAND="GNU" VIDEO_CARDS="apm ark ati chips cirrus cyrix dummy fbdev glint i128 i740 i810 imstt mga neomagic nsc nv rendition s3 s3virge savage siliconmotion sis sisusb tdfx tga trident tseng v4l vesa vga via vmware voodoo"
Unset:  CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LDFLAGS, LINGUAS, PORTAGE_RSYNC_EXTRA_OPTS
Comment 1 Christopher Covington 2007-02-04 13:59:21 UTC
Created attachment 109122 [details]
/etc/yaws.conf
Comment 2 Christopher Covington 2007-03-02 16:45:26 UTC
This problem is solved for me by version 1.68.
Comment 3 Jakub Moc (RETIRED) gentoo-dev 2007-11-17 20:41:17 UTC
This has been masked for 7+ months without anyone stepping up to bump this, suggest removing the package.

# Stefan Cornelius <dercorny@gentoo.org> (2 Mar 2007)
# Masked wrt security bug #158958
www-servers/yaws

Comment 4 Samuli Suominen (RETIRED) gentoo-dev 2008-05-15 13:02:46 UTC
Gone.
Comment 5 Vincent de Phily 2008-06-02 12:32:27 UTC
Not sure if this is the right place to ask, but how do we get this package back in the tree ? I'm using yaws in a production environement (with a 1.75 ebuild, upstream fixed the vulnerability long ago), and would be happy to be a proxy maintainer (or whichever way users should maintain packages) for this package.
Comment 6 Thilo Bangert (RETIRED) (RETIRED) gentoo-dev 2008-06-02 21:01:47 UTC
the www-servers herd/team and i would be happy to be your proxy. please attach your ebuild to a new bug and assign it to me.

thanks