Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 87163 - net-analyzer/snmpmon-0.5 sandbox violation
Summary: net-analyzer/snmpmon-0.5 sandbox violation
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo TreeCleaner Project
URL:
Whiteboard: Pending removal 04 Jan 2008
Keywords: PMASKED
Depends on:
Blocks:
 
Reported: 2005-03-29 13:29 UTC by Paul Collins
Modified: 2008-01-07 13:59 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
makefile as requested (Makefile,12.63 KB, text/plain)
2005-03-31 10:21 UTC, Paul Collins
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Paul Collins 2005-03-29 13:29:02 UTC
snmpmon tries to create directories in the root (i.e. /share) instead of being chrooted to /usr.

Reproducible: Always
Steps to Reproduce:


Actual Results:  
--------------------------- ACCESS VIOLATION SUMMARY ---------------------------
LOG FILE = "/tmp/sandbox-net-analyzer_-_snmpmon-0.5-1287.log"

open_wr:   /bin/snmpmon
mkdir:     /share



Portage 2.0.51.19 (default-linux/x86/2004.3, gcc-3.3.5, glibc-2.3.4.20040808-r1,
2.6.10-gentoo-r6 i686)
=================================================================
System uname: 2.6.10-gentoo-r6 i686 Intel(R) Pentium(R) M processor 1.60GHz
Gentoo Base System version 1.6.10
Python:              dev-lang/python-2.3.4-r1 [2.3.4 (#1, Feb  8 2005, 09:31:05)]
dev-lang/python:     2.3.4-r1
sys-devel/autoconf:  2.59-r6, 2.13
sys-devel/automake:  1.7.9-r1, 1.8.5-r3, 1.5, 1.4_p6, 1.6.3, 1.9.4
sys-devel/binutils:  2.15.92.0.2-r1
sys-devel/libtool:   1.5.10-r4
virtual/os-headers:  2.6.8.1-r2
ACCEPT_KEYWORDS="x86"
AUTOCLEAN="yes"
CFLAGS="-march=pentium3 -O3 -mmmx -msse -msse2 -fomit-frame-pointer -pipe"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/2/share/config /usr/kde/3.3/env
/usr/kde/3.3/share/config /usr/kde/3.3/shutdown /usr/kde/3/share/config
/usr/lib/X11/xkb /usr/lib/mozilla/defaults/pref /usr/share/config
/var/qmail/control"
CONFIG_PROTECT_MASK="/etc/gconf /etc/terminfo /etc/env.d"
CXXFLAGS="-march=pentium3 -O3 -mmmx -msse -msse2 -fomit-frame-pointer -pipe"
DISTDIR="/usr/portage/distfiles"
FEATURES="autoaddcvs autoconfig ccache distlocks sandbox sfperms strict userpriv"
GENTOO_MIRRORS="http://gentoo.ccccom.com"
LDFLAGS="-Wl,-O1"
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_TMPDIR="/usr/portage_tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage"
SYNC="rsync://igor.san.msc.com/gentoo-portage"
USE="x86 X aalib acl acpi acpi4linux aim alsa apache2 async avi berkdb
bitmap-fonts bonobo cdb cddb cdr cjk crypt cups curl dio directfb divx4linux doc
dvd dvdr edl emboss encode esd evms2 evo fam fax fbdev flac font-server
foomaticdb fortran freetype ftp gd gdbm gif gimp gimpprint gpm gstreamer gtk
gtk2 gtkhtml guile icq imagemagick imap imlib imlib2 innodb ipv6 irda java jpeg
junit kde ldap libg++ libwww lirc live mad maildir makecheck matroska md5sum mha
mikmod mmx motif mozilla moznocompose moznoirc moznomail mozp3p mozsvg mp3 mpeg
mpeg4 mplayer msn mysql mysqli nas ncurses network nls norewrite objc odbc
offensive ofx oggvorbis opengl pam pcre pdflib perl php plotutils png pnp posix
pthreads python qt quicktime radeon readline rtc samba sasl sdl slang snmp
speedo spell sse sse2 ssl svg svga sysvipc tcltk tcpd tiff transcode truetype
truetype-fonts trusted type1 type1-fonts unicode usb vim-with-x wifi wxwin
wxwindows xml xml2 xmms xv xvid zlib"
Unset:  ASFLAGS, CBUILD, CTARGET, LANG, LC_ALL
Comment 1 Carsten Lohrke (RETIRED) gentoo-dev 2005-03-31 09:03:20 UTC
Hm, the ebuild is a bit ugly, but I have no idea why this should happen. /usr/bin and /usr/share are hardcoded. Can you attach the Makefile, please? Are you sure not to have an ebuild in your overlay?
Comment 2 Paul Collins 2005-03-31 10:21:35 UTC
Created attachment 54941 [details]
makefile as requested

I've attached the makefile that it generated out of the work directory. As far
as overlays, this package can't (or at the very least, shouldn't) be affected
by that. I don't have that package in the overlay directory, and none of it's
dependancies are in there either.
Comment 3 Markus Ullmann (RETIRED) gentoo-dev 2007-07-24 20:35:12 UTC
Reassign to maintainer
Comment 4 Jakub Moc (RETIRED) gentoo-dev 2007-07-24 20:37:29 UTC
(In reply to comment #3)
> Reassign to maintainer

Well, I intentionally re-assigned this to m-needed because maintainer hasn't cared for over two years.
 

Comment 5 Samuli Suominen (RETIRED) gentoo-dev 2007-09-29 12:31:37 UTC
Carlo, if you are not going to fix it..

+1 from my treecleaner vote.
Comment 6 Jakub Moc (RETIRED) gentoo-dev 2007-09-29 12:34:14 UTC
+1, broken for ages, noone cares, last release February 25, 2004.
Comment 7 Samuli Suominen (RETIRED) gentoo-dev 2008-01-07 13:59:57 UTC
gone