[#293697] p8 EPERM (try 4) expat.git=2.4.3-alt1

Girar awaiter (vseleznv) girar-builder at altlinux.org
Wed Feb 2 18:44:59 MSK 2022


https://git.altlinux.org/tasks/293697/logs/events.4.1.log

2022-Feb-02 15:41:50 :: task #293697 for p8 resumed by vseleznv:
2022-Feb-02 15:41:50 :: message: Security backport
#100 build 2.4.3-alt1 from /people/vseleznv/packages/expat.git fetched at 2022-Jan-18 12:26:47
2022-Feb-02 15:41:51 :: [i586] #100 expat.git 2.4.3-alt1: build start
2022-Feb-02 15:41:51 :: [x86_64] #100 expat.git 2.4.3-alt1: build start
2022-Feb-02 15:42:11 :: [i586] #100 expat.git 2.4.3-alt1: build OK (cached)
2022-Feb-02 15:42:12 :: [x86_64] #100 expat.git 2.4.3-alt1: build OK (cached)
2022-Feb-02 15:42:20 :: #100: expat.git 2.4.3-alt1: build check OK
2022-Feb-02 15:42:20 :: build check OK
2022-Feb-02 15:42:23 :: noarch check OK
2022-Feb-02 15:42:24 :: plan: src +1 -1 =18243, i586 +5 -5 =35350, x86_64 +5 -5 =35354
#100 expat 2.2.4-alt0.M80P.1 -> 2.4.3-alt1
 Tue Jan 18 2022 Vladimir D. Seleznev <vseleznv at altlinux> 2.4.3-alt1
 - Updated to 2.4.3 (with multiple security fixes).
 - Fixes:
   + CVE-2021-45960 issues with left shift by >= 29 places in function storeAtts that
     can lead to realloc misbehavior;
   + CVE-2021-46143 Integer overflow on variable m_groupSize in function doProlog;
   + CVE-2022-22822 Integer overflows near memory allocation in function addBinding;
   + CVE-2022-22823 Integer overflows near memory allocation in function build_model;
   + CVE-2022-22824 Integer overflows near memory allocation in function defineAttribute;
   + CVE-2022-22825 Integer overflows near memory allocation in function lookup;
 [...]
2022-Feb-02 15:42:24 :: expat: closes bugs: 41571
2022-Feb-02 15:42:24 :: expat: fixes vulnerabilities: CVE-2018-20843 CVE-2019-15903
2022-Feb-02 15:42:24 :: expat: mentions vulnerabilities: CVE-2021-45960 CVE-2021-46143 CVE-2022-22822 CVE-2022-22823 CVE-2022-22824 CVE-2022-22825 CVE-2022-22826 CVE-2022-22827
2022-Feb-02 15:42:53 :: patched apt indices
2022-Feb-02 15:42:57 :: created next repo
2022-Feb-02 15:43:05 :: duplicate provides check OK
2022-Feb-02 15:43:36 :: dependencies check OK
2022-Feb-02 15:43:36 :: [i586 x86_64] no need to repeat ELF symbols check
2022-Feb-02 15:43:36 :: [i586 x86_64] ELF symbols check OK
2022-Feb-02 15:43:59 :: [i586] #100 expat: install check OK (cached)
2022-Feb-02 15:43:59 :: [x86_64] #100 expat: install check OK (cached)
2022-Feb-02 15:44:03 :: [i586] #100 expat-debuginfo: install check OK (cached)
2022-Feb-02 15:44:03 :: [x86_64] #100 expat-debuginfo: install check OK (cached)
2022-Feb-02 15:44:07 :: [i586] #100 libexpat: install check OK (cached)
2022-Feb-02 15:44:07 :: [x86_64] #100 libexpat: install check OK (cached)
2022-Feb-02 15:44:11 :: [i586] #100 libexpat-debuginfo: install check OK (cached)
2022-Feb-02 15:44:11 :: [x86_64] #100 libexpat-debuginfo: install check OK (cached)
	i586: libexpat-devel=2.4.3-alt1 post-install unowned files:
 /usr/lib/cmake
2022-Feb-02 15:44:15 :: [i586] #100 libexpat-devel: install check OK (cached)
	x86_64: libexpat-devel=2.4.3-alt1 post-install unowned files:
 /usr/lib64/cmake
2022-Feb-02 15:44:15 :: [x86_64] #100 libexpat-devel: install check OK (cached)
2022-Feb-02 15:44:16 :: [x86_64-i586] plan: #0 +2 -2 =11977
2022-Feb-02 15:44:29 :: [x86_64-i586] generated apt indices
2022-Feb-02 15:44:30 :: [x86_64-i586] created next repo
2022-Feb-02 15:44:39 :: [x86_64-i586] dependencies check OK
warning: #100: expat.git tag `2.4.3-alt1' is not inherited from /gears/e/expat.git branch `p8' (relaxed by sotor)
2022-Feb-02 15:44:39 :: gears inheritance check COND-OK for: #100 
warning: #100: expat-2.4.3-alt1.src.rpm: missing last changelog entry from expat-2.2.4-alt0.M80P.1.src.rpm (relaxed by sotor):
* Mon Aug 28 2017	at at altlinux	2.2.4-alt0
2022-Feb-02 15:44:39 :: srpm inheritance check COND-OK for: #100 
girar-check-perms: access to expat DENIED for vseleznv: project `expat' is not listed in the acl file for repository `p8', and the policy for such projects in `p8' is to deny
check-subtask-perms: #100: expat: Operation not permitted
2022-Feb-02 15:44:44 :: acl check FAILED
2022-Feb-02 15:44:51 :: created contents_index files
2022-Feb-02 15:44:57 :: created hash files: i586 src x86_64-i586 x86_64
2022-Feb-02 15:44:59 :: task #293697 for p8 EPERM


More information about the Sisyphus-incominger mailing list