[#391565] p11 EPERM glpi.git=10.0.19-alt1

Girar awaiter (zidex) girar-builder at altlinux.org
Sat Aug 2 14:19:22 MSK 2025


https://git.altlinux.org/tasks/391565/logs/events.1.1.log
https://packages.altlinux.org/tasks/391565

subtask  name  aarch64  i586  x86_64
   #100  glpi     1:43  1:44    1:16

2025-Aug-02 11:13:22 :: task #391565 for p11 started by zidex:
2025-Aug-02 11:13:23 :: message: security_fix
#100 build 10.0.19-alt1 from /people/zidex/packages/glpi.git fetched at 2025-Aug-02 11:12:37
2025-Aug-02 11:13:24 :: [i586] #100 glpi.git 10.0.19-alt1: build start
2025-Aug-02 11:13:24 :: [aarch64] #100 glpi.git 10.0.19-alt1: build start
2025-Aug-02 11:13:24 :: [x86_64] #100 glpi.git 10.0.19-alt1: build start
2025-Aug-02 11:14:40 :: [x86_64] #100 glpi.git 10.0.19-alt1: build OK
2025-Aug-02 11:15:07 :: [aarch64] #100 glpi.git 10.0.19-alt1: build OK
2025-Aug-02 11:15:08 :: [i586] #100 glpi.git 10.0.19-alt1: build OK
2025-Aug-02 11:15:29 :: #100: glpi.git 10.0.19-alt1: build check OK
2025-Aug-02 11:15:30 :: build check OK
2025-Aug-02 11:15:45 :: noarch check OK
2025-Aug-02 11:15:46 :: plan: src +1 -1 =19749, noarch +5 -5 =20867
#100 glpi 10.0.18-alt1 -> 10.0.19-alt1
 Wed Jul 16 2025 Pavel Zilke <zidex at altlinux> 10.0.19-alt1
 - New version 10.0.19
 - This release fixes a security issue that has been recently discovered. Update is recommended!
 - Security fixes:
  + CVE-2025-27514 : Stored XSS on projects kanban
  + CVE-2025-52567 : Blind SSRF in RSS feeds and planning
  + CVE-2025-52897 : XSS and open redirection in planning
  + CVE-2025-53008 : Mail receiver credentials exfiltration
  + CVE-2025-53357 : Reservations modification by unauthorized user
  + CVE-2025-53113 : Access to unallowed items information through external links
 [...]
2025-Aug-02 11:15:47 :: glpi: mentions vulnerabilities: CVE-2025-27514 CVE-2025-52567 CVE-2025-52897 CVE-2025-53008 CVE-2025-53357 CVE-2025-53113 CVE-2025-53111 CVE-2025-53112 CVE-2025-53105
2025-Aug-02 11:16:13 :: patched apt indices
2025-Aug-02 11:16:22 :: created next repo
2025-Aug-02 11:16:32 :: duplicate provides check OK
2025-Aug-02 11:17:08 :: dependencies check OK
2025-Aug-02 11:17:27 :: [x86_64] #100 glpi: install check OK
2025-Aug-02 11:17:28 :: [i586] #100 glpi: install check OK
2025-Aug-02 11:17:37 :: [aarch64] #100 glpi: install check OK
2025-Aug-02 11:17:40 :: [x86_64] #100 glpi-apache2: install check OK
2025-Aug-02 11:17:41 :: [i586] #100 glpi-apache2: install check OK
2025-Aug-02 11:17:53 :: [x86_64] #100 glpi-php8.1: install check OK
2025-Aug-02 11:17:54 :: [i586] #100 glpi-php8.1: install check OK
2025-Aug-02 11:17:55 :: [aarch64] #100 glpi-apache2: install check OK
2025-Aug-02 11:18:05 :: [x86_64] #100 glpi-php8.2: install check OK
2025-Aug-02 11:18:07 :: [i586] #100 glpi-php8.2: install check OK
2025-Aug-02 11:18:13 :: [aarch64] #100 glpi-php8.1: install check OK
2025-Aug-02 11:18:18 :: [x86_64] #100 glpi-php8.3: install check OK
2025-Aug-02 11:18:20 :: [i586] #100 glpi-php8.3: install check OK
2025-Aug-02 11:18:31 :: [aarch64] #100 glpi-php8.2: install check OK
2025-Aug-02 11:18:49 :: [aarch64] #100 glpi-php8.3: install check OK
2025-Aug-02 11:18:51 :: gears inheritance check OK
2025-Aug-02 11:18:51 :: srpm inheritance check OK
girar-check-perms: access to glpi DENIED for zidex: project `glpi' is not listed in the acl file for repository `p11', and the policy for such projects in `p11' is to deny
check-subtask-perms: #100: glpi: needs approvals from members of @maint and @tester groups
2025-Aug-02 11:18:53 :: acl check FAILED
2025-Aug-02 11:19:12 :: created contents_index files
2025-Aug-02 11:19:18 :: created hash files: noarch src
2025-Aug-02 11:19:22 :: task #391565 for p11 EPERM


More information about the Sisyphus-incominger mailing list