From: Alexander Tiurin <alexanderyt@gmail.com>
To: gentoo-hardened@lists.gentoo.org
Subject: Re: [gentoo-hardened] linux32 chroot issue
Date: Mon, 24 Mar 2014 20:53:15 +0400 [thread overview]
Message-ID: <533062FB.8010809@gmail.com> (raw)
In-Reply-To: <530F3E39.4060906@opensource.dyc.edu>
On 27.02.2014 17:31, Anthony G. Basile wrote:
> On 02/26/2014 01:09 PM, Alexander Tiurin wrote:
>> I tried to reproduce this issue on another hardware (core2quad instead
>> core i7). emerge works fine. No errors detected.
>> Kernel, kernel config and enviroment is equal.
>> That's odd.
>>
> Okay. Thanks for getting back because I was at a loss to help you. If
> you figure out what *is* different let us know.
>
I upgraded kernel up to 3.13.2-hardened-r3, and portage return error:
ACCESS DENIED mkdir: /var
(line 2035 in http://pastebin.com/nsCV06Ca)
emerge proftp without debug info. Now no errors as ACCESS DENIED
/dev/{tty,null}
>>> Verifying ebuild manifests
>>> Emerging (1 of 1) net-ftp/proftpd-1.3.4c
>>> Failed to emerge net-ftp/proftpd-1.3.4c, Log file:
>>> '/var/log/portage/net-ftp:proftpd-1.3.4c:20140324-160939.log'
>>> Jobs: 0 of 1 complete, 1 failed Load avg: 1.59,
1.34, 1.46
* Package: net-ftp/proftpd-1.3.4c
* Repository: gentoo
* Maintainer: bernd@lommerzheim.com
voyageur@gentoo.org,slyfox@gentoo.org,net-ftp@gentoo.org,proxy-maint@gentoo.org
* USE: acl caps elibc_glibc kernel_linux ncurses nls pam pcre
tcpd userland_GNU x86
* FEATURES: sandbox
ACCESS DENIED mkdir: /var
install: cannot change permissions of
‘/var/tmp/portage/net-ftp/proftpd-1.3.4c/work’: No such file or directory
* ERROR: net-ftp/proftpd-1.3.4c failed (unpack phase):
* Failed to create dir '/var/tmp/portage/net-ftp/proftpd-1.3.4c/work'
*
* Call stack:
* ebuild.sh, line 708: Called ebuild_main 'unpack'
* phase-functions.sh, line 955: Called dyn_unpack
* phase-functions.sh, line 243: Called die
* The specific snippet of code:
* install -m${PORTAGE_WORKDIR_MODE:-0700} -d "${WORKDIR}"
|| die "Failed to create dir '${WORKDIR}'"
*
* If you need support, post the output of `emerge --info
'=net-ftp/proftpd-1.3.4c'`,
* the complete build log and the output of `emerge -pqv
'=net-ftp/proftpd-1.3.4c'`.
* The complete build log is located at
'/var/log/portage/net-ftp:proftpd-1.3.4c:20140324-160939.log'.
* For convenience, a symlink to the build log is located at
'/var/tmp/portage/net-ftp/proftpd-1.3.4c/temp/build.log'.
* The ebuild environment file is located at
'/var/tmp/portage/net-ftp/proftpd-1.3.4c/temp/environment'.
* Working directory: '/var/tmp/portage/net-ftp/proftpd-1.3.4c'
* S: '/var/tmp/portage/net-ftp/proftpd-1.3.4c/work/proftpd-1.3.4c'
--------------------------- ACCESS VIOLATION SUMMARY
---------------------------
LOG FILE "/var/log/sandbox/sandbox-13354.log"
VERSION 1.0
FORMAT: F - Function called
FORMAT: S - Access Status
FORMAT: P - Path as passed to function
FORMAT: A - Absolute Path (not canonical)
FORMAT: R - Canonical Path
FORMAT: C - Command Line
F: mkdir
S: deny
P: /var
A: /var
R: /var
C: install -m0700 -d /var tmp/portage/net-ftp/proftpd-1.3.4c/work
I changed step by step grsec kernel config options, but it not worked
for me. Maybe I missed something.
prev parent reply other threads:[~2014-03-24 16:52 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-02-21 22:48 [gentoo-hardened] linux32 chroot issue Alexander Tiurin
2014-02-22 14:20 ` Anthony G. Basile
2014-02-22 15:33 ` Alexander Tiurin
2014-02-26 18:09 ` Alexander Tiurin
2014-02-27 13:31 ` Anthony G. Basile
2014-03-24 16:53 ` Alexander Tiurin [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=533062FB.8010809@gmail.com \
--to=alexanderyt@gmail.com \
--cc=gentoo-hardened@lists.gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox