public inbox for gentoo-hardened@lists.gentoo.org
 help / color / mirror / Atom feed
From: Alexander Tiurin <alexanderyt@gmail.com>
To: gentoo-hardened@lists.gentoo.org
Subject: Re: [gentoo-hardened] linux32 chroot issue
Date: Mon, 24 Mar 2014 20:53:15 +0400	[thread overview]
Message-ID: <533062FB.8010809@gmail.com> (raw)
In-Reply-To: <530F3E39.4060906@opensource.dyc.edu>



On 27.02.2014 17:31, Anthony G. Basile wrote:
> On 02/26/2014 01:09 PM, Alexander Tiurin wrote:
>> I tried to reproduce this issue on another hardware (core2quad instead
>> core i7). emerge works fine. No errors detected.
>> Kernel, kernel config and enviroment  is equal.
>> That's odd.
>>
> Okay. Thanks for getting back because I was at a loss to help you.  If
> you figure out what *is* different let us know.
>

I upgraded kernel up to 3.13.2-hardened-r3, and portage return error:

ACCESS DENIED  mkdir:        /var
(line 2035 in  http://pastebin.com/nsCV06Ca)




emerge proftp without debug info. Now no errors as ACCESS DENIED 
/dev/{tty,null}

 >>> Verifying ebuild manifests
 >>> Emerging (1 of 1) net-ftp/proftpd-1.3.4c
 >>> Failed to emerge net-ftp/proftpd-1.3.4c, Log file:
 >>>  '/var/log/portage/net-ftp:proftpd-1.3.4c:20140324-160939.log'
 >>> Jobs: 0 of 1 complete, 1 failed                 Load avg: 1.59, 
1.34, 1.46
  * Package:    net-ftp/proftpd-1.3.4c
  * Repository: gentoo
  * Maintainer: bernd@lommerzheim.com 
voyageur@gentoo.org,slyfox@gentoo.org,net-ftp@gentoo.org,proxy-maint@gentoo.org
  * USE:        acl caps elibc_glibc kernel_linux ncurses nls pam pcre 
tcpd userland_GNU x86
  * FEATURES:   sandbox
ACCESS DENIED  mkdir:        /var
install: cannot change permissions of 
‘/var/tmp/portage/net-ftp/proftpd-1.3.4c/work’: No such file or directory
  * ERROR: net-ftp/proftpd-1.3.4c failed (unpack phase):
  *   Failed to create dir '/var/tmp/portage/net-ftp/proftpd-1.3.4c/work'
  *
  * Call stack:
  *            ebuild.sh, line 708:  Called ebuild_main 'unpack'
  *   phase-functions.sh, line 955:  Called dyn_unpack
  *   phase-functions.sh, line 243:  Called die
  * The specific snippet of code:
  *              install -m${PORTAGE_WORKDIR_MODE:-0700} -d "${WORKDIR}" 
|| die "Failed to create dir '${WORKDIR}'"
  *
  * If you need support, post the output of `emerge --info 
'=net-ftp/proftpd-1.3.4c'`,
  * the complete build log and the output of `emerge -pqv 
'=net-ftp/proftpd-1.3.4c'`.
  * The complete build log is located at 
'/var/log/portage/net-ftp:proftpd-1.3.4c:20140324-160939.log'.
  * For convenience, a symlink to the build log is located at 
'/var/tmp/portage/net-ftp/proftpd-1.3.4c/temp/build.log'.
  * The ebuild environment file is located at 
'/var/tmp/portage/net-ftp/proftpd-1.3.4c/temp/environment'.
  * Working directory: '/var/tmp/portage/net-ftp/proftpd-1.3.4c'
  * S: '/var/tmp/portage/net-ftp/proftpd-1.3.4c/work/proftpd-1.3.4c'
--------------------------- ACCESS VIOLATION SUMMARY 
---------------------------
LOG FILE "/var/log/sandbox/sandbox-13354.log"

VERSION 1.0
FORMAT: F - Function called
FORMAT: S - Access Status
FORMAT: P - Path as passed to function
FORMAT: A - Absolute Path (not canonical)
FORMAT: R - Canonical Path
FORMAT: C - Command Line

F: mkdir
S: deny
P: /var
A: /var
R: /var
C: install -m0700 -d /var tmp/portage/net-ftp/proftpd-1.3.4c/work



I changed step by step grsec kernel config options, but it not worked 
for me. Maybe I missed something.


      reply	other threads:[~2014-03-24 16:52 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-02-21 22:48 [gentoo-hardened] linux32 chroot issue Alexander Tiurin
2014-02-22 14:20 ` Anthony G. Basile
2014-02-22 15:33   ` Alexander Tiurin
2014-02-26 18:09     ` Alexander Tiurin
2014-02-27 13:31       ` Anthony G. Basile
2014-03-24 16:53         ` Alexander Tiurin [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=533062FB.8010809@gmail.com \
    --to=alexanderyt@gmail.com \
    --cc=gentoo-hardened@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox