ALT Linux Girar Builder robot reports
 help / color / mirror / Atom feed
From: "Girar awaiter (sin)" <girar-builder@altlinux.org>
To: Evgeny Sinelnikov <sin@altlinux.org>
Cc: sisyphus-incominger@lists.altlinux.org,
	girar-builder-p11@altlinux.org,
	girar-builder-p11@lists.altlinux.org
Subject: [#388680] p11 EPERM sudo.git=1.9.16p2-alt3
Date: Tue, 1 Jul 2025 19:26:11 +0000
Message-ID: <girar.task.388680.1.1@gyle.mskdc.altlinux.org> (raw)

https://git.altlinux.org/tasks/388680/logs/events.1.1.log
https://packages.altlinux.org/tasks/388680

subtask  name  aarch64  i586  x86_64
   #100  sudo     2:11  1:28    1:22

2025-Jul-01 19:18:10 :: task #388680 for p11 started by sin:
2025-Jul-01 19:18:10 :: message: security_release
#100 build 1.9.16p2-alt3 from /gears/s/sudo.git fetched at 2025-Jul-01 18:24:56 from sisyphus
2025-Jul-01 19:18:12 :: [i586] #100 sudo.git 1.9.16p2-alt3: build start
2025-Jul-01 19:18:12 :: [x86_64] #100 sudo.git 1.9.16p2-alt3: build start
2025-Jul-01 19:18:12 :: [aarch64] #100 sudo.git 1.9.16p2-alt3: build start
2025-Jul-01 19:19:34 :: [x86_64] #100 sudo.git 1.9.16p2-alt3: build OK
2025-Jul-01 19:19:40 :: [i586] #100 sudo.git 1.9.16p2-alt3: build OK
2025-Jul-01 19:20:23 :: [aarch64] #100 sudo.git 1.9.16p2-alt3: build OK
2025-Jul-01 19:20:44 :: #100: sudo.git 1.9.16p2-alt3: build check OK
2025-Jul-01 19:20:46 :: build check OK
2025-Jul-01 19:20:52 :: noarch check OK
2025-Jul-01 19:20:54 :: plan: src +1 -1 =19695, aarch64 +6 -6 =34708, i586 +6 -6 =33805, noarch +1 -1 =20810, x86_64 +6 -6 =35474
#100 sudo 1.9.16p2-alt2 -> 1:1.9.16p2-alt3
 Tue Jul 01 2025 Evgeny Sinelnikov <sin@altlinux> 1:1.9.16p2-alt3
 - Security release (fixes: CVE-2025-32462, CVE-2025-32463) (closes: 55007):
  + Sudo's -h (--host) option could be specified when running a command or
    editing a file. This could enable a local privilege escalation attack if the
    sudoers file allows the user to run commands on a different host.
    For more information, see Local Privilege Escalation via host option:
    https://www.sudo.ws/security/advisories/host_any/
  + An attacker can leverage sudo's -R (--chroot) option to run arbitrary
    commands as root, even if they are not listed in the sudoers file. The chroot
    support has been deprecated an will be removed entirely in a future release.
 [...]
2025-Jul-01 19:20:54 :: sudo: closes bugs: 55007
2025-Jul-01 19:20:54 :: sudo: fixes vulnerabilities: CVE-2025-32462 CVE-2025-32463
2025-Jul-01 19:21:35 :: patched apt indices
2025-Jul-01 19:21:44 :: created next repo
2025-Jul-01 19:21:54 :: duplicate provides check OK
2025-Jul-01 19:22:32 :: dependencies check OK
2025-Jul-01 19:23:02 :: [x86_64 i586 aarch64] ELF symbols check OK
2025-Jul-01 19:23:16 :: [i586] #100 sudo: install check OK
2025-Jul-01 19:23:16 :: [x86_64] #100 sudo: install check OK
2025-Jul-01 19:23:23 :: [i586] #100 sudo-debuginfo: install check OK
2025-Jul-01 19:23:24 :: [x86_64] #100 sudo-debuginfo: install check OK
2025-Jul-01 19:23:26 :: [aarch64] #100 sudo: install check OK
2025-Jul-01 19:23:30 :: [i586] #100 sudo-devel: install check OK
2025-Jul-01 19:23:30 :: [x86_64] #100 sudo-devel: install check OK
2025-Jul-01 19:23:36 :: [i586] #100 sudo-logsrvd: install check OK
2025-Jul-01 19:23:37 :: [x86_64] #100 sudo-logsrvd: install check OK
2025-Jul-01 19:23:38 :: [aarch64] #100 sudo-debuginfo: install check OK
2025-Jul-01 19:23:44 :: [i586] #100 sudo-logsrvd-debuginfo: install check OK
2025-Jul-01 19:23:44 :: [x86_64] #100 sudo-logsrvd-debuginfo: install check OK
2025-Jul-01 19:23:49 :: [aarch64] #100 sudo-devel: install check OK
2025-Jul-01 19:23:52 :: [i586] #100 sudo-python: install check OK
2025-Jul-01 19:23:52 :: [x86_64] #100 sudo-python: install check OK
2025-Jul-01 19:24:00 :: [aarch64] #100 sudo-logsrvd: install check OK
2025-Jul-01 19:24:02 :: [i586] #100 sudo-python-debuginfo: install check OK
2025-Jul-01 19:24:02 :: [x86_64] #100 sudo-python-debuginfo: install check OK
2025-Jul-01 19:24:12 :: [aarch64] #100 sudo-logsrvd-debuginfo: install check OK
2025-Jul-01 19:24:25 :: [aarch64] #100 sudo-python: install check OK
2025-Jul-01 19:24:40 :: [aarch64] #100 sudo-python-debuginfo: install check OK
2025-Jul-01 19:24:42 :: [x86_64-i586] plan: #2 +2 -2 =11690
2025-Jul-01 19:25:02 :: [x86_64-i586] arepo build OK
2025-Jul-01 19:25:21 :: [x86_64-i586] generated apt indices
2025-Jul-01 19:25:23 :: [x86_64-i586] created next repo
2025-Jul-01 19:25:36 :: [x86_64-i586] dependencies check OK
2025-Jul-01 19:25:38 :: gears inheritance check OK
2025-Jul-01 19:25:38 :: srpm inheritance check OK
girar-check-perms: access to sudo DENIED for sin: project `sudo' is not listed in the acl file for repository `p11', and the policy for such projects in `p11' is to deny
check-subtask-perms: #100: sudo: needs approvals from members of @maint and @tester groups
2025-Jul-01 19:25:41 :: acl check FAILED
2025-Jul-01 19:26:01 :: created contents_index files
2025-Jul-01 19:26:08 :: created hash files: aarch64 i586 noarch src x86_64-i586 x86_64
2025-Jul-01 19:26:11 :: task #388680 for p11 EPERM


             reply	other threads:[~2025-07-01 19:26 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-07-01 19:26 Girar awaiter (sin) [this message]
2025-07-02 14:48 ` [#388680] p11 DONE (try 2) sudo.git=1.9.16p2-alt3 Girar pender (amakeenk)

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=girar.task.388680.1.1@gyle.mskdc.altlinux.org \
    --to=girar-builder@altlinux.org \
    --cc=devel@lists.altlinux.org \
    --cc=girar-builder-p11@altlinux.org \
    --cc=girar-builder-p11@lists.altlinux.org \
    --cc=sin@altlinux.org \
    --cc=sisyphus-incominger@lists.altlinux.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link

ALT Linux Girar Builder robot reports

This inbox may be cloned and mirrored by anyone:

	git clone --mirror http://lore.altlinux.org/sisyphus-incominger/0 sisyphus-incominger/git/0.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 sisyphus-incominger sisyphus-incominger/ http://lore.altlinux.org/sisyphus-incominger \
		sisyphus-incominger@lists.altlinux.org sisyphus-incominger@lists.altlinux.ru sisyphus-incominger@lists.altlinux.com
	public-inbox-index sisyphus-incominger

Example config snippet for mirrors.
Newsgroup available over NNTP:
	nntp://lore.altlinux.org/org.altlinux.lists.sisyphus-incominger


AGPL code for this site: git clone https://public-inbox.org/public-inbox.git