From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.1 (2015-04-28) on sa.local.altlinux.org X-Spam-Level: X-Spam-Status: No, score=-3.3 required=5.0 tests=BAYES_00,RP_MATCHES_RCVD autolearn=unavailable autolearn_force=no version=3.4.1 Date: Wed, 3 Sep 2025 06:23:10 +0000 From: "Girar awaiter (protvin)" To: Constantin Sunzow Subject: [#393866] p11 EPERM libtiff5.git=4.4.0-alt7 Message-ID: Mail-Followup-To: Girar awaiter robot MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline X-girar-task-id: 393866 X-girar-task-owner: protvin X-girar-task-repo: p11 X-girar-task-try: 1 X-girar-task-iter: 1 X-girar-task-status: EPERM X-girar-task-URL: https://git.altlinux.org/tasks/393866/ X-girar-task-log: logs/events.1.1.log X-girar-task-summary: [#393866] p11 EPERM libtiff5.git=4.4.0-alt7 User-Agent: Mutt/1.10.1 (2018-07-13) Cc: sisyphus-incominger@lists.altlinux.org, girar-builder-p11@altlinux.org, girar-builder-p11@lists.altlinux.org X-BeenThere: sisyphus-incominger@lists.altlinux.org X-Mailman-Version: 2.1.12 Precedence: list Reply-To: ALT Devel discussion list List-Id: ALT Linux Girar Builder robot reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 03 Sep 2025 06:23:13 -0000 Archived-At: List-Archive: https://git.altlinux.org/tasks/393866/logs/events.1.1.log https://packages.altlinux.org/tasks/393866 subtask name aarch64 i586 x86_64 #100 libtiff5 1:21 56 52 2025-Sep-03 06:17:28 :: task #393866 for p11 started by protvin: 2025-Sep-03 06:17:28 :: message: Security update #100 build 4.4.0-alt7 from /gears/l/libtiff5.git fetched at 2025-Sep-03 06:17:11 from sisyphus 2025-Sep-03 06:17:30 :: [x86_64] #100 libtiff5.git 4.4.0-alt7: build start 2025-Sep-03 06:17:30 :: [i586] #100 libtiff5.git 4.4.0-alt7: build start 2025-Sep-03 06:17:30 :: [aarch64] #100 libtiff5.git 4.4.0-alt7: build start 2025-Sep-03 06:18:22 :: [x86_64] #100 libtiff5.git 4.4.0-alt7: build OK 2025-Sep-03 06:18:26 :: [i586] #100 libtiff5.git 4.4.0-alt7: build OK 2025-Sep-03 06:18:51 :: [aarch64] #100 libtiff5.git 4.4.0-alt7: build OK 2025-Sep-03 06:19:02 :: #100: libtiff5.git 4.4.0-alt7: build check OK 2025-Sep-03 06:19:03 :: build check OK 2025-Sep-03 06:19:05 :: noarch check OK 2025-Sep-03 06:19:07 :: plan: src +1 -1 =19766, aarch64 +2 -2 =34826, i586 +2 -2 =33876, x86_64 +2 -2 =35604 #100 libtiff5 4.4.0-alt6 -> 4.4.0-alt7 Tue Sep 02 2025 Constantin Sunzow 4.4.0-alt7 - Fixes: + CVE-2024-13978 NULL Pointer Dereference + CVE-2025-8851 Stack-based Buffer Overflow + CVE-2025-9165 Missing Release of Memory after Effective Lifetime + CVE-2025-8176 Use After Free + CVE-2025-8177 Buffer Copy without Checking Size of Input + CVE-2025-8534 NULL Pointer Dereference 2025-Sep-03 06:19:07 :: libtiff5: fixes vulnerabilities: CVE-2024-13978 CVE-2025-8851 CVE-2025-9165 CVE-2025-8176 CVE-2025-8177 CVE-2025-8534 2025-Sep-03 06:19:49 :: patched apt indices 2025-Sep-03 06:19:58 :: created next repo 2025-Sep-03 06:20:08 :: duplicate provides check OK 2025-Sep-03 06:20:44 :: dependencies check OK 2025-Sep-03 06:21:17 :: [x86_64 i586 aarch64] ELF symbols check OK 2025-Sep-03 06:21:30 :: [i586] #100 libtiff5: install check OK 2025-Sep-03 06:21:30 :: [x86_64] #100 libtiff5: install check OK 2025-Sep-03 06:21:37 :: [i586] #100 libtiff5-debuginfo: install check OK 2025-Sep-03 06:21:38 :: [x86_64] #100 libtiff5-debuginfo: install check OK 2025-Sep-03 06:21:39 :: [aarch64] #100 libtiff5: install check OK 2025-Sep-03 06:21:51 :: [aarch64] #100 libtiff5-debuginfo: install check OK 2025-Sep-03 06:21:53 :: [x86_64-i586] plan: #1 +1 -1 =11702 2025-Sep-03 06:22:09 :: [x86_64-i586] arepo build OK 2025-Sep-03 06:22:27 :: [x86_64-i586] generated apt indices 2025-Sep-03 06:22:29 :: [x86_64-i586] created next repo 2025-Sep-03 06:22:43 :: [x86_64-i586] dependencies check OK 2025-Sep-03 06:22:44 :: gears inheritance check OK 2025-Sep-03 06:22:45 :: srpm inheritance check OK girar-check-perms: access to libtiff5 DENIED for protvin: project `libtiff5' is not listed in the acl file for repository `p11', and the policy for such projects in `p11' is to deny check-subtask-perms: #100: libtiff5: needs approvals from members of @maint and @tester groups 2025-Sep-03 06:22:46 :: acl check FAILED 2025-Sep-03 06:22:59 :: created contents_index files 2025-Sep-03 06:23:07 :: created hash files: aarch64 i586 src x86_64-i586 x86_64 2025-Sep-03 06:23:10 :: task #393866 for p11 EPERM