Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nginx: CVE-2018-16843, CVE-2018-16844 updates #50417

Merged
merged 2 commits into from Nov 15, 2018
Merged

Conversation

alyssais
Copy link
Member

@alyssais alyssais commented Nov 15, 2018

https://nginx.org/en/security_advisories.html

  • Tested using sandboxing (nix.useSandbox on NixOS, or option sandbox in nix.conf on non-NixOS)
  • Built on platform(s)
    • NixOS
    • macOS
    • other Linux distributions
  • Tested via one or more NixOS test(s) if existing and applicable for the change (look inside nixos/tests)
  • Tested compilation of all pkgs that depend on this change using nix-shell -p nox --run "nox-review wip"
  • Tested execution of all binary files (usually in ./result/bin/)
  • Determined the impact on package closure size (by running nix path-info -S before and after)
  • Fits CONTRIBUTING.md.

@GrahamcOfBorg
Copy link

Success on aarch64-linux (full log)

Attempted: nginxMainline, nginxStable

Partial log (click to expand)

test -d '/nix/store/r0qri05npyisb7n9csav2hqmna5brnvv-nginx-1.14.1/logs' \
        || mkdir -p '/nix/store/r0qri05npyisb7n9csav2hqmna5brnvv-nginx-1.14.1/logs'
make[1]: Leaving directory '/build/nginx-1.14.1'
post-installation fixup
shrinking RPATHs of ELF executables and libraries in /nix/store/r0qri05npyisb7n9csav2hqmna5brnvv-nginx-1.14.1
shrinking /nix/store/r0qri05npyisb7n9csav2hqmna5brnvv-nginx-1.14.1/bin/nginx
strip is /nix/store/p9akxn2sfy4wkhqdqa3li97pc6jaz3r1-binutils-2.30/bin/strip
stripping (with command strip and flags -S) in /nix/store/r0qri05npyisb7n9csav2hqmna5brnvv-nginx-1.14.1/bin
patching script interpreter paths in /nix/store/r0qri05npyisb7n9csav2hqmna5brnvv-nginx-1.14.1
checking for references to /build in /nix/store/r0qri05npyisb7n9csav2hqmna5brnvv-nginx-1.14.1...

@GrahamcOfBorg
Copy link

Success on x86_64-linux (full log)

Attempted: nginxMainline, nginxStable

Partial log (click to expand)

test -d '/nix/store/jzqdif48f7sm79x6ic8b5pd3dirfhi4z-nginx-1.15.6/logs' \
        || mkdir -p '/nix/store/jzqdif48f7sm79x6ic8b5pd3dirfhi4z-nginx-1.15.6/logs'
make[1]: Leaving directory '/build/nginx-1.15.6'
post-installation fixup
shrinking RPATHs of ELF executables and libraries in /nix/store/jzqdif48f7sm79x6ic8b5pd3dirfhi4z-nginx-1.15.6
shrinking /nix/store/jzqdif48f7sm79x6ic8b5pd3dirfhi4z-nginx-1.15.6/bin/nginx
strip is /nix/store/vcc4svb8gy29g4pam2zja6llkbcwsyiq-binutils-2.30/bin/strip
stripping (with command strip and flags -S) in /nix/store/jzqdif48f7sm79x6ic8b5pd3dirfhi4z-nginx-1.15.6/bin
patching script interpreter paths in /nix/store/jzqdif48f7sm79x6ic8b5pd3dirfhi4z-nginx-1.15.6
checking for references to /build in /nix/store/jzqdif48f7sm79x6ic8b5pd3dirfhi4z-nginx-1.15.6...

@Mic92
Copy link
Member

Mic92 commented Nov 15, 2018

@GrahamcOfBorg build nginxMainline nginxStable

@GrahamcOfBorg
Copy link

Success on aarch64-linux (full log)

Attempted: nginxMainline, nginxStable

Partial log (click to expand)

/nix/store/grbg31cc35kqdcyssbx5y3g39srixh0h-nginx-1.15.6
/nix/store/r0qri05npyisb7n9csav2hqmna5brnvv-nginx-1.14.1

@GrahamcOfBorg
Copy link

Success on x86_64-linux (full log)

Attempted: nginxMainline, nginxStable

Partial log (click to expand)

/nix/store/jzqdif48f7sm79x6ic8b5pd3dirfhi4z-nginx-1.15.6
/nix/store/q4282aas4zxz9qv6xmf2j6hkcfyr89s3-nginx-1.14.1

@Mic92
Copy link
Member

Mic92 commented Nov 15, 2018

@GrahamcOfBorg test nginx

@GrahamcOfBorg
Copy link

No attempt on x86_64-linux (full log)

The following builds were skipped because they don't evaluate on x86_64-linux: tests.nginx

Partial log (click to expand)

error: while evaluating 'recursiveUpdate' at /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/lib/attrsets.nix:415:26, called from /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/lib/attrsets.nix:148:28:
while evaluating 'recursiveUpdateUntil' at /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/lib/attrsets.nix:384:37, called from /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/lib/attrsets.nix:416:5:
while evaluating 'zipAttrsWith' at /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/lib/attrsets.nix:347:21, called from /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/lib/attrsets.nix:394:8:
while evaluating 'zipAttrsWithNames' at /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/lib/attrsets.nix:332:33, called from /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/lib/attrsets.nix:347:27:
while evaluating anonymous function at /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/lib/lists.nix:113:41, called from /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/lib/attrsets.nix:347:46:
while evaluating the attribute 'nginx' at /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/nixos/tests/all-tests.nix:150:3:
while evaluating 'handleTest' at /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/nixos/tests/all-tests.nix:17:22, called from /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/nixos/tests/all-tests.nix:150:11:
while evaluating 'discoverTests' at /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/nixos/tests/all-tests.nix:13:19, called from /var/lib/gc-of-borg/.nix-test-rs/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/rbvermaa-spot/nixos/tests/all-tests.nix:18:5:
access to path '/nix/store/rysr1m2g0b5p1zsvd27d5a8w716jjh32-rbvermaa-spot' is forbidden in restricted mode

@GrahamcOfBorg
Copy link

No attempt on aarch64-linux (full log)

The following builds were skipped because they don't evaluate on aarch64-linux: tests.nginx

Partial log (click to expand)

Cannot nix-instantiate `tests.nginx' because:
error: while evaluating 'recursiveUpdate' at /var/lib/gc-of-borg/nix-test-rs-32/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-aarch64-community-32/lib/attrsets.nix:415:26, called from /var/lib/gc-of-borg/nix-test-rs-32/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-aarch64-community-32/lib/attrsets.nix:148:28:
while evaluating 'recursiveUpdateUntil' at /var/lib/gc-of-borg/nix-test-rs-32/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-aarch64-community-32/lib/attrsets.nix:384:37, called from /var/lib/gc-of-borg/nix-test-rs-32/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-aarch64-community-32/lib/attrsets.nix:416:5:
while evaluating 'zipAttrsWith' at /var/lib/gc-of-borg/nix-test-rs-32/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-aarch64-community-32/lib/attrsets.nix:347:21, called from /var/lib/gc-of-borg/nix-test-rs-32/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-aarch64-community-32/lib/attrsets.nix:394:8:
while evaluating 'zipAttrsWithNames' at /var/lib/gc-of-borg/nix-test-rs-32/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-aarch64-community-32/lib/attrsets.nix:332:33, called from /var/lib/gc-of-borg/nix-test-rs-32/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-aarch64-community-32/lib/attrsets.nix:347:27:
while evaluating the attribute 'nginx' at /var/lib/gc-of-borg/nix-test-rs-32/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-aarch64-community-32/nixos/tests/all-tests.nix:150:3:
while evaluating 'handleTest' at /var/lib/gc-of-borg/nix-test-rs-32/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-aarch64-community-32/nixos/tests/all-tests.nix:17:22, called from /var/lib/gc-of-borg/nix-test-rs-32/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-aarch64-community-32/nixos/tests/all-tests.nix:150:11:
while evaluating 'discoverTests' at /var/lib/gc-of-borg/nix-test-rs-32/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-aarch64-community-32/nixos/tests/all-tests.nix:13:19, called from /var/lib/gc-of-borg/nix-test-rs-32/repo/38dca4e3aa6bca43ea96d2fcc04e8229/builder/grahamc-aarch64-community-32/nixos/tests/all-tests.nix:18:5:
access to path '/nix/store/7q6vn0id70i526plicgc8mvnx7b63kz4-grahamc-aarch64-community-32' is forbidden in restricted mode

@Mic92
Copy link
Member

Mic92 commented Nov 15, 2018

run locally: /nix/store/7s0b46n3cm4fl7hak7i6jc3cav5znkx6-vm-test-run-nginx

@Mic92 Mic92 merged commit c957808 into NixOS:master Nov 15, 2018
@Mic92
Copy link
Member

Mic92 commented Nov 15, 2018

backport 850a877 8fa2565

@GrahamcOfBorg
Copy link

Success on x86_64-darwin (full log)

Attempted: nginxMainline, nginxStable

Partial log (click to expand)

        || mkdir -p '/nix/store/jg8z6x69yswyb9wjyfgmmmizxxilrv8i-nginx-1.14.1/logs'
test -d '/nix/store/jg8z6x69yswyb9wjyfgmmmizxxilrv8i-nginx-1.14.1/html' \
        || cp -R html '/nix/store/jg8z6x69yswyb9wjyfgmmmizxxilrv8i-nginx-1.14.1'
test -d '/nix/store/jg8z6x69yswyb9wjyfgmmmizxxilrv8i-nginx-1.14.1/logs' \
        || mkdir -p '/nix/store/jg8z6x69yswyb9wjyfgmmmizxxilrv8i-nginx-1.14.1/logs'
make[1]: Leaving directory '/private/tmp/nix-build-nginx-1.14.1.drv-0/nginx-1.14.1'
post-installation fixup
strip is /nix/store/g5r4apl0za012ffs6ladinwa5w0m1l3k-cctools-binutils-darwin/bin/strip
stripping (with command strip and flags -S) in /nix/store/jg8z6x69yswyb9wjyfgmmmizxxilrv8i-nginx-1.14.1/bin
patching script interpreter paths in /nix/store/jg8z6x69yswyb9wjyfgmmmizxxilrv8i-nginx-1.14.1

@alyssais alyssais deleted the nginx branch November 22, 2018 11:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants