[Bug 207965] [nanobsd] regression during disk image build after CVE-2015-2304 fix/libarchive 3.2.0 update

bugzilla-noreply at freebsd.org bugzilla-noreply at freebsd.org
Mon Mar 14 01:25:25 UTC 2016


https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=207965

            Bug ID: 207965
           Summary: [nanobsd] regression during disk image build after
                    CVE-2015-2304 fix/libarchive 3.2.0 update
           Product: Base System
           Version: 11.0-CURRENT
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Only Me
          Priority: ---
         Component: conf
          Assignee: freebsd-bugs at FreeBSD.org
          Reporter: junovitch at freebsd.org

The nanobsd script is relying on behaviour that has been patched in the next
release of libarchive
(https://github.com/libarchive/libarchive/commit/5935715).

Excerpt from /usr/obj/nanobsd.soekris/_.di

Populating s1a from /usr/obj/nanobsd.soekris/_.w
/usr/obj/nanobsd.soekris/_.mnt/.cpio: .: Path is absolute: Unknown error: -1

/usr/obj/nanobsd.soekris/_.mnt/./varcpio: ./var: Path is absolute: Unknown
error: -1

This prevents building a good image.  I haven't dug into a suggested fix as of
yet.

See also:
- https://github.com/libarchive/libarchive/pull/110
- http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2304

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the freebsd-bugs mailing list