Comment 5 for bug 837804

Revision history for this message
C de-Avillez (hggdh2) wrote :

Re-tagging qa-testing-passed, per Kees:

2011-09-02 18:30:22 hggdh kees: FAIL: /proc/$pid/ DAC bypass on setuid (CVE-2011-1020)
2011-09-02 18:31:23 hggdh kees: on Lucid EC2 2.6.32-318.38
2011-09-02 18:31:27 @kees hggdh: ?? which kernel, can you paste output?
2011-09-02 18:32:31 hggdh kees: http://pastebin.ubuntu.com/680900/
2011-09-02 18:32:43 hggdh (this is a m1.large instance
2011-09-02 18:32:53 hggdh m1.small did not show this error
2011-09-02 18:33:24 @kees hunh
2011-09-02 18:33:33 @kees that looks like a legit regression :(
2011-09-02 18:34:08 @kees it's possible there's some kind of additional race condition, but it really shouldn't report those ffff lines at all.
2011-09-02 18:34:58 hggdh kees: thank you, I will open a new bug
2011
-09-02 18:35:39 @kees hggdh: okay, cool. and it always happens, even on repeated runs?
2011-09-02 18:36:04 hggdh kees: not sure, still I am preparing to run it again ;-)
2011-09-02 18:36:09 * kees -> out for the long weekend, see everyone next week
2011-09-02 18:36:14 @kees hggdh: okay, keep me posted. thanks!
2011-09-02 18:38:52 hggdh kees: more fun, now I really have a stacktrace
2011-09-02 18:47:46 hggdh kess 3 out of 7 so far
2011-09-02 18:50:28 hggdh kees: 5 out of 10. I think it is too high, but it is your call
2011-09-02 19:24:41 hggdh kees: bug 840002 opened
2011-09-03 01:13:22 @kees hggdh: i would say ignore this failure. the test looks like it can give false positives on some faster systems
2011-09-03 03:06:04 <-- apw (<email address hidden>) has quit (Ping timeout)
2011-09-03 09:02:21 lamont kees: I saved it for you if you want it... I didn't feel up to opening it
2011-09-03 09:02:39 lamont though I may just have to make a tarpit just to see what it has
2011-09-03 09:08:52 lamont sigh. ca-certificates
2011-09-03 09:58:25 hggdh kees: please comment on bug 837804 that you are OK with it; I will, then set it to go