Page MenuHomePhabricator

scripts: add MACHO Canary check to security-check.py
ClosedPublic

Authored by PiRK on Apr 4 2023, 09:28.

Details

Reviewers
Fabien
Group Reviewers
Restricted Project
Commits
rABC3b0f8829c72b: scripts: add MACHO Canary check to security-check.py
Summary

This is a backport of core#18713

Depends on D13553

Test Plan

gitian builds

Diff Detail

Repository
rABC Bitcoin ABC
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

Tail of the build log:

[11:04:31] :	 [Step 1/1]  * [new tag]             phabricator/diff/39199 -> phabricator/diff/39199
[11:04:31] :	 [Step 1/1]  * [new tag]             phabricator/diff/39201 -> phabricator/diff/39201
[11:04:31] :	 [Step 1/1]  * [new tag]             phabricator/diff/8992  -> phabricator/diff/8992
[11:04:31] :	 [Step 1/1]  * [new tag]             phabricator/diff/8993  -> phabricator/diff/8993
[11:04:31] :	 [Step 1/1]  * [new branch]          master                 -> master
[11:04:31] :	 [Step 1/1] --- Building for bullseye amd64 ---
[11:04:31] :	 [Step 1/1] Stopping target if it is up
[11:04:31] :	 [Step 1/1] Error response from daemon: No such container: gitian-target
[11:04:31] :	 [Step 1/1] Error: No such container: gitian-target
[11:04:31] :	 [Step 1/1] Making a new image copy
[11:04:31] :	 [Step 1/1] Starting target
[11:04:31] :	 [Step 1/1] Checking if target is up.
[11:04:31] :	 [Step 1/1] Preparing build environment
[11:04:31] :	 [Step 1/1] Updating apt-get repository (log in var/install.log)
[11:04:31] :	 [Step 1/1] Installing additional packages (log in var/install.log)
[11:04:31] :	 [Step 1/1] Upgrading system, may take a while (log in var/install.log)
[11:04:31] :	 [Step 1/1] Creating package manifest
[11:04:31] :	 [Step 1/1] Creating build script (var/build-script)
[11:04:31] :	 [Step 1/1] Running build script (log in var/build.log)
[11:04:31] :	 [Step 1/1] ./bin/gbuild:23:in `system!': failed to run on-target setarch x86_64 bash -x < var/build-script > var/build.log 2>&1 (RuntimeError)
[11:04:31] :	 [Step 1/1] 	from ./bin/gbuild:185:in `build_one_configuration'
[11:04:31] :	 [Step 1/1] 	from ./bin/gbuild:339:in `block (2 levels) in <main>'
[11:04:31] :	 [Step 1/1] 	from ./bin/gbuild:334:in `each'
[11:04:31] :	 [Step 1/1] 	from ./bin/gbuild:334:in `block in <main>'
[11:04:31] :	 [Step 1/1] 	from ./bin/gbuild:332:in `each'
[11:04:31] :	 [Step 1/1] 	from ./bin/gbuild:332:in `<main>'
[11:04:31] :	 [Step 1/1] Build gitian-osx failed with exit code 1
[11:04:31]W:	 [Step 1/1] + RESULT=1
[11:04:31]W:	 [Step 1/1] + pushd /home/teamcity/infra
[11:04:31]W:	 [Step 1/1] + docker-compose stop apt-cache-proxy
[11:04:31] :	 [Step 1/1] ~/infra ~/buildAgent/work/jailed-build/bitcoin-abc ~/buildAgent/work/jailed-build
[11:04:31]W:	 [Step 1/1] Stopping abc-apt-cache-proxy ... 
[11:04:42]W:	 [Step 1/1]  [1A [2K
[11:04:42]W:	 [Step 1/1] Stopping abc-apt-cache-proxy ...  [32mdone [0m
[11:04:42]W:	 [Step 1/1]  [1B+ popd
[11:04:42]W:	 [Step 1/1] + exit 1
[11:04:42] :	 [Step 1/1] ~/buildAgent/work/jailed-build/bitcoin-abc ~/buildAgent/work/jailed-build
[11:04:42]W:	 [Step 1/1] Process exited with code 1
[11:04:42]E:	 [Step 1/1] Process exited with code 1 (Step: Command Line)
[11:04:42] :	 [Step 1/1] Waiting for 1 service processes to complete
[11:04:42]E:	 [Step 1/1] Ant JUnit report watcher
[11:04:42]E:		 [Ant JUnit report watcher] No reports found for paths:
[11:04:42]E:		 [Ant JUnit report watcher] /home/teamcity/buildAgent/work/jailed-build/results/artifacts/junit/*.xml
[11:04:42]E:	 [Step 1/1] Step Command Line failed
[11:04:43]E: Ant JUnit report watcher
[11:04:43]E:	 [Ant JUnit report watcher] No reports found for paths:
[11:04:43]E:	 [Ant JUnit report watcher] +:results/test_bitcoin.xml
[11:04:43]E:	 [Ant JUnit report watcher] +:results/**/junit_results*.xml
[11:04:43] : Publishing internal artifacts
[11:04:43] :	 [Publishing internal artifacts] Publishing 1 file using [ArtifactsCachePublisher]
[11:04:43] :	 [Publishing internal artifacts] Publishing 1 file using [WebPublisher]
[11:04:43]W: Publishing artifacts
[11:04:43] :	 [Publishing artifacts] Collecting files to publish: [+:results/**/junit_results*.xml, +:bitcoin-abc/abc-ci-builds/gitian-osx/gitian-results => gitian-osx.tar.gz]
[11:04:43]W:	 [Publishing artifacts] Artifacts path 'results/**/junit_results*.xml' not found
[11:04:43] :	 [Publishing artifacts] Creating archive gitian-osx.tar.gz
[11:04:43] :		 [Creating archive gitian-osx.tar.gz] Creating /home/teamcity/buildAgent/temp/buildTmp/TarPreprocessor1577793987043521901/gitian-osx.tar.gz
[11:04:43] :		 [Creating archive gitian-osx.tar.gz] Archive was created, file size 209.34 KB (214370 bytes)
[11:04:43] :	 [Publishing artifacts] Publishing 1 file using [ArtifactsCachePublisher]: bitcoin-abc/abc-ci-builds/gitian-osx/gitian-results => gitian-osx.tar.gz
[11:04:43] :	 [Publishing artifacts] Publishing 1 file using [WebPublisher]: bitcoin-abc/abc-ci-builds/gitian-osx/gitian-results => gitian-osx.tar.gz
[11:04:44] : Build finished
PiRK edited the summary of this revision. (Show Details)

rebase and try without LAZY_BINDINGS (remove D13554 from the stack)

PiRK published this revision for review.Apr 4 2023, 16:13
Fabien added a subscriber: Fabien.
Fabien added inline comments.
contrib/devtools/security-check.py
268–273 ↗(On Diff #39238)
This revision is now accepted and ready to land.Apr 4 2023, 16:37