Build log
nerves_system_rpi5
ex_dgraph 0.2.0-beta.3 · fail · run ex_dgraph-0.2.0-beta.3-1791174392487
539 of 539 lines
1Resolving Hex dependencies...2Resolution completed in 0.19s3Unchanged:4 circular_buffer 1.1.05 connection 1.0.46 cowboy 2.6.3 VULNERABLE!7 EEF-CVE-2026-8466 (HIGH)8 aka: CVE-2026-8466, GHSA-jfc2-q6qh-g5x89 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy10 https://osv.dev/vulnerability/EEF-CVE-2026-84661112 EEF-CVE-2026-65624 (MEDIUM)13 aka: CVE-2026-6562414 Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion15 https://osv.dev/vulnerability/EEF-CVE-2026-656241617 GHSA-w4f7-4cxr-rv3c (MEDIUM)18 aka: CVE-2026-43966, EEF-CVE-2026-4396619 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability20 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c21 cowlib 2.7.3 VULNERABLE!22 EEF-CVE-2026-59248 (HIGH)23 aka: CVE-2026-5924824 Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS25 https://osv.dev/vulnerability/EEF-CVE-2026-592482627 EEF-CVE-2026-43970 (HIGH)28 aka: CVE-2026-43970, GHSA-84f2-rp86-235p29 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame30 https://osv.dev/vulnerability/EEF-CVE-2026-439703132 EEF-CVE-2026-43968 (MEDIUM)33 aka: CVE-2026-43968, GHSA-hv23-4qp7-8c8r34 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/135 https://osv.dev/vulnerability/EEF-CVE-2026-439683637 EEF-CVE-2026-7790 (HIGH)38 aka: CVE-2026-7790, GHSA-32p9-57cr-4x6539 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS40 https://osv.dev/vulnerability/EEF-CVE-2026-779041 db_connection 1.1.342 elixir_make 0.10.043 elixir_uuid 1.2.144 ex_dgraph 0.2.0-beta.345 grpc 0.3.1 VULNERABLE!46 EEF-CVE-2026-48854 (HIGH)47 aka: CVE-2026-48854, GHSA-q8gf-9rvj-gmgj48 Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc49 https://osv.dev/vulnerability/EEF-CVE-2026-4885450 gun 1.3.3 VULNERABLE!51 EEF-CVE-2026-43973 (HIGH)52 aka: CVE-2026-43973, GHSA-r53j-fjj5-mv7753 gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion54 https://osv.dev/vulnerability/EEF-CVE-2026-439735556 GHSA-w4f7-4cxr-rv3c (MEDIUM)57 aka: CVE-2026-43966, EEF-CVE-2026-4396658 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability59 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c60 interactive_cmd 0.1.461 morphix 0.6.062 nerves 2.0.0-pre.263 nerves_discovery 0.1.564 nerves_logging 0.2.465 nerves_runtime 0.13.1366 nerves_system_bbb 2.30.267 nerves_system_br 1.34.468 nerves_system_mangopi_mq_pro 0.17.269 nerves_system_qemu_aarch64 0.4.270 nerves_system_rpi0 2.1.271 nerves_system_rpi4 2.1.272 nerves_system_rpi5 2.1.273 nerves_system_trellis 0.5.074 nerves_system_x86_64 1.34.275 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.176 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.177 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.178 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.179 nerves_toolchain_x86_64_nerves_linux_musl 15.3.180 nerves_uevent 0.1.781 poison 3.1.082 poolboy 1.5.283 property_table 0.3.484 protobuf 0.6.385 ranch 1.7.186 retry 0.11.287 ring_logger 0.11.788 tablet 0.3.389 toolshed 0.5.090 uboot_env 1.0.291* Getting ex_dgraph (Hex package)92* Getting nerves (Hex package)93* Getting ring_logger (Hex package)94* Getting toolshed (Hex package)95* Getting nerves_runtime (Hex package)96* Getting nerves_system_bbb (Hex package)97* Getting nerves_system_mangopi_mq_pro (Hex package)98* Getting nerves_system_qemu_aarch64 (Hex package)99* Getting nerves_system_rpi0 (Hex package)100* Getting nerves_system_rpi4 (Hex package)101* Getting nerves_system_rpi5 (Hex package)102* Getting nerves_system_trellis (Hex package)103* Getting nerves_system_x86_64 (Hex package)104* Getting nerves_system_br (Hex package)105* Getting nerves_toolchain_x86_64_nerves_linux_musl (Hex package)106* Getting nerves_toolchain_armv7_nerves_linux_gnueabihf (Hex package)107* Getting nerves_toolchain_aarch64_nerves_linux_gnu (Hex package)108* Getting nerves_toolchain_armv6_nerves_linux_gnueabihf (Hex package)109* Getting nerves_toolchain_riscv64_nerves_linux_gnu (Hex package)110* Getting nerves_logging (Hex package)111* Getting nerves_uevent (Hex package)112* Getting uboot_env (Hex package)113* Getting elixir_make (Hex package)114* Getting property_table (Hex package)115* Getting circular_buffer (Hex package)116* Getting interactive_cmd (Hex package)117* Getting nerves_discovery (Hex package)118* Getting tablet (Hex package)119* Getting db_connection (Hex package)120* Getting elixir_uuid (Hex package)121* Getting grpc (Hex package)122* Getting morphix (Hex package)123* Getting poison (Hex package)124* Getting poolboy (Hex package)125* Getting protobuf (Hex package)126* Getting retry (Hex package)127* Getting cowboy (Hex package)128* Getting gun (Hex package)129* Getting cowlib (Hex package)130* Getting ranch (Hex package)131* Getting connection (Hex package)132Found packages with security advisories, see above for details133 warning: String.strip/1 is deprecated. Use String.trim/1 instead134 │135 4 │ @version File.read!("VERSION") |> String.strip136 │ ~137 │138 └─ /work/proj/deps_rpi5/poison/mix.exs:4:44: Poison.Mixfile (module)139140==> nerves_system_br141Generated nerves_system_br app142==> connection143Compiling 1 file (.ex)144 warning: using single-quoted strings to represent charlists is deprecated.145 Use ~c"" if you indeed want a charlist or use "" instead.146 You may run "mix format --migrate" to change all single-quoted147 strings to use the ~c sigil and fix this warning.148 │149 553 │ [{:data, [{'State', mod_state}]}]150 │ ~151 │152 └─ lib/connection.ex:553:20153154 warning: using single-quoted strings to represent charlists is deprecated.155 Use ~c"" if you indeed want a charlist or use "" instead.156 You may run "mix format --migrate" to change all single-quoted157 strings to use the ~c sigil and fix this warning.158 │159 680 │ format = '** Generic server ~p terminating \n' ++160 │ ~161 │162 └─ lib/connection.ex:680:14163164 warning: using single-quoted strings to represent charlists is deprecated.165 Use ~c"" if you indeed want a charlist or use "" instead.166 You may run "mix format --migrate" to change all single-quoted167 strings to use the ~c sigil and fix this warning.168 │169 681 │ '** Last message in was ~p~n' ++ ## No last message170 │ ~171 │172 └─ lib/connection.ex:681:7173174 warning: using single-quoted strings to represent charlists is deprecated.175 Use ~c"" if you indeed want a charlist or use "" instead.176 You may run "mix format --migrate" to change all single-quoted177 strings to use the ~c sigil and fix this warning.178 │179 682 │ '** When Server state == ~p~n' ++180 │ ~181 │182 └─ lib/connection.ex:682:7183184 warning: using single-quoted strings to represent charlists is deprecated.185 Use ~c"" if you indeed want a charlist or use "" instead.186 You may run "mix format --migrate" to change all single-quoted187 strings to use the ~c sigil and fix this warning.188 │189 683 │ '** Reason for termination == ~n** ~p~n'190 │ ~191 │192 └─ lib/connection.ex:683:7193194 warning: System.stacktrace/0 is deprecated. Use __STACKTRACE__ instead195 │196 429 │ init_stop(starter, name, {reason, System.stacktrace()})197 │ ~198 │199 └─ lib/connection.ex:429:50: Connection.init_it/6200 └─ lib/connection.ex:431:45: Connection.init_it/6201 └─ lib/connection.ex:491:57: Connection.handle_call/3202 └─ lib/connection.ex:540:41: Connection.code_change/3203 └─ lib/connection.ex:581:57: Connection.terminate/2204 └─ lib/connection.ex:625:49: Connection.enter_connect/5205 └─ lib/connection.ex:628:34: Connection.enter_connect/5206 └─ lib/connection.ex:631:45: Connection.enter_connect/5207 └─ lib/connection.ex:657:49: Connection.enter_terminate/5208 └─ lib/connection.ex:660:34: Connection.enter_terminate/5209 └─ lib/connection.ex:663:45: Connection.enter_terminate/5210 └─ lib/connection.ex:744:24: Connection.connect/3211 └─ lib/connection.ex:770:24: Connection.disconnect/3212 └─ lib/connection.ex:813:57: Connection.handle_async/3213214Generated connection app215==> circular_buffer216Compiling 1 file (.ex)217Generated circular_buffer app218==> poison219Compiling 4 files (.ex)220 warning: using single-quoted strings to represent charlists is deprecated.221 Use ~c"" if you indeed want a charlist or use "" instead.222 You may run "mix format --migrate" to change all single-quoted223 strings to use the ~c sigil and fix this warning.224 │225 93 │ for {char, seq} <- Enum.zip('"\\\n\t\r\f\b', '"\\ntrfb') do226 │ ~227 │228 └─ lib/poison/encoder.ex:93:31229230 warning: using single-quoted strings to represent charlists is deprecated.231 Use ~c"" if you indeed want a charlist or use "" instead.232 You may run "mix format --migrate" to change all single-quoted233 strings to use the ~c sigil and fix this warning.234 │235 93 │ for {char, seq} <- Enum.zip('"\\\n\t\r\f\b', '"\\ntrfb') do236 │ ~237 │238 └─ lib/poison/encoder.ex:93:48239240 warning: using single-quoted strings to represent charlists is deprecated.241 Use ~c"" if you indeed want a charlist or use "" instead.242 You may run "mix format --migrate" to change all single-quoted243 strings to use the ~c sigil and fix this warning.244 │245 139 │ defp chunk_size(<<char>> <> _, _mode, acc) when char <= 0x1F or char in '"\\' do246 │ ~247 │248 └─ lib/poison/encoder.ex:139:75249250 warning: using single-quoted strings to represent charlists is deprecated.251 Use ~c"" if you indeed want a charlist or use "" instead.252 You may run "mix format --migrate" to change all single-quoted253 strings to use the ~c sigil and fix this warning.254 │255 77 │ defp value(<<char, _ :: binary>> = string, pos, _keys) when char in '-0123456789' do256 │ ~257 │258 └─ lib/poison/parser.ex:77:71259260 warning: using single-quoted strings to represent charlists is deprecated.261 Use ~c"" if you indeed want a charlist or use "" instead.262 You may run "mix format --migrate" to change all single-quoted263 strings to use the ~c sigil and fix this warning.264 │265 155 │ defp number_int(<<char, _ :: binary>> = string, pos, acc) when char in '123456789' do266 │ ~267 │268 └─ lib/poison/parser.ex:155:74269270 warning: using single-quoted strings to represent charlists is deprecated.271 Use ~c"" if you indeed want a charlist or use "" instead.272 You may run "mix format --migrate" to change all single-quoted273 strings to use the ~c sigil and fix this warning.274 │275 171 │ defp number_exp(<<e>> <> rest, frac, pos, acc) when e in 'eE' do276 │ ~277 │278 └─ lib/poison/parser.ex:171:60279280 warning: using single-quoted strings to represent charlists is deprecated.281 Use ~c"" if you indeed want a charlist or use "" instead.282 You may run "mix format --migrate" to change all single-quoted283 strings to use the ~c sigil and fix this warning.284 │285 197 │ defp number_digits(<<char>> <> rest = string, pos) when char in '0123456789' do286 │ ~287 │288 └─ lib/poison/parser.ex:197:67289290 warning: using single-quoted strings to represent charlists is deprecated.291 Use ~c"" if you indeed want a charlist or use "" instead.292 You may run "mix format --migrate" to change all single-quoted293 strings to use the ~c sigil and fix this warning.294 │295 205 │ defp number_digits_count(<<char>> <> rest, acc) when char in '0123456789' do296 │ ~297 │298 └─ lib/poison/parser.ex:205:64299300 warning: using single-quoted strings to represent charlists is deprecated.301 Use ~c"" if you indeed want a charlist or use "" instead.302 You may run "mix format --migrate" to change all single-quoted303 strings to use the ~c sigil and fix this warning.304 │305 229 │ for {seq, char} <- Enum.zip('"\\ntr/fb', '"\\\n\t\r/\f\b') do306 │ ~307 │308 └─ lib/poison/parser.ex:229:31309310 warning: using single-quoted strings to represent charlists is deprecated.311 Use ~c"" if you indeed want a charlist or use "" instead.312 You may run "mix format --migrate" to change all single-quoted313 strings to use the ~c sigil and fix this warning.314 │315 229 │ for {seq, char} <- Enum.zip('"\\ntr/fb', '"\\\n\t\r/\f\b') do316 │ ~317 │318 └─ lib/poison/parser.ex:229:44319320 warning: using single-quoted strings to represent charlists is deprecated.321 Use ~c"" if you indeed want a charlist or use "" instead.322 You may run "mix format --migrate" to change all single-quoted323 strings to use the ~c sigil and fix this warning.324 │325 239 │ when a1 in 'dD' and a2 in 'dD'326 │ ~327 │328 └─ lib/poison/parser.ex:239:16329330 warning: using single-quoted strings to represent charlists is deprecated.331 Use ~c"" if you indeed want a charlist or use "" instead.332 You may run "mix format --migrate" to change all single-quoted333 strings to use the ~c sigil and fix this warning.334 │335 239 │ when a1 in 'dD' and a2 in 'dD'336 │ ~337 │338 └─ lib/poison/parser.ex:239:31339340 warning: using single-quoted strings to represent charlists is deprecated.341 Use ~c"" if you indeed want a charlist or use "" instead.342 You may run "mix format --migrate" to change all single-quoted343 strings to use the ~c sigil and fix this warning.344 │345 240 │ and (b1 in '89abAB')346 │ ~347 │348 └─ lib/poison/parser.ex:240:16349350 warning: using single-quoted strings to represent charlists is deprecated.351 Use ~c"" if you indeed want a charlist or use "" instead.352 You may run "mix format --migrate" to change all single-quoted353 strings to use the ~c sigil and fix this warning.354 │355 274 │ defp skip_whitespace(<<char>> <> rest, pos) when char in '\s\n\t\r' do356 │ ~357 │358 └─ lib/poison/parser.ex:274:60359360 warning: Application.get_env/2 is discouraged in the module body, use Application.compile_env/3 instead361 │362 22 │ if Application.get_env(:poison, :native) do363 │ ~364 │365 └─ lib/poison/parser.ex:22:18: Poison.Parser (module)366367 warning: use Bitwise is deprecated. import Bitwise instead368 │369 26 │ use Bitwise370 │ ~~~~~~~~~~~371 │372 └─ lib/poison/parser.ex:26: Poison.Parser (module)373374 warning: the variable "count" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator375 │376 199 │ <<digits :: binary-size(count), rest :: binary>> = string377 │ ~378 │379 └─ lib/poison/parser.ex:199:29: Poison.Parser.number_digits/2380381 warning: the variable "count" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator382 │383 225 │ <<chunk :: binary-size(count), rest :: binary>> = string384 │ ~385 │386 └─ lib/poison/parser.ex:225:28: Poison.Parser.string_continue/3387388 warning: use Bitwise is deprecated. import Bitwise instead389 │390 83 │ use Bitwise391 │ ~~~~~~~~~~~392 │393 └─ lib/poison/encoder.ex:83: Poison.Encoder.BitString (module)394395 warning: the variable "size" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator396 │397 135 │ <<chunk :: binary-size(size), rest :: binary>> = string398 │ ~399 │400 └─ lib/poison/encoder.ex:135:28: Poison.Encoder.BitString.escape/2401402 warning: Integer.to_char_list/2 is deprecated. Use Integer.to_charlist/2 instead403 │404 173 │ case Integer.to_char_list(char, 16) do405 │ ~406 │407 └─ lib/poison/encoder.ex:173:18: Poison.Encoder.BitString.seq/1408409Generated poison app410==> nerves_compatibility_test411===> Analyzing applications...412===> Compiling ranch413 ┌─ src/ranch_conns_sup.erl:414 │415 80 │ catch erlang:send(SupPid, {?MODULE, active_connections, self(), Tag},416 │ ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.417Compile directive 'nowarn_deprecated_catch' can be used to suppress418warnings in selected modules.419420421 ┌─ src/ranch_ssl.erl:422 │423 142 │ case ssl:ssl_accept(CSocket, Opts, Timeout) of424 │ ╰── Warning: ssl:ssl_accept/3 is removed; use ssl:handshake/1,2,3 instead425426427==> tablet428Compiling 2 files (.ex)429Generated tablet app430==> protobuf431Compiling 20 files (.ex)432 warning: this clause cannot match because a previous clause at line 253 matches the same pattern as this clause433 │434 254 │ defp cal_repeated(_props, %{repeated: true, oneof: true}), do:435 │ ~436 │437 └─ lib/protobuf/dsl.ex:254:8438439warning: pattern matching on 0.0 is equivalent to matching only on +0.0. Instead you must match on +0.0 or -0.0440└─ lib/protobuf/encoder.ex: Protobuf.Encoder.skip_field?/3441442 warning: Logger.warn/1 is deprecated. Use Logger.warning/2 instead443 │444 119 │ val = decode_type_m(type, key, val)445 │ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~446 │447 └─ lib/protobuf/decoder.ex:119: Protobuf.Decoder.build_struct/3448449 warning: the variable "len" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator450 │451 270 │ <<bytes::bytes-size(len), rest::bits>> = bin452 │ ~453 │454 └─ lib/protobuf/decoder.ex:270:25: Protobuf.Decoder.raw_handle_varint/4455456 warning: Logger.warn/1 is deprecated. Use Logger.warning/2 instead457 │458 303 │ decode_type_m(type, key, v)459 │ ~~~~~~~~~~~~~~~~~~~~~~~~~~~460 │461 └─ lib/protobuf/decoder.ex:303: Protobuf.Decoder.put_packed_field/3462463 warning: System.stacktrace/0 is deprecated. Use __STACKTRACE__ instead464 │465 65 │ stacktrace = System.stacktrace()466 │ ~467 │468 └─ lib/protobuf/encoder.ex:65:27: Protobuf.Encoder.encode_fields/5469470 warning: the following clause is redundant:471472 defp cal_repeated(_props, %{repeated: true, oneof: true})473474 it has type:475476 dynamic(), %{..., oneof: true, repeated: true}477478 previous clauses have already matched on the following types:479480 %{..., map?: true}, term()481 term(), %{..., repeated: true}482483 │484 254 │ defp cal_repeated(_props, %{repeated: true, oneof: true}), do:485 │ ~486 │487 └─ lib/protobuf/dsl.ex:254:8: Protobuf.DSL.cal_repeated/2488489 warning: incompatible types given to Protobuf.Decoder.decode/2:490491 Protobuf.Decoder.decode(data, mod)492493 given types:494495 -dynamic(%{..., __struct__: atom()})-, dynamic(atom())496497 but expected one of:498499 bitstring(), atom()500501 where "data" was given the type:502503 # type: dynamic(%{..., __struct__: atom()})504 # from: lib/protobuf.ex:29:21505 %mod{} = data506507 where "mod" was given the type:508509 # type: dynamic(atom())510 # from: lib/protobuf.ex:29:21511 %mod{} = data512513 type warning found at:514 │515 30 │ Protobuf.Decoder.decode(data, mod)516 │ ~517 │518 └─ lib/protobuf.ex:30:22: Protobuf.decode/1519520Generated protobuf app521==> elixir_make522Compiling 8 files (.ex)523Generated elixir_make app524==> nerves_logging525 CC kmsg_tailer.o526 LD kmsg_tailer527Compiling 5 files (.ex)528Generated nerves_logging app529==> nerves_compatibility_test530===> Analyzing applications...531===> Compiling cowlib532===> Compiling src/cow_sse.erl failed533 ┌─ src/cow_sse.erl:534 │535 56 │ -> {event, parsed_event(), State} | {more, State}.536 │ ╰── type variable 'State' is only used once (is unbound)537538539** (Mix) Could not compile dependency :cowlib, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/rpi5/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile cowlib --force", update it with "mix deps.update cowlib" or clean it with "mix deps.clean cowlib"