ex_utcp

Build log

nerves_system_x86_64

ex_utcp 0.3.2 · fail · run ex_utcp-0.3.2-1790915419313
718 of 718 lines
1Resolving Hex dependencies...2Resolution completed in 0.492s3Unchanged:4  absinthe 1.12.05  absinthe_plug 1.5.106  bunch 1.6.47  bunch_native 0.5.28  bundlex 1.5.89  castore 1.0.2110  circular_buffer 1.1.011  cowboy 2.19.012  cowlib 2.20.0 VULNERABLE!13    EEF-CVE-2026-43966 (MEDIUM)14    aka: CVE-2026-43966, GHSA-w4f7-4cxr-rv3c15    HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/216    https://osv.dev/vulnerability/EEF-CVE-2026-439661718    EEF-CVE-2026-43969 (LOW)19    aka: CVE-2026-43969, GHSA-g2wm-735q-3f5620    Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/121    https://osv.dev/vulnerability/EEF-CVE-2026-4396922  crc 0.11.023  dotenvy 1.2.124  elixir_make 0.10.025  elixir_uuid 1.2.126  ex_dtls 0.18.127  ex_ice 0.16.128  ex_libsrtp 0.7.429  ex_rtcp 0.4.230  ex_rtp 0.4.131  ex_sdp 1.3.032  ex_stun 0.2.133  ex_turn 0.2.334  ex_utcp 0.3.235  ex_webrtc 0.17.036  finch 0.24.037  flow 1.2.438  fuzzy_compare 1.1.039  gen_stage 1.3.240  googleapis 0.1.041  grpc 0.11.5 VULNERABLE!42    EEF-CVE-2026-53430 (HIGH)43    aka: CVE-2026-53430, GHSA-6ccx-9c9f-327w44    grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/145    https://osv.dev/vulnerability/EEF-CVE-2026-534304647    EEF-CVE-2026-48854 (HIGH)48    aka: CVE-2026-48854, GHSA-q8gf-9rvj-gmgj49    Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc50    https://osv.dev/vulnerability/EEF-CVE-2026-488545152    EEF-CVE-2026-48853 (CRITICAL)53    aka: CVE-2026-48853, GHSA-grp7-v8xh-rj7h54    Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc55    https://osv.dev/vulnerability/EEF-CVE-2026-488535657    EEF-CVE-2026-48599 (HIGH)58    aka: CVE-2026-48599, GHSA-mwr4-5g34-j5cq59    Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding60    https://osv.dev/vulnerability/EEF-CVE-2026-4859961  gun 2.6.0 VULNERABLE!62    GHSA-w4f7-4cxr-rv3c (MEDIUM)63    aka: CVE-2026-43966, EEF-CVE-2026-4396664    cowboy and gun affected by an HTTP Request/Response Splitting vulnerability65    https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c66  haystack 0.1.067  hpax 1.1.068  interactive_cmd 0.1.469  jason 1.4.570  membrane_precompiled_dependency_provider 0.2.471  mime 2.0.772  mint 1.11.073  nerves 1.15.074  nerves_discovery 0.1.575  nerves_logging 0.2.476  nerves_runtime 0.13.1377  nerves_system_br 1.34.478  nerves_system_mangopi_mq_pro 0.17.279  nerves_system_rpi4 2.1.280  nerves_system_trellis 0.5.081  nerves_system_x86_64 1.34.282  nerves_toolchain_aarch64_nerves_linux_gnu 15.3.183  nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.184  nerves_toolchain_riscv64_nerves_linux_gnu 15.3.185  nerves_toolchain_x86_64_nerves_linux_musl 15.3.186  nerves_uevent 0.1.787  nimble_options 1.1.188  nimble_parsec 1.4.289  nimble_pool 1.1.090  octo_fetch 0.5.091  peep 4.4.092  plug 1.20.393  plug_crypto 2.2.094  prom_ex 1.12.095  property_table 0.3.496  protobuf 0.17.097  qex 0.5.298  ranch 2.3.099  req 0.7.4100  ring_logger 0.11.7101  shmex 0.5.2102  shoehorn 0.9.3103  ssl_verify_fun 1.1.7104  stemmer 1.2.0105  tablet 0.3.3106  telemetry 1.4.2107  telemetry_metrics 1.2.0108  telemetry_metrics_prometheus_core 1.2.1109  telemetry_poller 1.3.0110  toolshed 0.5.0111  truffle_hog 0.1.0112  uboot_env 1.0.2113  unifex 1.2.5114  websockex 0.5.1115  yamerl 0.10.0116  yaml_elixir 2.12.2117  zarex 1.0.6118* Getting ex_utcp (Hex package)119* Getting nerves (Hex package)120* Getting shoehorn (Hex package)121* Getting ring_logger (Hex package)122* Getting toolshed (Hex package)123* Getting nerves_runtime (Hex package)124* Getting nerves_system_mangopi_mq_pro (Hex package)125* Getting nerves_system_rpi4 (Hex package)126* Getting nerves_system_trellis (Hex package)127* Getting nerves_system_x86_64 (Hex package)128* Getting nerves_system_br (Hex package)129* Getting nerves_toolchain_x86_64_nerves_linux_musl (Hex package)130* Getting nerves_toolchain_armv7_nerves_linux_gnueabihf (Hex package)131* Getting nerves_toolchain_aarch64_nerves_linux_gnu (Hex package)132* Getting nerves_toolchain_riscv64_nerves_linux_gnu (Hex package)133* Getting nerves_logging (Hex package)134* Getting nerves_uevent (Hex package)135* Getting uboot_env (Hex package)136* Getting elixir_make (Hex package)137* Getting property_table (Hex package)138* Getting circular_buffer (Hex package)139* Getting interactive_cmd (Hex package)140* Getting jason (Hex package)141* Getting nerves_discovery (Hex package)142* Getting tablet (Hex package)143* Getting absinthe (Hex package)144* Getting absinthe_plug (Hex package)145* Getting dotenvy (Hex package)146* Getting ex_webrtc (Hex package)147* Getting fuzzy_compare (Hex package)148* Getting grpc (Hex package)149* Getting haystack (Hex package)150* Getting prom_ex (Hex package)151* Getting protobuf (Hex package)152* Getting req (Hex package)153* Getting telemetry (Hex package)154* Getting telemetry_metrics (Hex package)155* Getting telemetry_poller (Hex package)156* Getting truffle_hog (Hex package)157* Getting websockex (Hex package)158* Getting yaml_elixir (Hex package)159* Getting yamerl (Hex package)160* Getting finch (Hex package)161* Getting mime (Hex package)162* Getting mint (Hex package)163* Getting nimble_options (Hex package)164* Getting nimble_pool (Hex package)165* Getting hpax (Hex package)166* Getting octo_fetch (Hex package)167* Getting peep (Hex package)168* Getting telemetry_metrics_prometheus_core (Hex package)169* Getting castore (Hex package)170* Getting ssl_verify_fun (Hex package)171* Getting stemmer (Hex package)172* Getting cowboy (Hex package)173* Getting cowlib (Hex package)174* Getting flow (Hex package)175* Getting googleapis (Hex package)176* Getting gun (Hex package)177* Getting gen_stage (Hex package)178* Getting ranch (Hex package)179* Getting crc (Hex package)180* Getting ex_dtls (Hex package)181* Getting ex_ice (Hex package)182* Getting ex_libsrtp (Hex package)183* Getting ex_rtcp (Hex package)184* Getting ex_rtp (Hex package)185* Getting ex_sdp (Hex package)186* Getting qex (Hex package)187* Getting bunch (Hex package)188* Getting elixir_uuid (Hex package)189* Getting bundlex (Hex package)190* Getting membrane_precompiled_dependency_provider (Hex package)191* Getting unifex (Hex package)192* Getting shmex (Hex package)193* Getting bunch_native (Hex package)194* Getting zarex (Hex package)195* Getting ex_stun (Hex package)196* Getting ex_turn (Hex package)197* Getting plug (Hex package)198* Getting plug_crypto (Hex package)199* Getting nimble_parsec (Hex package)200Found packages with security advisories, see above for details201You have added/upgraded packages you could sponsor, run `mix hex.sponsor` to learn more202==> jason203Compiling 10 files (.ex)204Generated jason app205==> tablet206Compiling 2 files (.ex)207Generated tablet app208==> elixir_make209Compiling 8 files (.ex)210Generated elixir_make app211==> nerves_discovery212Compiling 5 files (.ex)213Generated nerves_discovery app214==> interactive_cmd215Compiling 1 file (.ex)216Generated interactive_cmd app217==> nerves218HOST_CC port.o219HOST_LD port220Compiling 55 files (.ex)221Generated nerves app222==> nerves_compatibility_test223224Nerves environment225  MIX_TARGET:   x86_64226  MIX_ENV:      prod227228Checking for prebuilt Nerves artifacts...229  Found nerves_system_x86_64 in cache230    /home/nerves/.nerves/artifacts/nerves_system_x86_64-portable-1.34.2231  Found nerves_toolchain_x86_64_nerves_linux_musl in cache232    /home/nerves/.nerves/artifacts/nerves_toolchain_x86_64_nerves_linux_musl-linux_x86_64-15.3.1233==> nerves234==> nerves_compatibility_test235236Nerves environment237  MIX_TARGET:   x86_64238  MIX_ENV:      prod239240 C      checksum_xor.c241 C      crc_8.c242 C      crc_algorithm.c243 C      crc_model.c244 C      crc_nif.c245 C      crc_resource.c246 C      xnif_slice.c247 LD     crc_nif.so248==> crc249Compiling 7 files (.erl)250Compiling 3 files (.ex)251Generated crc app252==> truffle_hog253Compiling 3 files (.ex)254Generated truffle_hog app255==> protobuf256Compiling 50 files (.ex)257Generated protobuf app258==> octo_fetch259Compiling 3 files (.ex)260Generated octo_fetch app261==> googleapis262Compiling 45 files (.ex)263Generated googleapis app264==> absinthe265Compiling 1 file (.yrl)266Compiling 1 file (.erl)267Compiling 265 files (.ex)268Generated absinthe app269==> grpc270Compiling 1 file (.erl)271warning: "xref: [exclude: ...]" in your mix.exs file is deprecated, instead use: "elixirc_options: [no_warn_undefined: ...]"272  (mix 1.20.3) lib/mix/tasks/compile.elixir.ex:243: Mix.Tasks.Compile.Elixir.xref_exclude_opts/2273  (mix 1.20.3) lib/mix/tasks/compile.elixir.ex:142: Mix.Tasks.Compile.Elixir.run/1274  (mix 1.20.3) lib/mix/task.ex:502: anonymous fn/3 in Mix.Task.run_task/5275  (mix 1.20.3) lib/mix/task.compiler.ex:299: Mix.Task.Compiler.run_compiler/2276  (mix 1.20.3) lib/mix/task.compiler.ex:287: Mix.Task.Compiler.run/4277  (mix 1.20.3) lib/mix/tasks/compile.all.ex:75: Mix.Tasks.Compile.All.do_run/2278279Compiling 65 files (.ex)280     warning: the variable "bytes_length" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator281     │282 346 │       <<head::binary-size(bytes_length), tail::binary>> -> {head, tail}283     │                           ~284     │285     └─ lib/grpc/client/adapters/mint/connection_process/connection_process.ex:346:27: GRPC.Client.Adapters.Mint.ConnectionProcess.chunk_body/2286287     warning: unused require Logger288     │289 113 │   require Logger290     │   ~291     │292     └─ lib/grpc/server.ex:113:3293294    warning: a struct for Protobuf.Protoc.Context is expected on struct update:295296        %Protobuf.Protoc.Context{297          ctx298          | syntax: syntax(desc.syntax),299            package: desc.package,300            dep_type_mapping: get_dep_type_mapping(ctx, desc.dependency, desc.name)301        }302303    but got type:304305        dynamic()306307    where "ctx" was given the type:308309        # type: dynamic()310        # from: lib/grpc/protoc/generator.ex:43:36311        ctx312313    when defining the variable "ctx", you must also pattern match on "%Protobuf.Protoc.Context{}"314315    type warning found at:316    │317 45 │       %Context{318    │       ~319    │320    └─ lib/grpc/protoc/generator.ex:45:7: GRPC.Protoc.Generator.generate_module_definitions/2321322    warning: Protobuf.Decoder.decode/2 is undefined or private. Did you mean:323324        * decode/3325326    │327 47 │     request = Protobuf.Decoder.decode(bin, Google.Protobuf.Compiler.CodeGeneratorRequest)328    │                                ~329    │330    └─ lib/grpc/protoc/cli.ex:47:32: GRPC.Protoc.CLI.main/1331332    warning: a struct for Protobuf.Protoc.Context is expected on struct update:333334        %Protobuf.Protoc.Context{ctx | plugins: String.split(plugins, "+")}335336    but got type:337338        dynamic()339340    where "ctx" was given the type:341342        # type: dynamic()343        # from: lib/grpc/protoc/cli.ex:86:43344        ctx345346    when defining the variable "ctx", you must also pattern match on "%Protobuf.Protoc.Context{}"347348    type warning found at:349    │350 87 │     %Context{ctx | plugins: String.split(plugins, "+")}351    │     ~352    │353    └─ lib/grpc/protoc/cli.ex:87:5: GRPC.Protoc.CLI.parse_param/2354355     warning: a struct for GRPC.Client.Connection is expected on struct update:356357         %GRPC.Client.Connection{358           base_state359           | lb_mod: lb_mod,360             lb_state: new_lb_state,361             virtual_channel: ch,362             real_channels: real_channels363         }364365     but got type:366367         dynamic(%{..., virtual_channel: term()})368369     where "base_state" was given the type:370371         # type: dynamic(%{..., virtual_channel: term()})372         # from: lib/grpc/client/connection.ex:417:11373         build_real_channels(addresses, base_state.virtual_channel, norm_opts, adapter)374375     when defining the variable "base_state", you must also pattern match on "%GRPC.Client.Connection{}"376377     type warning found at:378     │379 423 │            %__MODULE__{380     │            ~381     │382     └─ lib/grpc/client/connection.ex:423:12: GRPC.Client.Connection.build_balanced_state/6383384    warning: a struct for Protobuf.Protoc.Context is expected on struct update:385386        %Protobuf.Protoc.Context{ctx | gen_descriptors?: true}387388    but got type:389390        dynamic()391392    where "ctx" was given the type:393394        # type: dynamic()395        # from: lib/grpc/protoc/cli.ex:90:49396        ctx397398    when defining the variable "ctx", you must also pattern match on "%Protobuf.Protoc.Context{}"399400    type warning found at:401    │402 93 │         %Context{ctx | gen_descriptors?: true}403    │         ~404    │405    └─ lib/grpc/protoc/cli.ex:93:9: GRPC.Protoc.CLI.parse_param/2406407     warning: a struct for GRPC.Client.Connection is expected on struct update:408409         %GRPC.Client.Connection{410           base_state411           | virtual_channel: ch,412             real_channels: %{<<to_string(host)::binary, ":", to_string(port)::binary>> => ch}413         }414415     but got type:416417         dynamic(%{..., virtual_channel: term()})418419     where "base_state" was given the type:420421         # type: dynamic(%{..., virtual_channel: term()})422         # from: lib/grpc/client/connection.ex:441:8423         vc = base_state.virtual_channel424425     when defining the variable "base_state", you must also pattern match on "%GRPC.Client.Connection{}"426427     type warning found at:428     │429 446 │          %__MODULE__{430     │          ~431     │432     └─ lib/grpc/client/connection.ex:446:10: GRPC.Client.Connection.build_direct_state/4433434     warning: a struct for Protobuf.Protoc.Context is expected on struct update:435436         %Protobuf.Protoc.Context{ctx | package_prefix: package}437438     but got type:439440         dynamic()441442     where "ctx" was given the type:443444         # type: dynamic()445         # from: lib/grpc/protoc/cli.ex:100:50446         ctx447448     when defining the variable "ctx", you must also pattern match on "%Protobuf.Protoc.Context{}"449450     type warning found at:451     │452 104 │       %Context{ctx | package_prefix: package}453     │       ~454     │455     └─ lib/grpc/protoc/cli.ex:104:7: GRPC.Protoc.CLI.parse_param/2456457     warning: a struct for Protobuf.Protoc.Context is expected on struct update:458459         %Protobuf.Protoc.Context{ctx | transform_module: Module.concat([module])}460461     but got type:462463         dynamic()464465     where "ctx" was given the type:466467         # type: dynamic()468         # from: lib/grpc/protoc/cli.ex:108:51469         ctx470471     when defining the variable "ctx", you must also pattern match on "%Protobuf.Protoc.Context{}"472473     type warning found at:474     │475 109 │     %Context{ctx | transform_module: Module.concat([module])}476     │     ~477     │478     └─ lib/grpc/protoc/cli.ex:109:5: GRPC.Protoc.CLI.parse_param/2479480     warning: a struct for Protobuf.Protoc.Context is expected on struct update:481482         %Protobuf.Protoc.Context{ctx | one_file_per_module?: true}483484     but got type:485486         dynamic()487488     where "ctx" was given the type:489490         # type: dynamic()491         # from: lib/grpc/protoc/cli.ex:112:53492         ctx493494     when defining the variable "ctx", you must also pattern match on "%Protobuf.Protoc.Context{}"495496     type warning found at:497     │498 115 │         %Context{ctx | one_file_per_module?: true}499     │         ~500     │501     └─ lib/grpc/protoc/cli.ex:115:9: GRPC.Protoc.CLI.parse_param/2502503     warning: a struct for GRPC.Channel is expected on struct update:504505         %GRPC.Channel{virtual_channel | host: host, port: port}506507     but got type:508509         dynamic()510511     where "virtual_channel" was given the type:512513         # type: dynamic()514         # from: lib/grpc/client/connection.ex:457:39515         virtual_channel516517     when defining the variable "virtual_channel", you must also pattern match on "%GRPC.Channel{}"518519     type warning found at:520     │521 460 │              %Channel{virtual_channel | host: host, port: port},522     │              ~523     │524     └─ lib/grpc/client/connection.ex:460:14: GRPC.Client.Connection.build_real_channels/4525526    warning: Protobuf.Decoder.decode/2 is undefined or private. Did you mean:527528        * decode/3529530    │531 27 │     Protobuf.Decoder.decode(binary, module)532    │                      ~533    │534    └─ lib/grpc/codec/web_text.ex:27:22: GRPC.Codec.WebText.decode/2535536     warning: a struct for GRPC.Channel is expected on struct update:537538         %GRPC.Channel{vc | host: host, port: port}539540     but got type:541542         dynamic()543544     where "vc" was given the type:545546         # type: dynamic()547         # from: lib/grpc/client/connection.ex:525:29548         vc549550     when defining the variable "vc", you must also pattern match on "%GRPC.Channel{}"551552     type warning found at:553     │554 526 │     %Channel{vc | host: host, port: port}555     │     ~556     │557     └─ lib/grpc/client/connection.ex:526:5: GRPC.Client.Connection.connect_real_channel/5558559     warning: incompatible types given to pick_channel/1:560561         pick_channel(opts)562563     given types:564565         -dynamic(empty_list() or non_empty_list(term(), term()))-566567     but expected one of:568569         %GRPC.Channel{}570571     where "opts" was given the type:572573         # type: dynamic(empty_list() or non_empty_list(term(), term()))574         # from: lib/grpc/client/connection.ex:178:46575         Keyword.merge(opts, ref: ref)576577     type warning found at:578     │579 188 │             case pick_channel(opts) do580     │                  ~581     │582     └─ lib/grpc/client/connection.ex:188:18: GRPC.Client.Connection.connect/2583584     warning: the following clause will never match:585586         nil ->587588     because it attempts to match on the result of:589590         scheme591592     which has type:593594         dynamic(not false and not nil)595596     type warning found at:597     │598 132 │       nil ->599     │       ~~~~~~600     │601     └─ lib/grpc/client/resolver.ex:132: GRPC.Client.Resolver.resolve/1602603Generated grpc app604==> ex_sdp605Compiling 26 files (.ex)606Generated ex_sdp app607==> stemmer608Compiling 12 files (.ex)609Generated stemmer app610==> haystack611Compiling 23 files (.ex)612Generated haystack app613==> fuzzy_compare614Compiling 8 files (.ex)615Generated fuzzy_compare app616==> absinthe_plug617Compiling 18 files (.ex)618     warning: unused require Logger619     │620 123 │   require Logger621     │   ~622     │623     └─ lib/absinthe/plug.ex:123:3624625Generated absinthe_plug app626==> peep627Compiling 18 files (.ex)628Generated peep app629==> prom_ex630Compiling 40 files (.ex)631     warning: Plug.Cowboy.child_spec/1 is undefined (module Plug.Cowboy is not available or is yet to be defined)632     │633 556 │       Plug.Cowboy.child_spec(634     │                   ~635     │636     └─ lib/prom_ex.ex:556:19: PromEx.metrics_server_child_spec/4637638Generated prom_ex app639==> req640Compiling 24 files (.ex)641Generated req app642==> bundlex643Compiling 39 files (.ex)644    warning: the following clause will never match:645646        :custom ->647648    because it attempts to match on the result of:649650        Bundlex.Platform.get_target!()651652    which has type:653654        dynamic(:nerves)655656    type warning found at:657    │658 82 │       :custom -> :nerves659    │       ~~~~~~~~~~~~~~~~~~660    │661    └─ lib/bundlex.ex:82: Bundlex.platform/0662663Generated bundlex app664==> bunch_native665Bundlex: Building natives: lib, bunch666Generated bunch_native app667==> shmex668Bundlex: Building natives: lib, shmex669Compiling 2 files (.ex)670Generated shmex app671==> unifex672Bundlex: Building natives: unifex673/work/proj/deps_x86_64/unifex/c_src/unifex/cnode/unifex/cnode.c: In function 'unifex_cnode_init':674/work/proj/deps_x86_64/unifex/c_src/unifex/cnode/unifex/cnode.c:172:49: warning: 'calloc' sizes specified with 'sizeof' in the earlier argument and not in the later argument [-Wcalloc-transposed-args]675  172 |   *env = (UnifexEnv){.node_name = calloc(sizeof(char), 256),676      |                                                 ^~~~677/work/proj/deps_x86_64/unifex/c_src/unifex/cnode/unifex/cnode.c:172:49: note: earlier argument should specify number of elements, later size of each element678Compiling 33 files (.ex)679    warning: unused require Bundlex.CNode680    │681  6 │   require Bundlex.CNode682    │   ~683    │684    └─ lib/unifex/cnode.ex:6:3685686Generated unifex app687==> ex_dtls688Bundlex: Building natives: native689Compiling 2 files (.ex)690Generated ex_dtls app691==> membrane_precompiled_dependency_provider692Compiling 1 file (.ex)693Generated membrane_precompiled_dependency_provider app694==> ex_libsrtp695Bundlex: Building natives: srtp696warning: Bundlex: Couldn't load OS dependency using {:precompiled, nil}697698ignored, no URL provided699700Loading using :pkg_config701702703could not compile dependency :ex_libsrtp, "mix compile" failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile ex_libsrtp --force", update it with "mix deps.update ex_libsrtp" or clean it with "mix deps.clean ex_libsrtp"704==> nerves_compatibility_test705** (Mix) Bundlex: Couldn't load OS dependency :libsrtp2 of package ex_libsrtp. Make sure to follow installation instructions that may be available in the readme of ex_libsrtp.706707Tried the following providers:708709Provider `{:precompiled, nil}` ignored, no URL provided710Provider `:pkg_config` couldn't load ["libsrtp2"] libraries with pkg-config due to:711	** (BundlexError) pkg-config error:712	Code: 1713	Package libsrtp2 was not found in the pkg-config search path.714	Perhaps you should add the directory containing `libsrtp2.pc'715	to the PKG_CONFIG_PATH environment variable716	Package 'libsrtp2', required by 'virtual:world', not found717718