exosculat

Build log

nerves_system_x86_64

exosculat 4.5.6 · fail · run exosculat-4.5.6-1791180968825
403 of 403 lines
1Resolving Hex dependencies...2Resolution completed in 0.233s3Unchanged:4  bandit 1.6.11 VULNERABLE!5    EEF-CVE-2026-39803 (HIGH)6    aka: CVE-2026-39803, GHSA-9q9q-324x-93r27    HTTP/1 chunked body reader ignores length cap in bandit8    https://osv.dev/vulnerability/EEF-CVE-2026-39803910    EEF-CVE-2026-39804 (HIGH)11    aka: CVE-2026-39804, GHSA-frh3-6pv6-rc8j12    WebSocket permessage-deflate inflate has no output-size cap in bandit13    https://osv.dev/vulnerability/EEF-CVE-2026-398041415    EEF-CVE-2026-39807 (MEDIUM)16    aka: CVE-2026-39807, GHSA-375f-4r2h-f99j17    Client-supplied URI scheme trusted without transport verification in bandit18    https://osv.dev/vulnerability/EEF-CVE-2026-398071920    EEF-CVE-2026-39805 (MEDIUM)21    aka: CVE-2026-39805, GHSA-c67r-gc9j-2qf722    CL.CL HTTP request smuggling via duplicate Content-Length in bandit23    https://osv.dev/vulnerability/EEF-CVE-2026-398052425    EEF-CVE-2026-42788 (MEDIUM)26    aka: CVE-2026-42788, GHSA-q6v9-r226-v65f27    HTTP/2 frame size limit checked after body is buffered in bandit28    https://osv.dev/vulnerability/EEF-CVE-2026-427882930    EEF-CVE-2026-39806 (HIGH)31    aka: CVE-2026-39806, GHSA-rf5q-vwxw-gmrf32    HTTP/1 chunked decoder infinite loop on requests with trailer fields in bandit33    https://osv.dev/vulnerability/EEF-CVE-2026-398063435    EEF-CVE-2026-42786 (HIGH)36    aka: CVE-2026-42786, GHSA-pf94-94m9-536p37    WebSocket fragmented message reassembly unbounded in bandit38    https://osv.dev/vulnerability/EEF-CVE-2026-427863940    EEF-CVE-2026-74836 (HIGH)41    aka: CVE-2026-74836, GHSA-xj8g-532w-jv9442    HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandit43    https://osv.dev/vulnerability/EEF-CVE-2026-748364445    EEF-CVE-2026-75484 (MEDIUM)46    aka: CVE-2026-75484, GHSA-x3gh-xhj4-3vq847    HTTP/2 header field values containing CR, LF or NUL are passed to the application unvalidated in Bandit48    https://osv.dev/vulnerability/EEF-CVE-2026-7548449  bpe 8.12.450  circular_buffer 1.1.051  elixir_make 0.10.052  exosculat 4.5.653  form 11.4.1554  hpax 1.1.055  interactive_cmd 0.1.456  kvs 10.8.357  mime 2.0.758  n2o 10.12.459  nerves 2.0.0-pre.260  nerves_discovery 0.1.561  nerves_logging 0.2.462  nerves_runtime 0.13.1363  nerves_system_bbb 2.30.264  nerves_system_br 1.34.465  nerves_system_mangopi_mq_pro 0.17.266  nerves_system_qemu_aarch64 0.4.267  nerves_system_rpi0 2.1.268  nerves_system_rpi4 2.1.269  nerves_system_rpi5 2.1.270  nerves_system_trellis 0.5.071  nerves_system_x86_64 1.34.272  nerves_toolchain_aarch64_nerves_linux_gnu 15.3.173  nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.174  nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.175  nerves_toolchain_riscv64_nerves_linux_gnu 15.3.176  nerves_toolchain_x86_64_nerves_linux_musl 15.3.177  nerves_uevent 0.1.778  nitro 11.4.1679  plug 1.15.6 VULNERABLE!80    EEF-CVE-2026-56814 (MEDIUM)81    aka: CVE-2026-56814, GHSA-95qv-c9g9-rm6382    Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)83    https://osv.dev/vulnerability/EEF-CVE-2026-568148485    EEF-CVE-2026-56813 (LOW)86    aka: CVE-2026-56813, GHSA-wpmj-jh88-rpgm87    Cookie attribute injection in Plug.Conn.Cookies.encode/288    https://osv.dev/vulnerability/EEF-CVE-2026-5681389  plug_crypto 2.2.090  property_table 0.3.491  ring_logger 0.11.792  rocksdb 2.6.293  syn 2.1.094  tablet 0.3.395  telemetry 1.4.296  thousand_island 1.5.097  toolshed 0.5.098  uboot_env 1.0.299  websock 0.5.3100  websock_adapter 0.6.0101* Getting exosculat (Hex package)102* Getting nerves (Hex package)103* Getting ring_logger (Hex package)104* Getting toolshed (Hex package)105* Getting nerves_runtime (Hex package)106* Getting nerves_system_bbb (Hex package)107* Getting nerves_system_mangopi_mq_pro (Hex package)108* Getting nerves_system_qemu_aarch64 (Hex package)109* Getting nerves_system_rpi0 (Hex package)110* Getting nerves_system_rpi4 (Hex package)111* Getting nerves_system_rpi5 (Hex package)112* Getting nerves_system_trellis (Hex package)113* Getting nerves_system_x86_64 (Hex package)114* Getting nerves_system_br (Hex package)115* Getting nerves_toolchain_x86_64_nerves_linux_musl (Hex package)116* Getting nerves_toolchain_armv7_nerves_linux_gnueabihf (Hex package)117* Getting nerves_toolchain_aarch64_nerves_linux_gnu (Hex package)118* Getting nerves_toolchain_armv6_nerves_linux_gnueabihf (Hex package)119* Getting nerves_toolchain_riscv64_nerves_linux_gnu (Hex package)120* Getting nerves_logging (Hex package)121* Getting nerves_uevent (Hex package)122* Getting uboot_env (Hex package)123* Getting elixir_make (Hex package)124* Getting property_table (Hex package)125* Getting circular_buffer (Hex package)126* Getting interactive_cmd (Hex package)127* Getting nerves_discovery (Hex package)128* Getting tablet (Hex package)129* Getting bandit (Hex package)130* Getting bpe (Hex package)131* Getting form (Hex package)132* Getting kvs (Hex package)133* Getting n2o (Hex package)134* Getting nitro (Hex package)135* Getting plug (Hex package)136* Getting rocksdb (Hex package)137* Getting syn (Hex package)138* Getting websock_adapter (Hex package)139* Getting websock (Hex package)140* Getting mime (Hex package)141* Getting plug_crypto (Hex package)142* Getting telemetry (Hex package)143* Getting hpax (Hex package)144* Getting thousand_island (Hex package)145Found packages with security advisories, see above for details146==> kvs147Compiling 6 files (.erl)148src/stores/kvs_fs.erl:70:10: Warning: function kvs_fs:get/2 is not exported149%   70|     case kvs_fs:get(TableName, Key) of150%     |          ^151152src/stores/kvs_rocks.erl:113:3: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.153Compile directive 'nowarn_deprecated_catch' can be used to suppress154warnings in selected modules.155%  113|   catch case lists:foldl(State_Machine, Initial_Object, Compiled_Operations) of156%     |   ^157158Compiling 1 file (.ex)159warning: cannot infer signatures from :ex_doc because it is not loaded160161Generated kvs app162==> nerves_compatibility_test163===> Analyzing applications...164===> Compiling syn165     ┌─ src/syn_registry.erl:166     │167 355 │      catch erlang:demonitor(MonitorRef, [flush]),168     │      ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.169Compile directive 'nowarn_deprecated_catch' can be used to suppress170warnings in selected modules.171172     ┌─ src/syn_registry.erl:173     │174 821 │              catch erlang:demonitor(MonitorRef, [flush]),175     │              ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.176Compile directive 'nowarn_deprecated_catch' can be used to suppress177warnings in selected modules.178179180    ┌─ src/syn_backbone.erl:181    │182 60 │      catch CustomEventHandler:module_info(exports),183    │      ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.184Compile directive 'nowarn_deprecated_catch' can be used to suppress185warnings in selected modules.186187188==> n2o189Compiling 18 files (.erl)190src/protos/n2o_ftp.erl:60:5: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.191Compile directive 'nowarn_deprecated_catch' can be used to suppress192warnings in selected modules.193%   60|     catch n2o:send(Sid, {direct, FTP}),194%     |     ^195196src/protos/n2o_ftp.erl:89:21: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.197Compile directive 'nowarn_deprecated_catch' can be used to suppress198warnings in selected modules.199%   89|                     catch n2o:send(Sid, {direct, FTP3}) end),200%     |                     ^201202src/n2o_proto.erl:80:5: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.203Compile directive 'nowarn_deprecated_catch' can be used to suppress204warnings in selected modules.205%   80|     catch Module:event(terminate).206%     |     ^207208Compiling 3 files (.ex)209Generated n2o app210==> nitro211Compiling 108 files (.erl)212src/nitro_pi.erl:91:5: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.213Compile directive 'nowarn_deprecated_catch' can be used to suppress214warnings in selected modules.215%   91|     catch cache(Tab,{Tab,Name},undefined), ok.216%     |     ^217218Compiling 4 files (.ex)219    warning: unused require Record220    │221  3 │   require Record222    │   ~223    │224    └─ lib/combo.ex:3:3225226Generated nitro app227==> form228Compiling 5 files (.erl)229Compiling 2 files (.ex)230    warning: unused require NITRO231    │232  4 │   require NITRO233    │   ~234    │235    └─ lib/api.ex:4:3236237Generated form app238==> plug239Compiling 1 file (.erl)240warning: "xref: [exclude: ...]" in your mix.exs file is deprecated, instead use: "elixirc_options: [no_warn_undefined: ...]"241  (mix 1.20.3) lib/mix/tasks/compile.elixir.ex:243: Mix.Tasks.Compile.Elixir.xref_exclude_opts/2242  (mix 1.20.3) lib/mix/tasks/compile.elixir.ex:142: Mix.Tasks.Compile.Elixir.run/1243  (mix 1.20.3) lib/mix/task.ex:502: anonymous fn/3 in Mix.Task.run_task/5244  (mix 1.20.3) lib/mix/task.compiler.ex:299: Mix.Task.Compiler.run_compiler/2245  (mix 1.20.3) lib/mix/task.compiler.ex:287: Mix.Task.Compiler.run/4246  (mix 1.20.3) lib/mix/tasks/compile.all.ex:75: Mix.Tasks.Compile.All.do_run/2247  (mix 1.20.3) lib/mix/task.ex:502: anonymous fn/3 in Mix.Task.run_task/5248  (mix 1.20.3) lib/mix/tasks/compile.ex:145: Mix.Tasks.Compile.run/1249  (mix 1.20.3) lib/mix/task.ex:502: anonymous fn/3 in Mix.Task.run_task/5250  (mix 1.20.3) lib/mix/tasks/deps.compile.ex:230: anonymous fn/2 in Mix.Tasks.Deps.Compile.do_mix/2251  (mix 1.20.3) lib/mix/project.ex:557: Mix.Project.in_project/4252  (elixir 1.20.3) lib/file.ex:2100: File.cd!/2253  (mix 1.20.3) lib/mix/dep.ex:279: Mix.Dep.in_dependency/3254  (mix 1.20.3) lib/mix/tasks/deps.compile.ex:138: Mix.Tasks.Deps.Compile.compile_single/3255  (elixir 1.20.3) lib/enum.ex:983: Enum."-each/2-lists^foreach/1-0-"/2256  (mix 1.20.3) lib/mix/tasks/deps.loadpaths.ex:114: anonymous fn/2 in Mix.Tasks.Deps.Loadpaths.deps_check/3257  (mix 1.20.3) lib/mix/sync/lock.ex:122: Mix.Sync.Lock.with_lock/3258  (mix 1.20.3) lib/mix/tasks/deps.loadpaths.ex:73: Mix.Tasks.Deps.Loadpaths.run/1259  (mix 1.20.3) lib/mix/task.ex:502: anonymous fn/3 in Mix.Task.run_task/5260  (mix 1.20.3) lib/mix/task.ex:572: Mix.Task.run_alias/6261  (mix 1.20.3) lib/mix/task.ex:560: Mix.Task.get_task_or_run/3262  (mix 1.20.3) lib/mix/task.ex:477: Mix.Task.maybe_load_or_compile_task/2263  (mix 1.20.3) lib/mix/task.ex:431: Mix.Task.do_run/3264  (mix 1.20.3) lib/mix/cli.ex:129: Mix.CLI.run_task/2265  /home/nerves/.elixir/bin/mix:7: (file)266  (elixir 1.20.3) src/elixir_compiler.erl:102: :elixir_compiler.dispatch/4267  (elixir 1.20.3) src/elixir_compiler.erl:76: :elixir_compiler.compile/4268  (elixir 1.20.3) src/elixir_compiler.erl:42: :elixir_compiler.optimize_defmodule/2269  (elixir 1.20.3) src/elixir_lexical.erl:18: :elixir_lexical.run/3270  (elixir 1.20.3) src/elixir_compiler.erl:21: :elixir_compiler.quoted/3271  (elixir 1.20.3) lib/module/parallel_checker.ex:157: Module.ParallelChecker.verify/1272  (elixir 1.20.3) lib/code.ex:1639: Code.require_file/2273  (elixir 1.20.3) lib/kernel/cli.ex:562: Kernel.CLI.wrapper/1274  (elixir 1.20.3) lib/enum.ex:1725: Enum."-map/2-lists^map/1-1-"/2275  (elixir 1.20.3) lib/kernel/cli.ex:93: Kernel.CLI.process_commands/1276  (elixir 1.20.3) lib/kernel/cli.ex:39: anonymous fn/2 in Kernel.CLI.main/1277  (elixir 1.20.3) lib/kernel/cli.ex:141: anonymous fn/3 in Kernel.CLI.exec_fun/2278279Compiling 40 files (.ex)280     warning: unused require Bitwise281     │282 105 │   require Bitwise283     │   ~284     │285     └─ lib/plug/csrf_protection.ex:105:3286287    warning: unused require Logger288    │289 52 │   require Logger290    │   ~291    │292    └─ lib/plug/request_id.ex:52:3293294     warning: the variable "prefix_size" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator295     │296 160 │         <<prefix::binary-size(prefix_size), char, suffix::binary-size(suffix_size)>> = segment297     │                               ~298     │299     └─ lib/plug/router/utils.ex:160:31: Plug.Router.Utils.build_path_clause/7300301     warning: the variable "suffix_size" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator302     │303 160 │         <<prefix::binary-size(prefix_size), char, suffix::binary-size(suffix_size)>> = segment304     │                                                                       ~305     │306     └─ lib/plug/router/utils.ex:160:71: Plug.Router.Utils.build_path_clause/7307308     warning: the following clause will never match:309310         {:error, reason} ->311312     because it attempts to match on the result of:313314         IO.binwrite(device, contents)315316     which has type:317318         dynamic(not {:error, term()})319320     type warning found at:321     │322 275 │       {:error, reason} ->323     │       ~~~~~~~~~~~~~~~~~~~324     │325     └─ lib/plug/parsers/multipart.ex:275: Plug.Parsers.MULTIPART.binwrite!/2326327    warning: a struct for Plug.Conn is expected on struct update:328329        %Plug.Conn{conn | method: method}330331    but got type:332333        dynamic()334335    where "conn" was given the type:336337        # type: dynamic()338        # from: lib/plug/method_override.ex:60:24339        conn340341    when defining the variable "conn", you must also pattern match on "%Plug.Conn{}"342343    type warning found at:344    │345 64 │       %Plug.Conn{conn | method: method}346    │       ~347    │348    └─ lib/plug/method_override.ex:64:7: Plug.MethodOverride.override_method/2349350    warning: a struct for Plug.Conn is expected on struct update:351352        %Plug.Conn{353          conn354          | adapter: {Plug.Adapters.Test.Conn, state},355            host: uri.host || conn.host || "www.example.com",356            method: method,357            owner: owner,358            path_info: split_path(uri.path),359            port: uri.port || conn_port,360            remote_ip: conn.remote_ip || {127, 0, 0, 1},361            req_headers: req_headers,362            request_path: uri.path,363            query_string: query,364            query_params: query_params || %Plug.Conn.Unfetched{aspect: :query_params},365            body_params: body_params || %Plug.Conn.Unfetched{aspect: :body_params},366            params: params || %Plug.Conn.Unfetched{aspect: :params},367            scheme: String.to_atom(String.downcase(uri.scheme || "http"))368        }369370    but got type:371372        dynamic(%{..., adapter: {atom(), term()}, port: term(), req_headers: term()})373374    where "conn" was given the types:375376        # type: dynamic(%{..., req_headers: term()})377        # from: lib/plug/adapters/test/conn.ex:21:7378        body_or_params(body_or_params, query, conn.req_headers, method)379380        # type: dynamic(%{..., adapter: {atom(), term()}, req_headers: term()})381        # from: lib/plug/adapters/test/conn.ex:30:22382        get_from_adapter(conn, :get_http_protocol, :"HTTP/1.1")383384        # type: dynamic(%{..., adapter: {atom(), term()}, port: term(), req_headers: term()})385        # from: lib/plug/adapters/test/conn.ex:39:30386        conn.port != 0387388    when defining the variable "conn", you must also pattern match on "%Plug.Conn{}"389390    type warning found at:391    │392 41 │     %Plug.Conn{393    │     ~394    │395    └─ lib/plug/adapters/test/conn.ex:41:5: Plug.Adapters.Test.Conn.conn/4396397Generated plug app398==> nerves_compatibility_test399fatal: not a git repository (or any parent up to mount point /)400Stopping at filesystem boundary (GIT_DISCOVERY_ACROSS_FILESYSTEM not set).401===> Hook for compile failed!402403** (Mix) Could not compile dependency :rocksdb, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/x86_64/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile rocksdb --force", update it with "mix deps.update rocksdb" or clean it with "mix deps.clean rocksdb"