Build log
nerves_system_rpi4
guardian_paseto 0.2.1 · fail · run guardian_paseto-0.2.1-1791192978619
469 of 469 lines
1Resolving Hex dependencies...2Resolution completed in 0.162s3Unchanged:4 blake2 1.0.45 circular_buffer 1.1.06 elixir_make 0.10.07 elixir_uuid 1.2.18 guardian 1.2.1 VULNERABLE!9 EEF-CVE-2026-54894 (MEDIUM)10 aka: CVE-2026-54894, GHSA-xqch-c77q-rgh511 Atom-table exhaustion denial of service in Guardian via unbounded atom creation from binary keys12 https://osv.dev/vulnerability/EEF-CVE-2026-548941314 EEF-CVE-2026-55735 (HIGH)15 aka: CVE-2026-55735, GHSA-7975-hp3r-5qhv16 Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocation17 https://osv.dev/vulnerability/EEF-CVE-2026-5573518 guardian_paseto 0.2.119 hkdf 0.1.020 interactive_cmd 0.1.421 jose 1.11.1222 libsalty2 0.3.023 nerves 2.0.0-pre.224 nerves_discovery 0.1.525 nerves_logging 0.2.426 nerves_runtime 0.13.1327 nerves_system_bbb 2.30.228 nerves_system_br 1.34.429 nerves_system_mangopi_mq_pro 0.17.230 nerves_system_qemu_aarch64 0.4.231 nerves_system_rpi0 2.1.232 nerves_system_rpi4 2.1.233 nerves_system_rpi5 2.1.234 nerves_system_trellis 0.5.035 nerves_system_x86_64 1.34.236 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.137 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.138 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.139 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.140 nerves_toolchain_x86_64_nerves_linux_musl 15.3.141 nerves_uevent 0.1.742 paseto 1.3.243 poison 3.1.044 property_table 0.3.445 ring_logger 0.11.746 tablet 0.3.347 toolshed 0.5.048 uboot_env 1.0.249* Getting guardian_paseto (Hex package)50* Getting nerves (Hex package)51* Getting ring_logger (Hex package)52* Getting toolshed (Hex package)53* Getting nerves_runtime (Hex package)54* Getting nerves_system_bbb (Hex package)55* Getting nerves_system_mangopi_mq_pro (Hex package)56* Getting nerves_system_qemu_aarch64 (Hex package)57* Getting nerves_system_rpi0 (Hex package)58* Getting nerves_system_rpi4 (Hex package)59* Getting nerves_system_rpi5 (Hex package)60* Getting nerves_system_trellis (Hex package)61* Getting nerves_system_x86_64 (Hex package)62* Getting nerves_system_br (Hex package)63* Getting nerves_toolchain_x86_64_nerves_linux_musl (Hex package)64* Getting nerves_toolchain_armv7_nerves_linux_gnueabihf (Hex package)65* Getting nerves_toolchain_aarch64_nerves_linux_gnu (Hex package)66* Getting nerves_toolchain_armv6_nerves_linux_gnueabihf (Hex package)67* Getting nerves_toolchain_riscv64_nerves_linux_gnu (Hex package)68* Getting nerves_logging (Hex package)69* Getting nerves_uevent (Hex package)70* Getting uboot_env (Hex package)71* Getting elixir_make (Hex package)72* Getting property_table (Hex package)73* Getting circular_buffer (Hex package)74* Getting interactive_cmd (Hex package)75* Getting nerves_discovery (Hex package)76* Getting tablet (Hex package)77* Getting elixir_uuid (Hex package)78* Getting guardian (Hex package)79* Getting paseto (Hex package)80* Getting poison (Hex package)81* Getting blake2 (Hex package)82* Getting hkdf (Hex package)83* Getting libsalty2 (Hex package)84* Getting jose (Hex package)85Found packages with security advisories, see above for details86 warning: String.strip/1 is deprecated. Use String.trim/1 instead87 │88 4 │ @version File.read!("VERSION") |> String.strip89 │ ~90 │91 └─ /work/proj/deps_rpi4/poison/mix.exs:4:44: Poison.Mixfile (module)9293==> nerves_system_br94Generated nerves_system_br app95==> circular_buffer96Compiling 1 file (.ex)97Generated circular_buffer app98==> poison99Compiling 4 files (.ex)100 warning: using single-quoted strings to represent charlists is deprecated.101 Use ~c"" if you indeed want a charlist or use "" instead.102 You may run "mix format --migrate" to change all single-quoted103 strings to use the ~c sigil and fix this warning.104 │105 93 │ for {char, seq} <- Enum.zip('"\\\n\t\r\f\b', '"\\ntrfb') do106 │ ~107 │108 └─ lib/poison/encoder.ex:93:31109110 warning: using single-quoted strings to represent charlists is deprecated.111 Use ~c"" if you indeed want a charlist or use "" instead.112 You may run "mix format --migrate" to change all single-quoted113 strings to use the ~c sigil and fix this warning.114 │115 93 │ for {char, seq} <- Enum.zip('"\\\n\t\r\f\b', '"\\ntrfb') do116 │ ~117 │118 └─ lib/poison/encoder.ex:93:48119120 warning: using single-quoted strings to represent charlists is deprecated.121 Use ~c"" if you indeed want a charlist or use "" instead.122 You may run "mix format --migrate" to change all single-quoted123 strings to use the ~c sigil and fix this warning.124 │125 139 │ defp chunk_size(<<char>> <> _, _mode, acc) when char <= 0x1F or char in '"\\' do126 │ ~127 │128 └─ lib/poison/encoder.ex:139:75129130 warning: using single-quoted strings to represent charlists is deprecated.131 Use ~c"" if you indeed want a charlist or use "" instead.132 You may run "mix format --migrate" to change all single-quoted133 strings to use the ~c sigil and fix this warning.134 │135 77 │ defp value(<<char, _ :: binary>> = string, pos, _keys) when char in '-0123456789' do136 │ ~137 │138 └─ lib/poison/parser.ex:77:71139140 warning: using single-quoted strings to represent charlists is deprecated.141 Use ~c"" if you indeed want a charlist or use "" instead.142 You may run "mix format --migrate" to change all single-quoted143 strings to use the ~c sigil and fix this warning.144 │145 155 │ defp number_int(<<char, _ :: binary>> = string, pos, acc) when char in '123456789' do146 │ ~147 │148 └─ lib/poison/parser.ex:155:74149150 warning: using single-quoted strings to represent charlists is deprecated.151 Use ~c"" if you indeed want a charlist or use "" instead.152 You may run "mix format --migrate" to change all single-quoted153 strings to use the ~c sigil and fix this warning.154 │155 171 │ defp number_exp(<<e>> <> rest, frac, pos, acc) when e in 'eE' do156 │ ~157 │158 └─ lib/poison/parser.ex:171:60159160 warning: using single-quoted strings to represent charlists is deprecated.161 Use ~c"" if you indeed want a charlist or use "" instead.162 You may run "mix format --migrate" to change all single-quoted163 strings to use the ~c sigil and fix this warning.164 │165 197 │ defp number_digits(<<char>> <> rest = string, pos) when char in '0123456789' do166 │ ~167 │168 └─ lib/poison/parser.ex:197:67169170 warning: using single-quoted strings to represent charlists is deprecated.171 Use ~c"" if you indeed want a charlist or use "" instead.172 You may run "mix format --migrate" to change all single-quoted173 strings to use the ~c sigil and fix this warning.174 │175 205 │ defp number_digits_count(<<char>> <> rest, acc) when char in '0123456789' do176 │ ~177 │178 └─ lib/poison/parser.ex:205:64179180 warning: using single-quoted strings to represent charlists is deprecated.181 Use ~c"" if you indeed want a charlist or use "" instead.182 You may run "mix format --migrate" to change all single-quoted183 strings to use the ~c sigil and fix this warning.184 │185 229 │ for {seq, char} <- Enum.zip('"\\ntr/fb', '"\\\n\t\r/\f\b') do186 │ ~187 │188 └─ lib/poison/parser.ex:229:31189190 warning: using single-quoted strings to represent charlists is deprecated.191 Use ~c"" if you indeed want a charlist or use "" instead.192 You may run "mix format --migrate" to change all single-quoted193 strings to use the ~c sigil and fix this warning.194 │195 229 │ for {seq, char} <- Enum.zip('"\\ntr/fb', '"\\\n\t\r/\f\b') do196 │ ~197 │198 └─ lib/poison/parser.ex:229:44199200 warning: using single-quoted strings to represent charlists is deprecated.201 Use ~c"" if you indeed want a charlist or use "" instead.202 You may run "mix format --migrate" to change all single-quoted203 strings to use the ~c sigil and fix this warning.204 │205 239 │ when a1 in 'dD' and a2 in 'dD'206 │ ~207 │208 └─ lib/poison/parser.ex:239:16209210 warning: using single-quoted strings to represent charlists is deprecated.211 Use ~c"" if you indeed want a charlist or use "" instead.212 You may run "mix format --migrate" to change all single-quoted213 strings to use the ~c sigil and fix this warning.214 │215 239 │ when a1 in 'dD' and a2 in 'dD'216 │ ~217 │218 └─ lib/poison/parser.ex:239:31219220 warning: using single-quoted strings to represent charlists is deprecated.221 Use ~c"" if you indeed want a charlist or use "" instead.222 You may run "mix format --migrate" to change all single-quoted223 strings to use the ~c sigil and fix this warning.224 │225 240 │ and (b1 in '89abAB')226 │ ~227 │228 └─ lib/poison/parser.ex:240:16229230 warning: using single-quoted strings to represent charlists is deprecated.231 Use ~c"" if you indeed want a charlist or use "" instead.232 You may run "mix format --migrate" to change all single-quoted233 strings to use the ~c sigil and fix this warning.234 │235 274 │ defp skip_whitespace(<<char>> <> rest, pos) when char in '\s\n\t\r' do236 │ ~237 │238 └─ lib/poison/parser.ex:274:60239240 warning: Application.get_env/2 is discouraged in the module body, use Application.compile_env/3 instead241 │242 22 │ if Application.get_env(:poison, :native) do243 │ ~244 │245 └─ lib/poison/parser.ex:22:18: Poison.Parser (module)246247 warning: use Bitwise is deprecated. import Bitwise instead248 │249 26 │ use Bitwise250 │ ~~~~~~~~~~~251 │252 └─ lib/poison/parser.ex:26: Poison.Parser (module)253254 warning: the variable "count" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator255 │256 199 │ <<digits :: binary-size(count), rest :: binary>> = string257 │ ~258 │259 └─ lib/poison/parser.ex:199:29: Poison.Parser.number_digits/2260261 warning: the variable "count" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator262 │263 225 │ <<chunk :: binary-size(count), rest :: binary>> = string264 │ ~265 │266 └─ lib/poison/parser.ex:225:28: Poison.Parser.string_continue/3267268 warning: use Bitwise is deprecated. import Bitwise instead269 │270 83 │ use Bitwise271 │ ~~~~~~~~~~~272 │273 └─ lib/poison/encoder.ex:83: Poison.Encoder.BitString (module)274275 warning: the variable "size" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator276 │277 135 │ <<chunk :: binary-size(size), rest :: binary>> = string278 │ ~279 │280 └─ lib/poison/encoder.ex:135:28: Poison.Encoder.BitString.escape/2281282 warning: Integer.to_char_list/2 is deprecated. Use Integer.to_charlist/2 instead283 │284 173 │ case Integer.to_char_list(char, 16) do285 │ ~286 │287 └─ lib/poison/encoder.ex:173:18: Poison.Encoder.BitString.seq/1288289Generated poison app290==> jose291Compiling 113 files (.erl)292src/jose_server.erl:137:7: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.293Compile directive 'nowarn_deprecated_catch' can be used to suppress294warnings in selected modules.295% 137| _ = catch jose_jwa:unsecured_signing(UnsecuredSigning),296% | ^297298src/jose_server.erl:797:7: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.299Compile directive 'nowarn_deprecated_catch' can be used to suppress300warnings in selected modules.301% 797| case catch jose_crypto_compat:crypto_one_time(Cipher, Key, PlainText, true) of302% | ^303304src/jose_server.erl:799:9: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.305Compile directive 'nowarn_deprecated_catch' can be used to suppress306warnings in selected modules.307% 799| case catch jose_crypto_compat:crypto_one_time(Cipher, Key, CipherText, false) of308% | ^309310src/jose_server.erl:809:7: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.311Compile directive 'nowarn_deprecated_catch' can be used to suppress312warnings in selected modules.313% 809| case catch jose_crypto_compat:crypto_one_time(Cipher, Key, IV, PlainText, true) of314% | ^315316src/jose_server.erl:811:9: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.317Compile directive 'nowarn_deprecated_catch' can be used to suppress318warnings in selected modules.319% 811| case catch jose_crypto_compat:crypto_one_time(Cipher, Key, IV, CipherText, false) of320% | ^321322src/jose_server.erl:821:7: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.323Compile directive 'nowarn_deprecated_catch' can be used to suppress324warnings in selected modules.325% 821| case catch jose_crypto_compat:crypto_one_time(Cipher, Key, IV, {AAD, PlainText}, true) of326% | ^327328src/jose_server.erl:823:9: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.329Compile directive 'nowarn_deprecated_catch' can be used to suppress330warnings in selected modules.331% 823| case catch jose_crypto_compat:crypto_one_time(Cipher, Key, IV, {AAD, CipherText, CipherTag}, false) of332% | ^333334src/jose_server.erl:837:7: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.335Compile directive 'nowarn_deprecated_catch' can be used to suppress336warnings in selected modules.337% 837| case catch public_key:encrypt_public(PlainText, PublicKey, FutureOptions) of338% | ^339340src/jose_server.erl:840:9: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.341Compile directive 'nowarn_deprecated_catch' can be used to suppress342warnings in selected modules.343% 840| case catch public_key:decrypt_private(CipherText, PrivateKey, FutureOptions) of344% | ^345346src/jose_server.erl:842:11: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.347Compile directive 'nowarn_deprecated_catch' can be used to suppress348warnings in selected modules.349% 842| case catch public_key:decrypt_private(rsa_ciphertext(Algorithm), PrivateKey, FutureOptions) of350% | ^351352src/jose_server.erl:859:7: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.353Compile directive 'nowarn_deprecated_catch' can be used to suppress354warnings in selected modules.355% 859| case catch public_key:encrypt_public(PlainText, PublicKey, LegacyOptions) of356% | ^357358src/jose_server.erl:862:9: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.359Compile directive 'nowarn_deprecated_catch' can be used to suppress360warnings in selected modules.361% 862| case catch public_key:decrypt_private(CipherText, PrivateKey, LegacyOptions) of362% | ^363364src/jose_server.erl:864:11: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.365Compile directive 'nowarn_deprecated_catch' can be used to suppress366warnings in selected modules.367% 864| case catch public_key:decrypt_private(rsa_ciphertext(Algorithm), PrivateKey, LegacyOptions) of368% | ^369370src/jose_server.erl:882:7: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.371Compile directive 'nowarn_deprecated_catch' can be used to suppress372warnings in selected modules.373% 882| case catch public_key:sign(Message, DigestType, PrivateKey, Options) of374% | ^375376src/jose_server.erl:885:9: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.377Compile directive 'nowarn_deprecated_catch' can be used to suppress378warnings in selected modules.379% 885| case catch public_key:verify(Message, DigestType, Signature, PublicKey, Options) of380% | ^381382src/jose_server.erl:897:7: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.383Compile directive 'nowarn_deprecated_catch' can be used to suppress384warnings in selected modules.385% 897| case catch public_key:sign(Message, DigestType, PrivateKey) of386% | ^387388src/jose_server.erl:900:9: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.389Compile directive 'nowarn_deprecated_catch' can be used to suppress390warnings in selected modules.391% 900| case catch public_key:verify(Message, DigestType, Signature, PublicKey) of392% | ^393394src/jwa/jose_jwa.erl:230:7: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.395Compile directive 'nowarn_deprecated_catch' can be used to suppress396warnings in selected modules.397% 230| case catch block_cipher(Cipher) of398% | ^399400src/jwa/jose_jwa.erl:238:7: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.401Compile directive 'nowarn_deprecated_catch' can be used to suppress402warnings in selected modules.403% 238| case catch ?MAYBE_START_JOSE(ets:lookup_element(?TAB, chacha20_poly1305_module, 2)) of404% | ^405406src/jwa/jose_jwa.erl:246:7: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.407Compile directive 'nowarn_deprecated_catch' can be used to suppress408warnings in selected modules.409% 246| case catch rsa_crypt(Padding) of410% | ^411412src/jwa/jose_jwa.erl:254:7: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.413Compile directive 'nowarn_deprecated_catch' can be used to suppress414warnings in selected modules.415% 254| case catch rsa_sign(Padding) of416% | ^417418src/jwa/jose_jwa.erl:262:7: Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.419Compile directive 'nowarn_deprecated_catch' can be used to suppress420warnings in selected modules.421% 262| case catch ?MAYBE_START_JOSE(ets:lookup_element(?TAB, xchacha20_poly1305_module, 2)) of422% | ^423424Compiling 8 files (.ex)425Generated jose app426==> tablet427Compiling 2 files (.ex)428Generated tablet app429==> elixir_make430Compiling 8 files (.ex)431Generated elixir_make app432==> nerves_logging433 CC kmsg_tailer.o434 LD kmsg_tailer435Compiling 5 files (.ex)436Generated nerves_logging app437==> elixir_uuid438Compiling 1 file (.ex)439 warning: use Bitwise is deprecated. import Bitwise instead440 │441 2 │ use Bitwise, only_operators: true442 │ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~443 │444 └─ lib/uuid.ex:2: UUID (module)445446Generated elixir_uuid app447==> nerves_discovery448Compiling 5 files (.ex)449Generated nerves_discovery app450==> ring_logger451Compiling 7 files (.ex)452Generated ring_logger app453==> libsalty2454mkdir -p priv455/home/nerves/.nerves/artifacts/nerves_toolchain_aarch64_nerves_linux_gnu-15.3.1/bin/aarch64-nerves-linux-gnu-gcc -o priv/salty_nif.so src/salty_nif.c -I/home/nerves/.nerves/artifacts/nerves_system_rpi4-2.1.2/staging/usr/lib/erlang/erts-17.0.6/include -I/home/nerves/.nerves/artifacts/nerves_system_rpi4-2.1.2/staging/usr/lib/erlang/lib/erl_interface-5.8.2/include -mabi=lp64 -fstack-protector-strong -mcpu=cortex-a72 -fPIE -pie -Wl,-z,now -Wl,-z,relro -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -pipe -O2 --sysroot /home/nerves/.nerves/artifacts/nerves_system_rpi4-2.1.2/staging -L/home/nerves/.nerves/artifacts/nerves_system_rpi4-2.1.2/staging/usr/lib/erlang/lib/erl_interface-5.8.2/lib -lei --sysroot=/home/nerves/.nerves/artifacts/nerves_system_rpi4-2.1.2/staging -fPIC -shared -lsodium -lei456src/salty_nif.c:19:10: fatal error: sodium.h: No such file or directory457 19 | #include "sodium.h"458 | ^~~~~~~~~~459compilation terminated.460make: *** [Makefile:37: priv/salty_nif.so] Error 1461could not compile dependency :libsalty2, "mix compile" failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile libsalty2 --force", update it with "mix deps.update libsalty2" or clean it with "mix deps.clean libsalty2"462==> nerves_compatibility_test463** (Mix) Could not compile with "make" (exit status: 2).464You need to have gcc and make installed. If you are using465Ubuntu or any other Debian-based system, install the packages466"build-essential". Also install "erlang-dev" package if not467included in your Erlang/OTP version. If you're on Fedora, run468"dnf group install 'Development Tools'".469