You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@whimsical.apache.org by "Sam Ruby (Jira)" <ji...@apache.org> on 2020/06/10 22:39:00 UTC

[jira] [Created] (WHIMSY-331) Roster tool broken - Insecure operation - spawn

Sam Ruby created WHIMSY-331:
-------------------------------

             Summary: Roster tool broken - Insecure operation - spawn
                 Key: WHIMSY-331
                 URL: https://issues.apache.org/jira/browse/WHIMSY-331
             Project: Whimsy
          Issue Type: Bug
          Components: Roster
            Reporter: Sam Ruby


On slack, people have been reporting errors in the roster tool when adding or removing a person from a PMC. I tried adding test_rubys to whimsy and got the following:


{
 "exception": "#<SecurityError: Insecure operation - spawn>",
 "backtrace": [
 "/usr/local/rvm/rubies/ruby-2.4.1/lib/ruby/2.4.0/open3.rb:199:in `spawn'",
 "/usr/local/rvm/rubies/ruby-2.4.1/lib/ruby/2.4.0/open3.rb:199:in `popen_run'",
 "/usr/local/rvm/rubies/ruby-2.4.1/lib/ruby/2.4.0/open3.rb:95:in `popen3'",
 "/usr/local/rvm/rubies/ruby-2.4.1/lib/ruby/2.4.0/open3.rb:258:in `capture3'",
 "/x1/srv/whimsy/lib/whimsy/asf/svn.rb:332:in `svn'",
 "/x1/srv/whimsy/lib/whimsy/asf/svn.rb:478:in `block in updateCI'",
 "/usr/local/rvm/rubies/ruby-2.4.1/lib/ruby/2.4.0/tmpdir.rb:89:in `mktmpdir'",
 "/x1/srv/whimsy/lib/whimsy/asf/svn.rb:473:in `updateCI'",
 "/x1/srv/whimsy/www/roster/views/actions/committee.json.rb:41:in `_evaluate'",
 "/x1/srv/whimsy/www/roster/main.rb:345:in `block in <top (required)>'",
 "/x1/srv/whimsy/lib/whimsy/asf/rack.rb:223:in `call'",
 "/x1/srv/whimsy/lib/whimsy/asf/rack.rb:48:in `call'",
 "/x1/srv/whimsy/lib/whimsy/asf/rack.rb:200:in `call'",
 "/x1/srv/whimsy/lib/whimsy/asf/rack.rb:254:in `call'",
 "/usr/local/rvm/gems/ruby-2.4.1/gems/passenger-6.0.2/src/ruby_supportlib/phusion_passenger/rack/thread_handler_extension.rb:97:in `process_request'",
 "/usr/local/rvm/gems/ruby-2.4.1/gems/passenger-6.0.2/src/ruby_supportlib/phusion_passenger/request_handler/thread_handler.rb:157:in `accept_and_process_next_request'",
 "/usr/local/rvm/gems/ruby-2.4.1/gems/passenger-6.0.2/src/ruby_supportlib/phusion_passenger/request_handler/thread_handler.rb:110:in `main_loop'",
 "/usr/local/rvm/gems/ruby-2.4.1/gems/passenger-6.0.2/src/ruby_supportlib/phusion_passenger/request_handler.rb:415:in `block (3 levels) in start_threads'",
 "/usr/local/rvm/gems/ruby-2.4.1/gems/passenger-6.0.2/src/ruby_supportlib/phusion_passenger/utils.rb:113:in `block in create_thread_and_abort_on_exception'"
 ]
}



--
This message was sent by Atlassian Jira
(v8.3.4#803005)