https://git.altlinux.org/tasks/421674/logs/events.2.1.log
https://packages.altlinux.org/tasks/421674
subtask name aarch64 i586 x86_64
#100 firefox 1:04:17 - 36:24
2026-Jun-18 08:25:51 :: task #421674 for p11 resumed by rauty:
2026-Jun-18 08:25:51 :: message: CVE fixes
#100 build 152.0-alt1 from /people/rauty/packages/firefox.git fetched at
2026-Jun-17 14:13:10
2026-Jun-18 08:25:53 :: [i586] #100 firefox.git 152.0-alt1: build start
2026-Jun-18 08:25:53 :: [x86_64] #100 firefox.git 152.0-alt1: build start
2026-Jun-18 08:25:53 :: [aarch64] #100 firefox.git 152.0-alt1: build start
2026-Jun-18 08:26:15 :: [i586] #100 firefox.git 152.0-alt1: build SKIPPED
2026-Jun-18 09:02:17 :: [x86_64] #100 firefox.git 152.0-alt1: build OK
2026-Jun-18 09:30:10 :: [aarch64] #100 firefox.git 152.0-alt1: build OK
2026-Jun-18 09:30:34 :: 100: build check OK
2026-Jun-18 09:30:35 :: build check OK
2026-Jun-18 09:30:42 :: #100: firefox.git 152.0-alt1: version check OK
2026-Jun-18 09:30:42 :: build version check OK
2026-Jun-18 09:32:28 :: noarch check OK
2026-Jun-18 09:32:30 :: plan: src +1 -1 =20413, aarch64 +3 -3 =36676, x86_64 +3
-3 =37686
#100 firefox 151.0.2-alt1 -> 152.0-alt1
Wed Jun 17 2026 Ajrat Makhmutov <rauty@altlinux> 152.0-alt1
- New version.
- Fixes:
+ CVE-2026-12289: Privilege escalation in the Graphics: WebRender component
+ CVE-2026-12290: Memory safety bug fixed in Firefox 152
+ CVE-2026-12291: Use-after-free in the Networking: HTTP component
+ CVE-2026-12292: Incorrect boundary conditions in the Web Audio component
+ CVE-2026-12293: Use-after-free in the Graphics: WebGPU component
+ CVE-2026-12294: Sandbox escape in the DOM: Workers component
+ CVE-2026-12295: Sandbox escape in the DOM: Navigation component
[...]
2026-Jun-18 09:32:30 :: firefox: fixes vulnerabilities: CVE-2026-12289
CVE-2026-12290 CVE-2026-12291 CVE-2026-12292 CVE-2026-12293 CVE-2026-12294
CVE-2026-12295 CVE-2026-12296 CVE-2026-12297 CVE-2026-12298 CVE-2026-12299
CVE-2026-12300 CVE-2026-12301 CVE-2026-12302 CVE-2026-12303 CVE-2026-12304
CVE-2026-12305 CVE-2026-12306 CVE-2026-12307 CVE-2026-12308 CVE-2026-12309
CVE-2026-12310 CVE-2026-12311 CVE-2026-12312 CVE-2026-12313 CVE-2026-12314
CVE-2026-12315 CVE-2026-12316 CVE-2026-12317 CVE-2026-12318 CVE-2026-12319
CVE-2026-12320 CVE-2026-12321 CVE-2026-12322 CVE-2026-12323 CVE-2026-12324
CVE-2026-12325 CVE-2026-12326 CVE-2026-12327 CVE-2026-12328 CVE-2026-10701
CVE-2026-10702
2026-Jun-18 09:33:18 :: patched apt indices
2026-Jun-18 09:33:28 :: created next repo
2026-Jun-18 09:33:38 :: duplicate provides check OK
2026-Jun-18 09:34:19 :: dependencies check OK
2026-Jun-18 09:34:57 :: [x86_64 aarch64] ELF symbols check OK
x86_64: firefox=152.0-alt1 post-install unowned files:
/usr/share/gnome-shell
/usr/share/gnome-shell/search-providers
/usr/share/icons/hicolor/22x22
/usr/share/icons/hicolor/22x22/apps
/usr/share/icons/hicolor/24x24
/usr/share/icons/hicolor/24x24/apps
/usr/share/icons/hicolor/256x256
/usr/share/icons/hicolor/256x256/apps
2026-Jun-18 09:35:23 :: [x86_64] #100 firefox: install check OK
aarch64: firefox=152.0-alt1 post-install unowned files:
/usr/share/gnome-shell
/usr/share/gnome-shell/search-providers
/usr/share/icons/hicolor/22x22
/usr/share/icons/hicolor/22x22/apps
/usr/share/icons/hicolor/24x24
/usr/share/icons/hicolor/24x24/apps
/usr/share/icons/hicolor/256x256
/usr/share/icons/hicolor/256x256/apps
2026-Jun-18 09:35:37 :: [aarch64] #100 firefox: install check OK
2026-Jun-18 09:35:41 :: [x86_64] #100 firefox-config-privacy: install check OK
2026-Jun-18 09:36:04 :: [aarch64] #100 firefox-config-privacy: install check OK
2026-Jun-18 09:36:38 :: [x86_64] #100 firefox-debuginfo: install check OK
2026-Jun-18 09:37:31 :: [aarch64] #100 firefox-debuginfo: install check OK
2026-Jun-18 09:37:51 :: [x86_64-i586] generated apt indices
2026-Jun-18 09:37:51 :: [x86_64-i586] created next repo
2026-Jun-18 09:38:02 :: [x86_64-i586] dependencies check OK
2026-Jun-18 09:38:04 :: gears inheritance check OK
2026-Jun-18 09:38:04 :: srpm inheritance check OK
girar-check-perms: access to firefox DENIED for rauty: project `firefox' is not
listed in the acl file for repository `p11', and the policy for such projects
in `p11' is to deny
check-subtask-perms: #100: firefox: needs approvals from members of @maint and
@tester groups
2026-Jun-18 09:38:05 :: acl check FAILED
2026-Jun-18 09:38:18 :: created contents_index files
2026-Jun-18 09:38:28 :: created hash files: aarch64 src x86_64
2026-Jun-18 09:38:31 :: task #421674 for p11 EPERM
_______________________________________________
Sisyphus-incominger mailing list
[email protected]
https://lists.altlinux.org/mailman/listinfo/sisyphus-incominger