Control: tags -1 moreinfo unreproducible
Control: severity -1 important

On Sun, 15 Nov 2020 13:25:11 +0200 Adrian Bunk <b...@debian.org> wrote:
> Source: openconnect
> Version: 8.10-1
> Severity: serious
> Tags: ftbfs
> 
> https://buildd.debian.org/status/fetch.php?pkg=openconnect&arch=i386&ver=8.10-1~bpo10%2B1&stamp=1589917131&raw=0

> https://buildd.debian.org/status/fetch.php?pkg=openconnect&arch=amd64&ver=8.10-1~bpo10%2B1&stamp=1589912458&raw=0

> https://buildd.debian.org/status/fetch.php?pkg=openconnect&arch=amd64&ver=8.10-2&stamp=1603997003&raw=0

> 
> ...
> FAIL: auth-username-pass
> ========================
> 
> Testing certificate auth... 
> warning: skipping unknown option 'cookie-validity'
> Parsing plain auth method subconfig using legacy format
> note: vhost:default: setting 'plain' as primary authentication method
> note: setting 'file' as supplemental config option
> listening (TCP) on [::]:443...
> listening (UDP) on [::]:443...
> ocserv[19194]: main: Starting 1 instances of ocserv-sm
> ocserv[19194]: main: not using control unix socket
> ocserv[19194]: main: initialized ocserv 1.1.1
> ocserv[19214]: sec-mod: reading supplemental config from files
> ocserv[19214]: sec-mod: sec-mod initialized (socket: 
> ./ocserv-socket.af571984.0)
> Connecting to obtain cookie... Failure: Could not receive cookie from server
> ocserv[19194]: main: termination request received; waiting for children to die
> FAIL auth-username-pass (exit status: 1)
> 
> FAIL: auth-certificate
> ======================
> 
> Testing certificate auth... 
> warning: skipping unknown option 'cookie-validity'
> Parsing plain auth method subconfig using legacy format
> note: vhost:default: setting 'certificate+plain' as primary authentication 
> method
> note: setting 'file' as supplemental config option
> listening (TCP) on [::]:443...
> listening (UDP) on [::]:443...
> ocserv[19199]: main: Starting 1 instances of ocserv-sm
> ocserv[19199]: main: not using control unix socket
> ocserv[19199]: main: initialized ocserv 1.1.1
> ocserv[19215]: sec-mod: reading supplemental config from files
> ocserv[19215]: sec-mod: sec-mod initialized (socket: 
> ./ocserv-socket.bee4d321.0)
> Connecting to obtain cookie (with key user-key-pkcs1.pem)... Failed to 
> connect to host 127.0.0.2
> Failed to open HTTPS connection to 127.0.0.2
> Failed to obtain WebVPN cookie
> Failure: Could not connect with key user-key-pkcs1.pem!
> ocserv[19199]: main: termination request received; waiting for children to die
> FAIL auth-certificate (exit status: 1)
> 
> FAIL: auth-nonascii
> ===================
> 
> Testing certificate auth with non-ASCII passwords... 
> warning: skipping unknown option 'cookie-validity'
> Parsing plain auth method subconfig using legacy format
> note: vhost:default: setting 'certificate+plain' as primary authentication 
> method
> note: setting 'file' as supplemental config option
> listening (TCP) on [::]:443...

Can't reproduce this in a sid chroot + unshare -n + ip link set dev lo up + ip 
addr del 127.0.0.1/8 dev lo

make  check-TESTS
make[3]: Entering directory '/tmp/openconnect-8.10/tests'
make[4]: Entering directory '/tmp/openconnect-8.10/tests'
PASS: autocompletion
PASS: seqtest
PASS: lzstest
PASS: auth-username-pass
PASS: auth-nonascii
PASS: id-test
PASS: auth-pkcs11
PASS: auth-certificate
PASS: cert-fingerprint

#  ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group 
default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever


Anything specific required to reproduce?

-- 
Kind regards,
Luca Boccassi

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to