==> Synchronizing chroot copy [/home/alhp/workspace/chroot/root] -> [build_186cfaaa-0167-4c9a-8e57-f400ee89636f]...done ==> Making package: malcontent 0.14.0-3.1 (Tue Apr 7 21:21:50 2026) ==> Retrieving sources... -> Cloning malcontent git repo... Cloning into bare repository '/home/alhp/workspace/build/x86-64-v2/malcontent-0.14.0-3/malcontent'... -> Cloning gvdb git repo... Cloning into bare repository '/home/alhp/workspace/build/x86-64-v2/malcontent-0.14.0-3/gvdb'... warning: redirecting to https://github.com/GNOME/gvdb.git/ -> Downloading tinycdb-0.81.tar.gz... % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 0 100 31901 100 31901 0 0 72743 0 0 100 31901 100 31901 0 0 72730 0 0 100 31901 100 31901 0 0 72720 0 0 -> Found 0001-meson-Statically-link-against-libgcc.patch ==> Validating source files with b2sums... malcontent ... Passed gvdb ... Skipped tinycdb-0.81.tar.gz ... Passed 0001-meson-Statically-link-against-libgcc.patch ... Passed ==> Making package: malcontent 0.14.0-3.1 (Tue Apr 7 19:22:01 2026) ==> Checking runtime dependencies... ==> Installing missing dependencies... resolving dependencies... looking for conflicting packages... Package (127) New Version Net Change extra/adwaita-cursors 50.0-1 11.41 MiB extra/adwaita-fonts 50.0-1 7.29 MiB extra/adwaita-icon-theme 50.0-1 1.19 MiB extra/adwaita-icon-theme-legacy 46.2-3 2.23 MiB extra/at-spi2-core 2.60.0-1 4.01 MiB extra/avahi 1:0.9rc4-1 2.00 MiB extra/bubblewrap 0.11.1-1 0.09 MiB extra/cairo 1.18.4-1 1.59 MiB extra/composefs 1.0.8-1 0.15 MiB extra/dav1d 1.5.3-1 1.78 MiB extra/dconf 0.49.0-1 0.45 MiB extra/default-cursors 3-1 0.00 MiB extra/desktop-file-utils 0.28-1 0.18 MiB extra/duktape 2.7.0-7 0.78 MiB extra/fontconfig 2:2.17.1-1 1.12 MiB extra/freetype2 2.14.3-1 1.66 MiB extra/fribidi 1.0.16-2 0.24 MiB extra/fuse-common 3.18.2-1 0.00 MiB extra/fuse3 3.18.2-1 0.48 MiB extra/gdk-pixbuf2 2.44.6-1 2.94 MiB extra/giflib 6.1.2-1 0.33 MiB extra/glib-networking 1:2.80.1-1 0.65 MiB extra/glycin 2.1.1-1 17.50 MiB extra/gobject-introspection-runtime 1.86.0-2 0.15 MiB extra/gperftools 2.18.1-1 2.01 MiB extra/graphite 1:1.3.14-6 0.20 MiB extra/gsettings-desktop-schemas 50.0-1 6.08 MiB extra/gsettings-system-schemas 50.0-1 0.02 MiB extra/gssdp 1.6.4-1 0.24 MiB extra/gst-plugins-bad-libs 1.28.1-2 14.50 MiB extra/gst-plugins-base-libs 1.28.1-2 12.66 MiB extra/gstreamer 1.28.1-2 11.76 MiB extra/gtest 1.17.0-2 1.63 MiB extra/gtk-update-icon-cache 1:4.22.2-1 0.04 MiB extra/gupnp 1:1.6.9-1 0.70 MiB extra/gupnp-igd 1.6.0-2 0.11 MiB extra/harfbuzz 14.0.0-2 4.66 MiB extra/highway 1.3.0-2 9.87 MiB extra/iso-codes 4.20.1-1 22.30 MiB extra/jbigkit 2.1-8 0.16 MiB extra/lcms2 2.18-1 0.68 MiB extra/libcloudproviders 0.4.0-1 0.32 MiB extra/libcolord 1.4.8-1 1.24 MiB extra/libcups 2:2.4.16-2 0.77 MiB extra/libdaemon 0.14-6 0.06 MiB extra/libdatrie 0.2.14-1 0.49 MiB extra/libdeflate 1.25-1 0.14 MiB extra/libdrm 2.4.131-1 1.28 MiB core/libedit 20251016_3.1-1 0.26 MiB extra/libepoxy 1.5.10-3 2.64 MiB extra/libfyaml 0.9.6-2 1.27 MiB extra/libgirepository 1.86.0-2 1.52 MiB extra/libglvnd 1.7.0-3 3.34 MiB extra/libgudev 238-3 0.38 MiB extra/libjpeg-turbo 3.1.4.1-1 2.43 MiB extra/libjxl 0.11.2-2 9.65 MiB extra/libmalcontent 0.14.0-3 0.41 MiB extra/libnice 0.1.23-1 1.81 MiB extra/libpciaccess 0.19-1 0.06 MiB extra/libpipewire 1:1.6.2-1 1.98 MiB extra/libpng 1.6.56-1 0.58 MiB extra/libproxy 0.5.12-1 0.10 MiB extra/librsvg 2:2.62.1-1 10.25 MiB extra/libsodium 1.0.21-1 0.60 MiB extra/libstemmer 3.0.1-1 0.60 MiB extra/libthai 0.1.30-1 1.24 MiB extra/libtiff 4.7.1-1 1.26 MiB extra/libunwind 1.8.2-1 0.29 MiB extra/libva 2.23.0-1 0.98 MiB extra/libwebp 1.6.0-2 1.04 MiB extra/libx11 1.8.13-1 9.78 MiB extra/libxau 1.0.12-1 0.02 MiB extra/libxcb 1.17.0-1 3.87 MiB extra/libxcursor 1.2.3-1 0.07 MiB extra/libxdamage 1.1.7-1 0.02 MiB extra/libxdmcp 1.1.5-1 0.13 MiB extra/libxext 1.3.7-1 0.30 MiB extra/libxfixes 6.0.2-1 0.04 MiB extra/libxft 2.3.9-1 0.13 MiB extra/libxi 1.8.2-1 0.48 MiB extra/libxinerama 1.1.6-1 0.02 MiB extra/libxkbcommon 1.13.1-1 1.03 MiB extra/libxkbcommon-x11 1.13.1-1 0.10 MiB extra/libxmlb 0.3.25-1 1.20 MiB extra/libxrandr 1.5.5-1 0.07 MiB extra/libxrender 0.9.12-1 0.09 MiB extra/libxshmfence 1.3.3-1 0.02 MiB extra/libxtst 1.2.5-1 0.11 MiB extra/libxv 1.0.13-1 0.06 MiB extra/libxxf86vm 1.1.7-1 0.03 MiB extra/llvm-libs 22.1.2-1 160.11 MiB extra/lm_sensors 1:3.6.2-1 0.48 MiB core/lzo 2.10-5 0.38 MiB extra/mesa 1:26.0.4-1 50.73 MiB core/mpdecimal 4.0.1-3 0.32 MiB extra/orc 0.4.42-1 1.36 MiB extra/ostree 2025.7-3 4.37 MiB extra/pipewire 1:1.6.2-1 2.94 MiB extra/pixman 0.46.4-1 0.74 MiB extra/rtkit 0.14-1 0.09 MiB extra/shared-mime-info 2.4-3 4.58 MiB extra/spirv-tools 1:1.4.341.0-2 7.59 MiB extra/tinysparql 3.11.0-1 3.88 MiB extra/vmaf 3.1.0-1 6.53 MiB extra/vulkan-icd-loader 1.4.341.0-1 0.58 MiB extra/wayland 1.24.0-1 0.82 MiB extra/xcb-proto 1.17.0-4 1.03 MiB extra/xdg-dbus-proxy 0.1.7-1 0.06 MiB extra/xdg-desktop-portal 1.20.3-2 1.77 MiB extra/xdg-utils 1.2.1-2 0.30 MiB extra/xkeyboard-config 2.47-1 10.23 MiB extra/xorg-xprop 1.2.8-1 0.05 MiB extra/xorgproto 2025.1-1 1.47 MiB extra/accountsservice 26.12.8-1 1.00 MiB extra/appstream 1.1.2-1 17.13 MiB extra/flatpak 1:1.16.3-1 7.45 MiB extra/graphene 1.10.8-2 0.98 MiB extra/gtk4 1:4.22.2-1 51.51 MiB extra/hicolor-icon-theme 0.18-1 0.05 MiB extra/json-glib 1.10.8-1 1.01 MiB extra/libadwaita 1:1.9.0-1 5.14 MiB extra/libgsystemservice 0.3.0-2 0.20 MiB extra/libsoup3 3.6.6-2 1.96 MiB extra/pango 1:1.57.1-1 2.33 MiB extra/polkit 127-3 1.95 MiB core/python 3.14.3-1 72.18 MiB extra/python-gobject 3.56.2-1 1.49 MiB Total Installed Size: 635.18 MiB :: Proceed with installation? [Y/n] checking keyring... checking package integrity... loading package files... checking for file conflicts... :: Processing package changes... installing duktape... installing polkit... installing accountsservice... installing libpng... installing freetype2... Optional dependencies for freetype2 harfbuzz: Improved autohinting [pending] installing fontconfig... Creating fontconfig configuration... Rebuilding fontconfig cache... installing xcb-proto... installing xorgproto... installing libxdmcp... installing libxau... installing libxcb... installing libx11... installing libxext... installing libxrender... installing lzo... installing pixman... installing cairo... installing bubblewrap... installing libjpeg-turbo... Optional dependencies for libjpeg-turbo java-runtime>11: for TurboJPEG Java wrapper installing jbigkit... installing libdeflate... installing libwebp... Optional dependencies for libwebp libwebp-utils: WebP conversion and inspection tools installing libtiff... Optional dependencies for libtiff freeglut: for using tiffgt installing lcms2... installing giflib... installing libunwind... installing gperftools... installing gtest... Optional dependencies for gtest python: gmock generator [pending] installing highway... installing libjxl... Optional dependencies for libjxl java-runtime: for JNI bindings installing dav1d... Optional dependencies for dav1d dav1d-doc: HTML documentation installing graphite... Optional dependencies for graphite graphite-docs: Documentation installing harfbuzz... Optional dependencies for harfbuzz harfbuzz-utils: utilities installing fribidi... installing libdatrie... installing libthai... installing libxft... installing pango... installing librsvg... installing glycin... Optional dependencies for glycin libheif: Load .avif, .heic and .heif installing shared-mime-info... installing gdk-pixbuf2... Optional dependencies for gdk-pixbuf2 libheif: Load .avif, .heic and .heif libopenraw: Load .arw, .cr2, .crw, .dng, .erf, .mrw, .nef, .orf, .pef and .raf libwmf: Load .apm and .wmf installing libfyaml... installing libstemmer... installing libxmlb... installing appstream... installing dconf... installing fuse-common... installing fuse3... installing json-glib... installing libmalcontent... installing composefs... installing libsodium... installing libdaemon... installing avahi... Optional dependencies for avahi gtk3: avahi-discover, avahi-discover-standalone, bshell, bssh, bvnc libevent: libevent bindings [installed] nss-mdns: NSS support for mDNS python-dbus: avahi-bookmarks, avahi-discover python-gobject: avahi-bookmarks, avahi-discover [pending] python-twisted: avahi-bookmarks installing ostree... installing mpdecimal... installing python... Optional dependencies for python python-setuptools: for building Python packages using tooling that is usually bundled with Python python-pip: for installing Python packages using tooling that is usually bundled with Python python-pipx: for installing Python software not packaged on Arch Linux sqlite: for a default database integration [installed] xz: for lzma [installed] tk: for tkinter installing libgirepository... installing gobject-introspection-runtime... installing python-gobject... Optional dependencies for python-gobject python-cairo: Cairo bindings installing default-cursors... Optional dependencies for default-cursors adwaita-cursors: default cursor theme [pending] installing wayland... installing xdg-dbus-proxy... installing xdg-utils... Optional dependencies for xdg-utils kde-cli-tools: for KDE Plasma5 support in xdg-open exo: for Xfce support in xdg-open pcmanfm: for LXDE support in xdg-open perl-file-mimeinfo: for generic support in xdg-open perl-net-dbus: Perl extension to dbus used in xdg-screensaver perl-x11-protocol: Perl X11 protocol used in xdg-screensaver xorg-xset: for X11 support in xdg-screensaver xorg-xprop: for X11 support in xdg-screensaver [pending] installing gstreamer... Optional dependencies for gstreamer python: gst-plugins-doc-cache-generator [installed] installing graphene... installing iso-codes... installing libpciaccess... installing libdrm... Optional dependencies for libdrm cairo: needed for modetest tool [installed] installing libxshmfence... installing libxxf86vm... installing libedit... installing llvm-libs... installing lm_sensors... Optional dependencies for lm_sensors rrdtool: for logging with sensord perl: for sensor detection and configuration convert [installed] installing spirv-tools... installing mesa... Optional dependencies for mesa opengl-man-pages: for the OpenGL API man pages installing libglvnd... installing libgudev... installing libxfixes... installing libxi... installing libxv... installing orc... installing gst-plugins-base-libs... installing libpipewire... installing pipewire... Created symlink '/etc/systemd/user/sockets.target.wants/pipewire.socket' → '/usr/lib/systemd/user/pipewire.socket'. Optional dependencies for pipewire gst-plugin-pipewire: GStreamer plugin pipewire-alsa: ALSA configuration pipewire-audio: Audio support pipewire-docs: Documentation pipewire-ffado: FireWire support pipewire-jack-client: PipeWire as JACK client pipewire-jack: JACK replacement pipewire-libcamera: Libcamera support pipewire-onnx: ONNX filter support pipewire-pulse: PulseAudio replacement pipewire-roc: ROC streaming pipewire-session-manager: Session manager pipewire-v4l2: V4L2 interceptor pipewire-x11-bell: X11 bell pipewire-zeroconf: Zeroconf support realtime-privileges: realtime privileges with rt module rtkit: realtime privileges with rtkit module [pending] installing rtkit... installing xdg-desktop-portal... Optional dependencies for xdg-desktop-portal geoclue: Geolocation portal xdg-desktop-portal-impl: Portal backends installing flatpak... installing adwaita-fonts... installing hicolor-icon-theme... installing adwaita-icon-theme-legacy... installing adwaita-cursors... installing adwaita-icon-theme... installing gsettings-system-schemas... installing gsettings-desktop-schemas... installing libxtst... installing xorg-xprop... installing at-spi2-core... installing desktop-file-utils... installing libproxy... installing glib-networking... installing libsoup3... Optional dependencies for libsoup3 samba: Windows Domain SSO installing gssdp... Optional dependencies for gssdp gtk4: gssdp-device-sniffer [pending] installing gupnp... Optional dependencies for gupnp python: gupnp-binding-tool [installed] installing gupnp-igd... installing libnice... Optional dependencies for libnice gstreamer: "nice" GStreamer plugin [installed] installing libva... Optional dependencies for libva intel-media-driver: backend for Intel GPUs (>= Broadwell) libva-intel-driver: backend for Intel GPUs (<= Haswell) libva-mesa-driver: backend for AMD and NVIDIA GPUs [installed] installing xkeyboard-config... installing libxkbcommon... Optional dependencies for libxkbcommon libxkbcommon-x11: xkbcli interactive-x11 [pending] wayland: xkbcli interactive-wayland [installed] installing libxkbcommon-x11... installing vulkan-icd-loader... Optional dependencies for vulkan-icd-loader vulkan-driver: packaged vulkan driver installing vmaf... installing gst-plugins-bad-libs... installing gtk-update-icon-cache... installing libcloudproviders... installing libcolord... installing libcups... installing libepoxy... installing libxcursor... installing libxdamage... installing libxinerama... installing libxrandr... installing tinysparql... installing gtk4... Optional dependencies for gtk4 evince: Default print preview command xdg-desktop-portal-gtk: Fallback portals for various APIs installing libadwaita... installing libgsystemservice... :: Running post-transaction hooks... ( 1/16) Creating system user accounts... Creating group 'polkitd' with GID 102. Creating group 'avahi' with GID 969. Creating user 'avahi' (Avahi mDNS/DNS-SD daemon) with UID 969 and GID 969. Creating group 'flatpak' with GID 968. Creating user 'flatpak' (Flatpak system helper) with UID 968 and GID 968. Creating user 'polkitd' (User for polkitd) with UID 102 and GID 102. Creating group 'rtkit' with GID 967. Creating user 'rtkit' (RealtimeKit) with UID 967 and GID 967. ( 2/16) Creating temporary files... ( 3/16) Reloading system manager configuration... Skipped: Current root is not booted. ( 4/16) Reloading user manager configuration... Skipped: Current root is not booted. ( 5/16) Updating the MIME type database... ( 6/16) Reloading device manager configuration... Skipped: Current root is not booted. ( 7/16) Arming ConditionNeedsUpdate... ( 8/16) Updating fontconfig configuration... ( 9/16) Updating the appstream cache... ✔ Metadata cache was updated successfully. (10/16) Restarting accounts-daemon... Skipped: Current root is not booted. (11/16) Reloading system bus configuration... Skipped: Current root is not booted. (12/16) Updating fontconfig cache... (13/16) Updating GIO module cache... (14/16) Compiling GSettings XML schema files... (15/16) Updating icon theme caches... (16/16) Updating the desktop file MIME type cache... ==> Checking buildtime dependencies... ==> Installing missing dependencies... resolving dependencies... looking for conflicting packages... Package (71) New Version Net Change extra/aom 3.13.3-1 9.16 MiB extra/docbook-xml 4.5-11 1.96 MiB extra/docbook-xsl 1.79.2-9 26.32 MiB extra/gd 2.3.3-9 0.64 MiB extra/ghostscript 10.07.0-1 43.77 MiB extra/gnome-desktop-common 1:44.5-1 2.45 MiB extra/graphviz 14.1.4-2 10.79 MiB extra/gsfonts 20200910-6 3.11 MiB extra/gts 0.7.6.121130-5 0.67 MiB extra/ijs 0.35-6 0.12 MiB extra/itstool 1:2.0.7-3 0.09 MiB extra/jbig2dec 0.20-1 0.15 MiB extra/l-smash 2.14.5-4 1.02 MiB extra/libavif 1.4.1-1 0.84 MiB extra/libde265 1.0.18-1 0.84 MiB extra/libheif 1.21.2-2 2.29 MiB extra/libice 1.1.2-1 0.36 MiB extra/libidn 1.43-1 0.85 MiB extra/libpaper 2.2.7-1 0.16 MiB extra/libsm 1.2.6-1 0.26 MiB extra/libxpm 3.5.18-1 0.16 MiB extra/libxslt 1.1.45-2 0.78 MiB extra/libxt 1.3.1-1 2.02 MiB extra/libyuv r2426+464c51a03-1 1.82 MiB extra/mallard-ducktype 1.0.2-13 0.62 MiB extra/netpbm 10.86.49-1 6.99 MiB extra/ninja 1.13.2-3 0.41 MiB extra/openh264 2.6.0-2 2.22 MiB extra/openjpeg2 2.5.4-1 13.37 MiB extra/perl-error 0.17030-3 0.04 MiB extra/perl-mailtools 2.22-3 0.10 MiB extra/perl-timedate 2.35-1 0.15 MiB extra/poppler-data 0.4.12-2 12.34 MiB extra/python-autocommand 2.2.2-9 0.08 MiB extra/python-dbus 1.4.0-2 0.62 MiB extra/python-jaraco.collections 5.1.0-3 0.11 MiB extra/python-jaraco.context 6.0.1-3 0.04 MiB extra/python-jaraco.functools 4.1.0-3 0.07 MiB extra/python-jaraco.text 4.0.0-4 0.08 MiB extra/python-jinja 1:3.1.6-3 2.04 MiB extra/python-lxml 6.0.2-2 5.76 MiB extra/python-magic 1:0.4.27-6 0.09 MiB extra/python-mako 1.3.10-4 0.98 MiB extra/python-markdown 3.10.2-1 1.13 MiB extra/python-markupsafe 3.0.3-1 0.09 MiB extra/python-more-itertools 11.0.1-1 0.76 MiB extra/python-pkg_resources 81.0.0-1 0.50 MiB extra/python-platformdirs 4.9.5-1 0.40 MiB extra/python-pygments 2.20.0-1 15.36 MiB extra/python-setuptools 1:82.0.1-1 7.35 MiB extra/python-smartypants 2.0.2-2 0.06 MiB extra/python-tqdm 4.67.3-1 0.62 MiB extra/python-typing_extensions 4.15.0-3 0.52 MiB extra/python-typogrify 2.1.0-2 0.10 MiB extra/python-wheel 0.46.3-1 0.31 MiB extra/rav1e 0.8.1-2 7.61 MiB extra/svt-av1 4.1.0-1 5.24 MiB extra/x264 3:0.165.r3222.b35605a-2 3.79 MiB extra/x265 4.1-1 20.84 MiB extra/yelp-xsl 49.0-1 1.47 MiB extra/zlib-ng 2.3.3-1 0.28 MiB extra/gi-docgen 2026.1-1 2.81 MiB extra/git 2.53.0-1 29.72 MiB core/glib2-devel 2.88.0-1 1.23 MiB extra/gnome-desktop-4 1:44.5-1 0.56 MiB extra/gobject-introspection 1.86.0-2 3.11 MiB extra/libglib-testing 0.2.0-1 0.23 MiB extra/meson 1.10.2-1 16.09 MiB extra/python-dbusmock 0.38.1-1 0.72 MiB extra/python-packaging 26.0-1 0.89 MiB extra/yelp-tools 42.1-2 0.16 MiB Total Installed Size: 278.70 MiB :: Proceed with installation? [Y/n] checking keyring... checking package integrity... loading package files... checking for file conflicts... :: Processing package changes... installing perl-error... installing perl-timedate... installing perl-mailtools... installing zlib-ng... installing git... Optional dependencies for git git-zsh-completion: upstream zsh completion tk: gitk and git gui openssh: ssh transport and crypto man: show help with `git command --help` perl-libwww: git svn perl-term-readkey: git svn and interactive.singlekey setting perl-io-socket-ssl: git send-email TLS support perl-authen-sasl: git send-email TLS support perl-cgi: gitweb (web interface) support python: git svn & git p4 [installed] subversion: git svn org.freedesktop.secrets: keyring credential helper libsecret: libsecret credential helper [installed] less: the default pager for git installing libice... installing libsm... installing libxt... installing libxpm... installing aom... installing libyuv... installing rav1e... installing svt-av1... installing libavif... installing libde265... Optional dependencies for libde265 sdl2-compat: for the decoder tool installing openh264... installing l-smash... installing x264... installing x265... installing libheif... Optional dependencies for libheif libjpeg-turbo: for heif-dec and heif-enc [installed] libpng: for heif-dec and heif-enc [installed] libtiff: for heif-dec and heif-enc [installed] dav1d: dav1d encoder [installed] ffmpeg: hardware decode openjpeg2: JPEG2000 decoder [pending] rav1e: rav1e encoder [installed] svt-av1: svt-av1 encoder [installed] installing gd... Optional dependencies for gd perl: bdftogd script [installed] installing jbig2dec... installing libpaper... installing ijs... installing openjpeg2... installing libidn... installing poppler-data... installing ghostscript... Optional dependencies for ghostscript gtk3: needed for gsx installing netpbm... installing gts... installing gsfonts... installing graphviz... Optional dependencies for graphviz mono: sharp bindings guile: guile bindings [installed] lua: lua bindings perl: perl bindings [installed] python: python bindings [installed] r: r bindings tcl: tcl bindings qt6-base: gvedit xterm: vimdot installing python-markupsafe... installing python-jinja... Optional dependencies for python-jinja python-babel: for i18n support installing python-magic... installing python-markdown... Optional dependencies for python-markdown python-yaml: parse Python in YAML metadata python-pygments: Code highlighting [pending] installing python-packaging... installing python-pygments... installing python-smartypants... installing python-typogrify... installing gi-docgen... installing glib2-devel... installing gnome-desktop-common... installing gnome-desktop-4... installing python-mako... Optional dependencies for python-mako python-babel: for i18n features python-beaker: for caching support python-dogpile.cache: for caching support python-pygments: for syntax highlighting [installed] python-pytest: for testing utilities installing python-more-itertools... installing python-jaraco.functools... installing python-jaraco.context... installing python-autocommand... installing python-jaraco.text... Optional dependencies for python-jaraco.text python-inflect: for show-newlines script installing python-jaraco.collections... installing python-platformdirs... installing python-wheel... Optional dependencies for python-wheel python-keyring: for wheel.signatures python-xdg: for wheel.signatures python-setuptools: for legacy bdist_wheel subcommand [pending] installing python-typing_extensions... installing python-pkg_resources... installing python-setuptools... installing gobject-introspection... installing libglib-testing... installing ninja... installing python-tqdm... Optional dependencies for python-tqdm python-requests: telegram installing meson... installing yelp-xsl... installing libxslt... Optional dependencies for libxslt python: Python bindings [installed] installing python-lxml... Optional dependencies for python-lxml python-beautifulsoup4: support for beautifulsoup parser to parse not well formed HTML python-cssselect: support for cssselect python-html5lib: support for html5lib parser python-lxml-docs: offline docs python-lxml-html-clean: enable htmlclean feature installing docbook-xml... installing itstool... installing docbook-xsl... installing mallard-ducktype... installing yelp-tools... installing python-dbus... Optional dependencies for python-dbus python-gobject: D-Bus services via PyGI [installed] installing python-dbusmock... :: Running post-transaction hooks... (1/7) Creating system user accounts... Creating group 'git' with GID 966. Creating user 'git' (git daemon user) with UID 966 and GID 966. (2/7) Reloading system manager configuration... Skipped: Current root is not booted. (3/7) Arming ConditionNeedsUpdate... (4/7) Updating fontconfig configuration... (5/7) Checking for old perl modules... (6/7) Updating fontconfig cache... (7/7) Updating the info directory file... ==> Retrieving sources... -> Found tinycdb-0.81.tar.gz -> Found 0001-meson-Statically-link-against-libgcc.patch ==> WARNING: Skipping all source file integrity checks. ==> Extracting sources... -> Creating working copy of malcontent git repo... Cloning into 'malcontent'... done. Switched to a new branch 'makepkg' -> Creating working copy of gvdb git repo... Cloning into 'gvdb'... done. -> Extracting tinycdb-0.81.tar.gz with bsdtar ==> Starting prepare()... Applied patch to 'nss/meson.build' cleanly. Submodule 'subprojects/gvdb' (https://gitlab.gnome.org/GNOME/gvdb.git) registered for path 'subprojects/gvdb' Synchronizing submodule url for 'subprojects/gvdb' Cloning into '/startdir/src/malcontent/subprojects/gvdb'... warning: --depth is ignored in local clones; use file:// instead. done. Submodule path 'subprojects/gvdb': checked out '466fc22016cf0981424e7121557611942191992f' ==> Starting build()... + exec meson setup --prefix /usr --libexecdir lib --sbindir bin --buildtype plain --auto-features enabled --wrap-mode nodownload -D b_pie=true -D python.bytecompile=1 malcontent build The Meson build system Version: 1.10.2 Source dir: /startdir/src/malcontent Build dir: /startdir/src/build Build type: native build Project name: malcontent Project version: 0.14.0 C compiler for the host machine: cc (gcc 15.2.1 "cc (GCC) 15.2.1 20260209") C linker for the host machine: cc ld.bfd 2.46 Host machine cpu family: x86_64 Host machine cpu: x86_64 Program python3 found: YES (/usr/bin/python) Found pkg-config: YES (/usr/bin/pkg-config) 2.5.1 Run-time dependency accountsservice found: YES 26.12.0 Run-time dependency dbus-1 found: YES 1.16.2 Run-time dependency polkit-gobject-1 found: YES 127 Program bash found: YES (/usr/bin/bash) Configuring config.h using configuration Compiler for C supports arguments -fno-strict-aliasing: YES Compiler for C supports arguments -fstack-protector-strong: YES Compiler for C supports arguments -Wunused: YES Compiler for C supports arguments -Warray-bounds: YES Compiler for C supports arguments -Wcast-align: YES Compiler for C supports arguments -Wclobbered: YES Compiler for C supports arguments -Wno-declaration-after-statement: YES Compiler for C supports arguments -Wdiscarded-qualifiers: YES Compiler for C supports arguments -Wduplicated-branches: YES Compiler for C supports arguments -Wduplicated-cond: YES Compiler for C supports arguments -Wempty-body: YES Compiler for C supports arguments -Wformat=2: YES Compiler for C supports arguments -Wformat-nonliteral: YES Compiler for C supports arguments -Wformat-security: YES Compiler for C supports arguments -Wformat-signedness: YES Compiler for C supports arguments -Wignored-qualifiers: YES Compiler for C supports arguments -Wimplicit-function-declaration: YES Compiler for C supports arguments -Wincompatible-pointer-types: YES Compiler for C supports arguments -Wincompatible-pointer-types-discards-qualifiers: NO Compiler for C supports arguments -Winit-self: YES Compiler for C supports arguments -Wint-conversion: YES Compiler for C supports arguments -Wlogical-op: YES Compiler for C supports arguments -Wmisleading-indentation: YES Compiler for C supports arguments -Wmissing-declarations: YES Compiler for C supports arguments -Wmissing-format-attribute: YES Compiler for C supports arguments -Wmissing-include-dirs: YES Compiler for C supports arguments -Wmissing-noreturn: YES Compiler for C supports arguments -Wmissing-parameter-type: YES Compiler for C supports arguments -Wmissing-prototypes: YES Compiler for C supports arguments -Wnested-externs: YES Compiler for C supports arguments -Wno-error=cpp: YES Compiler for C supports arguments -Wmissing-field-initializers: YES Compiler for C supports arguments -Wno-suggest-attribute=format: YES Compiler for C supports arguments -Wno-unused-parameter: YES Compiler for C supports arguments -Wnull-dereference: YES Compiler for C supports arguments -Wold-style-definition: YES Compiler for C supports arguments -Woverflow: YES Compiler for C supports arguments -Woverride-init: YES Compiler for C supports arguments -Wparentheses: YES Compiler for C supports arguments -Wpointer-arith: YES Compiler for C supports arguments -Wredundant-decls: YES Compiler for C supports arguments -Wreturn-type: YES Compiler for C supports arguments -Wshadow: YES Compiler for C supports arguments -Wsign-compare: YES Compiler for C supports arguments -Wno-error=strict-aliasing: YES Compiler for C supports arguments -Wstrict-prototypes: YES Compiler for C supports arguments -Wswitch-default: YES Compiler for C supports arguments -Wswitch-enum: YES Compiler for C supports arguments -Wtype-limits: YES Compiler for C supports arguments -Wundef: YES Compiler for C supports arguments -Wuninitialized: YES Compiler for C supports arguments -Wunused-but-set-variable: YES Compiler for C supports arguments -Wunused-result: YES Compiler for C supports arguments -Wunused-variable: YES Compiler for C supports arguments -Wwrite-strings: YES Build-time dependency gi-docgen found: YES 2026.1 Program gi-docgen found: YES (/usr/bin/gi-docgen) Run-time dependency gsystemservice-0 found: YES 0.3.0 Executing subproject gvdb gvdb| Project name: gvdb gvdb| Project version: 0.0 gvdb| C compiler for the host machine: cc (gcc 15.2.1 "cc (GCC) 15.2.1 20260209") gvdb| C linker for the host machine: cc ld.bfd 2.46 gvdb| Build targets in project: 0 gvdb| Subproject gvdb finished. Dependency gvdb found: YES 0.0 (overridden) Executing subproject tinycdb tinycdb| Project name: tinycdb tinycdb| Project version: 0.81 tinycdb| C compiler for the host machine: cc (gcc 15.2.1 "cc (GCC) 15.2.1 20260209") tinycdb| C linker for the host machine: cc ld.bfd 2.46 tinycdb| Build targets in project: 1 tinycdb| Subproject tinycdb finished. Configuring untranslated-com.endlessm.ParentalControls.policy using configuration Program msgfmt found: YES (/usr/bin/msgfmt) Configuring com.endlessm.ParentalControls.rules using configuration Program xmllint found: YES (/usr/bin/xmllint) Program itstool found: YES (/usr/bin/itstool) Program msgmerge found: YES (/usr/bin/msgmerge) Program msgfmt found: YES (/usr/bin/msgfmt) Run-time dependency gio-2.0 found: YES 2.88.0 Run-time dependency glib-2.0 found: YES 2.88.0 Run-time dependency gobject-2.0 found: YES 2.88.0 Dependency accountsservice found: YES 26.12.0 (cached) Run-time dependency gio-unix-2.0 found: YES 2.88.0 Dependency glib-2.0 found: YES 2.88.0 (cached) Program /usr/bin/glib-mkenums found: YES (/usr/bin/glib-mkenums) Dependency glib-2.0 found: YES 2.88.0 (cached) Program /usr/bin/glib-mkenums found: YES (/usr/bin/glib-mkenums) Found pkg-config: YES (/usr/bin/pkg-config) 2.5.1 Run-time dependency gobject-introspection-1.0 found: YES 1.86.0 Dependency gobject-introspection-1.0 found: YES 1.86.0 (cached) Program /usr/bin/g-ir-scanner found: YES (/usr/bin/g-ir-scanner) Dependency gobject-introspection-1.0 found: YES 1.86.0 (cached) Program /usr/bin/g-ir-compiler found: YES (/usr/bin/g-ir-compiler) Configuring libmalcontent.toml using configuration Dependency gio-2.0 found: YES 2.88.0 (cached) Dependency gio-unix-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Dependency gobject-2.0 found: YES 2.88.0 (cached) Run-time dependency glib-testing-0 found: YES 0.2.0 Program gdbus-codegen found: YES (/usr/bin/gdbus-codegen) Configuring app-filter.test using configuration Configuring session-limits.test using configuration Configuring web-filter.test using configuration Run-time dependency gtk4 found: YES 4.22.2 Run-time dependency libadwaita-1 found: YES 1.9.0 Checking for function "atexit" : YES Dependency gio-2.0 found: YES 2.88.0 (cached) Program /usr/bin/glib-compile-resources found: YES (/usr/bin/glib-compile-resources) Dependency accountsservice found: YES 26.12.0 (cached) Dependency gio-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Dependency gobject-2.0 found: YES 2.88.0 (cached) Run-time dependency appstream found: YES 1.1.2 Run-time dependency flatpak found: YES 1.16.3 Program xmllint found: YES (/usr/bin/xmllint) Configuring libmalcontent-ui.toml using configuration Program gdbus-codegen found: YES (/usr/bin/gdbus-codegen) Dependency gio-2.0 found: YES 2.88.0 (cached) Dependency gio-unix-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Dependency gobject-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Program /usr/bin/glib-mkenums found: YES (/usr/bin/glib-mkenums) Dependency glib-2.0 found: YES 2.88.0 (cached) Program /usr/bin/glib-mkenums found: YES (/usr/bin/glib-mkenums) Program xmllint found: YES (/usr/bin/xmllint) Dependency gio-2.0 found: YES 2.88.0 (cached) Dependency gio-unix-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Dependency gobject-2.0 found: YES 2.88.0 (cached) Dependency glib-testing-0 found: YES 0.2.0 (cached) Program gdbus-codegen found: YES (/usr/bin/gdbus-codegen) Configuring extension-agent-polkit.test using configuration Configuring timer-store.test using configuration Program gdbus-codegen found: YES (/usr/bin/gdbus-codegen) Dependency libcdb from subproject subprojects/tinycdb-0.81 found: YES 0.81 Dependency gio-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Dependency gobject-2.0 found: YES 2.88.0 (cached) Run-time dependency libsoup-3.0 found: YES 3.6.6 Dependency glib-2.0 found: YES 2.88.0 (cached) Program /usr/bin/glib-mkenums found: YES (/usr/bin/glib-mkenums) Dependency glib-2.0 found: YES 2.88.0 (cached) Program /usr/bin/glib-mkenums found: YES (/usr/bin/glib-mkenums) Program xmllint found: YES (/usr/bin/xmllint) Dependency gio-2.0 found: YES 2.88.0 (cached) Dependency gio-unix-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Dependency gobject-2.0 found: YES 2.88.0 (cached) Dependency glib-testing-0 found: YES 0.2.0 (cached) Configuring filter-list.test using configuration Checking for function "atexit" : YES (cached) Dependency gio-2.0 found: YES 2.88.0 (cached) Program /usr/bin/glib-compile-resources found: YES (/usr/bin/glib-compile-resources) Dependency glib-2.0 found: YES 2.88.0 (cached) Program /usr/bin/glib-mkenums found: YES (/usr/bin/glib-mkenums) Dependency glib-2.0 found: YES 2.88.0 (cached) Program /usr/bin/glib-mkenums found: YES (/usr/bin/glib-mkenums) Dependency accountsservice found: YES 26.12.0 (cached) Dependency gio-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Dependency gobject-2.0 found: YES 2.88.0 (cached) Dependency polkit-gobject-1 found: YES 127 (cached) Run-time dependency gnome-desktop-4 found: YES 44.5 Run-time dependency json-glib-1.0 found: YES 1.10.8 Configuring org.freedesktop.MalcontentControl.service using configuration Program desktop-file-validate found: YES (/usr/bin/desktop-file-validate) Program appstreamcli found: YES (/usr/bin/appstreamcli) Program xmllint found: YES (/usr/bin/xmllint) Program gtk4-update-icon-cache found: YES (/usr/bin/gtk4-update-icon-cache) Program update-desktop-database found: YES (/usr/bin/update-desktop-database) Dependency gio-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Dependency gobject-2.0 found: YES 2.88.0 (cached) Configuring org.freedesktop.MalcontentTimer1.conf using configuration Configuring org.freedesktop.MalcontentTimer1.service using configuration Run-time dependency systemd found: YES 260 Configuring malcontent-timerd.conf using configuration Dependency systemd found: YES 260 (cached) Configuring malcontent-timerd.service using configuration Program python3 found: YES (/usr/bin/python) Configuring malcontent-timerd.py.test using configuration Configuring systemd-analyze.py.test using configuration Dependency gio-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Dependency gobject-2.0 found: YES 2.88.0 (cached) Dependency polkit-gobject-1 found: YES 127 (cached) Configuring org.freedesktop.MalcontentTimer1.ExtensionAgent.conf using configuration Configuring org.freedesktop.MalcontentTimer1.ExtensionAgent.service using configuration Dependency systemd found: YES 260 (cached) Configuring malcontent-timer-extension-agent.conf using configuration Dependency systemd found: YES 260 (cached) Configuring malcontent-timer-extension-agent.service using configuration Program python3 found: YES (/usr/bin/python) Configuring malcontent-timer-extension-agent.py.test using configuration Configuring systemd-analyze.py.test using configuration Dependency gio-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Dependency gobject-2.0 found: YES 2.88.0 (cached) Configuring org.freedesktop.MalcontentWeb1.conf using configuration Configuring org.freedesktop.MalcontentWeb1.service using configuration Dependency systemd found: YES 260 (cached) Configuring malcontent-webd.conf using configuration Dependency systemd found: YES 260 (cached) Configuring malcontent-webd.service using configuration Program python3 found: YES (/usr/bin/python) Configuring malcontent-webd.py.test using configuration Configuring systemd-analyze.py.test using configuration Dependency gio-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Dependency gobject-2.0 found: YES 2.88.0 (cached) Dependency systemd found: YES 260 (cached) Configuring malcontent-webd-update.service using configuration Dependency systemd found: YES 260 (cached) Program python3 found: YES (/usr/bin/python) Configuring malcontent-webd-update.py.test using configuration Configuring systemd-analyze.py.test using configuration Dependency libcdb from subproject subprojects/tinycdb-0.81 found: YES 0.81 Compiler for C supports link arguments -static-libgcc: YES Program python3 found: YES (/usr/bin/python) Dependency gio-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Dependency libcdb found: YES 0.81 (cached) Configuring nss-malcontent.test using configuration Configuring nss-objdump.py.test using configuration Library pam found: YES Library pam_misc found: YES Dependency gio-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Dependency gobject-2.0 found: YES 2.88.0 (cached) Dependency glib-2.0 found: YES 2.88.0 (cached) Library dl found: YES Configuring pam_malcontent.test using configuration Program msginit found: YES (/usr/bin/msginit) Program msgmerge found: YES (/usr/bin/msgmerge) Program xgettext found: YES (/usr/bin/xgettext) Build targets in project: 157 malcontent 0.14.0 Subprojects gvdb : YES tinycdb : YES User defined options auto_features : enabled b_pie : true buildtype : plain libexecdir : lib prefix : /usr python.bytecompile: 1 sbindir : bin wrap_mode : nodownload Found ninja-1.13.2 at /usr/bin/ninja Generating targets: 0%| | 0/157 eta ? Writing build.ninja: 0%| | 0/293 eta ? ninja: Entering directory `/startdir/src/build' [1/229] Generating libmalcontent-timer/properties-iface.c with a custom command [2/229] Generating libmalcontent-timer/child-iface.h with a custom command [3/229] Generating libmalcontent-timer/child-iface.c with a custom command [4/229] Generating libmalcontent-timer/parent-iface.h with a custom command [5/229] Generating libmalcontent-timer/parent-iface.c with a custom command [6/229] Generating libmalcontent-timer/extension-agent-iface.h with a custom command [7/229] Generating libmalcontent-timer/extension-agent-iface.c with a custom command [8/229] Generating libmalcontent-timer/extension-agent-request-iface.c with a custom command [9/229] Generating GObject enum file libmalcontent/enums.h (wrapped by meson because command contains newlines, to capture output) [10/229] Generating libmalcontent-ui/resources_h with a custom command [11/229] Generating libmalcontent-timer/extension-agent-request-iface.h with a custom command [12/229] Generating libmalcontent-web/filtering-iface.h with a custom command [13/229] Compiling C object subprojects/tinycdb-0.81/libcdb.a.p/cdb_find.c.o [14/229] Generating libmalcontent-ui/resources_c with a custom command [15/229] Generating libmalcontent-timer/properties-iface.h with a custom command [16/229] Generating libmalcontent-web/filtering-iface.c with a custom command [17/229] Compiling C object subprojects/tinycdb-0.81/libcdb.a.p/cdb_findnext.c.o [18/229] Compiling C object subprojects/tinycdb-0.81/libcdb.a.p/cdb_pack.c.o [19/229] Compiling C object subprojects/tinycdb-0.81/libcdb.a.p/cdb_unpack.c.o [20/229] Compiling C object subprojects/tinycdb-0.81/libcdb.a.p/cdb_hash.c.o [21/229] Generating GObject enum file libmalcontent/enums.c (wrapped by meson because command contains newlines, to capture output) [22/229] Compiling C object subprojects/tinycdb-0.81/libcdb.a.p/cdb_seq.c.o [23/229] Generating libmalcontent/tests/accounts-service-iface.c with a custom command [24/229] Generating libmalcontent/tests/accounts-service-extension-iface.h with a custom command [25/229] Generating GObject enum file libmalcontent-timer/enums.h (wrapped by meson because command contains newlines, to capture output) [26/229] Compiling C object subprojects/tinycdb-0.81/libcdb.a.p/cdb_seek.c.o [27/229] Compiling C object subprojects/tinycdb-0.81/libcdb.a.p/cdb_make_add.c.o [28/229] Generating libmalcontent/tests/accounts-service-iface.h with a custom command [29/229] Generating GObject enum file libmalcontent-web/enums.c (wrapped by meson because command contains newlines, to capture output) [30/229] Generating GObject enum file libmalcontent-timer/enums.c (wrapped by meson because command contains newlines, to capture output) [31/229] Generating GObject enum file libmalcontent-web/enums.h (wrapped by meson because command contains newlines, to capture output) [32/229] Compiling C object subprojects/tinycdb-0.81/libcdb.a.p/cdb_make.c.o [33/229] Generating libmalcontent-timer/tests/polkit-authority-iface.c with a custom command [34/229] Generating libmalcontent/tests/accounts-service-extension-iface.c with a custom command [35/229] Generating libmalcontent-timer/tests/polkit-authority-iface.h with a custom command [36/229] Generating malcontent-control/resources_c with a custom command [37/229] Compiling C object subprojects/tinycdb-0.81/libcdb.a.p/cdb_make_put.c.o [38/229] Compiling C object subprojects/tinycdb-0.81/libcdb.a.p/cdb_init.c.o [39/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/time-span.c.o [40/229] Compiling C object libmalcontent/libmalcontent-0.so.0.14.0.p/init.c.o [41/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/.._subprojects_gvdb_gvdb_gvdb-reader.c.o [42/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/meson-generated_.._properties-iface.c.o [43/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/meson-generated_.._child-iface.c.o [44/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/meson-generated_.._extension-agent-request-iface.c.o [45/229] Compiling C object libmalcontent/libmalcontent-0.so.0.14.0.p/meson-generated_.._enums.c.o [46/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/meson-generated_.._extension-agent-iface.c.o [47/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/meson-generated_.._enums.c.o [48/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/meson-generated_.._parent-iface.c.o [49/229] Compiling C object libmalcontent-ui/libmalcontent-ui-1.so.0.14.0.p/meson-generated_.._resources.c.o [50/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/extension-agent-object-polkit.c.o [51/229] Compiling C object libmalcontent/libmalcontent-0.so.0.14.0.p/user.c.o [52/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/.._subprojects_gvdb_gvdb_gvdb-builder.c.o [53/229] Compiling C object libmalcontent-web/libmalcontent-web-1.a.p/filter-list.c.o [54/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/timer-service.c.o [55/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/timer-store.c.o [56/229] Compiling C object libmalcontent/libmalcontent-0.so.0.14.0.p/app-filter.c.o [57/229] Compiling C object libmalcontent/libmalcontent-0.so.0.14.0.p/manager.c.o [58/229] Compiling C object libmalcontent/libmalcontent-0.so.0.14.0.p/user-manager.c.o [59/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/extension-agent-object.c.o [60/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/extension-agent-service.c.o [61/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/parent-timer-service.c.o [62/229] Compiling C object libmalcontent-web/libmalcontent-web-1.a.p/meson-generated_.._filtering-iface.c.o [63/229] Generating malcontent-control/resources_h with a custom command [64/229] Generating GObject enum file malcontent-control/cc-timelike-editor-enums.c (wrapped by meson because command contains newlines, to capture output) [65/229] Linking static target subprojects/tinycdb-0.81/libcdb.a [66/229] Generating yelp doc help/bg/help-malcontent-bg-gmo [67/229] Generating yelp doc help/da/help-malcontent-da-gmo [68/229] Generating yelp doc help/de/help-malcontent-de-gmo [69/229] Generating yelp doc help/es/help-malcontent-es-gmo [70/229] Compiling C object libmalcontent/libmalcontent-0.so.0.14.0.p/session-limits.c.o [71/229] Compiling C object libmalcontent/libmalcontent-0.so.0.14.0.p/web-filter.c.o [72/229] Compiling C object libmalcontent-web/libmalcontent-web-1.a.p/meson-generated_.._enums.c.o [73/229] Compiling C object libmalcontent-web/libmalcontent-web-1.a.p/filtering-dbus-service.c.o [74/229] Compiling C object libmalcontent-web/libmalcontent-web-1.a.p/web-service.c.o [75/229] Generating GObject enum file malcontent-control/cc-timelike-editor-enums.h (wrapped by meson because command contains newlines, to capture output) [76/229] Generating yelp doc help/hu/help-malcontent-hu-gmo [77/229] Generating yelp doc help/id/help-malcontent-id-gmo [78/229] Generating yelp doc help/it/help-malcontent-it-gmo [79/229] Generating yelp doc help/pl/help-malcontent-pl-gmo [80/229] Generating yelp doc help/pt_BR/help-malcontent-pt_BR-gmo [81/229] Generating yelp doc help/ru/help-malcontent-ru-gmo [82/229] Generating yelp doc help/sv/help-malcontent-sv-gmo [83/229] Generating yelp doc help/tr/help-malcontent-tr-gmo [84/229] Generating yelp doc help/uk/help-malcontent-uk-gmo [85/229] Compiling C object libmalcontent-timer/libmalcontent-timer-1.a.p/child-timer-service.c.o [86/229] Compiling C object libmalcontent-web/libmalcontent-web-1.a.p/filter-updater.c.o [87/229] Linking static target libmalcontent-web/libmalcontent-web-1.a [88/229] Linking static target libmalcontent-timer/libmalcontent-timer-1.a [89/229] Compiling C object libmalcontent-timer/tests/extension-agent-polkit.p/meson-generated_.._polkit-authority-iface.c.o [90/229] Compiling C object libmalcontent/tests/web-filter.p/meson-generated_.._accounts-service-iface.c.o [91/229] Compiling C object libmalcontent/tests/session-limits.p/meson-generated_.._accounts-service-extension-iface.c.o [92/229] Compiling C object libmalcontent-ui/libmalcontent-ui-1.so.0.14.0.p/restrict-applications-selector.c.o [93/229] Compiling C object libmalcontent/tests/app-filter.p/meson-generated_.._accounts-service-iface.c.o [94/229] Compiling C object libmalcontent/tests/web-filter.p/meson-generated_.._accounts-service-extension-iface.c.o [95/229] Compiling C object libmalcontent/tests/web-filter.p/web-filter.c.o [96/229] Compiling C object libmalcontent/tests/session-limits.p/meson-generated_.._accounts-service-iface.c.o [97/229] Compiling C object libmalcontent-timer/tests/timer-store.p/timer-store.c.o [98/229] Compiling C object libmalcontent/tests/app-filter.p/meson-generated_.._accounts-service-extension-iface.c.o [99/229] Compiling C object libmalcontent-web/tests/filter-list.p/filter-list.c.o [100/229] Compiling C object malcontent-control/malcontent-control.p/meson-generated_.._resources.c.o [101/229] Compiling C object libmalcontent-timer/tests/extension-agent-polkit.p/extension-agent-polkit.c.o [102/229] Compiling C object libmalcontent-ui/libmalcontent-ui-1.so.0.14.0.p/restrict-applications-dialog.c.o [103/229] Compiling C object libmalcontent-ui/libmalcontent-ui-1.so.0.14.0.p/user-controls.c.o [104/229] Compiling C object malcontent-timerd/malcontent-timerd.p/main.c.o [105/229] Compiling C object libmalcontent/tests/session-limits.p/session-limits.c.o [106/229] Compiling C object malcontent-control/malcontent-control.p/cc-duration-editor.c.o [107/229] Compiling C object malcontent-control/malcontent-control.p/access-page.c.o [108/229] Compiling C object libmalcontent/tests/app-filter.p/app-filter.c.o [109/229] Compiling C object malcontent-control/malcontent-control.p/cc-bar-chart-group.c.o [110/229] Compiling C object malcontent-control/malcontent-control.p/cc-bar-chart-bar.c.o [111/229] Compiling C object malcontent-control/malcontent-control.p/cc-duration-row.c.o [112/229] Compiling C object malcontent-control/malcontent-control.p/cc-screen-time-statistics-row.c.o [113/229] Compiling C object malcontent-control/malcontent-control.p/cc-time-row.c.o [114/229] Compiling C object malcontent-control/malcontent-control.p/cc-timelike-editor.c.o [115/229] Compiling C object malcontent-control/malcontent-control.p/main.c.o [116/229] Compiling C object malcontent-control/malcontent-control.p/user-selector.c.o [117/229] Compiling C object malcontent-timer-extension-agent/malcontent-timer-extension-agent.p/main.c.o [118/229] Compiling C object malcontent-webd/malcontent-webd.p/main.c.o [119/229] Compiling C object malcontent-webd-update/malcontent-webd-update.p/main.c.o [120/229] Compiling C object malcontent-control/malcontent-control.p/meson-generated_.._cc-timelike-editor-enums.c.o [121/229] Compiling C object malcontent-control/malcontent-control.p/application.c.o [122/229] Compiling C object malcontent-control/malcontent-control.p/cc-bar-chart.c.o [123/229] Compiling C object malcontent-control/malcontent-control.p/cc-time-editor.c.o [124/229] Compiling C object malcontent-control/malcontent-control.p/cc-timelike-editor-layout.c.o [125/229] Compiling C object malcontent-control/malcontent-control.p/cc-timelike-entry.c.o [126/229] Compiling C object malcontent-control/malcontent-control.p/screen-time-statistics-row.c.o [127/229] Compiling C object malcontent-control/malcontent-control.p/time-page.c.o [128/229] Compiling C object malcontent-control/malcontent-control.p/user-image.c.o [129/229] Compiling C object malcontent-control/malcontent-control.p/user-page.c.o [130/229] Compiling C object nss/libnss_malcontent.so.0.14.0.p/nss-malcontent.c.o [131/229] Compiling C object nss/tests/libnss_hardcoded.so.0.14.0.p/nss-hardcoded.c.o [132/229] Compiling C object pam/tests/pam_malcontent.p/pam_malcontent.c.o [133/229] Compiling C object nss/tests/nss-malcontent.p/nss-malcontent.c.o [134/229] Compiling C object pam/pam_malcontent.so.p/pam_malcontent.c.o [135/229] Merging translations for accounts-service/com.endlessm.ParentalControls.policy [136/229] Generating yelp doc help/bg/help-malcontent-bg [137/229] Generating yelp doc help/da/help-malcontent-da [138/229] Generating yelp doc help/de/help-malcontent-de [139/229] Generating yelp doc help/es/help-malcontent-es [140/229] Generating yelp doc help/hu/help-malcontent-hu [141/229] Generating yelp doc help/id/help-malcontent-id [142/229] Generating yelp doc help/it/help-malcontent-it [143/229] Generating yelp doc help/pl/help-malcontent-pl [144/229] Generating yelp doc help/ru/help-malcontent-ru [145/229] Generating yelp doc help/sv/help-malcontent-sv [146/229] Building translation po/af/LC_MESSAGES/malcontent-af.mo [147/229] Building translation po/ar/LC_MESSAGES/malcontent-ar.mo [148/229] Generating yelp doc help/pt_BR/help-malcontent-pt_BR [149/229] Generating yelp doc help/tr/help-malcontent-tr [150/229] Generating yelp doc help/uk/help-malcontent-uk [151/229] Merging translations for malcontent-control/org.freedesktop.MalcontentControl.desktop [152/229] Merging translations for malcontent-control/org.freedesktop.MalcontentControl.metainfo.xml [153/229] Merging translations for malcontent-control/org.freedesktop.MalcontentControl.policy [154/229] Linking target malcontent-webd-update/malcontent-webd-update [155/229] Linking target nss/libnss_malcontent.so.0.14.0 [156/229] Linking target nss/tests/libnss_hardcoded.so.0.14.0 [157/229] Linking target pam/tests/pam_malcontent [158/229] Building translation po/bg/LC_MESSAGES/malcontent-bg.mo [159/229] Building translation po/bn/LC_MESSAGES/malcontent-bn.mo [160/229] Building translation po/ca/LC_MESSAGES/malcontent-ca.mo [161/229] Building translation po/ca@valencia/LC_MESSAGES/malcontent-ca@valencia.mo [162/229] Building translation po/cs/LC_MESSAGES/malcontent-cs.mo [163/229] Building translation po/da/LC_MESSAGES/malcontent-da.mo [164/229] Building translation po/de/LC_MESSAGES/malcontent-de.mo [165/229] Building translation po/el/LC_MESSAGES/malcontent-el.mo [166/229] Building translation po/eo/LC_MESSAGES/malcontent-eo.mo [167/229] Building translation po/es/LC_MESSAGES/malcontent-es.mo [168/229] Building translation po/eu/LC_MESSAGES/malcontent-eu.mo [169/229] Building translation po/fa/LC_MESSAGES/malcontent-fa.mo [170/229] Building translation po/fi/LC_MESSAGES/malcontent-fi.mo [171/229] Building translation po/fr/LC_MESSAGES/malcontent-fr.mo [172/229] Building translation po/fur/LC_MESSAGES/malcontent-fur.mo [173/229] Building translation po/gd/LC_MESSAGES/malcontent-gd.mo [174/229] Building translation po/gl/LC_MESSAGES/malcontent-gl.mo [175/229] Building translation po/he/LC_MESSAGES/malcontent-he.mo [176/229] Building translation po/hi/LC_MESSAGES/malcontent-hi.mo [177/229] Building translation po/hr/LC_MESSAGES/malcontent-hr.mo [178/229] Building translation po/hu/LC_MESSAGES/malcontent-hu.mo [179/229] Building translation po/id/LC_MESSAGES/malcontent-id.mo [180/229] Building translation po/it/LC_MESSAGES/malcontent-it.mo [181/229] Building translation po/ka/LC_MESSAGES/malcontent-ka.mo [182/229] Building translation po/kk/LC_MESSAGES/malcontent-kk.mo [183/229] Building translation po/ko/LC_MESSAGES/malcontent-ko.mo [184/229] Building translation po/lt/LC_MESSAGES/malcontent-lt.mo [185/229] Building translation po/lv/LC_MESSAGES/malcontent-lv.mo [186/229] Building translation po/ml/LC_MESSAGES/malcontent-ml.mo [187/229] Building translation po/ms/LC_MESSAGES/malcontent-ms.mo [188/229] Building translation po/nb/LC_MESSAGES/malcontent-nb.mo [189/229] Building translation po/nl/LC_MESSAGES/malcontent-nl.mo [190/229] Building translation po/oc/LC_MESSAGES/malcontent-oc.mo [191/229] Building translation po/pa/LC_MESSAGES/malcontent-pa.mo [192/229] Building translation po/pl/LC_MESSAGES/malcontent-pl.mo [193/229] Building translation po/pt/LC_MESSAGES/malcontent-pt.mo [194/229] Building translation po/pt_BR/LC_MESSAGES/malcontent-pt_BR.mo [195/229] Building translation po/ro/LC_MESSAGES/malcontent-ro.mo [196/229] Building translation po/sk/LC_MESSAGES/malcontent-sk.mo [197/229] Building translation po/sr/LC_MESSAGES/malcontent-sr.mo [198/229] Building translation po/ru/LC_MESSAGES/malcontent-ru.mo [199/229] Building translation po/sl/LC_MESSAGES/malcontent-sl.mo [200/229] Building translation po/sr@latin/LC_MESSAGES/malcontent-sr@latin.mo [201/229] Building translation po/th/LC_MESSAGES/malcontent-th.mo [202/229] Building translation po/uk/LC_MESSAGES/malcontent-uk.mo [203/229] Building translation po/sv/LC_MESSAGES/malcontent-sv.mo [204/229] Building translation po/vi/LC_MESSAGES/malcontent-vi.mo [205/229] Building translation po/tr/LC_MESSAGES/malcontent-tr.mo [206/229] Building translation po/zh_TW/LC_MESSAGES/malcontent-zh_TW.mo [207/229] Building translation po/zh_CN/LC_MESSAGES/malcontent-zh_CN.mo [208/229] Linking target nss/tests/nss-malcontent [209/229] Linking target libmalcontent/libmalcontent-0.so.0.14.0 [210/229] Generating symbol file libmalcontent/libmalcontent-0.so.0.14.0.p/libmalcontent-0.so.0.14.0.symbols [211/229] Linking target pam/pam_malcontent.so [212/229] Linking target libmalcontent-web/tests/filter-list [213/229] Linking target libmalcontent/tests/web-filter [214/229] Linking target libmalcontent-timer/tests/timer-store [215/229] Linking target malcontent-timer-extension-agent/malcontent-timer-extension-agent [216/229] Linking target libmalcontent/tests/app-filter [217/229] Linking target libmalcontent-ui/libmalcontent-ui-1.so.0.14.0 [218/229] Generating symbol file libmalcontent-ui/libmalcontent-ui-1.so.0.14.0.p/libmalcontent-ui-1.so.0.14.0.symbols [219/229] Linking target libmalcontent/tests/session-limits [220/229] Linking target libmalcontent-timer/tests/extension-agent-polkit [221/229] Linking target malcontent-webd/malcontent-webd [222/229] Generating libmalcontent/Malcontent-0.gir with a custom command (wrapped by meson to set env) ../malcontent/libmalcontent/manager.c:202: Warning: Malcontent: unexpected annotation: not ../malcontent/libmalcontent/user.c:198: Warning: Malcontent: unexpected annotation: nullable ../malcontent/libmalcontent/user.c:216: Warning: Malcontent: unexpected annotation: not ../malcontent/libmalcontent/user.c:248: Warning: Malcontent: unexpected annotation: nullable ../malcontent/libmalcontent/user.c:281: Warning: Malcontent: unexpected annotation: nullable ../malcontent/libmalcontent/user-manager.c:170: Warning: Malcontent: unexpected annotation: not :: Warning: Malcontent: (ErrorQuarkFunction)app_filter_error_quark: mct_app_filter_error_quark: Couldn't find corresponding enumeration [223/229] Linking target malcontent-timerd/malcontent-timerd [224/229] Generating libmalcontent/Malcontent-0.typelib with a custom command [225/229] Linking target malcontent-control/malcontent-control [226/229] Generating libmalcontent-ui/MalcontentUi-1.gir with a custom command (wrapped by meson to set env) ../malcontent/libmalcontent-ui/restrict-applications-dialog.c:180: Warning: MalcontentUi: unexpected annotation: not ../malcontent/libmalcontent-ui/restrict-applications-dialog.c:199: Warning: MalcontentUi: unexpected annotation: nullable ../malcontent/libmalcontent-ui/restrict-applications-selector.c:222: Warning: MalcontentUi: unexpected annotation: not ../malcontent/libmalcontent-ui/restrict-applications-selector.c:240: Warning: MalcontentUi: unexpected annotation: nullable ../malcontent/libmalcontent-ui/user-controls.c:852: Warning: MalcontentUi: unexpected annotation: nullable ../malcontent/libmalcontent-ui/user-controls.c:867: Warning: MalcontentUi: unexpected annotation: nullable ../malcontent/libmalcontent-ui/user-controls.c:883: Warning: MalcontentUi: unexpected annotation: nullable ../malcontent/libmalcontent-ui/user-controls.c:919: Warning: MalcontentUi: unexpected annotation: nullable ../malcontent/libmalcontent-ui/user-controls.c:942: Warning: MalcontentUi: unexpected annotation: nullable ../malcontent/libmalcontent-ui/user-controls.c:961: Warning: MalcontentUi: unexpected annotation: nullable ../malcontent/libmalcontent-ui/user-controls.c:978: Warning: MalcontentUi: unexpected annotation: not [227/229] Generating libmalcontent-ui/MalcontentUi-1.typelib with a custom command [228/229] Generating libmalcontent/docs/libmalcontent-docs with a custom command [229/229] Generating libmalcontent-ui/docs/libmalcontent-ui-docs with a custom command INFO: autodetecting backend as ninja INFO: calculating backend command to run: /usr/bin/ninja -C /startdir/src/build ==> Starting check()... ninja: Entering directory `/startdir/src/build' ninja: no work to do. 1/27 accounts-service - malcontent:validate-dbus-api OK 0.20s 2/27 libmalcontent - malcontent:web-filter OK 0.18s 3/27 libmalcontent-timer - malcontent:validate-dbus-api OK 0.16s 4/27 libmalcontent-timer - malcontent:timer-store OK 0.14s 5/27 libmalcontent-web - malcontent:validate-dbus-api OK 0.14s 6/27 libmalcontent-web - malcontent:filter-list OK 0.13s 7/27 malcontent-control - malcontent:validate-desktop OK 0.13s 8/27 malcontent-control - malcontent:validate-metainfo OK 0.12s 9/27 malcontent-control - malcontent:validate-policy OK 0.10s 10/27 libmalcontent-ui - malcontent:validate-ui OK 0.21s 11/27 malcontent-control - malcontent:validate-ui OK 0.14s 12/27 nss - malcontent:nss-malcontent OK 0.04s 13/27 pam - malcontent:pam_malcontent OK 0.02s 14/27 malcontent-timerd - malcontent:systemd-analyze.py FAIL 0.15s exit status 1 >>> MALLOC_CHECK_=2 MSAN_OPTIONS=halt_on_error=1:abort_on_error=1:print_summary=1:print_stacktrace=1 G_TEST_BUILDDIR=/startdir/src/build/malcontent-timerd/tests MALLOC_PERTURB_=253 MESON_TEST_ITERATION=1 G_TEST_SRCDIR=/startdir/src/malcontent/malcontent-timerd/tests G_ENABLE_DIAGNOSTIC=1 LC_ALL=C.UTF-8 PYTHONPATH=/startdir/src/build/tests/lib:/startdir/src/malcontent/tests/lib G_DEBUG=gc-friendly,fatal-warnings ASAN_OPTIONS=halt_on_error=1:abort_on_error=1:print_summary=1 UBSAN_OPTIONS=halt_on_error=1:abort_on_error=1:print_summary=1:print_stacktrace=1 /usr/bin/python -B /startdir/src/build/../malcontent/malcontent-timerd/tests/systemd-analyze.py ――――――――――――――――――――――――――――――――――――― ✀ ――――――――――――――――――――――――――――――――――――― TAP version 13 not ok 1 __main__.TestSystemdAnalyze.test_security_score --- message: | Traceback (most recent call last): File "/startdir/src/malcontent/tests/lib/systemdanalyze.py", line 85, in test_security_score self.assertIn(self.expectedMessage, out) ~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^ AssertionError: 'SAFE 😀' not found in "NAME DESCRIPTION EXPOSURE\n✓ SystemCallFilter=~@swap System call allow list defined for service, and @swap is not included \n✓ SystemCallFilter=~@resources System call allow list defined for service, and @resources is not included \n✓ SystemCallFilter=~@reboot System call allow list defined for service, and @reboot is not included \n✓ SystemCallFilter=~@raw-io System call allow list defined for service, and @raw-io is not included \n✓ SystemCallFilter=~@privileged System call allow list defined for service, and @privileged is not included \n✓ SystemCallFilter=~@obsolete System call allow list defined for service, and @obsolete is not included \n✓ SystemCallFilter=~@mount System call allow list defined for service, and @mount is not included \n✓ SystemCallFilter=~@module System call allow list defined for service, and @module is not included \n✓ SystemCallFilter=~@debug System call allow list defined for service, and @debug is not included \n✓ SystemCallFilter=~@cpu-emulation System call allow list defined for service, and @cpu-emulation is not included \n✓ SystemCallFilter=~@clock System call allow list defined for service, and @clock is not included \n✓ RemoveIPC= Service user cannot leave SysV IPC objects around \n✗ RootDirectory=/RootImage= Service runs within the host's root directory 0.1\n✓ User=/DynamicUser= Service runs under a static non-root user identity \n✓ RestrictRealtime= Service realtime scheduling access is restricted \n✓ CapabilityBoundingSet=~CAP_SYS_TIME Service processes cannot change the system clock \n✓ NoNewPrivileges= Service processes cannot acquire new privileges \n✓ AmbientCapabilities= Service process does not receive ambient capabilities \n✓ CapabilityBoundingSet=~CAP_BPF Service may not load BPF programs \n✓ SystemCallArchitectures= Service may execute system calls only with native ABI \n✗ RestrictAddressFamilies=~AF_UNIX Service may allocate local sockets 0.1\n✓ ProtectSystem= Service has strict read-only access to the OS file hierarchy \n✓ ProtectProc= Service has restricted access to process tree (/proc hidepid=) \n✓ SupplementaryGroups= Service has no supplementary groups \n✓ CapabilityBoundingSet=~CAP_SYS_RAWIO Service has no raw I/O access \n✓ CapabilityBoundingSet=~CAP_SYS_PTRACE Service has no ptrace() debugging abilities \n✓ CapabilityBoundingSet=~CAP_SYS_(NICE|RESOURCE) Service has no privileges to change resource use parameters \n✓ CapabilityBoundingSet=~CAP_NET_ADMIN Service has no network configuration privileges \n✓ CapabilityBoundingSet=~CAP_NET_(BIND_SERVICE|BROADCAST|RAW) Service has no elevated networking privileges \n✓ CapabilityBoundingSet=~CAP_AUDIT_* Service has no audit subsystem access \n✓ CapabilityBoundingSet=~CAP_SYS_ADMIN Service has no administrator privileges \n✓ PrivateNetwork= Service has no access to the host's network \n✓ PrivateTmp= Service has no access to other software's temporary files \n✓ ProcSubset= Service has no access to non-process /proc files (/proc subset=) \n✓ CapabilityBoundingSet=~CAP_SYSLOG Service has no access to kernel logging \n✓ ProtectHome= Service has no access to home directories \n✓ PrivateDevices= Service has no access to hardware devices \n✗ DeviceAllow= Service has a device ACL with some special devices: char-rtc:r 0.1\n✓ KeyringMode= Service doesn't share key material with other services \n✓ Delegate= Service does not maintain its own delegated control group subtree \n✓ PrivateUsers= Service does not have access to other users \n✓ NotifyAccess= Service child processes cannot alter service state \n✓ ProtectClock= Service cannot write to the hardware clock or system clock \n✓ CapabilityBoundingSet=~CAP_SYS_PACCT Service cannot use acct() \n✓ CapabilityBoundingSet=~CAP_KILL Service cannot send UNIX signals to arbitrary processes \n✓ ProtectKernelLogs= Service cannot read from or write to the kernel log ring buffer \n✓ CapabilityBoundingSet=~CAP_WAKE_ALARM Service cannot program timers that wake up the system \n✓ CapabilityBoundingSet=~CAP_(DAC_*|FOWNER|IPC_OWNER) Service cannot override UNIX file/IPC permission checks \n✓ ProtectControlGroups= Service cannot modify the control group file system \n✓ CapabilityBoundingSet=~CAP_LINUX_IMMUTABLE Service cannot mark files immutable \n✓ CapabilityBoundingSet=~CAP_IPC_LOCK Service cannot lock memory into RAM \n✓ ProtectKernelModules= Service cannot load or read kernel modules \n✓ CapabilityBoundingSet=~CAP_SYS_MODULE Service cannot load kernel modules \n✓ CapabilityBoundingSet=~CAP_SYS_TTY_CONFIG Service cannot issue vhangup() \n✓ CapabilityBoundingSet=~CAP_SYS_BOOT Service cannot issue reboot() \n✓ CapabilityBoundingSet=~CAP_SYS_CHROOT Service cannot issue chroot() \n✓ PrivateMounts= Service cannot install system mounts \n✓ CapabilityBoundingSet=~CAP_BLOCK_SUSPEND Service cannot establish wake locks \n✓ MemoryDenyWriteExecute= Service cannot create writable executable memory mappings \n✓ RestrictNamespaces=~user Service cannot create user namespaces \n✓ RestrictNamespaces=~pid Service cannot create process namespaces \n✓ RestrictNamespaces=~net Service cannot create network namespaces \n✓ RestrictNamespaces=~uts Service cannot create hostname namespaces \n✓ RestrictNamespaces=~mnt Service cannot create file system namespaces \n✓ CapabilityBoundingSet=~CAP_LEASE Service cannot create file leases \n✓ CapabilityBoundingSet=~CAP_MKNOD Service cannot create device nodes \n✓ RestrictNamespaces=~cgroup Service cannot create cgroup namespaces \n✓ RestrictNamespaces=~ipc Service cannot create IPC namespaces \n✓ ProtectHostname= Service cannot change system host/domainname \n✓ CapabilityBoundingSet=~CAP_(CHOWN|FSETID|SETFCAP) Service cannot change file ownership/access mode/capabilities \n✓ CapabilityBoundingSet=~CAP_SET(UID|GID|PCAP) Service cannot change UID/GID identities/capabilities \n✓ LockPersonality= Service cannot change ABI personality \n✓ ProtectKernelTunables= Service cannot alter kernel tunables (/proc/sys, …) \n✓ RestrictAddressFamilies=~AF_PACKET Service cannot allocate packet sockets \n✓ RestrictAddressFamilies=~AF_NETLINK Service cannot allocate netlink sockets \n✓ RestrictAddressFamilies=~… Service cannot allocate exotic sockets \n✓ RestrictAddressFamilies=~AF_(INET|INET6) Service cannot allocate Internet sockets \n✓ CapabilityBoundingSet=~CAP_MAC_* Service cannot adjust SMACK MAC \n✓ IPAddressDeny= Service blocks all IP address ranges \n✓ RestrictSUIDSGID= SUID/SGID file creation by service is restricted \n✓ UMask= Files created by service are accessible only by service's own user by default \n\n→ Overall exposure level for malcontent-timerd.service: 0.2 SAFE :-}" ... 1..1 ―――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――― 15/27 malcontent-webd - malcontent:systemd-analyze.py FAIL 0.15s exit status 1 >>> MALLOC_CHECK_=2 MSAN_OPTIONS=halt_on_error=1:abort_on_error=1:print_summary=1:print_stacktrace=1 MALLOC_PERTURB_=203 G_TEST_SRCDIR=/startdir/src/malcontent/malcontent-webd/tests MESON_TEST_ITERATION=1 G_ENABLE_DIAGNOSTIC=1 LC_ALL=C.UTF-8 PYTHONPATH=/startdir/src/build/tests/lib:/startdir/src/malcontent/tests/lib G_DEBUG=gc-friendly,fatal-warnings ASAN_OPTIONS=halt_on_error=1:abort_on_error=1:print_summary=1 G_TEST_BUILDDIR=/startdir/src/build/malcontent-webd/tests UBSAN_OPTIONS=halt_on_error=1:abort_on_error=1:print_summary=1:print_stacktrace=1 /usr/bin/python -B /startdir/src/build/../malcontent/malcontent-webd/tests/systemd-analyze.py ――――――――――――――――――――――――――――――――――――― ✀ ――――――――――――――――――――――――――――――――――――― TAP version 13 not ok 1 __main__.TestSystemdAnalyze.test_security_score --- message: | Traceback (most recent call last): File "/startdir/src/malcontent/tests/lib/systemdanalyze.py", line 85, in test_security_score self.assertIn(self.expectedMessage, out) ~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^ AssertionError: 'OK 🙂' not found in "NAME DESCRIPTION EXPOSURE\n✓ SystemCallFilter=~@swap System call allow list defined for service, and @swap is not included \n✓ SystemCallFilter=~@resources System call allow list defined for service, and @resources is not included \n✓ SystemCallFilter=~@reboot System call allow list defined for service, and @reboot is not included \n✓ SystemCallFilter=~@raw-io System call allow list defined for service, and @raw-io is not included \n✓ SystemCallFilter=~@privileged System call allow list defined for service, and @privileged is not included \n✓ SystemCallFilter=~@obsolete System call allow list defined for service, and @obsolete is not included \n✓ SystemCallFilter=~@mount System call allow list defined for service, and @mount is not included \n✓ SystemCallFilter=~@module System call allow list defined for service, and @module is not included \n✓ SystemCallFilter=~@debug System call allow list defined for service, and @debug is not included \n✓ SystemCallFilter=~@cpu-emulation System call allow list defined for service, and @cpu-emulation is not included \n✓ SystemCallFilter=~@clock System call allow list defined for service, and @clock is not included \n✓ RemoveIPC= Service user cannot leave SysV IPC objects around \n✗ RootDirectory=/RootImage= Service runs within the host's root directory 0.1\n✓ User=/DynamicUser= Service runs under a static non-root user identity \n✓ RestrictRealtime= Service realtime scheduling access is restricted \n✓ CapabilityBoundingSet=~CAP_SYS_TIME Service processes cannot change the system clock \n✓ NoNewPrivileges= Service processes cannot acquire new privileges \n✓ AmbientCapabilities= Service process does not receive ambient capabilities \n✓ CapabilityBoundingSet=~CAP_BPF Service may not load BPF programs \n✓ SystemCallArchitectures= Service may execute system calls only with native ABI \n✗ RestrictAddressFamilies=~AF_UNIX Service may allocate local sockets 0.1\n✗ RestrictAddressFamilies=~AF_(INET|INET6) Service may allocate Internet sockets 0.3\n✓ ProtectSystem= Service has strict read-only access to the OS file hierarchy \n✓ ProtectProc= Service has restricted access to process tree (/proc hidepid=) \n✓ SupplementaryGroups= Service has no supplementary groups \n✓ CapabilityBoundingSet=~CAP_SYS_RAWIO Service has no raw I/O access \n✓ CapabilityBoundingSet=~CAP_SYS_PTRACE Service has no ptrace() debugging abilities \n✓ CapabilityBoundingSet=~CAP_SYS_(NICE|RESOURCE) Service has no privileges to change resource use parameters \n✓ CapabilityBoundingSet=~CAP_NET_ADMIN Service has no network configuration privileges \n✓ CapabilityBoundingSet=~CAP_NET_(BIND_SERVICE|BROADCAST|RAW) Service has no elevated networking privileges \n✓ CapabilityBoundingSet=~CAP_AUDIT_* Service has no audit subsystem access \n✓ CapabilityBoundingSet=~CAP_SYS_ADMIN Service has no administrator privileges \n✓ PrivateTmp= Service has no access to other software's temporary files \n✓ ProcSubset= Service has no access to non-process /proc files (/proc subset=) \n✓ CapabilityBoundingSet=~CAP_SYSLOG Service has no access to kernel logging \n✓ ProtectHome= Service has no access to home directories \n✓ PrivateDevices= Service has no access to hardware devices \n✗ PrivateNetwork= Service has access to the host's network 0.5\n✗ DeviceAllow= Service has a device ACL with some special devices: char-rtc:r 0.1\n✓ KeyringMode= Service doesn't share key material with other services \n✓ Delegate= Service does not maintain its own delegated control group subtree \n✓ PrivateUsers= Service does not have access to other users \n✗ IPAddressDeny= Service does not define an IP address allow list 0.2\n✓ NotifyAccess= Service child processes cannot alter service state \n✓ ProtectClock= Service cannot write to the hardware clock or system clock \n✓ CapabilityBoundingSet=~CAP_SYS_PACCT Service cannot use acct() \n✓ CapabilityBoundingSet=~CAP_KILL Service cannot send UNIX signals to arbitrary processes \n✓ ProtectKernelLogs= Service cannot read from or write to the kernel log ring buffer \n✓ CapabilityBoundingSet=~CAP_WAKE_ALARM Service cannot program timers that wake up the system \n✓ CapabilityBoundingSet=~CAP_(DAC_*|FOWNER|IPC_OWNER) Service cannot override UNIX file/IPC permission checks \n✓ ProtectControlGroups= Service cannot modify the control group file system \n✓ CapabilityBoundingSet=~CAP_LINUX_IMMUTABLE Service cannot mark files immutable \n✓ CapabilityBoundingSet=~CAP_IPC_LOCK Service cannot lock memory into RAM \n✓ ProtectKernelModules= Service cannot load or read kernel modules \n✓ CapabilityBoundingSet=~CAP_SYS_MODULE Service cannot load kernel modules \n✓ CapabilityBoundingSet=~CAP_SYS_TTY_CONFIG Service cannot issue vhangup() \n✓ CapabilityBoundingSet=~CAP_SYS_BOOT Service cannot issue reboot() \n✓ CapabilityBoundingSet=~CAP_SYS_CHROOT Service cannot issue chroot() \n✓ PrivateMounts= Service cannot install system mounts \n✓ CapabilityBoundingSet=~CAP_BLOCK_SUSPEND Service cannot establish wake locks \n✓ MemoryDenyWriteExecute= Service cannot create writable executable memory mappings \n✓ RestrictNamespaces=~user Service cannot create user namespaces \n✓ RestrictNamespaces=~pid Service cannot create process namespaces \n✓ RestrictNamespaces=~net Service cannot create network namespaces \n✓ RestrictNamespaces=~uts Service cannot create hostname namespaces \n✓ RestrictNamespaces=~mnt Service cannot create file system namespaces \n✓ CapabilityBoundingSet=~CAP_LEASE Service cannot create file leases \n✓ CapabilityBoundingSet=~CAP_MKNOD Service cannot create device nodes \n✓ RestrictNamespaces=~cgroup Service cannot create cgroup namespaces \n✓ RestrictNamespaces=~ipc Service cannot create IPC namespaces \n✓ ProtectHostname= Service cannot change system host/domainname \n✓ CapabilityBoundingSet=~CAP_(CHOWN|FSETID|SETFCAP) Service cannot change file ownership/access mode/capabilities \n✓ CapabilityBoundingSet=~CAP_SET(UID|GID|PCAP) Service cannot change UID/GID identities/capabilities \n✓ LockPersonality= Service cannot change ABI personality \n✓ ProtectKernelTunables= Service cannot alter kernel tunables (/proc/sys, …) \n✓ RestrictAddressFamilies=~AF_PACKET Service cannot allocate packet sockets \n✓ RestrictAddressFamilies=~AF_NETLINK Service cannot allocate netlink sockets \n✓ RestrictAddressFamilies=~… Service cannot allocate exotic sockets \n✓ CapabilityBoundingSet=~CAP_MAC_* Service cannot adjust SMACK MAC \n✓ RestrictSUIDSGID= SUID/SGID file creation by service is restricted \n✗ UMask= Files created by service are world-readable by default 0.1\n\n→ Overall exposure level for malcontent-webd.service: 1.1 OK :-)" ... 1..1 ―――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――― 16/27 malcontent-webd-update - malcontent:systemd-analyze.py FAIL 0.13s exit status 1 >>> MALLOC_CHECK_=2 MSAN_OPTIONS=halt_on_error=1:abort_on_error=1:print_summary=1:print_stacktrace=1 G_TEST_BUILDDIR=/startdir/src/build/malcontent-webd-update/tests MALLOC_PERTURB_=123 MESON_TEST_ITERATION=1 G_ENABLE_DIAGNOSTIC=1 LC_ALL=C.UTF-8 PYTHONPATH=/startdir/src/build/tests/lib:/startdir/src/malcontent/tests/lib G_DEBUG=gc-friendly,fatal-warnings ASAN_OPTIONS=halt_on_error=1:abort_on_error=1:print_summary=1 G_TEST_SRCDIR=/startdir/src/malcontent/malcontent-webd-update/tests UBSAN_OPTIONS=halt_on_error=1:abort_on_error=1:print_summary=1:print_stacktrace=1 /usr/bin/python -B /startdir/src/build/../malcontent/malcontent-webd-update/tests/systemd-analyze.py ――――――――――――――――――――――――――――――――――――― ✀ ――――――――――――――――――――――――――――――――――――― TAP version 13 not ok 1 __main__.TestSystemdAnalyze.test_security_score --- message: | Traceback (most recent call last): File "/startdir/src/malcontent/tests/lib/systemdanalyze.py", line 85, in test_security_score self.assertIn(self.expectedMessage, out) ~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^ AssertionError: 'SAFE 😀' not found in "NAME DESCRIPTION EXPOSURE\n✓ SystemCallFilter=~@swap System call allow list defined for service, and @swap is not included \n✓ SystemCallFilter=~@resources System call allow list defined for service, and @resources is not included \n✓ SystemCallFilter=~@reboot System call allow list defined for service, and @reboot is not included \n✓ SystemCallFilter=~@raw-io System call allow list defined for service, and @raw-io is not included \n✓ SystemCallFilter=~@privileged System call allow list defined for service, and @privileged is not included \n✓ SystemCallFilter=~@obsolete System call allow list defined for service, and @obsolete is not included \n✓ SystemCallFilter=~@mount System call allow list defined for service, and @mount is not included \n✓ SystemCallFilter=~@module System call allow list defined for service, and @module is not included \n✓ SystemCallFilter=~@debug System call allow list defined for service, and @debug is not included \n✓ SystemCallFilter=~@cpu-emulation System call allow list defined for service, and @cpu-emulation is not included \n✓ SystemCallFilter=~@clock System call allow list defined for service, and @clock is not included \n✓ RemoveIPC= Service user cannot leave SysV IPC objects around \n✗ RootDirectory=/RootImage= Service runs within the host's root directory 0.1\n✓ User=/DynamicUser= Service runs under a static non-root user identity \n✓ RestrictRealtime= Service realtime scheduling access is restricted \n✓ CapabilityBoundingSet=~CAP_SYS_TIME Service processes cannot change the system clock \n✓ NoNewPrivileges= Service processes cannot acquire new privileges \n✓ AmbientCapabilities= Service process does not receive ambient capabilities \n✓ CapabilityBoundingSet=~CAP_BPF Service may not load BPF programs \n✓ SystemCallArchitectures= Service may execute system calls only with native ABI \n✗ RestrictAddressFamilies=~AF_UNIX Service may allocate local sockets 0.1\n✓ ProtectSystem= Service has strict read-only access to the OS file hierarchy \n✓ ProtectProc= Service has restricted access to process tree (/proc hidepid=) \n✓ SupplementaryGroups= Service has no supplementary groups \n✓ CapabilityBoundingSet=~CAP_SYS_RAWIO Service has no raw I/O access \n✓ CapabilityBoundingSet=~CAP_SYS_PTRACE Service has no ptrace() debugging abilities \n✓ CapabilityBoundingSet=~CAP_SYS_(NICE|RESOURCE) Service has no privileges to change resource use parameters \n✓ CapabilityBoundingSet=~CAP_NET_ADMIN Service has no network configuration privileges \n✓ CapabilityBoundingSet=~CAP_NET_(BIND_SERVICE|BROADCAST|RAW) Service has no elevated networking privileges \n✓ CapabilityBoundingSet=~CAP_AUDIT_* Service has no audit subsystem access \n✓ CapabilityBoundingSet=~CAP_SYS_ADMIN Service has no administrator privileges \n✓ PrivateNetwork= Service has no access to the host's network \n✓ PrivateTmp= Service has no access to other software's temporary files \n✓ ProcSubset= Service has no access to non-process /proc files (/proc subset=) \n✓ CapabilityBoundingSet=~CAP_SYSLOG Service has no access to kernel logging \n✓ ProtectHome= Service has no access to home directories \n✓ PrivateDevices= Service has no access to hardware devices \n✗ DeviceAllow= Service has a device ACL with some special devices: char-rtc:r 0.1\n✓ KeyringMode= Service doesn't share key material with other services \n✓ Delegate= Service does not maintain its own delegated control group subtree \n✓ PrivateUsers= Service does not have access to other users \n✓ NotifyAccess= Service child processes cannot alter service state \n✓ ProtectClock= Service cannot write to the hardware clock or system clock \n✓ CapabilityBoundingSet=~CAP_SYS_PACCT Service cannot use acct() \n✓ CapabilityBoundingSet=~CAP_KILL Service cannot send UNIX signals to arbitrary processes \n✓ ProtectKernelLogs= Service cannot read from or write to the kernel log ring buffer \n✓ CapabilityBoundingSet=~CAP_WAKE_ALARM Service cannot program timers that wake up the system \n✓ CapabilityBoundingSet=~CAP_(DAC_*|FOWNER|IPC_OWNER) Service cannot override UNIX file/IPC permission checks \n✓ ProtectControlGroups= Service cannot modify the control group file system \n✓ CapabilityBoundingSet=~CAP_LINUX_IMMUTABLE Service cannot mark files immutable \n✓ CapabilityBoundingSet=~CAP_IPC_LOCK Service cannot lock memory into RAM \n✓ ProtectKernelModules= Service cannot load or read kernel modules \n✓ CapabilityBoundingSet=~CAP_SYS_MODULE Service cannot load kernel modules \n✓ CapabilityBoundingSet=~CAP_SYS_TTY_CONFIG Service cannot issue vhangup() \n✓ CapabilityBoundingSet=~CAP_SYS_BOOT Service cannot issue reboot() \n✓ CapabilityBoundingSet=~CAP_SYS_CHROOT Service cannot issue chroot() \n✓ PrivateMounts= Service cannot install system mounts \n✓ CapabilityBoundingSet=~CAP_BLOCK_SUSPEND Service cannot establish wake locks \n✓ MemoryDenyWriteExecute= Service cannot create writable executable memory mappings \n✓ RestrictNamespaces=~user Service cannot create user namespaces \n✓ RestrictNamespaces=~pid Service cannot create process namespaces \n✓ RestrictNamespaces=~net Service cannot create network namespaces \n✓ RestrictNamespaces=~uts Service cannot create hostname namespaces \n✓ RestrictNamespaces=~mnt Service cannot create file system namespaces \n✓ CapabilityBoundingSet=~CAP_LEASE Service cannot create file leases \n✓ CapabilityBoundingSet=~CAP_MKNOD Service cannot create device nodes \n✓ RestrictNamespaces=~cgroup Service cannot create cgroup namespaces \n✓ RestrictNamespaces=~ipc Service cannot create IPC namespaces \n✓ ProtectHostname= Service cannot change system host/domainname \n✓ CapabilityBoundingSet=~CAP_(CHOWN|FSETID|SETFCAP) Service cannot change file ownership/access mode/capabilities \n✓ CapabilityBoundingSet=~CAP_SET(UID|GID|PCAP) Service cannot change UID/GID identities/capabilities \n✓ LockPersonality= Service cannot change ABI personality \n✓ ProtectKernelTunables= Service cannot alter kernel tunables (/proc/sys, …) \n✓ RestrictAddressFamilies=~AF_PACKET Service cannot allocate packet sockets \n✓ RestrictAddressFamilies=~AF_NETLINK Service cannot allocate netlink sockets \n✓ RestrictAddressFamilies=~… Service cannot allocate exotic sockets \n✓ RestrictAddressFamilies=~AF_(INET|INET6) Service cannot allocate Internet sockets \n✓ CapabilityBoundingSet=~CAP_MAC_* Service cannot adjust SMACK MAC \n✓ IPAddressDeny= Service blocks all IP address ranges \n✓ RestrictSUIDSGID= SUID/SGID file creation by service is restricted \n✗ UMask= Files created by service are world-readable by default 0.1\n\n→ Overall exposure level for malcontent-webd-update.service: 0.2 SAFE :-}" ... 1..1 ―――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――― 17/27 malcontent-timer-extension-agent - malcontent:systemd-analyze.py FAIL 0.17s exit status 1 >>> MALLOC_CHECK_=2 MSAN_OPTIONS=halt_on_error=1:abort_on_error=1:print_summary=1:print_stacktrace=1 MESON_TEST_ITERATION=1 G_TEST_SRCDIR=/startdir/src/malcontent/malcontent-timer-extension-agent/tests MALLOC_PERTURB_=1 LC_ALL=C.UTF-8 PYTHONPATH=/startdir/src/build/tests/lib:/startdir/src/malcontent/tests/lib G_DEBUG=gc-friendly,fatal-warnings ASAN_OPTIONS=halt_on_error=1:abort_on_error=1:print_summary=1 G_ENABLE_DIAGNOSTIC=1 UBSAN_OPTIONS=halt_on_error=1:abort_on_error=1:print_summary=1:print_stacktrace=1 G_TEST_BUILDDIR=/startdir/src/build/malcontent-timer-extension-agent/tests /usr/bin/python -B /startdir/src/build/../malcontent/malcontent-timer-extension-agent/tests/systemd-analyze.py ――――――――――――――――――――――――――――――――――――― ✀ ――――――――――――――――――――――――――――――――――――― TAP version 13 not ok 1 __main__.TestSystemdAnalyze.test_security_score --- message: | Traceback (most recent call last): File "/startdir/src/malcontent/tests/lib/systemdanalyze.py", line 85, in test_security_score self.assertIn(self.expectedMessage, out) ~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^ AssertionError: 'SAFE 😀' not found in "NAME DESCRIPTION EXPOSURE\n✓ SystemCallFilter=~@swap System call allow list defined for service, and @swap is not included \n✓ SystemCallFilter=~@resources System call allow list defined for service, and @resources is not included \n✓ SystemCallFilter=~@reboot System call allow list defined for service, and @reboot is not included \n✓ SystemCallFilter=~@raw-io System call allow list defined for service, and @raw-io is not included \n✓ SystemCallFilter=~@privileged System call allow list defined for service, and @privileged is not included \n✓ SystemCallFilter=~@obsolete System call allow list defined for service, and @obsolete is not included \n✓ SystemCallFilter=~@mount System call allow list defined for service, and @mount is not included \n✓ SystemCallFilter=~@module System call allow list defined for service, and @module is not included \n✓ SystemCallFilter=~@debug System call allow list defined for service, and @debug is not included \n✓ SystemCallFilter=~@cpu-emulation System call allow list defined for service, and @cpu-emulation is not included \n✓ SystemCallFilter=~@clock System call allow list defined for service, and @clock is not included \n✓ RemoveIPC= Service user cannot leave SysV IPC objects around \n✗ RootDirectory=/RootImage= Service runs within the host's root directory 0.1\n✓ User=/DynamicUser= Service runs under a static non-root user identity \n✓ RestrictRealtime= Service realtime scheduling access is restricted \n✓ CapabilityBoundingSet=~CAP_SYS_TIME Service processes cannot change the system clock \n✓ NoNewPrivileges= Service processes cannot acquire new privileges \n✓ AmbientCapabilities= Service process does not receive ambient capabilities \n✓ CapabilityBoundingSet=~CAP_BPF Service may not load BPF programs \n✓ SystemCallArchitectures= Service may execute system calls only with native ABI \n✗ RestrictAddressFamilies=~AF_UNIX Service may allocate local sockets 0.1\n✓ ProtectSystem= Service has strict read-only access to the OS file hierarchy \n✓ ProtectProc= Service has restricted access to process tree (/proc hidepid=) \n✓ SupplementaryGroups= Service has no supplementary groups \n✓ CapabilityBoundingSet=~CAP_SYS_RAWIO Service has no raw I/O access \n✓ CapabilityBoundingSet=~CAP_SYS_PTRACE Service has no ptrace() debugging abilities \n✓ CapabilityBoundingSet=~CAP_SYS_(NICE|RESOURCE) Service has no privileges to change resource use parameters \n✓ CapabilityBoundingSet=~CAP_NET_ADMIN Service has no network configuration privileges \n✓ CapabilityBoundingSet=~CAP_NET_(BIND_SERVICE|BROADCAST|RAW) Service has no elevated networking privileges \n✓ CapabilityBoundingSet=~CAP_AUDIT_* Service has no audit subsystem access \n✓ CapabilityBoundingSet=~CAP_SYS_ADMIN Service has no administrator privileges \n✓ PrivateNetwork= Service has no access to the host's network \n✓ PrivateTmp= Service has no access to other software's temporary files \n✓ ProcSubset= Service has no access to non-process /proc files (/proc subset=) \n✓ CapabilityBoundingSet=~CAP_SYSLOG Service has no access to kernel logging \n✓ ProtectHome= Service has no access to home directories \n✓ PrivateDevices= Service has no access to hardware devices \n✗ DeviceAllow= Service has a device ACL with some special devices: char-rtc:r 0.1\n✓ KeyringMode= Service doesn't share key material with other services \n✓ Delegate= Service does not maintain its own delegated control group subtree \n✓ PrivateUsers= Service does not have access to other users \n✓ NotifyAccess= Service child processes cannot alter service state \n✓ ProtectClock= Service cannot write to the hardware clock or system clock \n✓ CapabilityBoundingSet=~CAP_SYS_PACCT Service cannot use acct() \n✓ CapabilityBoundingSet=~CAP_KILL Service cannot send UNIX signals to arbitrary processes \n✓ ProtectKernelLogs= Service cannot read from or write to the kernel log ring buffer \n✓ CapabilityBoundingSet=~CAP_WAKE_ALARM Service cannot program timers that wake up the system \n✓ CapabilityBoundingSet=~CAP_(DAC_*|FOWNER|IPC_OWNER) Service cannot override UNIX file/IPC permission checks \n✓ ProtectControlGroups= Service cannot modify the control group file system \n✓ CapabilityBoundingSet=~CAP_LINUX_IMMUTABLE Service cannot mark files immutable \n✓ CapabilityBoundingSet=~CAP_IPC_LOCK Service cannot lock memory into RAM \n✓ ProtectKernelModules= Service cannot load or read kernel modules \n✓ CapabilityBoundingSet=~CAP_SYS_MODULE Service cannot load kernel modules \n✓ CapabilityBoundingSet=~CAP_SYS_TTY_CONFIG Service cannot issue vhangup() \n✓ CapabilityBoundingSet=~CAP_SYS_BOOT Service cannot issue reboot() \n✓ CapabilityBoundingSet=~CAP_SYS_CHROOT Service cannot issue chroot() \n✓ PrivateMounts= Service cannot install system mounts \n✓ CapabilityBoundingSet=~CAP_BLOCK_SUSPEND Service cannot establish wake locks \n✓ MemoryDenyWriteExecute= Service cannot create writable executable memory mappings \n✓ RestrictNamespaces=~user Service cannot create user namespaces \n✓ RestrictNamespaces=~pid Service cannot create process namespaces \n✓ RestrictNamespaces=~net Service cannot create network namespaces \n✓ RestrictNamespaces=~uts Service cannot create hostname namespaces \n✓ RestrictNamespaces=~mnt Service cannot create file system namespaces \n✓ CapabilityBoundingSet=~CAP_LEASE Service cannot create file leases \n✓ CapabilityBoundingSet=~CAP_MKNOD Service cannot create device nodes \n✓ RestrictNamespaces=~cgroup Service cannot create cgroup namespaces \n✓ RestrictNamespaces=~ipc Service cannot create IPC namespaces \n✓ ProtectHostname= Service cannot change system host/domainname \n✓ CapabilityBoundingSet=~CAP_(CHOWN|FSETID|SETFCAP) Service cannot change file ownership/access mode/capabilities \n✓ CapabilityBoundingSet=~CAP_SET(UID|GID|PCAP) Service cannot change UID/GID identities/capabilities \n✓ LockPersonality= Service cannot change ABI personality \n✓ ProtectKernelTunables= Service cannot alter kernel tunables (/proc/sys, …) \n✓ RestrictAddressFamilies=~AF_PACKET Service cannot allocate packet sockets \n✓ RestrictAddressFamilies=~AF_NETLINK Service cannot allocate netlink sockets \n✓ RestrictAddressFamilies=~… Service cannot allocate exotic sockets \n✓ RestrictAddressFamilies=~AF_(INET|INET6) Service cannot allocate Internet sockets \n✓ CapabilityBoundingSet=~CAP_MAC_* Service cannot adjust SMACK MAC \n✓ IPAddressDeny= Service blocks all IP address ranges \n✓ RestrictSUIDSGID= SUID/SGID file creation by service is restricted \n✓ UMask= Files created by service are accessible only by service's own user by default \n\n→ Overall exposure level for malcontent-timer-extension-agent.service: 0.2 SAFE :-}" ... 1..1 ―――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――――― 18/27 libmalcontent - malcontent:app-filter OK 0.31s 19/27 libmalcontent - malcontent:session-limits OK 0.34s 20/27 nss - malcontent:nss-objdump.py OK 0.15s 21/27 malcontent-timer-extension-agent - malcontent:malcontent-timer-extension-agent.py OK 0.28s 22/27 malcontent-webd - malcontent:malcontent-webd.py OK 0.42s 23/27 malcontent-timerd - malcontent:malcontent-timerd.py OK 0.49s 24/27 libmalcontent-timer - malcontent:extension-agent-polkit OK 0.58s 25/27 malcontent-webd-update - malcontent:malcontent-webd-update.py OK 0.67s 26/27 docs - malcontent:libmalcontent-docs OK 1.67s 27/27 docs - malcontent:libmalcontent-ui-docs OK 3.71s Summary of Failures: 14/27 malcontent-timerd - malcontent:systemd-analyze.py FAIL 0.15s exit status 1 15/27 malcontent-webd - malcontent:systemd-analyze.py FAIL 0.15s exit status 1 16/27 malcontent-webd-update - malcontent:systemd-analyze.py FAIL 0.13s exit status 1 17/27 malcontent-timer-extension-agent - malcontent:systemd-analyze.py FAIL 0.17s exit status 1 Ok: 23 Fail: 4 Full log written to /startdir/src/build/meson-logs/testlog.txt ==> ERROR: A failure occurred in check(). Aborting... ==> ERROR: Build failed, check /home/alhp/workspace/chroot/build_186cfaaa-0167-4c9a-8e57-f400ee89636f/build