Disclosure: Supervisor security vulnerability

Is it possible that standard procedure to install a fresh install on a Raspberry Pi 4 has been affected by this patch? I don’t understand why my RPi4 blocks the installation process…

Home Assistant logo
Preparing Home Assistant
s6-rc: info: service s6rc-oneshot-runner: starting
s6-rc: info: service s6rc-oneshot-runner successfully started
s6-rc: info: service fix-attrs: starting
s6-rc: info: service fix-attrs successfully started
s6-rc: info: service legacy-cont-init: starting
cont-init: info: running /etc/cont-init.d/udev.sh
[02:32:45] INFO: Using udev information from host
cont-init: info: /etc/cont-init.d/udev.sh exited 0
s6-rc: info: service legacy-cont-init successfully started
s6-rc: info: service legacy-services: starting
services-up: info: copying legacy longrun supervisor (no readiness notification)
services-up: info: copying legacy longrun watchdog (no readiness notification)
s6-rc: info: service legacy-services successfully started
[02:32:46] INFO: Starting local supervisor watchdog...
23-03-14 02:32:52 INFO (MainThread) [__main__] Initializing Supervisor setup
23-03-14 02:32:52 INFO (MainThread) [supervisor.docker.network] Can't find Supervisor network, creating a new network
23-03-14 02:32:52 INFO (MainThread) [supervisor.bootstrap] Seting up coresys for machine: raspberrypi4-64
23-03-14 02:32:52 INFO (SyncWorker_0) [supervisor.docker.supervisor] Attaching to Supervisor ghcr.io/home-assistant/aarch64-hassio-supervisor with version 2022.12.1
23-03-14 02:32:52 INFO (SyncWorker_0) [supervisor.docker.supervisor] Connecting Supervisor to hassio-network
23-03-14 02:32:53 INFO (MainThread) [supervisor.resolution.evaluate] Starting system evaluation with state CoreState.INITIALIZE
23-03-14 02:32:53 INFO (MainThread) [supervisor.resolution.evaluate] System evaluation complete
23-03-14 02:32:53 INFO (MainThread) [__main__] Setting up Supervisor
23-03-14 02:32:53 INFO (MainThread) [supervisor.api] Starting API on 172.30.32.2
23-03-14 02:32:53 INFO (MainThread) [supervisor.hardware.monitor] Started Supervisor hardware monitor
23-03-14 02:32:53 INFO (MainThread) [supervisor.dbus.manager] Connected to system D-Bus.
23-03-14 02:32:53 INFO (MainThread) [supervisor.dbus.agent] Load dbus interface io.hass.os
23-03-14 02:32:53 INFO (MainThread) [supervisor.dbus.hostname] Load dbus interface org.freedesktop.hostname1
23-03-14 02:32:53 INFO (MainThread) [supervisor.dbus.logind] Load dbus interface org.freedesktop.login1
23-03-14 02:32:53 INFO (MainThread) [supervisor.dbus.network] Load dbus interface org.freedesktop.NetworkManager
23-03-14 02:32:53 INFO (MainThread) [supervisor.dbus.rauc] Load dbus interface de.pengutronix.rauc
23-03-14 02:32:53 INFO (MainThread) [supervisor.dbus.resolved] Load dbus interface org.freedesktop.resolve1
23-03-14 02:32:53 INFO (MainThread) [supervisor.dbus.systemd] Load dbus interface org.freedesktop.systemd1
23-03-14 02:32:53 INFO (MainThread) [supervisor.dbus.timedate] Load dbus interface org.freedesktop.timedate1
23-03-14 02:32:54 INFO (MainThread) [supervisor.host.services] Updating service information
23-03-14 02:32:54 INFO (MainThread) [supervisor.host.sound] Updating PulseAudio information
23-03-14 02:32:54 INFO (MainThread) [supervisor.host.network] Updating local network information
23-03-14 02:32:54 INFO (MainThread) [supervisor.host.apparmor] Loading AppArmor Profiles: {'hassio-supervisor'}
23-03-13 22:32:55 INFO (MainThread) [supervisor.docker.monitor] Started docker events monitor
23-03-13 22:32:55 INFO (SyncWorker_0) [supervisor.docker.interface] Found ghcr.io/home-assistant/aarch64-hassio-cli versions: [<AwesomeVersion CalVer '2022.11.0'>]
23-03-13 22:32:55 INFO (SyncWorker_0) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/aarch64-hassio-cli with version 2022.11.0
23-03-13 22:32:55 INFO (MainThread) [supervisor.plugins.cli] Starting CLI plugin
23-03-13 22:32:56 INFO (SyncWorker_0) [supervisor.docker.cli] Starting CLI ghcr.io/home-assistant/aarch64-hassio-cli with version 2022.11.0 - 172.30.32.5
23-03-13 22:32:56 INFO (SyncWorker_0) [supervisor.docker.interface] Found ghcr.io/home-assistant/aarch64-hassio-dns versions: [<AwesomeVersion CalVer '2022.04.1'>]
23-03-13 22:32:56 INFO (SyncWorker_0) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/aarch64-hassio-dns with version 2022.04.1
23-03-13 22:32:56 INFO (MainThread) [supervisor.plugins.dns] Starting CoreDNS plugin
23-03-13 22:32:58 INFO (SyncWorker_0) [supervisor.docker.dns] Starting DNS ghcr.io/home-assistant/aarch64-hassio-dns with version 2022.04.1 - 172.30.32.3
23-03-13 22:32:58 INFO (MainThread) [supervisor.plugins.dns] Updated /etc/resolv.conf
23-03-13 22:32:58 INFO (SyncWorker_0) [supervisor.docker.interface] Found ghcr.io/home-assistant/aarch64-hassio-audio versions: [<AwesomeVersion CalVer '2022.07.0'>]
23-03-13 22:32:58 INFO (SyncWorker_0) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/aarch64-hassio-audio with version 2022.07.0
23-03-13 22:32:58 INFO (MainThread) [supervisor.plugins.audio] Starting Audio plugin
23-03-13 22:33:00 INFO (SyncWorker_0) [supervisor.docker.audio] Starting Audio ghcr.io/home-assistant/aarch64-hassio-audio with version 2022.07.0 - 172.30.32.4
23-03-13 22:33:00 INFO (SyncWorker_0) [supervisor.docker.interface] Found ghcr.io/home-assistant/aarch64-hassio-observer versions: [<AwesomeVersion CalVer '2021.10.0'>]
23-03-13 22:33:00 INFO (SyncWorker_0) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/aarch64-hassio-observer with version 2021.10.0
23-03-13 22:33:00 INFO (MainThread) [supervisor.plugins.observer] Starting observer plugin
23-03-13 22:33:02 INFO (SyncWorker_0) [supervisor.docker.observer] Starting Observer ghcr.io/home-assistant/aarch64-hassio-observer with version 2021.10.0 - 172.30.32.6
23-03-13 22:33:02 INFO (SyncWorker_0) [supervisor.docker.interface] Found ghcr.io/home-assistant/aarch64-hassio-multicast versions: [<AwesomeVersion CalVer '2022.02.0'>]
23-03-13 22:33:02 INFO (SyncWorker_0) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/aarch64-hassio-multicast with version 2022.02.0
23-03-13 22:33:02 INFO (MainThread) [supervisor.plugins.multicast] Starting Multicast plugin
23-03-13 22:33:03 INFO (SyncWorker_0) [supervisor.docker.multicast] Starting Multicast ghcr.io/home-assistant/aarch64-hassio-multicast with version 2022.02.0 - Host
23-03-13 22:33:03 INFO (MainThread) [supervisor.updater] Fetching update data from https://version.home-assistant.io/stable.json
23-03-13 22:33:09 INFO (MainThread) [supervisor.homeassistant.secrets] Loaded 0 Home Assistant secrets
23-03-13 22:33:09 INFO (SyncWorker_0) [supervisor.docker.interface] No version found for ghcr.io/home-assistant/raspberrypi4-64-homeassistant
23-03-13 22:33:09 INFO (MainThread) [supervisor.homeassistant.core] No Home Assistant Docker image ghcr.io/home-assistant/raspberrypi4-64-homeassistant found.
23-03-13 22:33:09 INFO (SyncWorker_0) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/raspberrypi4-64-homeassistant with version landingpage
23-03-13 22:33:09 INFO (MainThread) [supervisor.homeassistant.core] Using preinstalled landingpage
23-03-13 22:33:09 INFO (MainThread) [supervisor.homeassistant.core] Starting HomeAssistant landingpage
23-03-13 22:33:09 INFO (MainThread) [supervisor.homeassistant.module] Update pulse/client.config: /data/tmp/homeassistant_pulse
23-03-13 22:33:10 INFO (SyncWorker_0) [supervisor.docker.homeassistant] Starting Home Assistant ghcr.io/home-assistant/raspberrypi4-64-homeassistant with version landingpage
23-03-13 22:33:10 INFO (MainThread) [supervisor.os.manager] Detect Home Assistant Operating System 9.5 / BootSlot A
23-03-13 22:33:10 INFO (MainThread) [supervisor.store.git] Cloning add-on https://github.com/hassio-addons/repository repository
23-03-13 22:33:10 INFO (MainThread) [supervisor.store.git] Cloning add-on https://github.com/esphome/home-assistant-addon repository
23-03-13 22:33:10 INFO (MainThread) [supervisor.store.git] Cloning add-on https://github.com/home-assistant/addons repository
23-03-13 22:33:15 ERROR (MainThread) [supervisor.store.git] Can't clone https://github.com/hassio-addons/repository repository: Cmd('git') failed due to: exit code(128)
cmdline: git clone -v --recursive --depth=1 --shallow-submodules https://github.com/hassio-addons/repository /data/addons/git/a0d7b954
stderr: 'Cloning into '/data/addons/git/a0d7b954'...
fatal: unable to access 'https://github.com/hassio-addons/repository/': Could not resolve host: github.com
'.
23-03-13 22:33:15 ERROR (MainThread) [supervisor.store] Can't retrieve data from https://github.com/hassio-addons/repository due to
23-03-13 22:33:15 INFO (MainThread) [supervisor.resolution.module] Create new suggestion SuggestionType.EXECUTE_REMOVE - ContextType.STORE / a0d7b954
23-03-13 22:33:15 INFO (MainThread) [supervisor.resolution.module] Create new issue IssueType.FATAL_ERROR - ContextType.STORE / a0d7b954
23-03-13 22:33:15 WARNING (SyncWorker_2) [supervisor.store.data] Can't read /data/addons/git/5c53de3b/esphome/config.yaml: Service esphome not found @ data['discovery'][0]. Got 'esphome'
23-03-13 22:33:15 WARNING (SyncWorker_2) [supervisor.store.data] Can't read /data/addons/git/5c53de3b/esphome-beta/config.yaml: Service esphome not found @ data['discovery'][0]. Got 'esphome'
23-03-13 22:33:15 WARNING (SyncWorker_2) [supervisor.store.data] Can't read /data/addons/git/5c53de3b/esphome-dev/config.yaml: Service esphome not found @ data['discovery'][0]. Got 'esphome'
23-03-13 22:33:15 INFO (MainThread) [supervisor.store] Loading add-ons from store: 24 all - 24 new - 0 remove
23-03-13 22:33:15 INFO (MainThread) [supervisor.addons] Found 0 installed add-ons
23-03-13 22:33:15 INFO (MainThread) [supervisor.backups.manager] Found 0 backup files
23-03-13 22:33:15 INFO (MainThread) [supervisor.discovery] Loaded 0 messages
23-03-13 22:33:15 INFO (MainThread) [supervisor.ingress] Loaded 0 ingress sessions
23-03-13 22:33:15 INFO (MainThread) [supervisor.resolution.check] Starting system checks with state CoreState.SETUP
23-03-13 22:33:15 INFO (MainThread) [supervisor.resolution.check] System checks complete
23-03-13 22:33:15 INFO (MainThread) [supervisor.resolution.evaluate] Starting system evaluation with state CoreState.SETUP
23-03-13 22:33:15 INFO (MainThread) [supervisor.resolution.evaluate] System evaluation complete
23-03-13 22:33:15 INFO (MainThread) [supervisor.jobs] 'ResolutionFixup.run_autofix' blocked from execution, system is not running - CoreState.SETUP
23-03-13 22:33:15 INFO (MainThread) [supervisor.resolution.evaluate] Starting system evaluation with state CoreState.SETUP
23-03-13 22:33:15 INFO (MainThread) [supervisor.resolution.evaluate] System evaluation complete
23-03-13 22:33:15 INFO (MainThread) [__main__] Running Supervisor
23-03-13 22:33:15 INFO (MainThread) [supervisor.os.manager] Rauc: A - marked slot kernel.0 as good
23-03-13 22:33:15 INFO (MainThread) [supervisor.supervisor] Fetching AppArmor profile https://version.home-assistant.io/apparmor.txt
23-03-13 22:33:17 INFO (MainThread) [supervisor.host.apparmor] Adding/updating AppArmor profile: hassio-supervisor
23-03-13 22:33:17 INFO (MainThread) [supervisor.supervisor] Update Supervisor to version 2023.03.1
23-03-13 22:33:17 INFO (SyncWorker_2) [supervisor.docker.interface] Downloading docker image ghcr.io/home-assistant/aarch64-hassio-supervisor with tag 2023.03.1.
23-03-13 22:39:32 ERROR (SyncWorker_2) [supervisor.docker.interface] Can't install ghcr.io/home-assistant/aarch64-hassio-supervisor:2023.03.1: 500 Server Error for http+docker://localhost/v1.41/images/create?tag=2023.03.1&fromImage=ghcr.io%2Fhome-assistant%2Faarch64-hassio-supervisor&platform=linux%2Farm64: Internal Server Error ("Get "https://ghcr.io/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)")
23-03-13 22:39:32 INFO (MainThread) [supervisor.resolution.module] Create new issue IssueType.UPDATE_FAILED - ContextType.SUPERVISOR / None
23-03-13 22:39:32 ERROR (MainThread) [supervisor.supervisor] Update of Supervisor failed: Can't install ghcr.io/home-assistant/aarch64-hassio-supervisor:2023.03.1: 500 Server Error for http+docker://localhost/v1.41/images/create?tag=2023.03.1&fromImage=ghcr.io%2Fhome-assistant%2Faarch64-hassio-supervisor&platform=linux%2Farm64: Internal Server Error ("Get "https://ghcr.io/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)")
23-03-13 22:39:32 CRITICAL (MainThread) [supervisor.core] Can't update Supervisor! This will break some Add-ons or affect future versions of Home Assistant!
23-03-13 22:39:32 INFO (MainThread) [supervisor.addons] Phase 'AddonStartup.INITIALIZE' starting 0 add-ons
23-03-13 22:39:32 INFO (MainThread) [supervisor.addons] Phase 'AddonStartup.SYSTEM' starting 0 add-ons
23-03-13 22:39:32 INFO (MainThread) [supervisor.addons] Phase 'AddonStartup.SERVICES' starting 0 add-ons
23-03-13 22:39:32 INFO (MainThread) [supervisor.core] Skiping start of Home Assistant
23-03-13 22:39:32 INFO (MainThread) [supervisor.addons] Phase 'AddonStartup.APPLICATION' starting 0 add-ons
23-03-13 22:39:32 INFO (MainThread) [supervisor.misc.tasks] All core tasks are scheduled
23-03-13 22:39:32 INFO (MainThread) [supervisor.core] Supervisor is up and running
23-03-13 22:39:32 INFO (MainThread) [supervisor.homeassistant.core] Home Assistant setup
23-03-13 22:39:32 INFO (MainThread) [supervisor.host.info] Updating local host information
23-03-13 22:39:32 INFO (MainThread) [supervisor.updater] Fetching update data from https://version.home-assistant.io/stable.json
23-03-13 22:39:32 INFO (MainThread) [supervisor.resolution.check] Starting system checks with state CoreState.RUNNING
23-03-13 22:39:32 INFO (MainThread) [supervisor.resolution.checks.base] Run check for IssueType.IPV4_CONNECTION_PROBLEM/ContextType.SYSTEM
23-03-13 22:39:32 INFO (MainThread) [supervisor.resolution.checks.base] Run check for IssueType.TRUST/ContextType.SUPERVISOR
23-03-13 22:39:32 INFO (SyncWorker_2) [supervisor.docker.interface] Updating image ghcr.io/home-assistant/raspberrypi4-64-homeassistant:landingpage to ghcr.io/home-assistant/raspberrypi4-64-homeassistant:2023.3.3
23-03-13 22:39:32 INFO (SyncWorker_2) [supervisor.docker.interface] Downloading docker image ghcr.io/home-assistant/raspberrypi4-64-homeassistant with tag 2023.3.3.
23-03-13 22:39:33 INFO (MainThread) [supervisor.host.services] Updating service information
23-03-13 22:39:33 INFO (MainThread) [supervisor.host.network] Updating local network information
23-03-13 22:39:33 INFO (MainThread) [supervisor.host.sound] Updating PulseAudio information
23-03-13 22:39:33 INFO (MainThread) [supervisor.host.manager] Host information reload completed
23-03-13 22:39:33 INFO (MainThread) [supervisor.resolution.checks.base] Run check for IssueType.DNS_SERVER_IPV6_ERROR/ContextType.DNS_SERVER
23-03-13 22:39:34 INFO (MainThread) [supervisor.resolution.checks.base] Run check for IssueType.FREE_SPACE/ContextType.SYSTEM
23-03-13 22:39:34 INFO (MainThread) [supervisor.resolution.checks.base] Run check for IssueType.SECURITY/ContextType.CORE
23-03-13 22:39:34 INFO (MainThread) [supervisor.resolution.checks.base] Run check for IssueType.NO_CURRENT_BACKUP/ContextType.SYSTEM
23-03-13 22:39:34 INFO (MainThread) [supervisor.resolution.module] Create new suggestion SuggestionType.CREATE_FULL_BACKUP - ContextType.SYSTEM / None
23-03-13 22:39:34 INFO (MainThread) [supervisor.resolution.module] Create new issue IssueType.NO_CURRENT_BACKUP - ContextType.SYSTEM / None
23-03-13 22:39:34 INFO (MainThread) [supervisor.resolution.checks.base] Run check for IssueType.DNS_SERVER_FAILED/ContextType.DNS_SERVER
23-03-13 22:39:34 INFO (MainThread) [supervisor.resolution.checks.base] Run check for IssueType.PWNED/ContextType.ADDON
23-03-13 22:39:34 INFO (MainThread) [supervisor.resolution.check] System checks complete
23-03-13 22:39:34 INFO (MainThread) [supervisor.resolution.evaluate] Starting system evaluation with state CoreState.RUNNING
23-03-13 22:39:35 INFO (MainThread) [supervisor.resolution.evaluate] System evaluation complete
23-03-13 22:39:35 INFO (MainThread) [supervisor.jobs] 'ResolutionFixup.run_autofix' blocked from execution, system is not healthy - supervisor
23-03-13 22:45:38 ERROR (SyncWorker_2) [supervisor.docker.interface] Can't install ghcr.io/home-assistant/raspberrypi4-64-homeassistant:2023.3.3: 500 Server Error for http+docker://localhost/v1.41/images/create?tag=2023.3.3&fromImage=ghcr.io%2Fhome-assistant%2Fraspberrypi4-64-homeassistant&platform=linux%2Farm64: Internal Server Error ("Get "https://ghcr.io/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)")
23-03-13 22:45:38 WARNING (MainThread) [supervisor.homeassistant.core] Error on Home Assistant installation. Retry in 30sec
23-03-13 22:46:08 INFO (SyncWorker_1) [supervisor.docker.interface] Updating image ghcr.io/home-assistant/raspberrypi4-64-homeassistant:landingpage to ghcr.io/home-assistant/raspberrypi4-64-homeassistant:2023.3.3
23-03-13 22:46:08 INFO (SyncWorker_1) [supervisor.docker.interface] Downloading docker image ghcr.io/home-assistant/raspberrypi4-64-homeassistant with tag 2023.3.3.
23-03-13 22:50:47 ERROR (SyncWorker_1) [supervisor.docker.interface] Can't install ghcr.io/home-assistant/raspberrypi4-64-homeassistant:2023.3.3: 500 Server Error for http+docker://localhost/v1.41/images/create?tag=2023.3.3&fromImage=ghcr.io%2Fhome-assistant%2Fraspberrypi4-64-homeassistant&platform=linux%2Farm64: Internal Server Error ("Get "https://ghcr.io/v2/home-assistant/raspberrypi4-64-homeassistant/manifests/sha256:f0d2db2dd30b41fe93f87d4efef9ea96be95838528d79d0503f53ee7e970ba5b": dial tcp 140.82.113.34:443: connect: no route to host")
23-03-13 22:50:47 WARNING (MainThread) [supervisor.homeassistant.core] Error on Home Assistant installation. Retry in 30sec
23-03-13 22:51:17 INFO (SyncWorker_2) [supervisor.docker.interface] Updating image ghcr.io/home-assistant/raspberrypi4-64-homeassistant:landingpage to ghcr.io/home-assistant/raspberrypi4-64-homeassistant:2023.3.3
23-03-13 22:51:17 INFO (SyncWorker_2) [supervisor.docker.interface] Downloading docker image ghcr.io/home-assistant/raspberrypi4-64-homeassistant with tag 2023.3.3.
23-03-13 22:54:07 ERROR (SyncWorker_2) [supervisor.docker.interface] Can't install ghcr.io/home-assistant/raspberrypi4-64-homeassistant:2023.3.3: 500 Server Error for http+docker://localhost/v1.41/images/create?tag=2023.3.3&fromImage=ghcr.io%2Fhome-assistant%2Fraspberrypi4-64-homeassistant&platform=linux%2Farm64: Internal Server Error ("Get "https://ghcr.io/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)")
23-03-13 22:54:07 WARNING (MainThread) [supervisor.homeassistant.core] Error on Home Assistant installation. Retry in 30sec
23-03-13 22:54:37 INFO (SyncWorker_1) [supervisor.docker.interface] Updating image ghcr.io/home-assistant/raspberrypi4-64-homeassistant:landingpage to ghcr.io/home-assistant/raspberrypi4-64-homeassistant:2023.3.3
23-03-13 22:54:37 INFO (SyncWorker_1) [supervisor.docker.interface] Downloading docker image ghcr.io/home-assistant/raspberrypi4-64-homeassistant with tag 2023.3.3.
23-03-13 22:57:00 ERROR (SyncWorker_1) [supervisor.docker.interface] Can't install ghcr.io/home-assistant/raspberrypi4-64-homeassistant:2023.3.3: 500 Server Error for http+docker://localhost/v1.41/images/create?tag=2023.3.3&fromImage=ghcr.io%2Fhome-assistant%2Fraspberrypi4-64-homeassistant&platform=linux%2Farm64: Internal Server Error ("Get "https://ghcr.io/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)")
23-03-13 22:57:00 WARNING (MainThread) [supervisor.homeassistant.core] Error on Home Assistant installation. Retry in 30sec
23-03-13 22:57:30 INFO (SyncWorker_0) [supervisor.docker.interface] Updating image ghcr.io/home-assistant/raspberrypi4-64-homeassistant:landingpage to ghcr.io/home-assistant/raspberrypi4-64-homeassistant:2023.3.3
23-03-13 22:57:30 INFO (SyncWorker_0) [supervisor.docker.interface] Downloading docker image ghcr.io/home-assistant/raspberrypi4-64-homeassistant with tag 2023.3.3.
s6-rc: info: service s6rc-oneshot-runner: starting
s6-rc: info: service s6rc-oneshot-runner successfully started
s6-rc: info: service fix-attrs: starting
s6-rc: info: service fix-attrs successfully started
s6-rc: info: service legacy-cont-init: starting
cont-init: info: running /etc/cont-init.d/udev.sh
[02:59:40] INFO: Using udev information from host
cont-init: info: /etc/cont-init.d/udev.sh exited 0
s6-rc: info: service legacy-cont-init successfully started
s6-rc: info: service legacy-services: starting
services-up: info: copying legacy longrun supervisor (no readiness notification)
services-up: info: copying legacy longrun watchdog (no readiness notification)
[02:59:40] INFO: Starting local supervisor watchdog...
s6-rc: info: service legacy-services successfully started
23-03-14 02:59:44 INFO (MainThread) [__main__] Initializing Supervisor setup
23-03-13 22:59:44 INFO (MainThread) [supervisor.bootstrap] Seting up coresys for machine: raspberrypi4-64
23-03-13 22:59:44 INFO (SyncWorker_0) [supervisor.docker.supervisor] Attaching to Supervisor ghcr.io/home-assistant/aarch64-hassio-supervisor with version 2022.12.1
23-03-13 22:59:44 INFO (MainThread) [supervisor.resolution.evaluate] Starting system evaluation with state CoreState.INITIALIZE
23-03-13 22:59:44 INFO (MainThread) [supervisor.resolution.evaluate] System evaluation complete
23-03-13 22:59:44 INFO (MainThread) [__main__] Setting up Supervisor
23-03-13 22:59:45 INFO (MainThread) [supervisor.api] Starting API on 172.30.32.2
23-03-13 22:59:45 INFO (MainThread) [supervisor.hardware.monitor] Started Supervisor hardware monitor
23-03-13 22:59:45 INFO (MainThread) [supervisor.dbus.manager] Connected to system D-Bus.
23-03-13 22:59:45 INFO (MainThread) [supervisor.dbus.agent] Load dbus interface io.hass.os
23-03-13 22:59:45 INFO (MainThread) [supervisor.dbus.hostname] Load dbus interface org.freedesktop.hostname1
23-03-13 22:59:45 INFO (MainThread) [supervisor.dbus.logind] Load dbus interface org.freedesktop.login1
23-03-13 22:59:45 INFO (MainThread) [supervisor.dbus.network] Load dbus interface org.freedesktop.NetworkManager
23-03-13 22:59:45 INFO (MainThread) [supervisor.dbus.rauc] Load dbus interface de.pengutronix.rauc
23-03-13 22:59:45 INFO (MainThread) [supervisor.dbus.resolved] Load dbus interface org.freedesktop.resolve1
23-03-13 22:59:45 INFO (MainThread) [supervisor.dbus.systemd] Load dbus interface org.freedesktop.systemd1
23-03-13 22:59:45 INFO (MainThread) [supervisor.dbus.timedate] Load dbus interface org.freedesktop.timedate1
23-03-13 22:59:45 INFO (MainThread) [supervisor.host.services] Updating service information
23-03-13 22:59:45 INFO (MainThread) [supervisor.host.sound] Updating PulseAudio information
23-03-13 22:59:46 INFO (MainThread) [supervisor.host.network] Updating local network information
23-03-13 22:59:46 INFO (MainThread) [supervisor.host.apparmor] Loading AppArmor Profiles: {'hassio-supervisor'}
23-03-13 22:59:46 INFO (MainThread) [supervisor.docker.monitor] Started docker events monitor
23-03-13 22:59:46 INFO (SyncWorker_0) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/aarch64-hassio-cli with version 2022.11.0
23-03-13 22:59:46 INFO (MainThread) [supervisor.plugins.cli] Starting CLI plugin
23-03-13 22:59:46 INFO (SyncWorker_0) [supervisor.docker.interface] Cleaning hassio_cli application
23-03-13 22:59:48 INFO (SyncWorker_0) [supervisor.docker.cli] Starting CLI ghcr.io/home-assistant/aarch64-hassio-cli with version 2022.11.0 - 172.30.32.5
23-03-13 22:59:48 INFO (SyncWorker_0) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/aarch64-hassio-dns with version 2022.04.1
23-03-13 22:59:48 INFO (MainThread) [supervisor.plugins.dns] Starting CoreDNS plugin
23-03-13 22:59:48 INFO (SyncWorker_0) [supervisor.docker.interface] Cleaning hassio_dns application
23-03-13 22:59:50 INFO (SyncWorker_0) [supervisor.docker.dns] Starting DNS ghcr.io/home-assistant/aarch64-hassio-dns with version 2022.04.1 - 172.30.32.3
23-03-13 22:59:50 INFO (MainThread) [supervisor.plugins.dns] Updated /etc/resolv.conf
23-03-13 22:59:50 INFO (SyncWorker_0) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/aarch64-hassio-audio with version 2022.07.0
23-03-13 22:59:50 INFO (MainThread) [supervisor.plugins.audio] Starting Audio plugin
23-03-13 22:59:50 INFO (SyncWorker_0) [supervisor.docker.interface] Cleaning hassio_audio application
23-03-13 22:59:51 INFO (SyncWorker_0) [supervisor.docker.audio] Starting Audio ghcr.io/home-assistant/aarch64-hassio-audio with version 2022.07.0 - 172.30.32.4
23-03-13 22:59:51 INFO (SyncWorker_0) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/aarch64-hassio-observer with version 2021.10.0
23-03-13 22:59:51 INFO (SyncWorker_0) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/aarch64-hassio-multicast with version 2022.02.0
23-03-13 22:59:51 INFO (MainThread) [supervisor.plugins.multicast] Starting Multicast plugin
23-03-13 22:59:51 INFO (SyncWorker_0) [supervisor.docker.interface] Cleaning hassio_multicast application
23-03-13 22:59:52 INFO (SyncWorker_0) [supervisor.docker.multicast] Starting Multicast ghcr.io/home-assistant/aarch64-hassio-multicast with version 2022.02.0 - Host
23-03-13 22:59:52 INFO (MainThread) [supervisor.updater] Fetching update data from https://version.home-assistant.io/stable.json
23-03-13 22:59:58 INFO (MainThread) [supervisor.homeassistant.secrets] Loaded 0 Home Assistant secrets
23-03-13 22:59:58 INFO (SyncWorker_1) [supervisor.docker.interface] Attaching to ghcr.io/home-assistant/raspberrypi4-64-homeassistant with version landingpage
23-03-13 22:59:58 INFO (MainThread) [supervisor.homeassistant.core] Starting HomeAssistant landingpage
23-03-13 22:59:58 WARNING (MainThread) [supervisor.homeassistant.core] Watchdog found Home Assistant failed, restarting...
23-03-13 22:59:58 INFO (MainThread) [supervisor.homeassistant.module] Update pulse/client.config: /data/tmp/homeassistant_pulse
23-03-13 22:59:58 INFO (SyncWorker_1) [supervisor.docker.interface] Cleaning homeassistant application
23-03-13 22:59:58 ERROR (MainThread) [supervisor.utils] Can't execute start while a task is in progress
23-03-13 22:59:59 INFO (SyncWorker_1) [supervisor.docker.homeassistant] Starting Home Assistant ghcr.io/home-assistant/raspberrypi4-64-homeassistant with version landingpage
23-03-13 22:59:59 INFO (MainThread) [supervisor.os.manager] Detect Home Assistant Operating System 9.5 / BootSlot A
23-03-13 22:59:59 WARNING (SyncWorker_0) [supervisor.store.data] Can't read /data/addons/git/5c53de3b/esphome/config.yaml: Service esphome not found @ data['discovery'][0]. Got 'esphome'
23-03-13 22:59:59 WARNING (SyncWorker_0) [supervisor.store.data] Can't read /data/addons/git/5c53de3b/esphome-beta/config.yaml: Service esphome not found @ data['discovery'][0]. Got 'esphome'
23-03-13 22:59:59 WARNING (SyncWorker_0) [supervisor.store.data] Can't read /data/addons/git/5c53de3b/esphome-dev/config.yaml: Service esphome not found @ data['discovery'][0]. Got 'esphome'
23-03-13 22:59:59 INFO (MainThread) [supervisor.store.git] Loading add-on /data/addons/core repository
23-03-13 22:59:59 INFO (MainThread) [supervisor.store.git] Cloning add-on https://github.com/hassio-addons/repository repository
23-03-13 22:59:59 INFO (MainThread) [supervisor.store.git] Loading add-on /data/addons/git/5c53de3b repository
23-03-13 23:00:01 WARNING (SyncWorker_2) [supervisor.store.data] Can't read /data/addons/git/5c53de3b/esphome/config.yaml: Service esphome not found @ data['discovery'][0]. Got 'esphome'
23-03-13 23:00:01 WARNING (SyncWorker_2) [supervisor.store.data] Can't read /data/addons/git/5c53de3b/esphome-beta/config.yaml: Service esphome not found @ data['discovery'][0]. Got 'esphome'
23-03-13 23:00:01 WARNING (SyncWorker_2) [supervisor.store.data] Can't read /data/addons/git/5c53de3b/esphome-dev/config.yaml: Service esphome not found @ data['discovery'][0]. Got 'esphome'
23-03-13 23:00:01 INFO (MainThread) [supervisor.store] Loading add-ons from store: 65 all - 65 new - 0 remove
23-03-13 23:00:01 INFO (MainThread) [supervisor.addons] Found 0 installed add-ons
23-03-13 23:00:01 INFO (MainThread) [supervisor.backups.manager] Found 0 backup files
23-03-13 23:00:01 INFO (MainThread) [supervisor.discovery] Loaded 0 messages
23-03-13 23:00:01 INFO (MainThread) [supervisor.ingress] Loaded 0 ingress sessions
23-03-13 23:00:01 INFO (MainThread) [supervisor.resolution.check] Starting system checks with state CoreState.SETUP
23-03-13 23:00:01 INFO (MainThread) [supervisor.resolution.check] System checks complete
23-03-13 23:00:01 INFO (MainThread) [supervisor.resolution.evaluate] Starting system evaluation with state CoreState.SETUP
23-03-13 23:00:01 INFO (MainThread) [supervisor.resolution.evaluate] System evaluation complete
23-03-13 23:00:01 INFO (MainThread) [supervisor.jobs] 'ResolutionFixup.run_autofix' blocked from execution, system is not running - CoreState.SETUP
23-03-13 23:00:01 INFO (MainThread) [supervisor.resolution.evaluate] Starting system evaluation with state CoreState.SETUP
23-03-13 23:00:01 INFO (MainThread) [supervisor.resolution.evaluate] System evaluation complete
23-03-13 23:00:01 INFO (MainThread) [__main__] Running Supervisor
23-03-13 23:00:01 INFO (MainThread) [supervisor.os.manager] Rauc: A - marked slot kernel.0 as good
23-03-13 23:00:01 INFO (MainThread) [supervisor.supervisor] Fetching AppArmor profile https://version.home-assistant.io/apparmor.txt
23-03-13 23:00:02 INFO (MainThread) [supervisor.host.apparmor] Adding/updating AppArmor profile: hassio-supervisor
23-03-13 23:00:02 INFO (MainThread) [supervisor.supervisor] Update Supervisor to version 2023.03.1
23-03-13 23:00:02 INFO (SyncWorker_2) [supervisor.docker.interface] Downloading docker image ghcr.io/home-assistant/aarch64-hassio-supervisor with tag 2023.03.1.
23-03-13 23:06:18 ERROR (SyncWorker_2) [supervisor.docker.interface] Can't install ghcr.io/home-assistant/aarch64-hassio-supervisor:2023.03.1: 500 Server Error for http+docker://localhost/v1.41/images/create?tag=2023.03.1&fromImage=ghcr.io%2Fhome-assistant%2Faarch64-hassio-supervisor&platform=linux%2Farm64: Internal Server Error ("Get "https://ghcr.io/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)")
23-03-13 23:06:18 INFO (MainThread) [supervisor.resolution.module] Create new issue IssueType.UPDATE_FAILED - ContextType.SUPERVISOR / None
23-03-13 23:06:18 ERROR (MainThread) [supervisor.supervisor] Update of Supervisor failed: Can't install ghcr.io/home-assistant/aarch64-hassio-supervisor:2023.03.1: 500 Server Error for http+docker://localhost/v1.41/images/create?tag=2023.03.1&fromImage=ghcr.io%2Fhome-assistant%2Faarch64-hassio-supervisor&platform=linux%2Farm64: Internal Server Error ("Get "https://ghcr.io/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)")
23-03-13 23:06:18 CRITICAL (MainThread) [supervisor.core] Can't update Supervisor! This will break some Add-ons or affect future versions of Home Assistant!
23-03-13 23:06:18 INFO (MainThread) [supervisor.addons] Phase 'AddonStartup.INITIALIZE' starting 0 add-ons
23-03-13 23:06:18 INFO (MainThread) [supervisor.addons] Phase 'AddonStartup.SYSTEM' starting 0 add-ons
23-03-13 23:06:18 INFO (MainThread) [supervisor.addons] Phase 'AddonStartup.SERVICES' starting 0 add-ons
(this can take up to 20 minutes)

You have a DNS or networking problem. Please start a fresh topic with your problem.

Disconnect all network cables, shutdown you wireless networks, turn off your router, turn off all power relays, remove batteries from all your devices, put your phone on fire and after a few days you probably will be safe… Or maybe not… You still having doors and windows at home right?

:stuck_out_tongue_winking_eye:

2 Likes

To rule out any malicious modifications to HA while this vulnerability was active, are there any tools already built to validate homeassistant os files, directories etc?

E.g. hypothetically if someone did get in and leave something for later? Modify/add code to tunnel out etc.

(Other than reinstalling from scratch / fresh image and manually reconfiguring integrations / copying over yaml, Migrating zwave devices etc (30 devices won’t be fun…))

A script could go though the entire SD card and compare each folder / file / size / to what it should be / a clean install. Anyone done anything like this yet?

1 Like

For HAOS that should be do-able, but any method that uses Docker should be (mostly) a case of checking the container hashes match what’s on the central registry. A simple reboot ensures that any live changes to a container are thrown away.

If all of those agree then the only other thing to do is to verify the OS - for HAOS the OS is replaced when you upgrade anyway so an OS upgrade is an easy step to take.

For anybody running Supervised it’ll be a little harder, but you can use tools like dpkg to verify the installed files against the package manifest, or use this approach.

The other option of course is to take a backup and restore it on a fresh install.

Any suggestions how I might get around this?

ha supervisor update
Processing… Done.

Error: Update of Supervisor failed: Can’t install ghcr.io/home-assistant/amd64-hassio-supervisor:2023.03.1: 500 Server Error for http+docker://localhost/v1.41/images/create?tag=2023.03.1&fromImage=ghcr.io%2Fhome-assistant%2Famd64-hassio-supervisor&platform=linux%2Famd64: Internal Server Error (“Get “https://ghcr.io/v2/”: net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)”)

My installation is currently at:

Home Assistant 2023.1.7
Supervisor 2023.01.1
Operating System 9.4
Frontend 20230110.0 - latest

From what I can tell, it isn’t a DNS problem.


Update: I was unable to apply any updates to Home Assistant in February too. So I just now restored the host to an earlier image, which reverted Home Assistant to:

Home Assistant 2022.12.9
Supervisor 2022.12.1
Operating System 9.4
Frontend 20221213.1

But attempting to update brought the same error as above, which is strange, since I’d been able to update to 2023.1.7 in January!?!

The logs for the reverted version also contained the following:

homeassistant.components.hassio.handler.HassioAPIError: ‘HomeAssistantCore.update’ blocked from execution, no host internet connection

Weird, as anything external I manually attempt to reach from the HA cli works…via IPv4.

ping ghcr.io
PING ghcr.io (140.82.113.33): 56 data bytes
64 bytes from 140.82.113.33: seq=0 ttl=47 time=38.816 ms
64 bytes from 140.82.113.33: seq=1 ttl=47 time=40.445 ms

I have IPv6 disabled in HA and I’m pretty sure it’s blocked on my network. Could that be the problem, might the updater have been restricted to IPv6 since February?

I got to core-2023.3.4 supervisor-2023.03.1 Home Assistant OS 9.5 without IPv6 being enabled on my network nor HA. So I don’t think IPv4-only is your problem.

I am running into the exact same issue and error message, here you can see more details about what is going on:

I got to core-2023.3.4 supervisor-2023.03.1 Home Assistant OS 9.5 without IPv6 being enabled on my network nor HA. So I don’t think IPv4-only is your problem.

Good to rule that out. Thanks much.

I had forgotten that in late January our internet provided changed the gateway technology we use. That changed our gateway addressing, which includes the DNS address, and I had neglected to update the static DNS address assigned to the Network Interface within Home Assistant. With that now corrected, I have Home Assistant fully up to date.

If your system’s network interface is set to static values, you might review them to see if you suffer the same issue.

A post was split to a new topic: No host internet connection

Good to be open and transparent to this, and a quick response to it with fix too… Thanx!
#weallwillbehackedsometime

This issue looks to be still active or once hacked, there is malware in your supervisor/install. 

It has been in play since 2022/10/27 16:39 and with my supervisor at 2023.04.0, the attacks are still happening.  

I am just about to backup and blow away the VM and start from scratch with min config. 

Any recommendation on what to avoid restoring?  Where virus/malware will be hidden in  /config??


There’s unlikely to be any malware there, but if there is it should be pretty obvious. The only things in your config folder should be YAML, JSON, the database, and the log file. Anything else is suspect (or installed by a custom component).

The alerts from your security software should be investigated to see if they’re actually anything of note, or just what happens when you’re accessible from the Internet (lots of failed exploit attempts against other software).

2 Likes

While technically a nabucasa connected device would expose the vulnerability, in order to connect to your instance the hacker would have to guess your unique URL. So unless nabucasa uses a very dumb algorithm for generating your unique URL (that is they are not randomly generated), the probability of someone guessing a nabucasa URL is very very very low. @frenck if you have information that indicates this isn’t correct please advise.

Read above, the list of NabuCasa domains, or anything else with an SSL certificate, is public knowledge.

So if I read this correctly there would be no issue of nabu casa exposing the individual URLs if they had uses a wildcard cert, i.e. *.ui.nabu.casa?

Turns out the random nabu casa URL was a security scam. Nabu casa should have made a clear statement that the random url provided no security. They report all URLs out to the internet so you’re basically putting you instance directly on the internet. I can’t believe I trusted nabu casa. Errrr!

What are you talking about “security scam”… Nabucasa makes no mention of a random url in the security information. Are you sure you didn’t get that info from a blog that made that assumption?

1 Like

They make no mention of the fact that your URL is reported out to the internet so you’re really directly exposing your system. They use a random URL that gives the impression of security. Using nabu casa is no different than putting the https port directly on the internet from your local network. Nabu casa never make this clear. That’s a scam.