Get the most out of your Centmin Mod LEMP stack
Become a Member

checksec 2.6.0 never installed (wrong dir in inc/downloads.inc) → "WARNING: 'sysctl' not found!" on

Discussion in 'Nginx, PHP-FPM & MariaDB MySQL' started by adamus007p, Oct 8, 2026 at 2:03 AM.

  1. adamus007p

    adamus007p Member

    380
    20
    18
    Feb 8, 2019
    Ratings:
    +40
    Local Time:
    10:04 AM
    Hi George,
    The Nginx 1.31.6 upgrade on 132.00stable.b201 (b1703e8) completed fine (nginx -t OK,
    sites up). However, the log shows this error once:
    cp: cannot stat '/svr-setup/checksec.sh-2.6.0/checksec': No such file or directory
    and this warning 19 times:
    WARNING: 'sysctl' not found! It's required for most checks.
    WARNING: Not all necessary commands found. Some tests might not work!

    Environment: AlmaLinux 9.8, Centmin Mod 132.00stable.b201, CHECKSEC_VERSION='2.6.0',
    EPEL checksec-2.5.0-2.el9 installed at /usr/bin/checksec.

    Cause 1 – wrong directory name in inc/downloads.inc, checksec_check():
    tar xzf "checksec-${CHECKSEC_VERSION}.tar.gz"
    \cp -af "${DIR_TMP}/checksec.sh-${CHECKSEC_VERSION}/checksec" /usr/local/bin/checksec
    The GitHub tarball now extracts to "checksec-2.6.0/" (tar tzf shows checksec-2.6.0/),
    not "checksec.sh-2.6.0/". So the cp fails, /usr/local/bin/checksec is never created,
    and the download is retried on every run.

    Cause 2 – the fallback, EPEL checksec 2.5.0, starts with `exec -c` (environment
    sanitising). That drops PATH, so `type sysctl` can't find /usr/sbin/sysctl even though
    it is installed. Running `checksec --version` from a normal root shell gives the same warning.

    The 2.6.0 binary from the extracted tarball works without warnings:
    /svr-setup/checksec-2.6.0/checksec --format=json --file=/usr/local/sbin/nginx --extended
    → relro full, canary yes, nx yes, pie yes ... no warnings


    Suggested fix in inc/downloads.inc:
    \cp -af "${DIR_TMP}/checksec-${CHECKSEC_VERSION}/checksec" /usr/local/bin/checksec
    or detect the extracted directory instead of hardcoding it:
    checksec_dir=$(tar tzf "checksec-${CHECKSEC_VERSION}.tar.gz" | head -1 | cut -d/ -f1)
    \cp -af "${DIR_TMP}/${checksec_dir}/checksec" /usr/local/bin/checksec
    It would also help to call /usr/local/bin/checksec explicitly in the nginx/php checksec
    functions, so they don't depend on PATH order or the EPEL 2.5.0 package.

    Minor (FYI): ngx_brotli CMake prints "Manually-specified variables were not used by the
    project: CMAKE_CXX_FLAGS" (cosmetic).

    Thanks!