Overview

Request 779354 superseded

better changes file entry (forwarded request 779353 from smithfarm)

Loading...

Request History
Nathan Cutler's avatar

smithfarm created request

better changes file entry (forwarded request 779353 from smithfarm)


Factory Auto's avatar

factory-auto added opensuse-review-team as a reviewer

Please review sources


Factory Auto's avatar

factory-auto added security-team as a reviewer

The package is submitted to an official product and it has warnings that indicate that it need to go through a security review. Those warnings can only be ignored in devel projects. For more information please read: https://en.opensuse.org/openSUSE:Package_security_guidelines#audit_bugs.


Factory Auto's avatar

factory-auto accepted review

Check script succeeded


Dominique Leuenberger's avatar

dimstar_suse added openSUSE:Factory:Staging:D as a reviewer

Being evaluated by staging project "openSUSE:Factory:Staging:D"


Dominique Leuenberger's avatar

dimstar_suse accepted review

Picked "openSUSE:Factory:Staging:D"


Saul Goodman's avatar

licensedigger accepted review

ok


Dominique Leuenberger's avatar

dimstar accepted review


Dominique Leuenberger's avatar

dimstar_suse added factory-staging as a reviewer

Being evaluated by group "factory-staging"


Dominique Leuenberger's avatar

dimstar_suse accepted review

Unstaged from project "openSUSE:Factory:Staging:D"


Malte Kraus's avatar

mkraus declined review

You are disabling some rpmlint checks that are critical to the operations of the security team. Please don't do that. If the permissions whitelistings/lints are wrong, tell us and we'll fix them. If it's urgent, we'll try to be quick about it - if you tell us.

I've already replied in bsc#1150366 that we can do the whitelisting of the setgid directory before the bug is fixed. But the rpmlints about /usr/bin/radosgw look worrying too. The way it's packaged it won't have any capabilities, but the permissions configuration still thinks it should. So whenever chkstat is run (which happens rather frequently on Tumbleweed), that binary gets assigned file capabilities that it apparently should not have. I'll work on removing these wrong entries...


Malte Kraus's avatar

mkraus declined request

You are disabling some rpmlint checks that are critical to the operations of the security team. Please don't do that. If the permissions whitelistings/lints are wrong, tell us and we'll fix them. If it's urgent, we'll try to be quick about it - if you tell us.

I've already replied in bsc#1150366 that we can do the whitelisting of the setgid directory before the bug is fixed. But the rpmlints about /usr/bin/radosgw look worrying too. The way it's packaged it won't have any capabilities, but the permissions configuration still thinks it should. So whenever chkstat is run (which happens rather frequently on Tumbleweed), that binary gets assigned file capabilities that it apparently should not have. I'll work on removing these wrong entries...


Nathan Cutler's avatar

smithfarm superseded request

superseded by 781553

openSUSE Build Service is sponsored by