service file permissions breaking due to file 5.47 / redhat-rpm-config
Petr Sklenar via devel <[email protected]>
| Newsgroups | gmane.linux.redhat.fedora.devel |
|---|---|
| Message-ID | <CAJgb=0JUus9yV7E9Mn9h6c+kzYkL_5Z-deNLoDbTQDusiLFJFg@mail.gmail.com> |
Hi,
while testing F45 Rawhide I noticed systemd complaining during boot:
Configuration file /usr/lib/systemd/system/flatpak-add-fedora-repos.service
is marked executable. Please remove executable permission bits.
Proceeding anyway.
It turns out file 5.47 now classifies .service files as
application/x-wine-extension-ini instead of text/plain. This breaks
brp-mangle-shebangs, which greps for text/ to find executable files
without shebangs and chmod -x them.
So any package using install -p without explicit -m 0644 for unit
files ends up shipping them with 0755. The big ones (systemd, httpd,
nginx...) set permissions explicitly, so they are unaffected.
I couldn't find a better way to check this than downloading the RPMs
and scanning them directly, since repodata don't include file
permissions:
dnf5 download --repo=rawhide --destdir /tmp/scan/ <package-list>
for f in /tmp/scan/*.rpm; do
rpm -qlp --dump "$f" \
| grep -E '/usr/lib/systemd/.*\.(service|socket|timer)' \
| grep '0100755 '
done
On an installed system it's simpler:
find /usr/lib/systemd -type f -name '*.service' -perm /111 -ls
I scanned all 1160 packages that ship unit files in rawhide
(x86_64 + noarch) and found 20 affected:
aprsd, archlinux-keyring, asahi-battery,
containernetworking-plugins, crossfire, flatpak,
gnupg2 (dirmngr, gpg-agent, keyboxd), grub2-tools,
ip-sentinel, liquidwar-server, Perlbal, restmbmaster,
scsi-target-utils, sgx-aesm, spindown, up-imapproxy,
vaultwarden, vsomeip3-routingmanager
Filed bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=2513643 (file)
https://bugzilla.redhat.com/show_bug.cgi?id=2513837 (redhat-rpm-config)
Note that these packages were built during the F45 mass rebuild,
so even if file or brp-mangle-shebangs gets fixed, these 20
packages won't pick up the fix until they are rebuilt individually.
RPM developers also pointed out in BZ#2512037 that relying on
brp-mangle-shebangs for this is fragile anyway, and specs should
just use install -m 0644.
Should we file individual bugs for these 20 packages, or fix the
specs directly? Either way they'll need a rebuild. I can go ahead
and file the bugzilla tickets if that makes sense.
--
Petr Sklenar
--
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new