|
 |
 |
 |
Changelog for rpmlint-2.3.0+git20220712.761ddf0-qubes.2.1.noarch.rpm :
* Tue Jul 12 2022 Martin Liška - Update to version 2.3.0+git20220712.761ddf0: * Improve syntax validation for digests.- Add skip-rpmlint-for-rpmlint.patch patch that skip linter this package. * Mon Jul 11 2022 mliskaAATTsuse.cz- Update to version 2.3.0+git20220711.46e6323: * systemd-tmpfiles: drop version from libtss2-fapi1 filename * Thu Jul 07 2022 mliskaAATTsuse.cz- Update to version 2.3.0+git20220707.07c9067: * Add temporary workaround for systemd package. * dbus-services: adjust power-profiles-daemon to new path (bsc#1201125) * Thu Jun 23 2022 mliskaAATTsuse.cz- Update to version 2.3.0+git20220623.5aa24e0: * checkbashism: fix stuck when run with Emacs * Add test for shell var detection in rpm-buildroot-usage * Fix rpm_buildroot_regex * Remove obsolete check no-cleaning-of-buildroot * Improve binary-or-shlib-defines-rpath error * Add `--file` as an alias for `--rpmlintrc` * Update shlib-policy-name-error score for openSUSE * Wed Jun 15 2022 mliskaAATTsuse.cz- Update to version 2.3.0+git20220615.aa4b7e2: * Rework format reporting for shlib-policy-name-error. * Increase badness for binary-or-shlib-defines-rpath. * Revert \"Use zypper for openSUSE.\" * Update shlib-policy-name-error score for openSUSE * Fri Jun 10 2022 matthias.gerstnerAATTsuse.com- Update to version 2.3.0+git20220610.33ea0cf: * systemd-tmpfiles whitelisting: also ignore -mini variants of systemd and udev * dbus-services: move wpa_supplicant.conf to /usr * dbus-services: move dnsmasq.conf to /usr * Thu Jun 09 2022 matthias.gerstnerAATTsuse.com- Update to version 2.3.0+git20220609.905726e: * systemd-tmpfiles check: raise badness to 10000 for strict config * systemd-tmpfiles: whitelist currenty set of affected packages * SystemdTmpfilesCheck: compare normalized lines for whitelistings * Wed May 25 2022 mliskaAATTsuse.cz- Update to version 2.3.0+git20220525.d213f48: * opensuse config: parse ValidLicenseExceptions * Report binary in shlib-policy-name-error error * Remove extra prints from tests. * Increase badness for executable-stack- Remove disable-SystemdTmpfilesCheck.patch. * Mon May 23 2022 Martin Liška - Add temporary patch disable-SystemdTmpfilesCheck.patch in order to build rpmlint with older rpmlint-mini. * Mon May 23 2022 mliskaAATTsuse.cz- Update to version 2.3.0+git20220523.e71c7f8: * SystemdTmpfilesCheck: add additional unit test for parsing logic * SystemdTmpfilesCheck: fix invalid member accesses * openSUSE: Do not allow files in /etc/NetworkManager/dispatcher.d anymore * Fri May 20 2022 mliskaAATTsuse.cz- Update to version 2.3.0+git20220519.82b9e76: * Release 2.3.0 * Skip shared-library-without-dependency-information for python. * Skip undefined-non-weak-symbol for python packages. * SystemdTmpfilesCheck: new check to restrict systemd-tmpfiles configuration. * Skip undefined-non-weak-symbol for python packages. * Fri May 13 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220511.fc030cd: * Add missing dependencies to setup.py * no-binary for all packages * Update docs about rpmlintrc auto-loading. * Mon May 09 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220509.ea27381: * Fix wrong git merge conflict resolution. * ErlangCheck: remove unneeded str() from the test * Fri May 06 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220506.414c402: * Temporarily disable binary-or-shlib-defines-rpath once boo#1199268 gets fixed * dbus-services: update tukitd config hash to latest reviewed version * Tue May 03 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220503.b807a0d: * dbus-services.toml: adjust whitelisting for switcheroo-control (bsc#1199065) * Mon May 02 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220502.c9ee67e: * Resolve $ORIGIN in binary-or-shlib-defines-rpath check. * Remove empty lines after for loops. * Tue Apr 26 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220425.0078554: * Fix up binary-or-shlib-defines-rpath error * Sat Apr 23 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220422.43144bd: * Improve executable-stack error. * Tue Apr 19 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220419.1dbd1ae: * dbus-services: remove gconf-polkit entry which is no longer shipped in Factory * Distinguish exit code in --strict mode. * Remove FIXME as we have a test for it. * Wed Apr 13 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220413.2dafaf8: * Add ergo user and group * Mon Apr 11 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220411.c02b482: * sudoers-whitelist: add another integration test whitelisting entry * Wed Apr 06 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220406.bcfe5ad: * sudoers whitelist: add preliminary ceph whitelisting (bsc#1196141) * Thu Mar 31 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220331.762044d: * Port opensuse checks. * Additional name cleanup in pkg.py. * lint.py: remove _check_valid_suffix and use str in (). * pkg.py cleanup * sudoers whitelist: add test entry for rpmlint-integration-test OBS package * Re-init AlternativesCheck for each package. * Wed Mar 30 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220330.4d069ea: * new whitelist restriction for /etc/sudoers.d (bsc#1172785) * Wed Mar 30 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220330.76fbb53: * Re-init AlternativesCheck for each package. * Sat Mar 26 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220325.40598ec: * dbus-services: whitelist usbguard (bsc#1196621) * Thu Mar 24 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220324.fe80080: * Test again for non-breaking space in test_tags.py. * dbus-services: add missing config whitelist for tukitd (bsc#1196149) * Wed Mar 23 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220323.1c77669: * Enhance --time-report * dbus services: adjust to accountsservice path move (bsc#1197354) * dbus services: NetworkManager-vpnc config locations (bsc#1197053) * dbus services: adjust NetworkManager-pptp config locations (bsc#1197054) * Use zypper for openSUSE. * Add SUSE version checks in spec files (#292). * Tue Mar 22 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220322.91ea8dc: * Remove garbage chars (c2a0 c2a0) from file. * Add only small badge for repology. * Add packaging status. * Wed Mar 09 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220308.a867f4a: * test_whitelist_syntax: extend the check to cover also digest entry structure * dbus whitelist: fix nodigests whitelisting, should contain the path * Remove extra empty lines. * Mon Mar 07 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220307.795b565: * D-Bus whitelistings: kpmcore: don\'t couple service file to digest * Thu Mar 03 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220303.8fe2218: * missing alpha_3 hye added for Armenian * Thu Mar 03 2022 matthias.gerstnerAATTsuse.com- Update to version 2.2.0+git20220303.3a948f5: * D-Bus services whitelist: add kpmcore (bsc#1178848) * dbus-services whitelist: add test whitelisting to cover dbus-file-parse-error * tests: add test that verifies security whitelisting syntax * security whitelistings: harmonize bug list syntax * Tue Mar 01 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220228.7070352: * FileDigestCheck: configure digest filter type per whitelisting entry * FileDigestCheck: also assert that a path key is present * dbus-services: adjust nm-priv-helper path (bsc#1194799) * dbus-services: whitelist nvme-stas (bsc#1195236) * FileDigestCheck: enable XML filtered digests for D-Bus services * FileDigestCheck: emit special {group}-file-parse-error if XML is bad * Fri Feb 25 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220225.739a708: * a8aa5cb3 pam-modules: whitelist pam-fscrypt (bsc#1195623) * ace7a9af dbus-services: whitelist nvme-stas (bsc#1195236) * b4d67b66 FileDigestCheck: enable XML filtered digests for D-Bus services * 068981ae FileDigestCheck: emit special {group}-file-parse-error if XML is bad * 816017cb dbus-services: whitelist tukitd (bsc#1196149) * 67c21c1e dbus-services: whitelist kcron helper * Wed Feb 23 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220223.8f7d3e1: * Speed up pkg.grep by utilizating mmap. * Update package dependency name. * Tue Feb 22 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220222.b4654f9: * Small tweaks to report formatting. * Start with the biggest files first in BashismsCheck. * Add new option --checks. * Mon Feb 21 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220221.0fec15f: * Speed up BashismsCheck by using md5sum of file. * Mon Feb 21 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220221.19e374d: * Include rpm2cpio (decompression and extraction) in --time-report. * Print only on decimal digit in time report. * Speed up pkg.grep. * Fix superfluous variable. * Sun Feb 13 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220211.709d2fa: * Require at least Python 3.8. * FileDigestCheck: implement support for file digest filtering * Sun Feb 06 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220204.4166915: * tests: add test case for FileDigestGroup with multiple package names * FileDigestCheck: support additional `packages = [\"pkg1\", \"pkg2\"]` syntax * FileDigestCheck: refactor digest group parsing and normalization * FileMetadataCheck: support additional `packages = [\"pkg1\", \"pkg2\"]` syntax * Wed Feb 02 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220202.cf37318: * pam-modules: remove now outdated entry for modules that moved into pam_unix * Thu Jan 27 2022 Martin Liška - Update to version 2.2.0+git20220127.05573d9: * dbus-services: whitelist NetworkManager nm-priv-helper (bsc#1194799). * Tue Jan 25 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220125.7caec47: * Add new option --ignore-unused-rpmlintrc. * Sat Jan 22 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220121.4f4f673: * Remove shared-library-not-executable for all shared libs. * Fix stupid mistake with shared-library-not-executable. * Remove duplicite argument for run_elf_checks and use PkgFile. * Set also LANGUAGE env. in ENGLISH_ENVIROMENT. * Fix LGTM warning about RE pattern. * Thu Jan 13 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220112.bfaf91a: * pam module whitelist: adjust package name for pam_winbind (bsc#1194573) * Fri Jan 07 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220106.43867d0: * Use readelf --debug-dump=no-follow-links if available. * Do not use ObjdumpParser if not needed. * Add icingaweb2 group * Filter unused-rpmlintrc-filter for late checks. * Wed Jan 05 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220105.2ac5ee1: * Use different Python package for ZStandard * Mon Jan 03 2022 mliskaAATTsuse.cz- Update to version 2.2.0+git20220103.bda86d8: * 64-bit powerpc targets do not have executable stack. * Tue Dec 21 2021 mliskaAATTsuse.cz- Update to version 2.2.0+git20211221.2fbc146: * fix connman-nmcompat whitelisting (bsc#1192827) - resides in a sub-package * Thu Dec 16 2021 mliskaAATTsuse.cz- Update to version 2.2.0+git20211216.95ed862: * Do not expect precise order of suggestions in spellchecking. * Thu Dec 16 2021 mliskaAATTsuse.cz- Update to version 2.2.0+git20211215.5196826: * Make missing-call-to-setgroups-before-setuid only warning. * Mon Dec 13 2021 pgajdosAATTsuse.com- pytest-runner is not required for build * Fri Dec 10 2021 Martin Liška - Update tarball naming to respect release version. * Fri Dec 10 2021 matthias.gerstnerAATTsuse.com- Update to version 2.2+git20211210.51d1bd9: * dbus-services whitelist: add connman nm compatibility interface (bsc#1192827) * Wed Dec 08 2021 mliskaAATTsuse.cz- Update to version 2.2+git20211208.c7ec6c4: * Fix typo in comment. * Release 2.2.0 * configs/Fedora: Sync Fedora rpmlint policies back upstream * Tue Nov 30 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211130.83af44b: * Add SUSE licenses generation script. * Sort input .rpm files so that the output is stable. (boo#1193189). * Fri Nov 26 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211126.ebc84d5: * allow rpmdiff for installed packages * Add diff.py wrapper script. * Fri Nov 26 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211125.fcbf5ab: * Make missing-PT_GNU_STACK-section more sensitive. * Tue Nov 23 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211122.36cebbc: * dbus-services: fix package name for setroubleshoot entries * Sat Nov 20 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211118.f21c64f: * duplicate postfix entry for postfix-bdb, whitelistings are tied to pacakges in rpmlint2 and need to be there for every package * Allow multiple spaces between paren * Mon Nov 15 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211113.372a30e: * Misplaced spaces causes regex to not match. * Add debuginfod user and update message. * Wed Nov 10 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211110.8430dc4: * polkit-rules-whitelist: follow-up whitelisting for gnome-initial-setup (bsc#1192542) * Wed Nov 10 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211109.f2e93f8: * Add missing re.compile. * Prevent duplicate files in lint input * Sat Nov 06 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211105.14a37df: * Fix backward compatibility with rpmlintrc files. * Fixed bug where a valid symlink is reported as invalid. This appears to be a regression from rpmlint 1. Comparing the two reveals that the comparison of link to path.parent would never make sense, and comparing link to path.name would resemble rpmlint 1\'s behavior. * dbus-services: add setroubleshoot whitelisting (bsc#1186344) * Wed Nov 03 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211103.8d20461: * permissions-whitelist: update texlive-filesystem digests * permissions-whitelist: update sendmail digests * Enhance error message of LibraryDependencyCheck. * Mon Nov 01 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211101.f2e73fe: * Fix no-library-dependency-for. * Sun Oct 31 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211027.7242d3d: * dbus-services: adjust wicked whitelisting to new paths (bsc#1192033) * Add new LibraryDependencyCheck. * Rework the lib_regex pattern * security whitelistings: test whitelistings for file-digest-mismatch errors * scoring.toml: fix alphabetical order of permissions-file errors * security whitelistings: add badness for file-digest-mismatch errors * Fri Oct 22 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211022.a5287ad: * Mitigate Perl false positives for no-dependency-on. * Thu Oct 21 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211021.74e867e: * Checking libalternatives entries and links. * Fix -r argument. * opensuse.toml: add permissions-parse-error to BlockedFilters * dbus-services: adjust digest for test whitelisting (need a different file there) * polkit-rules-whitelist: fix package name for test whitelisting * Remove unused VS code settings. * Whitelisting pam_u2f module (bsc#1190790) * Tue Oct 19 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211019.ca2517e: * Ignore library names that have number in their names. * Tue Oct 19 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211018.b53feea: * Tweak shlib-policy-name-error. * Fri Oct 15 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211015.6dc5311: * Drop badness of shlib-policy-name-error for now. * Thu Oct 14 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211014.e3fbbb9: * Update shlib-policy-name-error. * Thu Oct 14 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211014.bddee7c: * Trigger shlib-policy-name-error only for lib * packages. * Thu Oct 14 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211013.5ed66cd: * Update wording for shlib-policy-name-error. * Fix changelog-time-in-future regarding timezones. * Tue Oct 12 2021 paolo.peregoAATTsuse.com- Update to version 2.1+git20211012.c27e0fe: * Adding whitelisting for pam_ssh_agent_auth. bsc#1190983 * Mon Oct 11 2021 mliskaAATTsuse.cz- Update to version 2.1+git20211011.4290515: * Enable shlib-policy-name-error error. * Mon Oct 11 2021 Martin Liška - Update to version 2.1+git20211011.a28fc6d: * Support %autochangelog in %changelog. * remove /run from disalloweddirs * Fix missing-dependency-on check. * dbus-services whitelisting: add power-profiles-daemon (bsc#1189900) * security whitelistings: add whitelistings for OBS integration test package * PolkitCheck: be robust against dead symlinks in actions directory * SUIDPermissionsCheck: remove unused permissions-ghostfile error * *-file-ghost descriptions: fix texts that are for some reason incomplete- Fixes boo#1190387. * Mon Oct 11 2021 Martin Liška - Enable changesgenerate. * Wed Oct 06 2021 Matthias Gerstner - Update to opensuse tip: * dbus-services: add oddjob-mkhomedir which got lost during migration (bsc#1169494) * Fri Oct 01 2021 Martin Liška - Update to tip: * fix lto-no-text-in-archive for rx port. * Thu Sep 30 2021 Martin Liška - Updade to opensuse tip: * skip %ghost files in SUIDPermissionsCheck. * Fri Sep 24 2021 Johannes Segitz - Update to 2.1+git20210924.ad0cf53 * Copied additional systemd whitelistings to match systemd-mini * Thu Sep 23 2021 Johannes Segitz - Update to version 2.1+git20210923.5ff1403 * whitelist pam_systemd.so for systemd-mini * Thu Sep 23 2021 Johannes Segitz - Update to version 2.1+git20210923.a41591b * whitelist pam_systemd_home.so for systemd-experimental * Wed Sep 22 2021 Johannes Segitz - Update to version 2.1+git20210922.d20a3f1 * Added mechanism to add exceptions for %ghost\'d files * Remove deprecated entries for world-writable entries * Remove malcontent whitelisting * Remove storeBackup cron whitelisting * Some path and package name fixes * Fri Sep 17 2021 Matthias Gerstner - Synchronize security whitelistings with whitelists from old rpmlint 1. This should fix some package build errors like in sssd.- Use correct camel case package names for packages like NetworkManager in whitelists. This should fix some package build errors.- Some general cleanup of whitelists. * Wed Sep 15 2021 Martin Liška - Bump to tip (various security fixes). * Sun Sep 05 2021 Martin Liška - Skip .cargo-checksum.json files in hidden-file-or-dir. * Thu Sep 02 2021 Martin Liška - Fix PieExecutables matching. * Thu Sep 02 2021 Martin Liška - KMP policy: support legacy \'packageand\' directive in Supplements (boo#1190103). * Wed Sep 01 2021 Martin Liška - Handle empty glibc archives (starting with version 2.34). * Fri Aug 27 2021 Martin Liška - Update package name for -M test. * Thu Aug 26 2021 Martin Liška - Add test multibuild target and reduce BuildRequirements for rpmlint package itself. * Wed Aug 25 2021 Martin Liška - Bump to opensuse tip. * Wed Aug 18 2021 Matthias Gerstner - whitelist deepin-api D-Bus services (bsc#1070943) * Wed Aug 18 2021 Martin Liška - Bump to version 2.1. * Fri Aug 06 2021 Martin Liška - Fix variable description expansion. * Thu Aug 05 2021 Martin Liška - Reduce Requirements for rpmlint-strict package. * Wed Aug 04 2021 Matthias Gerstner - whitelist oddjob-gpupdate PAM and D-Bus (bsc#1188680) * Thu Jul 22 2021 Martin Liška - Bump to tip (adds --mini-mode argument). * Thu Jul 01 2021 Martin Liška - Bump to tip (fix not working -i option). * Tue Jun 29 2021 Martin Liška - Bump to tip. * Tue Jun 29 2021 Martin Liška - Make rpmlint-strict only a simple package with one config file. * Tue Jun 29 2021 Martin Liška - Add Conflicts directive. * Tue Jun 29 2021 Martin Liška - Use BuildIgnore: rpmlint-strict in order to fix boo#1187749. * Fri Jun 25 2021 Martin Liška - Bump to tip.- Rename scoring-strict.toml to scoring-strict.override.toml in order to use override mechanism. * Thu Jun 24 2021 Martin Liška - Removed legacy patches: * extend-suse-conffiles-check.diff * docdata-examples.diff * devel-provide-is-devel-package.diff * fix-diag-sortorder.diff * check-for-self-provides.diff- Add disable-flake.patch patch. * Thu Jun 24 2021 Martin Liška - Add rpmlint-strict sub-package that includes scoring-strict.toml. * Thu Jun 24 2021 Martin Liška - Bump to tip: adds scoring-strict.toml config and BlockedFilters. * Thu Jun 24 2021 Martin Liška - Bump to tip, includes fix for Rust libraries. * Thu Jun 17 2021 Martin Liška - Install configs with 644. * Thu May 27 2021 Martin Liška - Update to Rpmlint 2.0: * RPMLint now is a \"normal\" Python application and now supports being imported like a standard Python module! This means that all the normal use-cases for RPMLint are still supported, but now you can make it a part of larger Python-based applications or services. * RPMLint uses a declarative TOML-based syntax for configuring RPMLint policy instead of Python code. * RPMLint now has an override system for the descriptions shown for various checks, so that distributions who want to give specific policy information can do so without patching the code. * RPMLint includes many more checks! Nearly all of the generally useful checks created by the openSUSE community have been merged into the tree, so distributions can now benefit from a wider offering of checks to implement policy enforcement. * RPMLint is Python 3 only and now supports Python 3.6 and newer. * RPMLint is now built and installed like a standard Python application using setuptools.- Removed legacy patches: * invalid-filerequires.diff * no-badness-return.diff * no-doc-for-lib.diff * only-reg-files-are-scripts.diff * remove-ghostfile-checks.diff * rpm415-workaround.diff * rpmgroup-checks.diff * rpmlint-suse.diff * suse-binarieschecks.diff * suse-checks.diff * suse-filter-exception.diff * suse-filter-more-verbose.diff * suse-ignore-specfile-errors.diff * suse-pkg-config-check.diff * suse-python3-naming-policy.diff * suse-shlib-devel-dependency.diff * suse-skip-macro-expansion.diff * suse-speccheck-utf8.diff * suse-url-check.diff * suse-version.diff * yast-provides.diff * 0001-ZipCheck-Also-ignore-RuntimeError.patch * accept-licenses-with-plus.patch * add-check-for-a-non-zero-.text-segment-in-.a-archive.patch * rpmlint-slpp-NUM-NUM.patch * rpmlint-tests-sle15.patch * suse-rpmlint-all-pie.patch * suse-spdx-license-exceptions.patch * suse-tests-without-badness.patch- Removed config fileS: * config * licenses.config * pie.config- Removed misc files: syntax-validator.py, README.packaging.txt, rpmlint-1.11.tar.gz, rpmlint-checks-master.tar.xz and rpmlint-tests-84.87+git20210226.d6b66e2.tar.xz. * Fri May 21 2021 Ludwig Nussel - whitelist setroubleshoot (boo#1186344) * Wed May 12 2021 Ludwig Nussel - whitelist systemd-homed (boo#1185285) * Fri May 07 2021 Matthias Gerstner - fix whitelisting for kdiskmark service (bsc#1182521) * Wed Mar 31 2021 Wolfgang Frisch - whitelist D-Bus Service org.kde.filesharing.samba.service (bsc#1175633) * Tue Mar 30 2021 Wolfgang Frisch - whitelist D-Bus Service org.jonmagon.kdiskmark.service (bsc#1182521) * Fri Feb 26 2021 Stephan Kulow - Add accept-licenses-with-plus.patch to accept any license ending with a + (as indicated in the SPDX syntax) * Fri Feb 26 2021 Stephan Kulow - Remove licenses ending with + from valid license array * Mon Feb 22 2021 Matthias Gerstner - whitelist pam_sss_gss.so PAM module (bsc#1182509) * Wed Feb 03 2021 chrisAATTcomputersalat.de- add \'otobo\' group/id * Mon Feb 01 2021 Stephan Kulow - Update valid spdx license exceptions- Allow the + version of all valid licenses (to avoid having to fix the parser) * Fri Jan 15 2021 Christopher Yeleighton - Fix a typo in suse-branding-wrong-branding-supplement * Sun Jan 10 2021 Martin Hauke - Add user \"h2o\" and group \"h2o\" for the h2o webserver * Tue Nov 17 2020 matthias.gerstnerAATTsuse.com- Update to version master: * Permissions: be robust against variables.conf not existing * CheckSUIDPermissions: enhance parser to support new permissions variables * Wed Nov 04 2020 Malte Kraus - allow pam_faillock.so PAM module (bsc#1171562) * Fri Oct 30 2020 Matthias Gerstner - whitelist malcontent PAM module (bsc#1177974) * Mon Oct 19 2020 Илья Индиго - Add user \"fluidsynth\" for FluidSynth General Midi daemon. * Mon Oct 12 2020 Matthias Gerstner - whitelist plasma5-disks smartmon helper (bsc#1176742) * Thu Oct 01 2020 Matthias Gerstner - whitelist D-Bus files for powerdevil chargethreshold (bsc#1176474) * Thu Oct 01 2020 Paolo Stivanin - Add \'gerbera\' as standard user and group * Fri Sep 11 2020 Ákos Szőts - Alphabetise StandardGroups and StandardUsers- Add \'radicale\' as a standard user and group * Fri Aug 14 2020 Marco Strigl - add user \"jvb\", \"jibri\", \"jicofo\" and group \"jitsi\" for Jitsi videomeeting service * Fri Jul 31 2020 matthias.gerstnerAATTsuse.com- Update of rpmlint-checks to version master: * Introduce new metadata whitelist type and related checks. Device files and world-writeable files will now be covered by new whitelists from rpmlint-security-whitelistings.- config: Enable new CheckWorldWritable and CheckDeviceFiles * Fri Jul 24 2020 matthias.gerstnerAATTsuse.com- whitelist kanidm PAM module (bsc#1173387) * Wed Jul 15 2020 matthias.gerstnerAATTsuse.com- whitelist D-Bus files for libvirt-dbus (bsc#1173093) * Wed Jul 08 2020 Илья Индиго - Add user and group \"ptokax\" for PtokaX DC++ hub. * Fri Jun 19 2020 Egbert Eich - Add user/group \'conman\' and \'munge\' and group \'warewulf\'. * Fri Jun 12 2020 cunixAATTmail.de- Add \'dnscrypt\' to StandardGroups and StandardUsers for package dnscrypt-proxy * Thu Jun 04 2020 matthias.gerstnerAATTsuse.com- whitelist pam_setquota (bsc#1171563) * Wed Jun 03 2020 Martin Hauke - Add \'_gns3\' to StandardGroups and StandardUsers * Mon May 25 2020 matthias.gerstnerAATTsuse.com- whitelist pam_usertype (bsc#1171564) * Wed May 20 2020 Johannes Segitz - whitelist cockpit PAM modules (bsc#1169614) * pam_cockpit_cert * pam_ssh_add * Wed May 20 2020 Adrian Schröter - Add daapd user and group for new forked-daapd package * Tue May 19 2020 Thomas Renninger - Add \'_cscreen\' to StandardGroups and StandardUsers * Tue May 12 2020 matthias.gerstnerAATTsuse.comCleanup of deprecated DBUSServices.WhiteList entries:- ca.desrt.dconf.service: this service was changed by upstream from a system-wide service to a session based service. The latter doesn\'t require a whitelisting any more.- wicked services (network-nanny.conf, wicked-dhcp4.conf, wicked-dhcp6.conf, wicked-autoip4.conf, wicked.conf): these have been renamed in August 2013 to org.opensuse.Network. *.conf. The old names probably never got released.- nfs-ganesha.service: A D-Bus file of that name probably never existed, there\'s just a regular systemd unit of that name.- org.drbd.drbdmanaged.conf, org.drbd.drbdmanaged.service: drbdmanage was just recently removed from Factory via sr#798685, because it is Python2 only and unmaintained.- org.freedesktop.NetworkManager.service: was removed in 2012, Factory revision 118, `Remove dbus system-service for NetworkManager, to prevent warnings about it not being running (bnc#738596)`.- org.kde.auth.conf: was from kdelibs4, removed from Factory in late 2019 via sr#738276 with the rest of kde4.- org.kde.kcontrol.kcmkdm.conf, org.kde.kcontrol.kcmkdm.service: was part of kdebase4-workspace, got deleted from Factory with the rest of kde4.- org.kde.kcontrol.kcmkwallet.conf, org.kde.kcontrol.kcmkwallet.service: they got renamed to kcmkwallet5.- org.opensuse.openqa.conf: upstream replaced a D-Bus interface with HTTP.- org.opensuse.zoneswitcher.service, org.opensuse.zoneswitcher.conf: the fwzs package got removed together with SuSEfirewall2 via sr#713580.- org.selinux.service: isn\'t included any more in our packaging of policycoreutils.- thunderbolt.conf, thunderbolt.service: this service never went live in Factory.- yum-updatesd.conf: yum was removed from Factory via sr#749200- openattic.conf, openattic.service: was part of SES3 but seems to have been dropped from SES4 and newer. Cleanup of deprecated PAMModules.WhiteList entries:- pam_cgroup.so: libcgroup was removed from Factory via sr#589236, due to conflicts with systemd and dead upstream.- pam_ck_connector.so: ConsoleKit was last used in SLE-11. It\'s long dead.- pam_cryptpass.so: cryptconfig was last shipped in SLE-12:GA and Leap 42.3. Got removed via FATE#323541.- pam_envoy.so: was removed from Factory because it failed to build for >= 6 weeks, see sr#737277- pam_fprint.so: was replaced by fprintd, see delete sr#220831.- pam-modules package (pam_homecheck.so, pam_pwcheck.so, pam_unix2.so): the pam-modules package was removed in 2017 from Factory, see sr#540149.- pam_mate_keyring.so: was never shipped, the packager switched to a different keyring daemon instead.- pam_p11_opensc.so, pam_p11_openssh.so: these two have been merged into pam_p11.so.- pam_rpasswd.so: was part of pwdutils which was replaced by shadow utilities in 2012 via sr#139683.- pam_smb_auth.so: was last part of SLE-12:GA and Leap 42.3. no upstream development, replaced by pam_winbind, see sr#478612- pam_smbpass.so: was removed in upstream version 4.4.2, because it loaded GPLv3 code into the address space of system services. somewhat replaced by pam_winbind. see https://bugzilla.redhat.com/show_bug.cgi?id=952766.- pam_tally.so: was removed from the pam package in 2013, replaced by tally2 obviously, the old one was buggy. * Mon May 11 2020 matthias.gerstnerAATTsuse.com- whitelist oddjob D-Bus services and PAM module (bsc#1169494) * Sun Apr 12 2020 Johannes Weberhofer - Added \'coturn\' to StandardGroups and StandardUsers * Tue Mar 31 2020 matthias.gerstnerAATTsuse.com- Update to version master: * Whitelisting: avoid duplicate checks / error messages for the same files * Whitelisting: fix whitelisting checks when files are symbolic links * Mention upstream repo in README * Fri Mar 27 2020 Axel Braun - Bug 1167431 - AUDIT-0: User/group orthanc for rpmlint * Thu Feb 20 2020 Malte Kraus - config: enable MixedFileOwnerships lint * Thu Feb 20 2020 Dr. Werner Fink - config: add \'mktex\' to StandardUsers (boo#1159740) * Mon Feb 17 2020 matthias.gerstnerAATTsuse.com- whitelist new mariadb pam module \"pam_user_map.so\" (bsc#1163362) * Thu Feb 06 2020 malte.krausAATTsuse.com- Update to version master: * CheckSUIDPermissions.py: fix permissions.d checks * add a lint to catch insecure mixed file/directory ownership similar to CVE-2019-3689 * Thu Feb 06 2020 malte.krausAATTsuse.com- Update to version 84.87+git20200206.7e2b64f: * permissions2: test that allowed permissions.d drop-ins work * test for new file-parent-ownership-mismatch lint * Fri Jan 31 2020 matthias.gerstnerAATTsuse.com- Whitelist a batch of PAM modules that have been forgotted to be whitelisted in the past, or have never been requested to be reviewed before (bsc#1150178). Since we want to add badness to the PAM warning in rpmlint we need to add those entries to avoid build errors of existing packages in Factory. * Thu Jan 30 2020 James Fehlig - config: add \'sanlock\' to StandardGroups and StandardUsers- config: add \'libvirt\' to StandardGroups * Thu Jan 30 2020 jsegitzAATTsuse.de- Update to version master: * CheckCronJobs: correct cronjob-unauthorized-file explanation * Use named constants to check file modes * CheckSUIDPermissions.py: check new permission paths * Wed Dec 18 2019 matthias.gerstnerAATTsuse.com- finally enable the new CheckCronJobs, the check is now available and should work in rpmlint-mini (bsc#1150175) * Mon Dec 16 2019 Nathan Cutler - config: add \'cephadm\' to StandardGroups and StandardUsers * Mon Dec 16 2019 matthias.gerstnerAATTsuse.com- whitelist pam_cgfs PAM module (bsc#1150519) * Mon Dec 16 2019 matthias.gerstnerAATTsuse.com- whitelist pam_pwquality PAM module (bsc#1150520) * Mon Dec 16 2019 matthias.gerstnerAATTsuse.com- whitelist pam_cifscreds PAM module (bsc#1150527) * Tue Dec 10 2019 matthias.gerstnerAATTsuse.com- Update to version master: * new common whitelisting code for CheckPolkitPrivs and CheckCronJobs * Thu Nov 28 2019 Malte Kraus - whitelist sssd infopipe (bsc#1157663)- whitelist sysprof3 D-Bus services (bsc#1151418) * Tue Oct 15 2019 Ludwig Nussel - filter install-info warnings. Handled by file triggers now (boo#1152169) * Mon Oct 07 2019 mlsAATTsuse.de- backport rpm415 workaround from upstream new patch: rpm415-workaround.diff * Mon Sep 30 2019 Ondřej Súkup - update add-check-for-a-non-zero-.text-segment-in-.a-archive.patch * fix condition for path * Fri Sep 20 2019 Malte Kraus - whitelist pam_envoy (bsc#1150525) * Fri Sep 20 2019 Ondřej Súkup - update add-check-for-a-non-zero-.text-segment-in-.a-archive.patch * dont check empty .text section on GHC libraries * Tue Sep 17 2019 dmuellerAATTsuse.com- Update rpmlint-checks to version master: * CheckFilelist: Add /usr/libexec to set of good prefixes * Wed Aug 28 2019 tchvatalAATTsuse.com- Update to version 84.87+git20190828.2c92180: * Revert \"added LTO errors as expected for debug tests\" * Wed Aug 28 2019 tchvatalAATTsuse.com- Update to version 84.87+git20190828.8fa8ac5: * Do not use -flto for debug tests. * Wed Aug 28 2019 Tomáš Chvátal - Do not validate rpm groups to avoid rpmlint warning as the group is not really mandatory (fate#326485) * Thu Aug 22 2019 Ludwig Nussel - whitelist systemd-portabled dbus files (boo#1145639) * Tue Aug 20 2019 kukukAATTsuse.com- Update to version master: * Allow /usr/etc as discussed on opensuse-factory and opensuse-packaging * Wed Aug 14 2019 Marketa Calabkova - Add user/group zabbix and zabbixs (bsc#1144018) * Fri Aug 09 2019 Martin Liška - Update add-check-for-a-non-zero-.text-segment-in-.a-archive.patch patch to align with: 38fc30cafe99d38059ca54b98bc87f5544f0bb4e * Thu Aug 08 2019 Dominique Leuenberger - Add Development/Languages/Go group. * Thu Aug 08 2019 Martin Liška - Update add-check-for-a-non-zero-.text-segment-in-.a-archive.patch patch to align with: 80126f7c7854d962cc64e54a6ab7e97067bb490d * Fri Aug 02 2019 Martin Liška - Update add-check-for-a-non-zero-.text-segment-in-.a-archive.patch patch to align with: https://github.com/rpm-software-management/rpmlint/commit/c59324fd68ba86c8382fe09d43f12de32d764354 * Sun Jul 28 2019 Martin Liška - Update add-check-for-a-non-zero-.text-segment-in-.a-archive.patch patch to: https://github.com/rpm-software-management/rpmlint/commit/97d6caf9ac3eb011e3f30dbc473f079b20fb56f9 * Mon Jul 22 2019 Martin Liška - Add add-check-for-a-non-zero-.text-segment-in-.a-archive.patch as a backport of: https://github.com/rpm-software-management/rpmlint/commit/2c809f34354d6ea690986541b268d47a3ca59092 * Tue May 14 2019 opensuse-packagingAATTopensuse.org- Update to rpmlint-checks to version master: * CheckDBUSServices: add additional directory to cover * Xinetd check making sure no packages use it wrt fate#323373 (#26) * Wed May 08 2019 jsegitzAATTsuse.com- Too trigger happy, adding back * ca.desrt.dconf.service * org.freedesktop.ColorManager.conf * Wed May 08 2019 jsegitzAATTsuse.com- Removed whitelisted DBUS files: * ConsoleKit.conf * NetworkManager-frontend.conf * Upstart.conf * backup-manager.conf * ca.desrt.dconf.service * cdemud-dbus.conf * com.redhat.storaged.conf * com.redhat.storaged.service * com.redhat.tuned.service * de.berlios.smb4k.mounthelper.conf * de.berlios.smb4k.mounthelper.service * hal.conf * kerneloops.dbus * net.hadess.SensorProxy.service * nm-avahi-autoipd.conf * nm-dhcp-client.conf * nm-novellvpn-service.conf * openqa-scheduler.service * openqa-websockets.service * org.blueman.Applet.service * org.freedesktop.ColorManager.conf * org.freedesktop.ConsoleKit.service * org.freedesktop.ModemManager.conf * org.freedesktop.ModemManager.service * org.freedesktop.PolicyKit.conf * org.freedesktop.PolicyKit.service * org.freedesktop.UDisks.conf * org.freedesktop.UDisks.service * org.freedesktop.colord-sane.conf * org.freedesktop.colord-sane.service * org.gnome.SettingsDaemon.DateTimeMechanism.conf * org.gnome.SettingsDaemon.DateTimeMechanism.service * org.kde.baloo.filewatch.conf * org.kde.baloo.filewatch.service * org.kde.kalarmrtcwake.conf * org.kde.kalarmrtcwake.service * org.kde.kcontrol.k3bsetup.conf * org.kde.kcontrol.k3bsetup.service * org.kde.kcontrol.kcmlightdm.conf * org.kde.kcontrol.kcmlightdm.service * org.kde.kcontrol.kcmremotewidgets.conf * org.kde.kcontrol.kcmremotewidgets.service * org.kde.nepomuk.filewatch.conf * org.kde.nepomuk.filewatch.service * org.kde.polkitkde1.helper.conf * org.kde.polkitkde1.helper.service * org.neard.service * org.opensuse.BackupManager.service * org.opensuse.YaST.modules.conf * org.opensuse.YaST.modules.service * org.opensuse.usbauth.service * org.opensuse.yast.SCR.conf * org.opensuse.yast.SCR.service * org.selinux.conf * org.synce.dccm.conf * org.synce.dccm.service * os-autoinst-openvswitch.service * pam_dbus.service * podsleuth.conf * rebootmgr.service * switcheroo-control.service * teamdAATT.service * webyast.permissions.conf * webyast.permissions.service.service They\'re not used anymore in current products, were never active or erroneously added. For details please see https://pes.suse.de/Maintenance-Security/Whitelists/cleanup_dbus/ * Tue May 07 2019 Malte Kraus - Whitelisted certmonger (bsc#1129452) * Fri Apr 12 2019 Thomas Bechtold - Add missing usernames for OpenStack services and drop the old names (which had the openstack- prefix) * Tue Mar 05 2019 mvetterAATTsuse.com- Add user/group \'minetest\' for Minetest 5.0.0 (bsc#1127911) * Mon Mar 04 2019 opensuse-packagingAATTopensuse.org- Update to version master: * CheckPolkitPrivs: fix new rules.d check to use extracted rpm path * Wed Feb 27 2019 opensuse-packagingAATTopensuse.org- Update rpmlint-checks to version master (bsc#1125314): * coding style: fix indentation to satisfy flake8 travis-ci test * CheckPolkitPrivs: implement new check for files put into rules.d dirs * CheckPolkitPrivs: separate and refactor check for actions * CheckPolkitPrivs: separate and refactor check of polkit-default-privs.d * CheckPolkitPrivs: remove oudated PolicyKit path * CheckPolkitPrivs: clearer error message for files in /etc/polkit-default-privs.d * Thu Feb 14 2019 jsegitzAATTsuse.com- Whitelisted pam_p11 (bsc#1123916) * Sat Feb 02 2019 Dirk Mueller - add 0001-ZipCheck-Also-ignore-RuntimeError.patch (bscs#1124054) * Fri Feb 01 2019 Axel Braun - added user/group tryton (GNU Health) * Mon Jan 14 2019 Dirk Mueller - disable UseVersionInChangelog by default * Sat Jan 12 2019 Dirk Mueller - update to 1.11: * Avoid exception on inaccessible scripts * Print out the error content on UnicodeError to make flake8 happy * Fix flake8 warning about missing space around operators * Use compressions when checking for backup files * Account for arch specific code in /usr/share * Check for installed libtool wrapper files * Check for missing optional dependencies * Consider gnome help for doc files * Check for noarch package with files in lib64 * Verify if description is longer than summary * Explicitly tell users how to set URL * Ignore pytest_cache directory * confusing-invalid-spec-name * Ignore orig/rej leftovers after patching * Reenable Travis testing against Fedora Rawhide * Check all sections that should not use %buildroot in them * Put in default buildroot value used by Fedora/openSUSE * Stricter interpreter check * Use compileall to avoid %buildroot to be in pyc * Drop deprecated config file usage, 0.88 is pretty old anyway * Adjust Version to not print outdated Copyright * Rework Travis checks against latest Centos and Fedora releases * Fix exception handling * Fix various flake8-import-order test regressions * Blacklist newer pycodestyle warnings * Fix compatibility with file 5.33+ * Python 3.7.0b5 magic number is 3394 * Update TagsCheck.py * pyc related tests: DRY * Fix getting pyc mtime on Python 3.7 * Always import XDG desktop files as utf8 * Fix Flake8 warnings * Update Magic values for Python 3.7 (Fixes #123) * Improve XDG Menu checks stability * Test added. * Ignore useless-provides on debuginfo provides (#112) * Properly handle the exception on missing files * Avoid calling close on undefined fd variable * Code formatting fixed to meet the style. * Modify FakePkg to let the test.sh pass. * _sourcedir macro defined. * Avoid summary-not-capitalized warning on digits * Avoid catch-all except statements * Use ImportError to avoid catch-all except: statements * Handle E741: ambiguous identifier * Accept python(abi) as a valid versioned python dependency * Binariescheck: Check for chroot/chdir on ARM, PPC * Avoid false positives on is_elf check * Handle %post scripts that contain non-ascii characters * Further tweak lib_regex * split wrong-script-interpreter into env-script-interpreter * Validate Appdata also when appstream-util is unavailable * Remove dependency on unicodedata * Lower false-positives on summary-not-capitalized * Tighten wrong-script-interpreter check to lower false positives * Check for unexpanded macros in more Tags * Rename local file variable to fname * Skip binaryinfo-readelf-failed on non-ELF archives * Add check for validating file extensions * Do not report error if call positions are unknown * Execute chroot tests also on x86 rpms * Tighten lib_regex to avoid false positive in python bindings * Better details for wrong-script-interpreter * Extend scm_regex to capture more SCM system files * AppDataCheck: Pass --nonet to appstream-util if NetworkEnabled is False * test: Fix cpio location in centos6 * test: Combine run commands in fedoradev container * test: Remove dnf upgrade from fedora containers * test: Dockerfile whitespace tweaks- drop patches that were upstreamed: 0001-Accept-python-abi-as-a-valid-versioned-python-depend.patch, 0001-Always-import-XDG-desktop-files-as-utf8.patch, 0001-Avoid-calling-close-on-undefined-fd-variable.patch, 0001-Avoid-false-positives-on-is_elf-check.patch, 0001-Backport-d8f423b575e8be387d33bc3af176baf978efacbb.patch, 0001-Binariescheck-Check-for-chroot-chdir-on-ARM-PPC.patch, 0001-Execute-chroot-tests-also-on-x86-rpms.patch, 0001-Extend-scm_regex-to-capture-more-SCM-system-files.patch, 0001-Fix-compatibility-with-file-5.33.patch, 0001-Handle-post-scripts-that-contain-non-ascii-character.patch, 0001-Improve-XDG-Menu-checks-stability.patch, 0001-Tighten-wrong-script-interpreter-check-to-lower-fals.patch, 0001-split-wrong-script-interpreter-into-env-script-inter.patch, 0003-Tighten-lib_regex-to-avoid-false-positive-in-python-.patch, 0007-Validate-Appdata-also-when-appstream-util-is-unavail.patch, better-wrong-script.diff, buildroot-doc.diff, buildroot-in-scripts.diff, compressed-backup-regex.diff, confusing-invalid-spec-name.diff, description-check.diff, drop-unicodedata-dep.diff, ignore-readelf-ar-error.diff, libtool-wrapper-check.diff, noarch-lib64.diff, omit_BUILDROOT_from_pyo_files.patch, selfconflicts-provide.diff, stricter-interpreter-check.diff, suse-whitelist-opensuse.diff, update-magic-values-python-37.patch, usr-arch.diff * Wed Jan 09 2019 opensuse-packagingAATTopensuse.org- Update to version master: * Flake8 fix * Wed Jan 09 2019 opensuse-packagingAATTopensuse.org- Update rpmlint-checks to version master (bsc#1116686): * Ignore decoding errors as we\'re not sure we know the encoding * Use UTF-8 encoding when opening .pc file (#42) * whitelist otrs permission file (#41) * Relax various flake8 warnings * Handle \'-n\' option for %service_del_preun %service_del_postun * There isn\'t a good standard, whether the directory should be called \'tests/\' or \'test/\' * Wed Jan 02 2019 Martin Liška - Add 0001-Backport-d8f423b575e8be387d33bc3af176baf978efacbb.patch
|
|
|