Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package rpmlint for openSUSE:Factory checked in at 2026-07-18 22:24:12 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/rpmlint (Old) and /work/SRC/openSUSE:Factory/.rpmlint.new.24530 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "rpmlint" Sat Jul 18 22:24:12 2026 rev:543 rq:1365933 version:2.9.0+git20260715.7b097339 Changes: -------- --- /work/SRC/openSUSE:Factory/rpmlint/rpmlint.changes 2026-07-02 20:07:39.209638146 +0200 +++ /work/SRC/openSUSE:Factory/.rpmlint.new.24530/rpmlint.changes 2026-07-18 22:24:16.060623161 +0200 @@ -1,0 +2,9 @@ +Wed Jul 15 10:50:55 UTC 2026 - Wolfgang Frisch <[email protected]> + +- Update to version 2.9.0+git20260715.7b097339: + * sysctl-whitelist: adjusted 50-coredump.conf digest for systemd (bsc#1267504) + * filedigestcheck: use custom socket unit parser to support multiple keys + * dbus-services: whitelist cosmic-greeter (bsc#1259401) + * dbus-services: adjust iwd configuration digest (bsc#1270347) + +------------------------------------------------------------------- Old: ---- rpmlint-2.9.0+git20260629.bd947d09.tar.xz New: ---- rpmlint-2.9.0+git20260715.7b097339.tar.xz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ rpmlint.spec ++++++ --- /var/tmp/diff_new_pack.rzZ64H/_old 2026-07-18 22:24:16.900651304 +0200 +++ /var/tmp/diff_new_pack.rzZ64H/_new 2026-07-18 22:24:16.900651304 +0200 @@ -23,7 +23,7 @@ %define name_suffix -%{flavor} %endif Name: rpmlint%{name_suffix} -Version: 2.9.0+git20260629.bd947d09 +Version: 2.9.0+git20260715.7b097339 Release: 0 Summary: RPM file correctness checker License: GPL-2.0-or-later ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.rzZ64H/_old 2026-07-18 22:24:16.956653180 +0200 +++ /var/tmp/diff_new_pack.rzZ64H/_new 2026-07-18 22:24:16.960653314 +0200 @@ -1,6 +1,6 @@ <servicedata> <service name="tar_scm"> <param name="url">https://github.com/rpm-software-management/rpmlint.git</param> - <param name="changesrevision">bd947d09488873488dc1bd4174f143077694bf2d</param></service></servicedata> + <param name="changesrevision">7b097339a5c2584f8259e7a0cd5cb5766310c557</param></service></servicedata> (No newline at EOF) ++++++ rpmlint-2.9.0+git20260629.bd947d09.tar.xz -> rpmlint-2.9.0+git20260715.7b097339.tar.xz ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/rpmlint-2.9.0+git20260629.bd947d09/configs/openSUSE/dbus-services.toml new/rpmlint-2.9.0+git20260715.7b097339/configs/openSUSE/dbus-services.toml --- old/rpmlint-2.9.0+git20260629.bd947d09/configs/openSUSE/dbus-services.toml 2026-06-29 16:53:33.000000000 +0200 +++ new/rpmlint-2.9.0+git20260715.7b097339/configs/openSUSE/dbus-services.toml 2026-07-15 12:50:14.000000000 +0200 @@ -1075,7 +1075,7 @@ package = "iwd" type = "dbus" note = "imported from rpmlint1 DBUSServices.WhiteList" -bug = "bsc#1108037" +bugs = ["bsc#1108037", "bsc#1270347"] [[FileDigestGroup.digests]] path = "/usr/share/dbus-1/system-services/net.connman.iwd.service" digester = "shell" @@ -1083,7 +1083,7 @@ [[FileDigestGroup.digests]] path = "/usr/share/dbus-1/system.d/iwd-dbus.conf" digester = "xml" -hash = "ed28e2c31bb8c89736c46374491f8c470ad5c73b961d1b5f71aef4ad134e492e" +hash = "c19903cb491eb728e94439b43501c67191c6d97f098aaf1abadc5f1b750a111b" [[FileDigestGroup]] package = "connman-nmcompat" @@ -1831,3 +1831,13 @@ path = "/usr/share/dbus-1/system.d/org.opensuse.tukit.Updated.conf" digester = "xml" hash = "abf27e413feacafdb95e5b48ae2d75f501d506feb6a0a46a96fab338bde1fd13" + +[[FileDigestGroup]] +package = "cosmic-greeter" +note = "supplies user account and configuration info for cosmic greeter" +bug = "bsc#1259401" +type = "dbus" +[[FileDigestGroup.digests]] +path = "/usr/share/dbus-1/system.d/com.system76.CosmicGreeter.conf" +digester = "xml" +hash = "11cc8aa9c1b4486369700620d1112ab9cb43649b73ab9cc511574bf7dcefce90" diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/rpmlint-2.9.0+git20260629.bd947d09/configs/openSUSE/sysctl-whitelist.toml new/rpmlint-2.9.0+git20260715.7b097339/configs/openSUSE/sysctl-whitelist.toml --- old/rpmlint-2.9.0+git20260629.bd947d09/configs/openSUSE/sysctl-whitelist.toml 2026-06-29 16:53:33.000000000 +0200 +++ new/rpmlint-2.9.0+git20260715.7b097339/configs/openSUSE/sysctl-whitelist.toml 2026-07-15 12:50:14.000000000 +0200 @@ -56,7 +56,7 @@ [[FileDigestGroup.digests]] path = "/usr/lib/sysctl.d/50-coredump.conf" digester = "shell" -hash = "54f2f502708e2b70ac5b6994b4162641fcdee4b834d8eba928d066e4795c4f04" +hash = "d3a082282a3e403ccba14cfee50e47da483943306f3405ece1b50c3fcde4c623" [[FileDigestGroup]] package = "aaa_base" diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/rpmlint-2.9.0+git20260629.bd947d09/rpmlint/filedigestcheck.py new/rpmlint-2.9.0+git20260715.7b097339/rpmlint/filedigestcheck.py --- old/rpmlint-2.9.0+git20260629.bd947d09/rpmlint/filedigestcheck.py 2026-06-29 16:53:33.000000000 +0200 +++ new/rpmlint-2.9.0+git20260715.7b097339/rpmlint/filedigestcheck.py 2026-07-15 12:50:14.000000000 +0200 @@ -1,5 +1,3 @@ -import configparser - # This module contains helper types used by the FileDigestCheck to implement # configuration-specific logic. @@ -13,24 +11,67 @@ def _open_socket_config(path): - """Opens a systemd .socket unit in `path` as an INI configuration file and - returns the ConfigParser instance resulting from it. On error None is - returned.""" - # systemd services files are not 100 % compatible with regular INI - # files, thus we make python's configparser a bit more relaxed. - config = configparser.ConfigParser( - interpolation=None, - strict=False - ) - - # by default option keys are converted to lower-case, we don't want that - config.optionxform = lambda opt: opt - - read = config.read(path) - if len(read) == 1: - return config + """Opens a systemd .socket unit in `path` and returns a dictionary + containing parsed data. On error None is returned.""" + + # Sadly we cannot use Python's configparser for this purpose, because the + # systemd semantics are too far apart from regular INI files. In + # particular we need to be able to process multiple keys of the same name + # in a given section, while configparser discards old values when running + # in non-strict mode. + + # see systemd.syntax(7) man page for the details of this syntax + # + # NOTE: we do not worry about quoting of strings and escaping here, for + # the purposes of the whitelisting this should be good enough (we only + # lookup simple key/value pairs, calculating a digest over quotes/escapes + # should work just as well). + + try: + ret = {} + section = None + multiline = '' + + with open(path) as fl: + for line in fl: + line = line.strip() + if not line or line.startswith('#') or line.startswith(';'): + # NOTE: comments are ignored even in multi-line continuation + continue + elif line.endswith('\\'): + # backslash is replaced by a space + multiline += line[:-1] + ' ' + continue - return None + line = multiline + line + multiline = '' + + if len(line) > 2 and line.startswith('[') and line.endswith(']'): + section = ret.setdefault(line[1:-1], {}) + continue + + if section is None: + # this would be a directive before a section appeared, + # which is invalid + return None + elif '=' not in line: + # all non-comment, non-section, non-continuation lines + # must contain an equal sign + return None + + # all non-comment, non-section, non-continuation lines must + # contain an equal sign + key, value = line.split('=', 1) + # extra whitespace surrounding the equal sign is ignored + key = key.rstrip() + value = value.lstrip() + + entries = section.setdefault(key, []) + entries.append(value) + + return ret + except OSError: + return None class VarlinkServiceCheck: @@ -51,15 +92,18 @@ # no socket section in a socket unit? not Varlink anyway. return False - try: - file_descriptor_name = socket_section['FileDescriptorName'] - except KeyError: - # no varlink service - return False + # It is unclear what happens when multiple FileDescriptorName + # assignments appear, the only logical thing would be to override + # previous occurences. Having this would be weird, however, so let's + # consider any appearance of varlink here. + for name in socket_section.get('FileDescriptorName', []): + # this is more of a convention, not a hard requirement, but so far all + # Varlink services we have use this scheme. + if name == 'varlink': + return True - # this is more of a convention, not a hard requirement, but so far all - # Varlink services we have use this scheme. - return file_descriptor_name == 'varlink' + # not a varlink service + return False # Digester types @@ -219,5 +263,5 @@ # yield all key/value pairs we're interested in for hashing for key in socket_section: if key in self.KEYS_TO_HASH: - value = socket_section[key] - yield f'{key}={value}\n'.encode() + for value in socket_section[key]: + yield f'{key}={value}\n'.encode() diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/rpmlint-2.9.0+git20260629.bd947d09/test/test_file_digest.py new/rpmlint-2.9.0+git20260715.7b097339/test/test_file_digest.py --- old/rpmlint-2.9.0+git20260629.bd947d09/test/test_file_digest.py 2026-06-29 16:53:33.000000000 +0200 +++ new/rpmlint-2.9.0+git20260715.7b097339/test/test_file_digest.py 2026-07-15 12:50:14.000000000 +0200 @@ -417,7 +417,7 @@ test.check(pkg) assert len(output.results) == 0 - # only this config should be complained about since if contains a varlink + # only this config should be complained about since it contains a varlink # FileDescriptorName RESTRICTED_SOCKET_DATA = '[Socket]\nFileDescriptorName=varlink\n' @@ -450,6 +450,16 @@ test.check(pkg) assert len(output.results) == 0 + # this contains duplicate keys for SocketMode, it should yield a different + # digest than MATCHING_SOCKET_DATA. + MISMATCHING_EXTRA_SOCKET_DATA = '[Socket]\nFileDescriptorName=varlink\nSocketMode=0111\nSocketMode=0777\n' + + output, test = get_digestcheck('digests_varlink.config') + with FakePkg('socketpkg') as pkg: + pkg.add_file_with_content('/sockets/the.socket', MISMATCHING_EXTRA_SOCKET_DATA) + test.check(pkg) + assert len(output.results) == 1 + # this adds Backlog=100, an uninteresting key, should yield the same digest SIMILAR_SOCKET_DATA = '[Socket]\nFileDescriptorName=varlink\nSocketMode=0777\nBacklog=100\n'
