Compare commits
8 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ca36a2c905 | ||
|
|
4c42798af0 | ||
|
|
240f0409e2 | ||
|
|
4c02befbcb | ||
|
|
e877718bf6 | ||
|
|
38052ffc8f |
||
|
|
081fabe6be | ||
|
|
b1535bd5ab |
12 changed files with 893 additions and 47 deletions
1
.gitignore
vendored
1
.gitignore
vendored
|
|
@ -221,3 +221,4 @@ setroubleshoot-2.2.93.tar.gz
|
|||
/setroubleshoot-3.3.34.tar.gz
|
||||
/setroubleshoot-3.3.35.tar.gz
|
||||
/setroubleshoot-3.3.36.tar.gz
|
||||
/setroubleshoot-3.3.37.tar.gz
|
||||
|
|
|
|||
443
0001-Update-GPL2-license-texts-to-the-latest-version.patch
Normal file
443
0001-Update-GPL2-license-texts-to-the-latest-version.patch
Normal file
|
|
@ -0,0 +1,443 @@
|
|||
From 96f8442e292e651437004d78abdbb8586ebb728e Mon Sep 17 00:00:00 2001
|
||||
From: Petr Lautrbach <lautrbach@redhat.com>
|
||||
Date: Tue, 2 Jun 2026 11:15:33 +0200
|
||||
Subject: [PATCH] Update GPL2 license texts to the latest version
|
||||
|
||||
Fixes: https://gitlab.com/setroubleshoot/setroubleshoot/-/work_items/6
|
||||
|
||||
setroubleshoot.x86_64: E: incorrect-fsf-address /usr/lib/python3.12/site-packages/setroubleshoot/browser.py
|
||||
setroubleshoot.x86_64: E: incorrect-fsf-address /usr/lib/python3.12/site-packages/setroubleshoot/gui_utils.py
|
||||
setroubleshoot-server.x86_64: E: incorrect-fsf-address /usr/bin/sealert
|
||||
setroubleshoot-server.x86_64: E: incorrect-fsf-address /usr/lib/python3.12/site-packages/setroubleshoot/Plugin.py
|
||||
...
|
||||
---
|
||||
COPYING | 15 +++++++--------
|
||||
src/SetroubleshootPrivileged.py | 5 ++---
|
||||
src/config.py.in | 3 +--
|
||||
src/default_encoding.c | 3 +--
|
||||
src/sealert | 3 +--
|
||||
src/seappletlegacy.c | 3 +--
|
||||
src/sedbus.c | 3 +--
|
||||
src/sedispatch.c | 3 +--
|
||||
src/setroubleshoot/Plugin.py | 3 +--
|
||||
src/setroubleshoot/__init__.py | 3 +--
|
||||
src/setroubleshoot/access_control.py | 3 +--
|
||||
src/setroubleshoot/analyze.py | 3 +--
|
||||
src/setroubleshoot/audit_data.py | 3 +--
|
||||
src/setroubleshoot/avc_audit.py | 3 +--
|
||||
src/setroubleshoot/browser.py | 3 +--
|
||||
src/setroubleshoot/email_alert.py | 3 +--
|
||||
src/setroubleshoot/errcode.py | 3 +--
|
||||
src/setroubleshoot/gui_utils.py | 3 +--
|
||||
src/setroubleshoot/html_util.py | 3 +--
|
||||
src/setroubleshoot/rpc.py | 3 +--
|
||||
src/setroubleshoot/rpc_interfaces.py | 3 +--
|
||||
src/setroubleshoot/server.py | 3 +--
|
||||
src/setroubleshoot/signature.py | 3 +--
|
||||
src/setroubleshoot/util.py | 3 +--
|
||||
src/setroubleshoot/xml_serialize.py | 3 +--
|
||||
src/setroubleshootd | 3 +--
|
||||
26 files changed, 33 insertions(+), 59 deletions(-)
|
||||
|
||||
diff --git a/COPYING b/COPYING
|
||||
index 623b625..6c6dbab 100644
|
||||
--- a/COPYING
|
||||
+++ b/COPYING
|
||||
@@ -1,8 +1,8 @@
|
||||
GNU GENERAL PUBLIC LICENSE
|
||||
Version 2, June 1991
|
||||
|
||||
- Copyright (C) 1989, 1991 Free Software Foundation, Inc.
|
||||
- 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
|
||||
+ Copyright (C) 1989, 1991 Free Software Foundation, Inc.,
|
||||
+ <https://fsf.org/>
|
||||
Everyone is permitted to copy and distribute verbatim copies
|
||||
of this license document, but changing it is not allowed.
|
||||
|
||||
@@ -15,7 +15,7 @@ software--to make sure the software is free for all its users. This
|
||||
General Public License applies to most of the Free Software
|
||||
Foundation's software and to any other program whose authors commit to
|
||||
using it. (Some other Free Software Foundation software is covered by
|
||||
-the GNU Library General Public License instead.) You can apply it to
|
||||
+the GNU Lesser General Public License instead.) You can apply it to
|
||||
your programs, too.
|
||||
|
||||
When we speak of free software, we are referring to freedom, not
|
||||
@@ -304,8 +304,7 @@ the "copyright" line and a pointer to where the full notice is found.
|
||||
GNU General Public License for more details.
|
||||
|
||||
You should have received a copy of the GNU General Public License
|
||||
- along with this program; if not, write to the Free Software
|
||||
- Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
|
||||
+ along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
|
||||
|
||||
Also add information on how to contact you by electronic and paper mail.
|
||||
@@ -330,11 +329,11 @@ necessary. Here is a sample; alter the names:
|
||||
Yoyodyne, Inc., hereby disclaims all copyright interest in the program
|
||||
`Gnomovision' (which makes passes at compilers) written by James Hacker.
|
||||
|
||||
- <signature of Ty Coon>, 1 April 1989
|
||||
- Ty Coon, President of Vice
|
||||
+ <signature of Moe Ghoul>, 1 April 1989
|
||||
+ Moe Ghoul, President of Vice
|
||||
|
||||
This General Public License does not permit incorporating your program into
|
||||
proprietary programs. If your program is a subroutine library, you may
|
||||
consider it more useful to permit linking proprietary applications with the
|
||||
-library. If this is what you want to do, use the GNU Library General
|
||||
+library. If this is what you want to do, use the GNU Lesser General
|
||||
Public License instead of this License.
|
||||
diff --git a/src/SetroubleshootPrivileged.py b/src/SetroubleshootPrivileged.py
|
||||
index c9f46da..845a006 100644
|
||||
--- a/src/SetroubleshootPrivileged.py
|
||||
+++ b/src/SetroubleshootPrivileged.py
|
||||
@@ -14,9 +14,8 @@
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
-# You should have received a copy of the GNU General Public License along
|
||||
-# with this program; if not, write to the Free Software Foundation, Inc.,
|
||||
-# 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||
+# You should have received a copy of the GNU General Public License
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
|
||||
import signal
|
||||
from gi.repository import GLib
|
||||
diff --git a/src/config.py.in b/src/config.py.in
|
||||
index 48a670a..d8e7e35 100644
|
||||
--- a/src/config.py.in
|
||||
+++ b/src/config.py.in
|
||||
@@ -14,8 +14,7 @@
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
__all__ = ['config_init',
|
||||
diff --git a/src/default_encoding.c b/src/default_encoding.c
|
||||
index 61d6382..75e9930 100644
|
||||
--- a/src/default_encoding.c
|
||||
+++ b/src/default_encoding.c
|
||||
@@ -15,8 +15,7 @@
|
||||
* GNU General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License
|
||||
- * along with this program; if not, write to the Free Software
|
||||
- * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
||||
+ * along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
*/
|
||||
|
||||
#include <Python.h>
|
||||
diff --git a/src/sealert b/src/sealert
|
||||
index c45f4fc..91af079 100755
|
||||
--- a/src/sealert
|
||||
+++ b/src/sealert
|
||||
@@ -16,8 +16,7 @@
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
from __future__ import print_function
|
||||
diff --git a/src/seappletlegacy.c b/src/seappletlegacy.c
|
||||
index d6ce7ec..1e14482 100644
|
||||
--- a/src/seappletlegacy.c
|
||||
+++ b/src/seappletlegacy.c
|
||||
@@ -17,8 +17,7 @@
|
||||
* GNU General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License
|
||||
- * along with this program; if not, write to the Free Software
|
||||
- * Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+ * along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
*
|
||||
* compile command
|
||||
* gcc -g sealerttrayicon.c -o sealerttrayicon `pkg-config --cflags --libs gtk+-2.0` -lnotify
|
||||
diff --git a/src/sedbus.c b/src/sedbus.c
|
||||
index 702bed7..fd4a860 100644
|
||||
--- a/src/sedbus.c
|
||||
+++ b/src/sedbus.c
|
||||
@@ -13,8 +13,7 @@
|
||||
* GNU General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License
|
||||
- * along with this program; if not, write to the Free Software
|
||||
- * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
||||
+ * along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
*
|
||||
* Authors:
|
||||
* Dan Walsh <dwalsh@redhat.com>
|
||||
diff --git a/src/sedispatch.c b/src/sedispatch.c
|
||||
index 07d9c90..b1b80fc 100644
|
||||
--- a/src/sedispatch.c
|
||||
+++ b/src/sedispatch.c
|
||||
@@ -13,8 +13,7 @@
|
||||
* GNU General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License
|
||||
- * along with this program; if not, write to the Free Software
|
||||
- * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
|
||||
+ * along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
*
|
||||
* Authors:
|
||||
* Dan Walsh <dwalsh@redhat.com>
|
||||
diff --git a/src/setroubleshoot/Plugin.py b/src/setroubleshoot/Plugin.py
|
||||
index 3c52b7f..13f31f0 100644
|
||||
--- a/src/setroubleshoot/Plugin.py
|
||||
+++ b/src/setroubleshoot/Plugin.py
|
||||
@@ -15,8 +15,7 @@
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
import gettext
|
||||
diff --git a/src/setroubleshoot/__init__.py b/src/setroubleshoot/__init__.py
|
||||
index ccb6b8b..0fe4d80 100644
|
||||
--- a/src/setroubleshoot/__init__.py
|
||||
+++ b/src/setroubleshoot/__init__.py
|
||||
@@ -12,6 +12,5 @@
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
diff --git a/src/setroubleshoot/access_control.py b/src/setroubleshoot/access_control.py
|
||||
index de16e32..3c2c02b 100644
|
||||
--- a/src/setroubleshoot/access_control.py
|
||||
+++ b/src/setroubleshoot/access_control.py
|
||||
@@ -13,8 +13,7 @@
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
"""Access control for setroubleshoot. For now this is only used for
|
||||
diff --git a/src/setroubleshoot/analyze.py b/src/setroubleshoot/analyze.py
|
||||
index d1c7ac6..b2bbce8 100644
|
||||
--- a/src/setroubleshoot/analyze.py
|
||||
+++ b/src/setroubleshoot/analyze.py
|
||||
@@ -13,8 +13,7 @@
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
from __future__ import print_function
|
||||
diff --git a/src/setroubleshoot/audit_data.py b/src/setroubleshoot/audit_data.py
|
||||
index 34cc3b1..d1e03d7 100644
|
||||
--- a/src/setroubleshoot/audit_data.py
|
||||
+++ b/src/setroubleshoot/audit_data.py
|
||||
@@ -15,8 +15,7 @@ import sys
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
__all__ = ['derive_record_format',
|
||||
diff --git a/src/setroubleshoot/avc_audit.py b/src/setroubleshoot/avc_audit.py
|
||||
index 5419280..2f61349 100644
|
||||
--- a/src/setroubleshoot/avc_audit.py
|
||||
+++ b/src/setroubleshoot/avc_audit.py
|
||||
@@ -13,8 +13,7 @@
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
__all__ = [
|
||||
diff --git a/src/setroubleshoot/browser.py b/src/setroubleshoot/browser.py
|
||||
index 47788a7..d8e9921 100644
|
||||
--- a/src/setroubleshoot/browser.py
|
||||
+++ b/src/setroubleshoot/browser.py
|
||||
@@ -13,8 +13,7 @@
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
from __future__ import absolute_import
|
||||
diff --git a/src/setroubleshoot/email_alert.py b/src/setroubleshoot/email_alert.py
|
||||
index 0921b99..8e41124 100644
|
||||
--- a/src/setroubleshoot/email_alert.py
|
||||
+++ b/src/setroubleshoot/email_alert.py
|
||||
@@ -14,8 +14,7 @@ from __future__ import absolute_import
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
__all__ = ['email_alert',
|
||||
diff --git a/src/setroubleshoot/errcode.py b/src/setroubleshoot/errcode.py
|
||||
index 2a2aa21..7a925b9 100644
|
||||
--- a/src/setroubleshoot/errcode.py
|
||||
+++ b/src/setroubleshoot/errcode.py
|
||||
@@ -13,8 +13,7 @@
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
import gettext
|
||||
from setroubleshoot.config import parse_config_setting, get_config
|
||||
diff --git a/src/setroubleshoot/gui_utils.py b/src/setroubleshoot/gui_utils.py
|
||||
index e28673a..cbec874 100644
|
||||
--- a/src/setroubleshoot/gui_utils.py
|
||||
+++ b/src/setroubleshoot/gui_utils.py
|
||||
@@ -14,8 +14,7 @@
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
# Needed to silence warnings if X display is not present
|
||||
diff --git a/src/setroubleshoot/html_util.py b/src/setroubleshoot/html_util.py
|
||||
index 5021683..c08e5b5 100644
|
||||
--- a/src/setroubleshoot/html_util.py
|
||||
+++ b/src/setroubleshoot/html_util.py
|
||||
@@ -13,8 +13,7 @@
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
|
||||
diff --git a/src/setroubleshoot/rpc.py b/src/setroubleshoot/rpc.py
|
||||
index 82fc294..2a874ae 100755
|
||||
--- a/src/setroubleshoot/rpc.py
|
||||
+++ b/src/setroubleshoot/rpc.py
|
||||
@@ -15,8 +15,7 @@ from __future__ import print_function
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
import xml.etree.ElementTree as ET
|
||||
diff --git a/src/setroubleshoot/rpc_interfaces.py b/src/setroubleshoot/rpc_interfaces.py
|
||||
index ec7ff50..5a42f0b 100644
|
||||
--- a/src/setroubleshoot/rpc_interfaces.py
|
||||
+++ b/src/setroubleshoot/rpc_interfaces.py
|
||||
@@ -13,8 +13,7 @@
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
from setroubleshoot.rpc import rpc_method, rpc_arg_type, rpc_callback, rpc_signal
|
||||
diff --git a/src/setroubleshoot/server.py b/src/setroubleshoot/server.py
|
||||
index 3369af1..cf0f345 100755
|
||||
--- a/src/setroubleshoot/server.py
|
||||
+++ b/src/setroubleshoot/server.py
|
||||
@@ -16,8 +16,7 @@ from __future__ import absolute_import
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
__all__ = ['RunFaultServer',
|
||||
diff --git a/src/setroubleshoot/signature.py b/src/setroubleshoot/signature.py
|
||||
index cf675ff..e4fee53 100755
|
||||
--- a/src/setroubleshoot/signature.py
|
||||
+++ b/src/setroubleshoot/signature.py
|
||||
@@ -17,8 +17,7 @@ from __future__ import print_function
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
import syslog
|
||||
diff --git a/src/setroubleshoot/util.py b/src/setroubleshoot/util.py
|
||||
index b6125aa..dd331b7 100755
|
||||
--- a/src/setroubleshoot/util.py
|
||||
+++ b/src/setroubleshoot/util.py
|
||||
@@ -14,8 +14,7 @@ from __future__ import absolute_import
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
__all__ = [
|
||||
diff --git a/src/setroubleshoot/xml_serialize.py b/src/setroubleshoot/xml_serialize.py
|
||||
index e1adf7f..596e276 100755
|
||||
--- a/src/setroubleshoot/xml_serialize.py
|
||||
+++ b/src/setroubleshoot/xml_serialize.py
|
||||
@@ -14,8 +14,7 @@ from __future__ import absolute_import
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
# Escaping
|
||||
diff --git a/src/setroubleshootd b/src/setroubleshootd
|
||||
index 3affe3a..2ad355b 100755
|
||||
--- a/src/setroubleshootd
|
||||
+++ b/src/setroubleshootd
|
||||
@@ -17,8 +17,7 @@
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
-# along with this program; if not, write to the Free Software
|
||||
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
|
||||
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
import sys
|
||||
import os
|
||||
--
|
||||
2.53.0
|
||||
|
||||
|
|
@ -1,39 +0,0 @@
|
|||
From fb4a884fe6266e664cc886273bad3b2ae761118a Mon Sep 17 00:00:00 2001
|
||||
From: Vit Mojzis <vmojzis@redhat.com>
|
||||
Date: Thu, 11 Dec 2025 13:50:45 +0100
|
||||
Subject: [PATCH] browser: Always show "Report Bug" button
|
||||
|
||||
Without python3-libreport the "Report Bug" button was not shown at all.
|
||||
After this change the button is always visible, but without libreport it
|
||||
is disabled and the tooltip tells the user how to enable it.
|
||||
|
||||
Signed-off-by: Vit Mojzis <vmojzis@redhat.com>
|
||||
---
|
||||
src/setroubleshoot/browser.py | 8 ++++++--
|
||||
1 file changed, 6 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/setroubleshoot/browser.py b/src/setroubleshoot/browser.py
|
||||
index 73fc26e..47788a7 100644
|
||||
--- a/src/setroubleshoot/browser.py
|
||||
+++ b/src/setroubleshoot/browser.py
|
||||
@@ -548,11 +548,15 @@ class BrowserApplet:
|
||||
report_button.connect("clicked", self.fix_bug, alert.local_id, plugin.analysis_id)
|
||||
vbox.add(report_button)
|
||||
|
||||
- elif plugin.report_bug and has_libreport:
|
||||
+ elif plugin.report_bug:
|
||||
report_button = Gtk.Button()
|
||||
report_button.set_label(_("Report\nBug"))
|
||||
report_button.show()
|
||||
- report_button.connect("clicked", self.report_bug, alert)
|
||||
+ if has_libreport:
|
||||
+ report_button.connect("clicked", self.report_bug, alert)
|
||||
+ else:
|
||||
+ report_button.set_sensitive(False)
|
||||
+ report_button.set_tooltip_text(_("Please install python3-libreport to enable bug reporting."))
|
||||
vbox.add(report_button)
|
||||
|
||||
vbox.set_sensitive(highlight)
|
||||
--
|
||||
2.52.0
|
||||
|
||||
|
|
@ -0,0 +1,80 @@
|
|||
From 4ffb87384c1c104f14db183b26d445c1685fb053 Mon Sep 17 00:00:00 2001
|
||||
From: Vit Mojzis <vmojzis@redhat.com>
|
||||
Date: Mon, 27 Jul 2026 17:06:52 +0200
|
||||
Subject: [PATCH] Limit RPC request size in RequestReceiver to prevent memory
|
||||
exhaustion
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
A local attacker could connect to the world-writable setroubleshootd
|
||||
UNIX socket and send a crafted RPC header with an arbitrarily large
|
||||
content-length value, then continuously stream body data. Because
|
||||
RequestReceiver.feed() appended incoming data to feed_buf without any
|
||||
upper bound and parse_header() trusted the content-length value
|
||||
directly, memory usage would grow until the daemon was OOM-killed by
|
||||
the MemoryMax=1G cgroup limit.
|
||||
|
||||
Add size limits at three levels:
|
||||
- Reject content-length values that are missing, negative, or exceed
|
||||
MAX_BODY_LEN (1 MiB) in parse_header()
|
||||
- Reject incomplete headers once feed_buf exceeds MAX_HEADER_LEN
|
||||
(8 KiB) without a terminator in process()
|
||||
- Cap total feed_buf size to MAX_HEADER_LEN + MAX_BODY_LEN in feed()
|
||||
as a catch-all safety net
|
||||
|
||||
All ValueError exceptions propagate to the existing except handler in
|
||||
handle_client_io(), which logs the error and closes only the offending
|
||||
client connection — the daemon continues serving other clients.
|
||||
|
||||
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
||||
---
|
||||
src/setroubleshoot/rpc.py | 10 ++++++++++
|
||||
1 file changed, 10 insertions(+)
|
||||
|
||||
diff --git a/src/setroubleshoot/rpc.py b/src/setroubleshoot/rpc.py
|
||||
index 2a874ae..aca2d7e 100755
|
||||
--- a/src/setroubleshoot/rpc.py
|
||||
+++ b/src/setroubleshoot/rpc.py
|
||||
@@ -710,6 +710,8 @@ class ListeningServer(ConnectionIO):
|
||||
|
||||
|
||||
class RequestReceiver:
|
||||
+ MAX_HEADER_LEN = 8192
|
||||
+ MAX_BODY_LEN = 1024 * 1024
|
||||
|
||||
def __init__(self, dispatchFunc):
|
||||
self.dispatchFunc = dispatchFunc
|
||||
@@ -736,6 +738,8 @@ class RequestReceiver:
|
||||
self.parse_header()
|
||||
continue
|
||||
else:
|
||||
+ if len(self.feed_buf) > self.MAX_HEADER_LEN:
|
||||
+ raise ValueError("RPC header too large")
|
||||
# Can't read header till more data arrives
|
||||
break
|
||||
if len(self.feed_buf) >= self.headerLen + self.bodyLen:
|
||||
@@ -754,6 +758,8 @@ class RequestReceiver:
|
||||
|
||||
def feed(self, data):
|
||||
self.feed_buf += data
|
||||
+ if len(self.feed_buf) > self.MAX_HEADER_LEN + self.MAX_BODY_LEN:
|
||||
+ raise ValueError("RPC request exceeds maximum allowed size")
|
||||
self.process()
|
||||
|
||||
def parse_header(self):
|
||||
@@ -768,7 +774,11 @@ class RequestReceiver:
|
||||
begin = match.end()
|
||||
else:
|
||||
break
|
||||
+ if 'content-length' not in self.header:
|
||||
+ raise ValueError("RPC request missing content-length")
|
||||
self.bodyLen = int(self.header['content-length'])
|
||||
+ if self.bodyLen < 0 or self.bodyLen > self.MAX_BODY_LEN:
|
||||
+ raise ValueError("RPC body length out of range")
|
||||
|
||||
#-----------------------------------------------------------------------------
|
||||
|
||||
--
|
||||
2.53.0
|
||||
|
||||
75
0003-Restrict-RPC-dispatch-to-registered-methods-only.patch
Normal file
75
0003-Restrict-RPC-dispatch-to-registered-methods-only.patch
Normal file
|
|
@ -0,0 +1,75 @@
|
|||
From 431d5a9a5f7ac4ce61210f4e21ecc64e79c8b31a Mon Sep 17 00:00:00 2001
|
||||
From: Vit Mojzis <vmojzis@redhat.com>
|
||||
Date: Mon, 27 Jul 2026 18:20:44 +0200
|
||||
Subject: [PATCH] Restrict RPC dispatch to registered methods only
|
||||
|
||||
get_method_implementation() used unrestricted getattr() to resolve
|
||||
attacker-controlled method names on handler objects. Since server.py
|
||||
binds the full connection object as the RPC handler via
|
||||
connect_rpc_interface('SETroubleshootServer', self), all inherited
|
||||
internal methods (acquire_write_lock, close_connection, etc.) became
|
||||
callable through crafted RPC requests.
|
||||
|
||||
An attacker could connect to the world-writable UNIX socket and invoke
|
||||
acquire_write_lock as a signal, then send any RPC method call. The
|
||||
response path calls send_data() which tries to acquire the same
|
||||
non-reentrant threading.Lock, deadlocking the daemon and making it
|
||||
unresponsive to all clients.
|
||||
|
||||
Validate the requested method name against interface_registry before
|
||||
calling getattr(). The method must exist in the registry with an
|
||||
rpc_def.type matching the expected RPC type ('method' or 'signal').
|
||||
Unregistered names now fall through to the existing "not implemented"
|
||||
error response instead of being dispatched. The expected_type parameter
|
||||
defaults to None for backward compatibility with any callers outside
|
||||
default_request_handler.
|
||||
|
||||
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
||||
---
|
||||
src/setroubleshoot/rpc.py | 13 ++++++++++---
|
||||
1 file changed, 10 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/src/setroubleshoot/rpc.py b/src/setroubleshoot/rpc.py
|
||||
index aca2d7e..6a6f31a 100755
|
||||
--- a/src/setroubleshoot/rpc.py
|
||||
+++ b/src/setroubleshoot/rpc.py
|
||||
@@ -869,10 +869,17 @@ class RpcChannel(ConnectionIO, RpcManage):
|
||||
result_code, result_msg)
|
||||
self.io_watch_remove()
|
||||
|
||||
- def get_method_implementation(self, interface, method):
|
||||
+ def get_method_implementation(self, interface, method, expected_type=None):
|
||||
handler_obj = self.rpc_handlers.get(interface, None)
|
||||
if handler_obj is None:
|
||||
return None
|
||||
+ if expected_type is not None:
|
||||
+ interface_dict = interface_registry.interfaces.get(interface)
|
||||
+ if interface_dict is None:
|
||||
+ return None
|
||||
+ rpc_def = interface_dict.get(method)
|
||||
+ if rpc_def is None or rpc_def.type != expected_type:
|
||||
+ return None
|
||||
method_ptr = getattr(handler_obj, method, None)
|
||||
return method_ptr
|
||||
|
||||
@@ -971,7 +978,7 @@ class RpcChannel(ConnectionIO, RpcManage):
|
||||
self.handle_return(type, rpc_id, body)
|
||||
elif type == 'method':
|
||||
interface, method, args = convert_rpc_xml_to_args(body)
|
||||
- method_ptr = self.get_method_implementation(interface, method)
|
||||
+ method_ptr = self.get_method_implementation(interface, method, 'method')
|
||||
if method_ptr:
|
||||
try:
|
||||
return_args = method_ptr(*args)
|
||||
@@ -990,7 +997,7 @@ class RpcChannel(ConnectionIO, RpcManage):
|
||||
self.emit_rpc(rpc_id, 'error_return', rpc_error_def, method, err_code, err_msg)
|
||||
elif type == 'signal':
|
||||
interface, method, args = convert_rpc_xml_to_args(body)
|
||||
- method_ptr = self.get_method_implementation(interface, method)
|
||||
+ method_ptr = self.get_method_implementation(interface, method, 'signal')
|
||||
if method_ptr:
|
||||
try:
|
||||
method_ptr(*args)
|
||||
--
|
||||
2.53.0
|
||||
|
||||
|
|
@ -0,0 +1,34 @@
|
|||
From 920ca71562e462ed4d1d02f3ce1b35dec33bd1bb Mon Sep 17 00:00:00 2001
|
||||
From: Vit Mojzis <vmojzis@redhat.com>
|
||||
Date: Fri, 7 Aug 2026 14:57:21 +0200
|
||||
Subject: [PATCH] Reject logon() when peer credentials are unavailable
|
||||
|
||||
get_credentials() returns uid=None for non-Unix client sockets (e.g. an
|
||||
INET/TCP listener). logon() then compared the supplied username against
|
||||
get_identity(None), which falls back to os.getuid() -- the daemon's own
|
||||
uid -- letting any caller authenticate as the 'setroubleshoot' account
|
||||
without a valid password on such a listener. Refuse logon outright when
|
||||
peer credentials could not be obtained.
|
||||
|
||||
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
||||
---
|
||||
src/setroubleshoot/server.py | 3 +++
|
||||
1 file changed, 3 insertions(+)
|
||||
|
||||
diff --git a/src/setroubleshoot/server.py b/src/setroubleshoot/server.py
|
||||
index cf0f345..bc38fa3 100755
|
||||
--- a/src/setroubleshoot/server.py
|
||||
+++ b/src/setroubleshoot/server.py
|
||||
@@ -324,6 +324,9 @@ class SetroubleshootdClientConnectionHandler(ClientConnectionHandler,
|
||||
def logon(self, type, username, password):
|
||||
log_debug("logon(%s) type=%s username=%s" % (self, type, username))
|
||||
|
||||
+ if self.uid is None:
|
||||
+ raise ProgramError(ERR_USER_LOOKUP, detail="peer credentials unavailable; refusing logon on non-unix socket")
|
||||
+
|
||||
if username != get_identity(self.uid):
|
||||
raise ProgramError(ERR_USER_LOOKUP, detail="uid=%s does not match logon username (%s)" % (self.uid, username))
|
||||
|
||||
--
|
||||
2.53.0
|
||||
|
||||
73
0005-Fix-port-handling.patch
Normal file
73
0005-Fix-port-handling.patch
Normal file
|
|
@ -0,0 +1,73 @@
|
|||
From 49f3d79ff621e7cf3876cea759ded665cd192528 Mon Sep 17 00:00:00 2001
|
||||
From: Vit Mojzis <vmojzis@redhat.com>
|
||||
Date: Fri, 7 Aug 2026 14:58:20 +0200
|
||||
Subject: [PATCH] Fix port handling
|
||||
|
||||
- Cast parsed port to int in SocketAddress.parse_inet_addr()
|
||||
|
||||
An explicit port in an {inet} address (e.g. "{inet}127.0.0.1:16983") was
|
||||
kept as the raw regex-matched string instead of being converted to int.
|
||||
socket.bind() requires an int port for AF_INET, so any configured
|
||||
INET/TCP listener with an explicit port failed with TypeError, silently
|
||||
swallowed by ListeningServer.open()'s exception handler, leaving the
|
||||
daemon running with no client listener at all.
|
||||
|
||||
- Forward the configured default port in get_socket_list_from_config()
|
||||
|
||||
parse_socket_address_list() defaults its default_port parameter to None,
|
||||
and get_socket_list_from_config() called it without passing one through,
|
||||
so any {inet} address with no explicit port (e.g. "{inet}127.0.0.1") ended
|
||||
up with SocketAddress.port = None instead of the configured
|
||||
connection.default_port, causing socket.bind() to fail with TypeError.
|
||||
|
||||
- Fix invalid default connection.default_port value
|
||||
|
||||
The shipped default was '69783' with a comment acknowledging it was a
|
||||
placeholder ("FIXME: figure out defined port"). 69783 exceeds the valid
|
||||
TCP port range (0-65535), so any {inet} listen_for_client/client_connect_to
|
||||
address with no explicit port failed with OverflowError on bind()/connect().
|
||||
|
||||
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
||||
---
|
||||
src/config.py.in | 2 +-
|
||||
src/setroubleshoot/rpc.py | 4 +++-
|
||||
2 files changed, 4 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/config.py.in b/src/config.py.in
|
||||
index d8e7e35..603a107 100644
|
||||
--- a/src/config.py.in
|
||||
+++ b/src/config.py.in
|
||||
@@ -182,7 +182,7 @@ An empty string implies no limit''',
|
||||
},
|
||||
'connection': {
|
||||
'default_port': {
|
||||
- 'value': '69783', # FIXME: figure out defined port,
|
||||
+ 'value': '16983',
|
||||
'description': '',
|
||||
},
|
||||
},
|
||||
diff --git a/src/setroubleshoot/rpc.py b/src/setroubleshoot/rpc.py
|
||||
index 6a6f31a..142228f 100755
|
||||
--- a/src/setroubleshoot/rpc.py
|
||||
+++ b/src/setroubleshoot/rpc.py
|
||||
@@ -100,7 +100,7 @@ def get_default_port():
|
||||
|
||||
def get_socket_list_from_config(cfg_section):
|
||||
addr_string = get_config(cfg_section, 'address_list')
|
||||
- socket_addresses = parse_socket_address_list(addr_string)
|
||||
+ socket_addresses = parse_socket_address_list(addr_string, get_default_port())
|
||||
return socket_addresses
|
||||
|
||||
|
||||
@@ -577,6 +577,8 @@ class SocketAddress(object):
|
||||
port = match.group(3)
|
||||
if port is None:
|
||||
port = self.default_port
|
||||
+ else:
|
||||
+ port = int(port)
|
||||
|
||||
if addr == 'hostname':
|
||||
addr = get_hostname()
|
||||
--
|
||||
2.53.0
|
||||
|
||||
50
0006-Require-root-to-delete-alerts-via-D-Bus.patch
Normal file
50
0006-Require-root-to-delete-alerts-via-D-Bus.patch
Normal file
|
|
@ -0,0 +1,50 @@
|
|||
From 66942f3b55339e59f768952312548e7eab3d19ca Mon Sep 17 00:00:00 2001
|
||||
From: Vit Mojzis <vmojzis@redhat.com>
|
||||
Date: Fri, 7 Aug 2026 17:44:46 +0200
|
||||
Subject: [PATCH] Require root to delete alerts via D-Bus
|
||||
|
||||
delete_alert() removed an alert from the shared host database without
|
||||
checking the caller's identity, and the shipped D-Bus policy allowed any
|
||||
local user to invoke it. An unprivileged local user could enumerate alerts
|
||||
with get_all_alerts and delete entries other users/administrators rely on.
|
||||
|
||||
Reject non-root callers in delete_alert() itself, and drop delete_alert
|
||||
from the default D-Bus policy context as defense in depth (root already
|
||||
has full access via the existing <policy user="root"> rule).
|
||||
|
||||
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
||||
---
|
||||
org.fedoraproject.Setroubleshootd.conf | 3 ---
|
||||
src/setroubleshoot/server.py | 2 ++
|
||||
2 files changed, 2 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/org.fedoraproject.Setroubleshootd.conf b/org.fedoraproject.Setroubleshootd.conf
|
||||
index 65a0daa..910958a 100644
|
||||
--- a/org.fedoraproject.Setroubleshootd.conf
|
||||
+++ b/org.fedoraproject.Setroubleshootd.conf
|
||||
@@ -35,9 +35,6 @@
|
||||
<allow send_destination="org.fedoraproject.Setroubleshootd"
|
||||
send_interface="org.fedoraproject.SetroubleshootdIface"
|
||||
send_member="set_filter"/>
|
||||
- <allow send_destination="org.fedoraproject.Setroubleshootd"
|
||||
- send_interface="org.fedoraproject.SetroubleshootdIface"
|
||||
- send_member="delete_alert"/>
|
||||
<allow send_destination="org.fedoraproject.Setroubleshootd"
|
||||
send_interface="org.freedesktop.DBus.Introspectable"/>
|
||||
</policy>
|
||||
diff --git a/src/setroubleshoot/server.py b/src/setroubleshoot/server.py
|
||||
index bc38fa3..dc29f63 100755
|
||||
--- a/src/setroubleshoot/server.py
|
||||
+++ b/src/setroubleshoot/server.py
|
||||
@@ -665,6 +665,8 @@ Deletes an alert from the database.
|
||||
|
||||
* `success(b)`:
|
||||
"""
|
||||
+ if self.connection.get_unix_user(sender) != 0:
|
||||
+ return False
|
||||
try:
|
||||
database = get_host_database()
|
||||
alert = self._get_alert(local_id, database)
|
||||
--
|
||||
2.53.0
|
||||
|
||||
55
0007-Protect-against-malicious-socket-blocking.patch
Normal file
55
0007-Protect-against-malicious-socket-blocking.patch
Normal file
|
|
@ -0,0 +1,55 @@
|
|||
From c30163055995cff80222899a35722819d8286417 Mon Sep 17 00:00:00 2001
|
||||
From: Vit Mojzis <vmojzis@redhat.com>
|
||||
Date: Fri, 7 Aug 2026 18:03:16 +0200
|
||||
Subject: [PATCH] Protect against malicious socket blocking
|
||||
|
||||
Set a timeout (socket.timeout config, 5s default) on accepted client
|
||||
sockets so a stuck send() eventually times out instead of hanging forever
|
||||
(send_data() already had a Socket.timeout handler for this). As a second,
|
||||
independent layer, skip clients that have not completed logon() in both
|
||||
places that fan data out to the 'sealert' pool: send_alert_notification()
|
||||
and ClientNotifier.signatures_updated().
|
||||
|
||||
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
||||
---
|
||||
src/setroubleshoot/rpc.py | 1 +
|
||||
src/setroubleshoot/server.py | 4 ++++
|
||||
2 files changed, 5 insertions(+)
|
||||
|
||||
diff --git a/src/setroubleshoot/rpc.py b/src/setroubleshoot/rpc.py
|
||||
index 142228f..ecfd062 100755
|
||||
--- a/src/setroubleshoot/rpc.py
|
||||
+++ b/src/setroubleshoot/rpc.py
|
||||
@@ -687,6 +687,7 @@ class ListeningServer(ConnectionIO):
|
||||
try:
|
||||
client_socket, client_address = socket.accept()
|
||||
fcntl.fcntl(client_socket.fileno(), fcntl.F_SETFD, fcntl.FD_CLOEXEC)
|
||||
+ client_socket.settimeout(RpcChannel.socket_timeout)
|
||||
client_handler = self.client_connection_handler_class(self.socket_address)
|
||||
client_handler.open(client_socket, client_address)
|
||||
self.connection_state.update(0, ConnectionState.PROBLEM_FLAGS)
|
||||
diff --git a/src/setroubleshoot/server.py b/src/setroubleshoot/server.py
|
||||
index dc29f63..6adc0c2 100755
|
||||
--- a/src/setroubleshoot/server.py
|
||||
+++ b/src/setroubleshoot/server.py
|
||||
@@ -149,6 +149,8 @@ def send_alert_notification(siginfo):
|
||||
system_bus.send_message(alert)
|
||||
|
||||
for client in connection_pool.clients('sealert'):
|
||||
+ if not (client.connection_state.flags & ConnectionState.AUTHENTICATED):
|
||||
+ continue
|
||||
client.alert(siginfo)
|
||||
|
||||
#------------------------------ Variables -------------------------------
|
||||
@@ -445,6 +447,8 @@ class ClientNotifier(object):
|
||||
|
||||
def signatures_updated(self, type, item):
|
||||
for client in self.connection_pool.clients('sealert'):
|
||||
+ if not (client.connection_state.flags & ConnectionState.AUTHENTICATED):
|
||||
+ continue
|
||||
client.signatures_updated(type, item)
|
||||
|
||||
|
||||
--
|
||||
2.53.0
|
||||
|
||||
|
|
@ -0,0 +1,38 @@
|
|||
From 271fcfc09a53fba13b0e31df18acdc5d2605cf05 Mon Sep 17 00:00:00 2001
|
||||
From: Vit Mojzis <vmojzis@redhat.com>
|
||||
Date: Fri, 7 Aug 2026 18:05:56 +0200
|
||||
Subject: [PATCH] Require privileged access to change email alert recipients
|
||||
|
||||
set_email_recipients() only checked that the RPC connection was
|
||||
authenticated, not that the caller was privileged. Since logon() grants
|
||||
authenticated state to any local user allowed to run the sealert client
|
||||
(client_users='*' by default) and never verifies the supplied password,
|
||||
any such user could overwrite the daemon-wide email_alert_recipients file
|
||||
that controls where SELinux alert emails are sent.
|
||||
|
||||
Reuse the existing fix_cmd privilege model (already used to gate running
|
||||
alert fix commands as root) to restrict this to root and users listed in
|
||||
fix_cmd_users.
|
||||
|
||||
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
||||
---
|
||||
src/setroubleshoot/server.py | 3 +++
|
||||
1 file changed, 3 insertions(+)
|
||||
|
||||
diff --git a/src/setroubleshoot/server.py b/src/setroubleshoot/server.py
|
||||
index 6adc0c2..bf7a294 100755
|
||||
--- a/src/setroubleshoot/server.py
|
||||
+++ b/src/setroubleshoot/server.py
|
||||
@@ -364,6 +364,9 @@ class SetroubleshootdClientConnectionHandler(ClientConnectionHandler,
|
||||
if not (self.connection_state.flags & ConnectionState.AUTHENTICATED):
|
||||
raise ProgramError(ERR_NOT_AUTHENTICATED)
|
||||
|
||||
+ if self.uid != 0 and not self.access.user_allowed('fix_cmd', self.username):
|
||||
+ raise ProgramError(ERR_USER_PROHIBITED)
|
||||
+
|
||||
email_recipients = recipients
|
||||
email_recipients.write_recipient_file(email_recipients_filepath)
|
||||
|
||||
--
|
||||
2.53.0
|
||||
|
||||
|
|
@ -5,16 +5,24 @@
|
|||
|
||||
Summary: Helps troubleshoot SELinux problems
|
||||
Name: setroubleshoot
|
||||
Version: 3.3.36
|
||||
Release: 3%{?dist}
|
||||
Version: 3.3.37
|
||||
Release: 6%{?dist}
|
||||
License: GPL-2.0-or-later
|
||||
URL: https://gitlab.com/setroubleshoot/setroubleshoot
|
||||
Source0: https://gitlab.com/-/project/24478376/uploads/51a9cda747130f92860720841a7fd9c9/setroubleshoot-3.3.36.tar.gz
|
||||
VCS: git:https://gitlab.com/setroubleshoot/setroubleshoot.git
|
||||
Source0: https://gitlab.com/-/project/24478376/uploads/cbdfc2a87b350583c32b168fd9aad9fd/setroubleshoot-3.3.37.tar.gz
|
||||
Source1: %{name}.tmpfiles
|
||||
Source2: %{name}.sysusers
|
||||
# git format-patch -N 3.3.36
|
||||
# git format-patch -N 3.3.37 -- . ':!src/sedispatch.h' ':!test'
|
||||
# for j in 00*patch; do printf "Patch: %s\n" $j; done
|
||||
Patch: 0001-browser-Always-show-Report-Bug-button.patch
|
||||
Patch: 0001-Update-GPL2-license-texts-to-the-latest-version.patch
|
||||
Patch: 0002-Limit-RPC-request-size-in-RequestReceiver-to-prevent.patch
|
||||
Patch: 0003-Restrict-RPC-dispatch-to-registered-methods-only.patch
|
||||
Patch: 0004-Reject-logon-when-peer-credentials-are-unavailable.patch
|
||||
Patch: 0005-Fix-port-handling.patch
|
||||
Patch: 0006-Require-root-to-delete-alerts-via-D-Bus.patch
|
||||
Patch: 0007-Protect-against-malicious-socket-blocking.patch
|
||||
Patch: 0008-Require-privileged-access-to-change-email-alert-reci.patch
|
||||
BuildRequires: gcc
|
||||
BuildRequires: make
|
||||
BuildRequires: libcap-ng-devel
|
||||
|
|
@ -96,10 +104,9 @@ install -p -m644 -D %{SOURCE2} $RPM_BUILD_ROOT%{_sysusersdir}/%{name}.conf
|
|||
%package server
|
||||
Summary: SELinux troubleshoot server
|
||||
|
||||
Requires: %{name}-plugins >= 3.3.10
|
||||
Requires: %{name}-plugins >= 3.3.15-7
|
||||
Requires: audit >= 3.0.1
|
||||
Requires: audit-libs-python3
|
||||
Requires: libxml2-python3
|
||||
Requires: rpm-python3
|
||||
Requires: libselinux-python3 >= 2.1.5-1
|
||||
Requires: policycoreutils-python-utils
|
||||
|
|
@ -194,6 +201,35 @@ to user preference. The same tools can be run on existing log files.
|
|||
%doc AUTHORS COPYING ChangeLog DBUS.md NEWS README TODO
|
||||
|
||||
%changelog
|
||||
* Fri Aug 07 2026 Vit Mojzis <vmojzis@redhat.com> - 3.3.37-6
|
||||
- Require privileged access to change email alert recipients
|
||||
- Protect against malicious socket blocking
|
||||
- Require root to delete alerts via D-Bus
|
||||
- Fix port handling
|
||||
- Reject logon() when peer credentials are unavailable
|
||||
- Restrict RPC dispatch to registered methods only
|
||||
|
||||
* Wed Jul 29 2026 Vit Mojzis <vmojzis@redhat.com> - 3.3.37-5
|
||||
- Update GPL2 license texts to the latest version
|
||||
- Limit RPC request size in RequestReceiver to prevent memory exhaustion
|
||||
|
||||
* Wed Jul 22 2026 Python Maint <python-maint@redhat.com> - 3.3.37-4
|
||||
- Rebuilt for Python 3.15.0b4 ABI change
|
||||
|
||||
* Fri Jul 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.37-3
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
|
||||
|
||||
* Tue Jul 14 2026 Ondrej Mosnáček <omosnacek@gmail.com> - 3.3.37-2
|
||||
- Remove the obsolete libxml2-python3 dependency
|
||||
|
||||
* Thu Jun 18 2026 Vit Mojzis <vmojzis@redhat.com> - 3.3.37-1
|
||||
- Migrate from libxml2 to xml.etree.ElementTree
|
||||
- Handle ImportError when setroubleshoot.browser is not available
|
||||
- Add support for multiple commands in fix_cmd
|
||||
|
||||
* Wed Jun 03 2026 Python Maint <python-maint@redhat.com> - 3.3.36-4
|
||||
- Rebuilt for Python 3.15
|
||||
|
||||
* Sat Jan 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.36-3
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
|
||||
|
||||
|
|
|
|||
2
sources
2
sources
|
|
@ -1 +1 @@
|
|||
SHA512 (setroubleshoot-3.3.36.tar.gz) = 089583970169d4127cf825d8660dc755cb154771b8e48f6b7558f8fa090491ad6ac492f435a8f410c73c46ab1500a203f4123fcda69b1cd7adbf792b5580cb83
|
||||
SHA512 (setroubleshoot-3.3.37.tar.gz) = 8b67b28c2e2d2f766c00723f2a67e82fc43079a9a5868c4598f80331bb12ae0e94749cd68fedc718462ae9203e5b9d363033902c699f597a79865d6d31df61cd
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue