Compare commits

..

No commits in common. "rawhide" and "f44" have entirely different histories.

12 changed files with 47 additions and 893 deletions

1
.gitignore vendored
View file

@ -221,4 +221,3 @@ setroubleshoot-2.2.93.tar.gz
/setroubleshoot-3.3.34.tar.gz
/setroubleshoot-3.3.35.tar.gz
/setroubleshoot-3.3.36.tar.gz
/setroubleshoot-3.3.37.tar.gz

View file

@ -1,443 +0,0 @@
From 96f8442e292e651437004d78abdbb8586ebb728e Mon Sep 17 00:00:00 2001
From: Petr Lautrbach <lautrbach@redhat.com>
Date: Tue, 2 Jun 2026 11:15:33 +0200
Subject: [PATCH] Update GPL2 license texts to the latest version
Fixes: https://gitlab.com/setroubleshoot/setroubleshoot/-/work_items/6
setroubleshoot.x86_64: E: incorrect-fsf-address /usr/lib/python3.12/site-packages/setroubleshoot/browser.py
setroubleshoot.x86_64: E: incorrect-fsf-address /usr/lib/python3.12/site-packages/setroubleshoot/gui_utils.py
setroubleshoot-server.x86_64: E: incorrect-fsf-address /usr/bin/sealert
setroubleshoot-server.x86_64: E: incorrect-fsf-address /usr/lib/python3.12/site-packages/setroubleshoot/Plugin.py
...
---
COPYING | 15 +++++++--------
src/SetroubleshootPrivileged.py | 5 ++---
src/config.py.in | 3 +--
src/default_encoding.c | 3 +--
src/sealert | 3 +--
src/seappletlegacy.c | 3 +--
src/sedbus.c | 3 +--
src/sedispatch.c | 3 +--
src/setroubleshoot/Plugin.py | 3 +--
src/setroubleshoot/__init__.py | 3 +--
src/setroubleshoot/access_control.py | 3 +--
src/setroubleshoot/analyze.py | 3 +--
src/setroubleshoot/audit_data.py | 3 +--
src/setroubleshoot/avc_audit.py | 3 +--
src/setroubleshoot/browser.py | 3 +--
src/setroubleshoot/email_alert.py | 3 +--
src/setroubleshoot/errcode.py | 3 +--
src/setroubleshoot/gui_utils.py | 3 +--
src/setroubleshoot/html_util.py | 3 +--
src/setroubleshoot/rpc.py | 3 +--
src/setroubleshoot/rpc_interfaces.py | 3 +--
src/setroubleshoot/server.py | 3 +--
src/setroubleshoot/signature.py | 3 +--
src/setroubleshoot/util.py | 3 +--
src/setroubleshoot/xml_serialize.py | 3 +--
src/setroubleshootd | 3 +--
26 files changed, 33 insertions(+), 59 deletions(-)
diff --git a/COPYING b/COPYING
index 623b625..6c6dbab 100644
--- a/COPYING
+++ b/COPYING
@@ -1,8 +1,8 @@
GNU GENERAL PUBLIC LICENSE
Version 2, June 1991
- Copyright (C) 1989, 1991 Free Software Foundation, Inc.
- 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
+ Copyright (C) 1989, 1991 Free Software Foundation, Inc.,
+ <https://fsf.org/>
Everyone is permitted to copy and distribute verbatim copies
of this license document, but changing it is not allowed.
@@ -15,7 +15,7 @@ software--to make sure the software is free for all its users. This
General Public License applies to most of the Free Software
Foundation's software and to any other program whose authors commit to
using it. (Some other Free Software Foundation software is covered by
-the GNU Library General Public License instead.) You can apply it to
+the GNU Lesser General Public License instead.) You can apply it to
your programs, too.
When we speak of free software, we are referring to freedom, not
@@ -304,8 +304,7 @@ the "copyright" line and a pointer to where the full notice is found.
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
- along with this program; if not, write to the Free Software
- Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
+ along with this program; if not, see <https://www.gnu.org/licenses/>.
Also add information on how to contact you by electronic and paper mail.
@@ -330,11 +329,11 @@ necessary. Here is a sample; alter the names:
Yoyodyne, Inc., hereby disclaims all copyright interest in the program
`Gnomovision' (which makes passes at compilers) written by James Hacker.
- <signature of Ty Coon>, 1 April 1989
- Ty Coon, President of Vice
+ <signature of Moe Ghoul>, 1 April 1989
+ Moe Ghoul, President of Vice
This General Public License does not permit incorporating your program into
proprietary programs. If your program is a subroutine library, you may
consider it more useful to permit linking proprietary applications with the
-library. If this is what you want to do, use the GNU Library General
+library. If this is what you want to do, use the GNU Lesser General
Public License instead of this License.
diff --git a/src/SetroubleshootPrivileged.py b/src/SetroubleshootPrivileged.py
index c9f46da..845a006 100644
--- a/src/SetroubleshootPrivileged.py
+++ b/src/SetroubleshootPrivileged.py
@@ -14,9 +14,8 @@
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
-# You should have received a copy of the GNU General Public License along
-# with this program; if not, write to the Free Software Foundation, Inc.,
-# 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
import signal
from gi.repository import GLib
diff --git a/src/config.py.in b/src/config.py.in
index 48a670a..d8e7e35 100644
--- a/src/config.py.in
+++ b/src/config.py.in
@@ -14,8 +14,7 @@
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
__all__ = ['config_init',
diff --git a/src/default_encoding.c b/src/default_encoding.c
index 61d6382..75e9930 100644
--- a/src/default_encoding.c
+++ b/src/default_encoding.c
@@ -15,8 +15,7 @@
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
- * along with this program; if not, write to the Free Software
- * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
+ * along with this program; if not, see <https://www.gnu.org/licenses/>.
*/
#include <Python.h>
diff --git a/src/sealert b/src/sealert
index c45f4fc..91af079 100755
--- a/src/sealert
+++ b/src/sealert
@@ -16,8 +16,7 @@
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
from __future__ import print_function
diff --git a/src/seappletlegacy.c b/src/seappletlegacy.c
index d6ce7ec..1e14482 100644
--- a/src/seappletlegacy.c
+++ b/src/seappletlegacy.c
@@ -17,8 +17,7 @@
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
- * along with this program; if not, write to the Free Software
- * Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+ * along with this program; if not, see <https://www.gnu.org/licenses/>.
*
* compile command
* gcc -g sealerttrayicon.c -o sealerttrayicon `pkg-config --cflags --libs gtk+-2.0` -lnotify
diff --git a/src/sedbus.c b/src/sedbus.c
index 702bed7..fd4a860 100644
--- a/src/sedbus.c
+++ b/src/sedbus.c
@@ -13,8 +13,7 @@
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
- * along with this program; if not, write to the Free Software
- * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
+ * along with this program; if not, see <https://www.gnu.org/licenses/>.
*
* Authors:
* Dan Walsh <dwalsh@redhat.com>
diff --git a/src/sedispatch.c b/src/sedispatch.c
index 07d9c90..b1b80fc 100644
--- a/src/sedispatch.c
+++ b/src/sedispatch.c
@@ -13,8 +13,7 @@
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
- * along with this program; if not, write to the Free Software
- * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
+ * along with this program; if not, see <https://www.gnu.org/licenses/>.
*
* Authors:
* Dan Walsh <dwalsh@redhat.com>
diff --git a/src/setroubleshoot/Plugin.py b/src/setroubleshoot/Plugin.py
index 3c52b7f..13f31f0 100644
--- a/src/setroubleshoot/Plugin.py
+++ b/src/setroubleshoot/Plugin.py
@@ -15,8 +15,7 @@
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
import gettext
diff --git a/src/setroubleshoot/__init__.py b/src/setroubleshoot/__init__.py
index ccb6b8b..0fe4d80 100644
--- a/src/setroubleshoot/__init__.py
+++ b/src/setroubleshoot/__init__.py
@@ -12,6 +12,5 @@
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
diff --git a/src/setroubleshoot/access_control.py b/src/setroubleshoot/access_control.py
index de16e32..3c2c02b 100644
--- a/src/setroubleshoot/access_control.py
+++ b/src/setroubleshoot/access_control.py
@@ -13,8 +13,7 @@
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
"""Access control for setroubleshoot. For now this is only used for
diff --git a/src/setroubleshoot/analyze.py b/src/setroubleshoot/analyze.py
index d1c7ac6..b2bbce8 100644
--- a/src/setroubleshoot/analyze.py
+++ b/src/setroubleshoot/analyze.py
@@ -13,8 +13,7 @@
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
from __future__ import print_function
diff --git a/src/setroubleshoot/audit_data.py b/src/setroubleshoot/audit_data.py
index 34cc3b1..d1e03d7 100644
--- a/src/setroubleshoot/audit_data.py
+++ b/src/setroubleshoot/audit_data.py
@@ -15,8 +15,7 @@ import sys
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
__all__ = ['derive_record_format',
diff --git a/src/setroubleshoot/avc_audit.py b/src/setroubleshoot/avc_audit.py
index 5419280..2f61349 100644
--- a/src/setroubleshoot/avc_audit.py
+++ b/src/setroubleshoot/avc_audit.py
@@ -13,8 +13,7 @@
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
__all__ = [
diff --git a/src/setroubleshoot/browser.py b/src/setroubleshoot/browser.py
index 47788a7..d8e9921 100644
--- a/src/setroubleshoot/browser.py
+++ b/src/setroubleshoot/browser.py
@@ -13,8 +13,7 @@
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
from __future__ import absolute_import
diff --git a/src/setroubleshoot/email_alert.py b/src/setroubleshoot/email_alert.py
index 0921b99..8e41124 100644
--- a/src/setroubleshoot/email_alert.py
+++ b/src/setroubleshoot/email_alert.py
@@ -14,8 +14,7 @@ from __future__ import absolute_import
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
__all__ = ['email_alert',
diff --git a/src/setroubleshoot/errcode.py b/src/setroubleshoot/errcode.py
index 2a2aa21..7a925b9 100644
--- a/src/setroubleshoot/errcode.py
+++ b/src/setroubleshoot/errcode.py
@@ -13,8 +13,7 @@
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
import gettext
from setroubleshoot.config import parse_config_setting, get_config
diff --git a/src/setroubleshoot/gui_utils.py b/src/setroubleshoot/gui_utils.py
index e28673a..cbec874 100644
--- a/src/setroubleshoot/gui_utils.py
+++ b/src/setroubleshoot/gui_utils.py
@@ -14,8 +14,7 @@
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
# Needed to silence warnings if X display is not present
diff --git a/src/setroubleshoot/html_util.py b/src/setroubleshoot/html_util.py
index 5021683..c08e5b5 100644
--- a/src/setroubleshoot/html_util.py
+++ b/src/setroubleshoot/html_util.py
@@ -13,8 +13,7 @@
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
diff --git a/src/setroubleshoot/rpc.py b/src/setroubleshoot/rpc.py
index 82fc294..2a874ae 100755
--- a/src/setroubleshoot/rpc.py
+++ b/src/setroubleshoot/rpc.py
@@ -15,8 +15,7 @@ from __future__ import print_function
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
import xml.etree.ElementTree as ET
diff --git a/src/setroubleshoot/rpc_interfaces.py b/src/setroubleshoot/rpc_interfaces.py
index ec7ff50..5a42f0b 100644
--- a/src/setroubleshoot/rpc_interfaces.py
+++ b/src/setroubleshoot/rpc_interfaces.py
@@ -13,8 +13,7 @@
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
from setroubleshoot.rpc import rpc_method, rpc_arg_type, rpc_callback, rpc_signal
diff --git a/src/setroubleshoot/server.py b/src/setroubleshoot/server.py
index 3369af1..cf0f345 100755
--- a/src/setroubleshoot/server.py
+++ b/src/setroubleshoot/server.py
@@ -16,8 +16,7 @@ from __future__ import absolute_import
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
__all__ = ['RunFaultServer',
diff --git a/src/setroubleshoot/signature.py b/src/setroubleshoot/signature.py
index cf675ff..e4fee53 100755
--- a/src/setroubleshoot/signature.py
+++ b/src/setroubleshoot/signature.py
@@ -17,8 +17,7 @@ from __future__ import print_function
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
import syslog
diff --git a/src/setroubleshoot/util.py b/src/setroubleshoot/util.py
index b6125aa..dd331b7 100755
--- a/src/setroubleshoot/util.py
+++ b/src/setroubleshoot/util.py
@@ -14,8 +14,7 @@ from __future__ import absolute_import
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
__all__ = [
diff --git a/src/setroubleshoot/xml_serialize.py b/src/setroubleshoot/xml_serialize.py
index e1adf7f..596e276 100755
--- a/src/setroubleshoot/xml_serialize.py
+++ b/src/setroubleshoot/xml_serialize.py
@@ -14,8 +14,7 @@ from __future__ import absolute_import
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
# Escaping
diff --git a/src/setroubleshootd b/src/setroubleshootd
index 3affe3a..2ad355b 100755
--- a/src/setroubleshootd
+++ b/src/setroubleshootd
@@ -17,8 +17,7 @@
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
-# along with this program; if not, write to the Free Software
-# Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
+# along with this program; if not, see <https://www.gnu.org/licenses/>.
#
import sys
import os
--
2.53.0

View file

@ -0,0 +1,39 @@
From fb4a884fe6266e664cc886273bad3b2ae761118a Mon Sep 17 00:00:00 2001
From: Vit Mojzis <vmojzis@redhat.com>
Date: Thu, 11 Dec 2025 13:50:45 +0100
Subject: [PATCH] browser: Always show "Report Bug" button
Without python3-libreport the "Report Bug" button was not shown at all.
After this change the button is always visible, but without libreport it
is disabled and the tooltip tells the user how to enable it.
Signed-off-by: Vit Mojzis <vmojzis@redhat.com>
---
src/setroubleshoot/browser.py | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/src/setroubleshoot/browser.py b/src/setroubleshoot/browser.py
index 73fc26e..47788a7 100644
--- a/src/setroubleshoot/browser.py
+++ b/src/setroubleshoot/browser.py
@@ -548,11 +548,15 @@ class BrowserApplet:
report_button.connect("clicked", self.fix_bug, alert.local_id, plugin.analysis_id)
vbox.add(report_button)
- elif plugin.report_bug and has_libreport:
+ elif plugin.report_bug:
report_button = Gtk.Button()
report_button.set_label(_("Report\nBug"))
report_button.show()
- report_button.connect("clicked", self.report_bug, alert)
+ if has_libreport:
+ report_button.connect("clicked", self.report_bug, alert)
+ else:
+ report_button.set_sensitive(False)
+ report_button.set_tooltip_text(_("Please install python3-libreport to enable bug reporting."))
vbox.add(report_button)
vbox.set_sensitive(highlight)
--
2.52.0

View file

@ -1,80 +0,0 @@
From 4ffb87384c1c104f14db183b26d445c1685fb053 Mon Sep 17 00:00:00 2001
From: Vit Mojzis <vmojzis@redhat.com>
Date: Mon, 27 Jul 2026 17:06:52 +0200
Subject: [PATCH] Limit RPC request size in RequestReceiver to prevent memory
exhaustion
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
A local attacker could connect to the world-writable setroubleshootd
UNIX socket and send a crafted RPC header with an arbitrarily large
content-length value, then continuously stream body data. Because
RequestReceiver.feed() appended incoming data to feed_buf without any
upper bound and parse_header() trusted the content-length value
directly, memory usage would grow until the daemon was OOM-killed by
the MemoryMax=1G cgroup limit.
Add size limits at three levels:
- Reject content-length values that are missing, negative, or exceed
MAX_BODY_LEN (1 MiB) in parse_header()
- Reject incomplete headers once feed_buf exceeds MAX_HEADER_LEN
(8 KiB) without a terminator in process()
- Cap total feed_buf size to MAX_HEADER_LEN + MAX_BODY_LEN in feed()
as a catch-all safety net
All ValueError exceptions propagate to the existing except handler in
handle_client_io(), which logs the error and closes only the offending
client connection — the daemon continues serving other clients.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---
src/setroubleshoot/rpc.py | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/src/setroubleshoot/rpc.py b/src/setroubleshoot/rpc.py
index 2a874ae..aca2d7e 100755
--- a/src/setroubleshoot/rpc.py
+++ b/src/setroubleshoot/rpc.py
@@ -710,6 +710,8 @@ class ListeningServer(ConnectionIO):
class RequestReceiver:
+ MAX_HEADER_LEN = 8192
+ MAX_BODY_LEN = 1024 * 1024
def __init__(self, dispatchFunc):
self.dispatchFunc = dispatchFunc
@@ -736,6 +738,8 @@ class RequestReceiver:
self.parse_header()
continue
else:
+ if len(self.feed_buf) > self.MAX_HEADER_LEN:
+ raise ValueError("RPC header too large")
# Can't read header till more data arrives
break
if len(self.feed_buf) >= self.headerLen + self.bodyLen:
@@ -754,6 +758,8 @@ class RequestReceiver:
def feed(self, data):
self.feed_buf += data
+ if len(self.feed_buf) > self.MAX_HEADER_LEN + self.MAX_BODY_LEN:
+ raise ValueError("RPC request exceeds maximum allowed size")
self.process()
def parse_header(self):
@@ -768,7 +774,11 @@ class RequestReceiver:
begin = match.end()
else:
break
+ if 'content-length' not in self.header:
+ raise ValueError("RPC request missing content-length")
self.bodyLen = int(self.header['content-length'])
+ if self.bodyLen < 0 or self.bodyLen > self.MAX_BODY_LEN:
+ raise ValueError("RPC body length out of range")
#-----------------------------------------------------------------------------
--
2.53.0

View file

@ -1,75 +0,0 @@
From 431d5a9a5f7ac4ce61210f4e21ecc64e79c8b31a Mon Sep 17 00:00:00 2001
From: Vit Mojzis <vmojzis@redhat.com>
Date: Mon, 27 Jul 2026 18:20:44 +0200
Subject: [PATCH] Restrict RPC dispatch to registered methods only
get_method_implementation() used unrestricted getattr() to resolve
attacker-controlled method names on handler objects. Since server.py
binds the full connection object as the RPC handler via
connect_rpc_interface('SETroubleshootServer', self), all inherited
internal methods (acquire_write_lock, close_connection, etc.) became
callable through crafted RPC requests.
An attacker could connect to the world-writable UNIX socket and invoke
acquire_write_lock as a signal, then send any RPC method call. The
response path calls send_data() which tries to acquire the same
non-reentrant threading.Lock, deadlocking the daemon and making it
unresponsive to all clients.
Validate the requested method name against interface_registry before
calling getattr(). The method must exist in the registry with an
rpc_def.type matching the expected RPC type ('method' or 'signal').
Unregistered names now fall through to the existing "not implemented"
error response instead of being dispatched. The expected_type parameter
defaults to None for backward compatibility with any callers outside
default_request_handler.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---
src/setroubleshoot/rpc.py | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/src/setroubleshoot/rpc.py b/src/setroubleshoot/rpc.py
index aca2d7e..6a6f31a 100755
--- a/src/setroubleshoot/rpc.py
+++ b/src/setroubleshoot/rpc.py
@@ -869,10 +869,17 @@ class RpcChannel(ConnectionIO, RpcManage):
result_code, result_msg)
self.io_watch_remove()
- def get_method_implementation(self, interface, method):
+ def get_method_implementation(self, interface, method, expected_type=None):
handler_obj = self.rpc_handlers.get(interface, None)
if handler_obj is None:
return None
+ if expected_type is not None:
+ interface_dict = interface_registry.interfaces.get(interface)
+ if interface_dict is None:
+ return None
+ rpc_def = interface_dict.get(method)
+ if rpc_def is None or rpc_def.type != expected_type:
+ return None
method_ptr = getattr(handler_obj, method, None)
return method_ptr
@@ -971,7 +978,7 @@ class RpcChannel(ConnectionIO, RpcManage):
self.handle_return(type, rpc_id, body)
elif type == 'method':
interface, method, args = convert_rpc_xml_to_args(body)
- method_ptr = self.get_method_implementation(interface, method)
+ method_ptr = self.get_method_implementation(interface, method, 'method')
if method_ptr:
try:
return_args = method_ptr(*args)
@@ -990,7 +997,7 @@ class RpcChannel(ConnectionIO, RpcManage):
self.emit_rpc(rpc_id, 'error_return', rpc_error_def, method, err_code, err_msg)
elif type == 'signal':
interface, method, args = convert_rpc_xml_to_args(body)
- method_ptr = self.get_method_implementation(interface, method)
+ method_ptr = self.get_method_implementation(interface, method, 'signal')
if method_ptr:
try:
method_ptr(*args)
--
2.53.0

View file

@ -1,34 +0,0 @@
From 920ca71562e462ed4d1d02f3ce1b35dec33bd1bb Mon Sep 17 00:00:00 2001
From: Vit Mojzis <vmojzis@redhat.com>
Date: Fri, 7 Aug 2026 14:57:21 +0200
Subject: [PATCH] Reject logon() when peer credentials are unavailable
get_credentials() returns uid=None for non-Unix client sockets (e.g. an
INET/TCP listener). logon() then compared the supplied username against
get_identity(None), which falls back to os.getuid() -- the daemon's own
uid -- letting any caller authenticate as the 'setroubleshoot' account
without a valid password on such a listener. Refuse logon outright when
peer credentials could not be obtained.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---
src/setroubleshoot/server.py | 3 +++
1 file changed, 3 insertions(+)
diff --git a/src/setroubleshoot/server.py b/src/setroubleshoot/server.py
index cf0f345..bc38fa3 100755
--- a/src/setroubleshoot/server.py
+++ b/src/setroubleshoot/server.py
@@ -324,6 +324,9 @@ class SetroubleshootdClientConnectionHandler(ClientConnectionHandler,
def logon(self, type, username, password):
log_debug("logon(%s) type=%s username=%s" % (self, type, username))
+ if self.uid is None:
+ raise ProgramError(ERR_USER_LOOKUP, detail="peer credentials unavailable; refusing logon on non-unix socket")
+
if username != get_identity(self.uid):
raise ProgramError(ERR_USER_LOOKUP, detail="uid=%s does not match logon username (%s)" % (self.uid, username))
--
2.53.0

View file

@ -1,73 +0,0 @@
From 49f3d79ff621e7cf3876cea759ded665cd192528 Mon Sep 17 00:00:00 2001
From: Vit Mojzis <vmojzis@redhat.com>
Date: Fri, 7 Aug 2026 14:58:20 +0200
Subject: [PATCH] Fix port handling
- Cast parsed port to int in SocketAddress.parse_inet_addr()
An explicit port in an {inet} address (e.g. "{inet}127.0.0.1:16983") was
kept as the raw regex-matched string instead of being converted to int.
socket.bind() requires an int port for AF_INET, so any configured
INET/TCP listener with an explicit port failed with TypeError, silently
swallowed by ListeningServer.open()'s exception handler, leaving the
daemon running with no client listener at all.
- Forward the configured default port in get_socket_list_from_config()
parse_socket_address_list() defaults its default_port parameter to None,
and get_socket_list_from_config() called it without passing one through,
so any {inet} address with no explicit port (e.g. "{inet}127.0.0.1") ended
up with SocketAddress.port = None instead of the configured
connection.default_port, causing socket.bind() to fail with TypeError.
- Fix invalid default connection.default_port value
The shipped default was '69783' with a comment acknowledging it was a
placeholder ("FIXME: figure out defined port"). 69783 exceeds the valid
TCP port range (0-65535), so any {inet} listen_for_client/client_connect_to
address with no explicit port failed with OverflowError on bind()/connect().
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---
src/config.py.in | 2 +-
src/setroubleshoot/rpc.py | 4 +++-
2 files changed, 4 insertions(+), 2 deletions(-)
diff --git a/src/config.py.in b/src/config.py.in
index d8e7e35..603a107 100644
--- a/src/config.py.in
+++ b/src/config.py.in
@@ -182,7 +182,7 @@ An empty string implies no limit''',
},
'connection': {
'default_port': {
- 'value': '69783', # FIXME: figure out defined port,
+ 'value': '16983',
'description': '',
},
},
diff --git a/src/setroubleshoot/rpc.py b/src/setroubleshoot/rpc.py
index 6a6f31a..142228f 100755
--- a/src/setroubleshoot/rpc.py
+++ b/src/setroubleshoot/rpc.py
@@ -100,7 +100,7 @@ def get_default_port():
def get_socket_list_from_config(cfg_section):
addr_string = get_config(cfg_section, 'address_list')
- socket_addresses = parse_socket_address_list(addr_string)
+ socket_addresses = parse_socket_address_list(addr_string, get_default_port())
return socket_addresses
@@ -577,6 +577,8 @@ class SocketAddress(object):
port = match.group(3)
if port is None:
port = self.default_port
+ else:
+ port = int(port)
if addr == 'hostname':
addr = get_hostname()
--
2.53.0

View file

@ -1,50 +0,0 @@
From 66942f3b55339e59f768952312548e7eab3d19ca Mon Sep 17 00:00:00 2001
From: Vit Mojzis <vmojzis@redhat.com>
Date: Fri, 7 Aug 2026 17:44:46 +0200
Subject: [PATCH] Require root to delete alerts via D-Bus
delete_alert() removed an alert from the shared host database without
checking the caller's identity, and the shipped D-Bus policy allowed any
local user to invoke it. An unprivileged local user could enumerate alerts
with get_all_alerts and delete entries other users/administrators rely on.
Reject non-root callers in delete_alert() itself, and drop delete_alert
from the default D-Bus policy context as defense in depth (root already
has full access via the existing <policy user="root"> rule).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---
org.fedoraproject.Setroubleshootd.conf | 3 ---
src/setroubleshoot/server.py | 2 ++
2 files changed, 2 insertions(+), 3 deletions(-)
diff --git a/org.fedoraproject.Setroubleshootd.conf b/org.fedoraproject.Setroubleshootd.conf
index 65a0daa..910958a 100644
--- a/org.fedoraproject.Setroubleshootd.conf
+++ b/org.fedoraproject.Setroubleshootd.conf
@@ -35,9 +35,6 @@
<allow send_destination="org.fedoraproject.Setroubleshootd"
send_interface="org.fedoraproject.SetroubleshootdIface"
send_member="set_filter"/>
- <allow send_destination="org.fedoraproject.Setroubleshootd"
- send_interface="org.fedoraproject.SetroubleshootdIface"
- send_member="delete_alert"/>
<allow send_destination="org.fedoraproject.Setroubleshootd"
send_interface="org.freedesktop.DBus.Introspectable"/>
</policy>
diff --git a/src/setroubleshoot/server.py b/src/setroubleshoot/server.py
index bc38fa3..dc29f63 100755
--- a/src/setroubleshoot/server.py
+++ b/src/setroubleshoot/server.py
@@ -665,6 +665,8 @@ Deletes an alert from the database.
* `success(b)`:
"""
+ if self.connection.get_unix_user(sender) != 0:
+ return False
try:
database = get_host_database()
alert = self._get_alert(local_id, database)
--
2.53.0

View file

@ -1,55 +0,0 @@
From c30163055995cff80222899a35722819d8286417 Mon Sep 17 00:00:00 2001
From: Vit Mojzis <vmojzis@redhat.com>
Date: Fri, 7 Aug 2026 18:03:16 +0200
Subject: [PATCH] Protect against malicious socket blocking
Set a timeout (socket.timeout config, 5s default) on accepted client
sockets so a stuck send() eventually times out instead of hanging forever
(send_data() already had a Socket.timeout handler for this). As a second,
independent layer, skip clients that have not completed logon() in both
places that fan data out to the 'sealert' pool: send_alert_notification()
and ClientNotifier.signatures_updated().
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---
src/setroubleshoot/rpc.py | 1 +
src/setroubleshoot/server.py | 4 ++++
2 files changed, 5 insertions(+)
diff --git a/src/setroubleshoot/rpc.py b/src/setroubleshoot/rpc.py
index 142228f..ecfd062 100755
--- a/src/setroubleshoot/rpc.py
+++ b/src/setroubleshoot/rpc.py
@@ -687,6 +687,7 @@ class ListeningServer(ConnectionIO):
try:
client_socket, client_address = socket.accept()
fcntl.fcntl(client_socket.fileno(), fcntl.F_SETFD, fcntl.FD_CLOEXEC)
+ client_socket.settimeout(RpcChannel.socket_timeout)
client_handler = self.client_connection_handler_class(self.socket_address)
client_handler.open(client_socket, client_address)
self.connection_state.update(0, ConnectionState.PROBLEM_FLAGS)
diff --git a/src/setroubleshoot/server.py b/src/setroubleshoot/server.py
index dc29f63..6adc0c2 100755
--- a/src/setroubleshoot/server.py
+++ b/src/setroubleshoot/server.py
@@ -149,6 +149,8 @@ def send_alert_notification(siginfo):
system_bus.send_message(alert)
for client in connection_pool.clients('sealert'):
+ if not (client.connection_state.flags & ConnectionState.AUTHENTICATED):
+ continue
client.alert(siginfo)
#------------------------------ Variables -------------------------------
@@ -445,6 +447,8 @@ class ClientNotifier(object):
def signatures_updated(self, type, item):
for client in self.connection_pool.clients('sealert'):
+ if not (client.connection_state.flags & ConnectionState.AUTHENTICATED):
+ continue
client.signatures_updated(type, item)
--
2.53.0

View file

@ -1,38 +0,0 @@
From 271fcfc09a53fba13b0e31df18acdc5d2605cf05 Mon Sep 17 00:00:00 2001
From: Vit Mojzis <vmojzis@redhat.com>
Date: Fri, 7 Aug 2026 18:05:56 +0200
Subject: [PATCH] Require privileged access to change email alert recipients
set_email_recipients() only checked that the RPC connection was
authenticated, not that the caller was privileged. Since logon() grants
authenticated state to any local user allowed to run the sealert client
(client_users='*' by default) and never verifies the supplied password,
any such user could overwrite the daemon-wide email_alert_recipients file
that controls where SELinux alert emails are sent.
Reuse the existing fix_cmd privilege model (already used to gate running
alert fix commands as root) to restrict this to root and users listed in
fix_cmd_users.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---
src/setroubleshoot/server.py | 3 +++
1 file changed, 3 insertions(+)
diff --git a/src/setroubleshoot/server.py b/src/setroubleshoot/server.py
index 6adc0c2..bf7a294 100755
--- a/src/setroubleshoot/server.py
+++ b/src/setroubleshoot/server.py
@@ -364,6 +364,9 @@ class SetroubleshootdClientConnectionHandler(ClientConnectionHandler,
if not (self.connection_state.flags & ConnectionState.AUTHENTICATED):
raise ProgramError(ERR_NOT_AUTHENTICATED)
+ if self.uid != 0 and not self.access.user_allowed('fix_cmd', self.username):
+ raise ProgramError(ERR_USER_PROHIBITED)
+
email_recipients = recipients
email_recipients.write_recipient_file(email_recipients_filepath)
--
2.53.0

View file

@ -5,24 +5,16 @@
Summary: Helps troubleshoot SELinux problems
Name: setroubleshoot
Version: 3.3.37
Release: 6%{?dist}
Version: 3.3.36
Release: 3%{?dist}
License: GPL-2.0-or-later
URL: https://gitlab.com/setroubleshoot/setroubleshoot
VCS: git:https://gitlab.com/setroubleshoot/setroubleshoot.git
Source0: https://gitlab.com/-/project/24478376/uploads/cbdfc2a87b350583c32b168fd9aad9fd/setroubleshoot-3.3.37.tar.gz
Source0: https://gitlab.com/-/project/24478376/uploads/51a9cda747130f92860720841a7fd9c9/setroubleshoot-3.3.36.tar.gz
Source1: %{name}.tmpfiles
Source2: %{name}.sysusers
# git format-patch -N 3.3.37 -- . ':!src/sedispatch.h' ':!test'
# git format-patch -N 3.3.36
# for j in 00*patch; do printf "Patch: %s\n" $j; done
Patch: 0001-Update-GPL2-license-texts-to-the-latest-version.patch
Patch: 0002-Limit-RPC-request-size-in-RequestReceiver-to-prevent.patch
Patch: 0003-Restrict-RPC-dispatch-to-registered-methods-only.patch
Patch: 0004-Reject-logon-when-peer-credentials-are-unavailable.patch
Patch: 0005-Fix-port-handling.patch
Patch: 0006-Require-root-to-delete-alerts-via-D-Bus.patch
Patch: 0007-Protect-against-malicious-socket-blocking.patch
Patch: 0008-Require-privileged-access-to-change-email-alert-reci.patch
Patch: 0001-browser-Always-show-Report-Bug-button.patch
BuildRequires: gcc
BuildRequires: make
BuildRequires: libcap-ng-devel
@ -104,9 +96,10 @@ install -p -m644 -D %{SOURCE2} $RPM_BUILD_ROOT%{_sysusersdir}/%{name}.conf
%package server
Summary: SELinux troubleshoot server
Requires: %{name}-plugins >= 3.3.15-7
Requires: %{name}-plugins >= 3.3.10
Requires: audit >= 3.0.1
Requires: audit-libs-python3
Requires: libxml2-python3
Requires: rpm-python3
Requires: libselinux-python3 >= 2.1.5-1
Requires: policycoreutils-python-utils
@ -201,35 +194,6 @@ to user preference. The same tools can be run on existing log files.
%doc AUTHORS COPYING ChangeLog DBUS.md NEWS README TODO
%changelog
* Fri Aug 07 2026 Vit Mojzis <vmojzis@redhat.com> - 3.3.37-6
- Require privileged access to change email alert recipients
- Protect against malicious socket blocking
- Require root to delete alerts via D-Bus
- Fix port handling
- Reject logon() when peer credentials are unavailable
- Restrict RPC dispatch to registered methods only
* Wed Jul 29 2026 Vit Mojzis <vmojzis@redhat.com> - 3.3.37-5
- Update GPL2 license texts to the latest version
- Limit RPC request size in RequestReceiver to prevent memory exhaustion
* Wed Jul 22 2026 Python Maint <python-maint@redhat.com> - 3.3.37-4
- Rebuilt for Python 3.15.0b4 ABI change
* Fri Jul 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.37-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Tue Jul 14 2026 Ondrej Mosnáček <omosnacek@gmail.com> - 3.3.37-2
- Remove the obsolete libxml2-python3 dependency
* Thu Jun 18 2026 Vit Mojzis <vmojzis@redhat.com> - 3.3.37-1
- Migrate from libxml2 to xml.etree.ElementTree
- Handle ImportError when setroubleshoot.browser is not available
- Add support for multiple commands in fix_cmd
* Wed Jun 03 2026 Python Maint <python-maint@redhat.com> - 3.3.36-4
- Rebuilt for Python 3.15
* Sat Jan 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 3.3.36-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild

View file

@ -1 +1 @@
SHA512 (setroubleshoot-3.3.37.tar.gz) = 8b67b28c2e2d2f766c00723f2a67e82fc43079a9a5868c4598f80331bb12ae0e94749cd68fedc718462ae9203e5b9d363033902c699f597a79865d6d31df61cd
SHA512 (setroubleshoot-3.3.36.tar.gz) = 089583970169d4127cf825d8660dc755cb154771b8e48f6b7558f8fa090491ad6ac492f435a8f410c73c46ab1500a203f4123fcda69b1cd7adbf792b5580cb83