Bug 1389045

Summary: python-flask-admin files are owned by mockbuild
Product: [Fedora] Fedora Reporter: Zbigniew Jędrzejewski-Szmek <zbyszek>
Component: python-flask-adminAssignee: Patrick Uiterwijk <puiterwijk>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: rawhideCC: itamar, puiterwijk, pviktori, tflink
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: python-flask-admin-1.5.0-4.fc28 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-05-14 17:53:56 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Zbigniew Jędrzejewski-Szmek 2016-10-26 17:48:23 UTC
Description of problem:
$ wget https://kojipkgs.fedoraproject.org//packages/python-flask-admin/1.4.2/1.fc25/noarch/python3-flask-admin-1.4.2-1.fc25.noarch.rpm https://kojipkgs.fedoraproject.org//packages/python-flask-admin/1.4.2/1.fc25/noarch/python-flask-admin-1.4.2-1.fc25.noarch.rpm
$ rpmls -l *rpm
drwxr-xr-x  mockbuild mockbuild /usr/lib/python3.5/site-packages/Flask_Admin-1.4.2-py3.5.egg-info
-rw-r--r--  mockbuild mockbuild /usr/lib/python3.5/site-packages/Flask_Admin-drwxr-xr-x  mockbuild mockbuild /usr/lib/python3.5/site-packages/flask_admin
-rw-r--r--  mockbuild mockbuild /usr/lib/python3.5/site-packages/flask_admin/__init__.py
...

Version-Release number of selected component (if applicable):
python-flask-admin-1.4.2-1

Comment 1 Fedora End Of Life 2017-11-16 19:08:40 UTC
This message is a reminder that Fedora 25 is nearing its end of life.
Approximately 4 (four) weeks from now Fedora will stop maintaining
and issuing updates for Fedora 25. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as EOL if it remains open with a Fedora  'version'
of '25'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version'
to a later Fedora version.

Thank you for reporting this issue and we are sorry that we were not
able to fix it before Fedora 25 is end of life. If you would still like
to see this bug fixed and are able to reproduce it against a later version
of Fedora, you are encouraged  change the 'version' to a later Fedora
version prior this bug is closed as described in the policy above.

Although we aim to fix as many bugs as possible during every release's
lifetime, sometimes those efforts are overtaken by events. Often a
more recent Fedora release includes newer upstream software that fixes
bugs or makes them obsolete.

Comment 2 Petr Viktorin 2017-12-02 14:45:14 UTC
I can still reproduce with python3-flask-admin 1.4.2-3.fc26

Comment 3 Itamar Reis Peixoto 2018-02-15 20:13:54 UTC
I think the ownership in the rpm are ok, what are the problem caused by having mockbuild owning the files ?

Comment 4 Zbigniew Jędrzejewski-Szmek 2018-02-15 20:33:22 UTC
Users are a primary mechanism of privilege separation. In particular, any files program owned by non-root users allow that user to inject code. Thus, privileges of doing stuff as mockbuild can be elevated to privileges of any other user running code which imports python-flask-admin.

The guidelines are pretty clear [https://fedoraproject.org/wiki/Packaging:Guidelines#File_Permissions]:
> Inside of /usr, files should be owned by root:root unless a more specific user or group is needed for security.

(and in this case having files owned by mockbuild decreases security, since it's not a dedicated user for this purpose, so that last clause does not apply.)

Comment 5 Fedora End Of Life 2018-05-03 08:23:22 UTC
This message is a reminder that Fedora 26 is nearing its end of life.
Approximately 4 (four) weeks from now Fedora will stop maintaining
and issuing updates for Fedora 26. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as EOL if it remains open with a Fedora  'version'
of '26'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version'
to a later Fedora version.

Thank you for reporting this issue and we are sorry that we were not
able to fix it before Fedora 26 is end of life. If you would still like
to see this bug fixed and are able to reproduce it against a later version
of Fedora, you are encouraged  change the 'version' to a later Fedora
version prior this bug is closed as described in the policy above.

Although we aim to fix as many bugs as possible during every release's
lifetime, sometimes those efforts are overtaken by events. Often a
more recent Fedora release includes newer upstream software that fixes
bugs or makes them obsolete.

Comment 6 Petr Viktorin 2018-05-03 16:24:57 UTC
I can still reproduce with python3-flask-admin 1.5.0-3.fc28

Comment 7 Itamar Reis Peixoto 2018-05-03 17:34:56 UTC
pull request at -> 

https://src.fedoraproject.org/rpms/python-flask-admin/pull-request/4

just commenting some offending lines, in next changes we can drop them if they are not required.

Comment 8 Fedora Update System 2018-05-05 03:56:09 UTC
python-flask-admin-1.5.0-4.fc28 has been submitted as an update to Fedora 28. https://bodhi.fedoraproject.org/updates/FEDORA-2018-fac3207a49

Comment 9 Fedora Update System 2018-05-06 10:08:23 UTC
python-flask-admin-1.5.0-4.fc28 has been pushed to the Fedora 28 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-fac3207a49

Comment 10 Fedora Update System 2018-05-14 17:53:56 UTC
python-flask-admin-1.5.0-4.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this bug report.