Bug 2047338

Summary: publicsuffix-list-dafsa/COPYING is group-writable
Product: Red Hat Enterprise Linux 9 Reporter: Timothée Ravier <travier>
Component: publicsuffix-listAssignee: Kamil Dudka <kdudka>
Status: CLOSED ERRATA QA Contact: qe-baseos-daemons
Severity: low Docs Contact:
Priority: low    
Version: CentOS StreamCC: bstinson, cverna, fsumsal, jwboyer, kdudka, veichler
Target Milestone: rcKeywords: Triaged
Target Release: ---Flags: pm-rhel: mirror+
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: publicsuffix-list-20210518-3.el9 Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-05-17 16:04:04 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Timothée Ravier 2022-01-27 16:23:17 UTC
This bug was initially created as a copy of Bug #2023515

I am copying this bug because: It is not fixed in C9S.

Description of problem:

# ls -l /usr/share/licenses/publicsuffix-list-dafsa/COPYING
-rw-rw-r--. 1 root root 16726 May  4  2018 /usr/share/licenses/publicsuffix-list-dafsa/COPYING

The file probably shouldn't be group-writable (has incorrect attr in the spec file).

Comment 1 Kamil Dudka 2022-01-27 16:35:26 UTC
The bug is already fixed in Fedora but it cannot be fixed in c9s unless it is approved for inclusion into RHEL-9.  Is there any business justification to fix this bug in RHEL-9?

Comment 3 Timothée Ravier 2022-01-27 16:52:39 UTC
We look for those "invalid" permissions in our tests in RHCOS (Red Hat Enterprise Linux CoreOS). Fixing this would simplify our tests.

Comment 11 Clement Verna 2022-02-10 17:54:58 UTC
Thanks for merging this :-)

Comment 15 Vojtech Eichler 2022-02-23 14:06:30 UTC
Moving to VERIFIED based on manual testing.

Comment 17 errata-xmlrpc 2022-05-17 16:04:04 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (new packages: publicsuffix-list), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2022:4069