Bug 2525507
| Summary: | Review Request: minkipc - Capability based security framework | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Ali Erdinc Koroglu <ali.koroglu> |
| Component: | Package Review | Assignee: | Hans de Goede <hans> |
| Status: | NEW --- | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | rawhide | CC: | hans, package-review |
| Target Milestone: | --- | Flags: | hans:
fedora-review?
|
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Ali Erdinc Koroglu
2026-08-28 08:35:26 UTC
I'm going to review this, assigning to myself. There are a number of issues with this package: 1. You have the same %changelog instead of %autochangelog as in a couple of your previous packages, please fix this for the next version. 2. its -devel install a /usr/include/object.h header which is a much much too generic header name 3. The udev-rules start the service based on quite generic device names / classes like /dev/tee* and mmc_rpmb, causing the services to also hw-activate on non Qualcomm hw when installed. I think it might be best to install this as a udev-rule example in %docs instead. That or fix the udev-rules to be more specific / selective. 4. A bigger problem is that the upstream sources seem to contain binary only firmware files, looking at: https://download.copr.fedorainfracloud.org/results/aekoroglu/fedora/fedora-rawhide-aarch64/10909154-minkipc/fedora-review/licensecheck.txt and then specifically at the "Unknown or generated" at the end it has: minkipc-1.2.9-build/minkipc-1.2.9/mink_platform/mink_test/qtvm_test/prebuilt_qtee_ta/credtestapp64.mbn ... minkipc-1.2.9-build/minkipc-1.2.9/ta/NO.LOGIN.BINARY.LICENSE.QTI.pdf minkipc-1.2.9-build/minkipc-1.2.9/ta/glymur/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/glymur/tzecotestapp.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/kaanapali/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/kaanapali/tzecotestapp.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/mahua/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/mahua/tzecotestapp.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/qcm2290/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/qcm2290/tzecotestapp.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/qcm6490/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/qcm6490/tzecotestapp.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs615/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs8300/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs8300/tzecotestapp.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs9100/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/qcs9100/tzecotestapp.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/shikra/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/shikra/tzecotestapp.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/sm8750/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/sm8750/tzecotestapp.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/x1e80100/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/x1e80100/tzecotestapp.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/x1p42100/FD02C9DA-306C-48C7-A49C-BBD827AE86EE.mbn minkipc-1.2.9-build/minkipc-1.2.9/ta/x1p42100/tzecotestapp.mbn The files under the 'ta/' dir are presumably licensed under: minkipc-1.2.9-build/minkipc-1.2.9/ta/NO.LOGIN.BINARY.LICENSE.QTI.pdf Which when converted to text appears to be the same license as under which Qualcomm linux-firmware files are shipped. Which would make them fall under the firmware-license exception: https://docs.fedoraproject.org/en-US/legal/license-approval/#_licenses_allowed_for_firmware But the minkipc-1.2.9-build/minkipc-1.2.9/mink_platform/mink_test/qtvm_test/prebuilt_qtee_ta/credtestapp64.mbn file does not seem to have any license specified at all! And even with the other firmware files being under an ok firmware license, none end up in the actual build rpms and the firmware-license extension starts with: "Some applications, drivers, and hardware require binary firmware images to boot Fedora Linux or function properly." which is clearly not the case here since we end up not packaging these at all. So I think it is just best to use a cleaned tarbal with *all* firmware files removed, see: https://fedorapeople.org/~tmz/guidelines/packaging-guidelines/SourceURL/#when-upstream-uses-prohibited-code |