Bug 1513290 - Review Request: ocaml-oasis - Tooling for building OCaml libraries and applications
Summary: Review Request: ocaml-oasis - Tooling for building OCaml libraries and applic...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Robert-André Mauchin 🐧
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-11-15 05:52 UTC by Andy Li
Modified: 2018-01-16 16:52 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-01-16 16:52:01 UTC
Type: ---
Embargoed:
zebob.m: fedora-review+


Attachments (Terms of Use)

Description Andy Li 2017-11-15 05:52:22 UTC
Spec URL: https://gist.github.com/andyli/32e655c7e638fe49894603045dcabbab/raw/03251fa42fc0f6b4b41f203e306365057ae35157/ocaml-oasis.spec
SRPM URL: https://gist.github.com/andyli/32e655c7e638fe49894603045dcabbab/raw/03251fa42fc0f6b4b41f203e306365057ae35157/ocaml-oasis-0.4.10-1.fc28.src.rpm
Description: Tooling for building OCaml libraries and applications
Fedora Account System Username: andyli

This is a dependency of a number of OCaml libs used by the next version of Haxe (v4.0.0).

Comment 1 Robert-André Mauchin 🐧 2017-11-15 18:28:09 UTC
There's a rpmlint error:

ocaml-oasis.x86_64: E: missing-call-to-chdir-with-chroot /usr/bin/oasis

missing-call-to-chdir-with-chroot:
This executable appears to call chroot without using chdir to change the
current directory. This is likely an error and permits an attacker to break
out of the chroot by using fchdir. While that's not always a security issue,
this has to be checked.

Comment 2 Andy Li 2017-11-16 01:41:27 UTC
I don't think oasis ever calls chroot: https://github.com/ocaml/oasis/search?utf8=%E2%9C%93&q=chroot&type=
It does call chdir though: https://github.com/ocaml/oasis/search?utf8=%E2%9C%93&q=chdir&type=

It seems like a common false-positive: https://bugzilla.redhat.com/show_bug.cgi?id=1396563

Comment 3 Robert-André Mauchin 🐧 2017-11-16 12:23:34 UTC
Hmmm, okay, package accepted then.

Comment 4 Gwyn Ciesla 2017-11-16 12:45:04 UTC
(fedrepo-req-admin):  The Pagure repository was created at https://src.fedoraproject.org/rpms/ocaml-oasis

Comment 5 Fedora Update System 2017-12-22 02:24:28 UTC
ocaml-oasis-0.4.10-3.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2017-1b7266f53e

Comment 6 Fedora Update System 2017-12-22 12:43:06 UTC
ocaml-oasis-0.4.10-3.fc27 has been pushed to the Fedora 27 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-1b7266f53e

Comment 7 Fedora Update System 2018-01-02 16:52:46 UTC
ocaml-oasis-0.4.10-3.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2018-01-03 01:49:17 UTC
ocaml-oasis-0.4.10-3.fc26 has been submitted as an update to Fedora 26. https://bodhi.fedoraproject.org/updates/FEDORA-2018-afda83891b

Comment 9 Fedora Update System 2018-01-03 23:55:09 UTC
ocaml-oasis-0.4.10-3.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-afda83891b

Comment 10 Fedora Update System 2018-01-05 11:01:16 UTC
ocaml-oasis-0.4.10-3.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-afda83891b

Comment 11 Fedora Update System 2018-01-16 16:52:01 UTC
ocaml-oasis-0.4.10-3.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.