Bug 1559711 - Review Request: libemu - The x86 shell-code detection and emulation
Summary: Review Request: libemu - The x86 shell-code detection and emulation
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Robert-André Mauchin 🐧
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On: 1559699
Blocks: FE-Legal FE-SECLAB
TreeView+ depends on / blocked
 
Reported: 2018-03-23 05:28 UTC by Michal Ambroz
Modified: 2018-04-21 03:39 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-04-15 02:34:20 UTC
Type: ---
Embargoed:
zebob.m: fedora-review+


Attachments (Terms of Use)

Description Michal Ambroz 2018-03-23 05:28:53 UTC
Spec URL: http://rebus.fedorapeople.org//libemu.spec
SRPM URL: http://rebus.fedorapeople.org//libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm

Description:
The libemu is a small library written in C offering basic x86 emulation and
shell-code detection using GetPC heuristics. Intended use is within network
intrusion/prevention detection and honeypots.

Comment 1 Michal Ambroz 2018-03-23 06:20:20 UTC
===== Koji scratch build 

$ koji build --scratch rawhide  libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm 
Uploading srpm: libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm
[====================================] 100% 00:00:00 561.05 KiB 626.21 KiB/sec
Created task: 25897719
Task info: https://koji.fedoraproject.org/koji/taskinfo?taskID=25897719
Watching tasks (this may be safely interrupted)...
25897719 build (rawhide, libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm): open (buildvm-ppc64le-13.ppc.fedoraproject.org)
  25897726 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, armv7hl): free
  25897725 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, s390x): free
  25897724 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, i686): free
  25897723 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, ppc64): free
  25897722 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, aarch64): open (buildvm-aarch64-09.arm.fedoraproject.org)
  25897721 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, ppc64le): free
  25897720 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, x86_64): free
  25897726 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, armv7hl): free -> open (buildvm-armv7-20.arm.fedoraproject.org)
  25897725 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, s390x): free -> open (buildvm-s390x-13.s390.fedoraproject.org)
  25897724 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, i686): free -> open (buildvm-13.phx2.fedoraproject.org)
  25897723 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, ppc64): free -> open (buildvm-ppc64-13.ppc.fedoraproject.org)
  25897721 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, ppc64le): free -> open (buildvm-ppc64le-13.ppc.fedoraproject.org)
  25897720 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, x86_64): free -> open (buildhw-05.phx2.fedoraproject.org)
  25897720 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, x86_64): open (buildhw-05.phx2.fedoraproject.org) -> closed
  0 free  7 open  1 done  0 failed
  25897724 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, i686): open (buildvm-13.phx2.fedoraproject.org) -> closed
  0 free  6 open  2 done  0 failed
  25897725 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, s390x): open (buildvm-s390x-13.s390.fedoraproject.org) -> closed
  0 free  5 open  3 done  0 failed
  25897722 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, aarch64): open (buildvm-aarch64-09.arm.fedoraproject.org) -> closed
  0 free  4 open  4 done  0 failed
  25897721 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, ppc64le): open (buildvm-ppc64le-13.ppc.fedoraproject.org) -> closed
  0 free  3 open  5 done  0 failed
  25897723 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, ppc64): open (buildvm-ppc64-13.ppc.fedoraproject.org) -> closed
  0 free  2 open  6 done  0 failed
  25897726 buildArch (libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm, armv7hl): open (buildvm-armv7-20.arm.fedoraproject.org) -> closed
  0 free  1 open  7 done  0 failed
25897719 build (rawhide, libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm): open (buildvm-ppc64le-13.ppc.fedoraproject.org) -> closed
  0 free  0 open  8 done  0 failed

25897719 build (rawhide, libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm) completed successfully

====== rpmlint 
$ rpmlint libemu.spec libemu-0.2.0-0.4.20130410gitab48695.fc27.src.rpm 
1 packages and 1 specfiles checked; 0 errors, 0 warnings.

====== knnown issues
fails to build the python3 package - I have the stanzas in the spec to see what is failing and how in koji

Comment 2 Michal Ambroz 2018-03-26 00:09:31 UTC
Spec URL: http://rebus.fedorapeople.org//libemu.spec
SRPM URL: http://rebus.fedorapeople.org//libemu-0.2.0-0.5.20130410gitab48695.fc27.src.rpm

- adding the missing python3-devel build dependency

Comment 3 Michal Ambroz 2018-03-26 11:57:18 UTC
Known issue - there is embedded version 1.4 of the libdasm library.
This should be de-referenced and updated to current version.

Adding dependency to #1559699

Comment 4 Robert-André Mauchin 🐧 2018-03-27 18:12:36 UTC
 - What's the point of:

|| touch python3_build_failed

|| touch %{buildroot}/%{python3_sitearch}/python3_install_failed
[ -f python3_build_failed ] && touch %{buildroot}/%{python3_sitearch}/python3_build_failed


 - Use the new %ldconfig_scriptlets. See https://fedoraproject.org/wiki/Changes/Removing_ldconfig_scriptlets#Upgrade.2Fcompatibility_impact

 - Not needed:

# ldconfig is provided by glibc
Requires(post): ldconfig
Requires(postun): ldconfig

 - How do you plan to unbundle libdasm since you're also packaging it?

Comment 5 Michal Ambroz 2018-03-30 03:08:46 UTC
Hello Robert,
> - What's the point of:
I just wanted to see the error-logs from the python3 build - although it is now failing. I do not plan to use this stanza

>- How do you plan to unbundle libdasm since you're also packaging it?
Yes I plan to unbundle it once it is ready as a standalone package.
Code here is the old-old version 1.4 (2006) with the same license doubts.
I plan to remove the libdasm.c and libdasm.h and use the system-installed library instead.

> ldconfig
OK will do.

Comment 6 Michal Ambroz 2018-04-02 00:02:52 UTC
Spec URL: http://rebus.fedorapeople.org/libemu.spec
SRPM URL: http://rebus.fedorapeople.org/libemu-0.2.0-7.20130410gitab48695.fc27.src.rpm

- unbundle the libdasm library and use system-installed one
- disable python3 build/installation as it doesn't work at this point

Comment 7 Robert-André Mauchin 🐧 2018-04-02 11:28:32 UTC
 - Use the new %ldconfig_scriptlets. See https://fedoraproject.org/wiki/Changes/Removing_ldconfig_scriptlets#Upgrade.2Fcompatibility_impact

 - Release in the header and in the %changelog are mismatched:

libemu.x86_64: W: incoherent-version-in-changelog 0.2.0-0.7.20130410gitab48695 ['0.2.0-7.20130410gitab48695.fc29', '0.2.0-7.20130410gitab48695']

 - [!]: Package should not use obsolete m4 macros
     Note: Some obsoleted macros found, see the attachment.
     See: https://fedorahosted.org/FedoraReview/wiki/AutoTools

AutoTools: Obsoleted m4s found
------------------------------
  AC_PROG_LIBTOOL found in: libemu-
  ab48695b7113db692982a1839e3d6eb9e73e90a9/configure.ac:49
  AM_CONFIG_HEADER found in: libemu-
  ab48695b7113db692982a1839e3d6eb9e73e90a9/configure.ac:14

Replace AC_PROG_LIBTOOL with LT_INIT and AM_CONFIG_HEADER with AC_CONFIG_HEADERS

 - Exclude libemu.so from Python2 provides

python2-libemu.x86_64: W: private-shared-object-provides /usr/lib64/python2.7/site-packages/libemu.so libemu.so()(64bit)

%global __provides_exclude_from ^%{python2_sitearch}/libemu.so$



Package Review
==============

Legend:
[x] = Pass, [!] = Fail, [-] = Not applicable, [?] = Not evaluated
[ ] = Manual review needed


===== MUST items =====

C/C++:
[x]: Package does not contain kernel modules.
[x]: Package contains no static executables.
[x]: Development (unversioned) .so files in -devel subpackage, if present.
     Note: Unversioned so-files in private %_libdir subdirectory (see
     attachment). Verify they are not in ld path.
[x]: Header files in -devel subpackage, if present.
[x]: ldconfig called in %post and %postun if required.
[x]: Package does not contain any libtool archives (.la)
[x]: Rpath absent or only used for internal libs.

Generic:
[x]: Package is licensed with an open-source compatible license and meets
     other legal requirements as defined in the legal section of Packaging
     Guidelines.
[-]: If (and only if) the source package includes the text of the
     license(s) in its own file, then that file, containing the text of the
     license(s) for the package is included in %license.
[x]: License field in the package spec file matches the actual license.
     Note: Checking patched sources after %prep for licenses. Licenses
     found: "GPL (v3)", "GPL (v2 or later)", "Unknown or generated". 51
     files have unknown license. Detailed output of licensecheck in
     /home/bob/packaging/review/libemu/review-libemu/licensecheck.txt
[x]: License file installed when any subpackage combination is installed.
[x]: %build honors applicable compiler flags or justifies otherwise.
[x]: Package contains no bundled libraries without FPC exception.
[x]: Changelog in prescribed format.
[x]: Sources contain only permissible code or content.
[-]: Package contains desktop file if it is a GUI application.
[x]: Development files must be in a -devel package
[x]: Package uses nothing in %doc for runtime.
[x]: Package consistently uses macros (instead of hard-coded directory
     names).
[x]: Package is named according to the Package Naming Guidelines.
[x]: Package does not generate any conflict.
[x]: Package obeys FHS, except libexecdir and /usr/target.
[-]: If the package is a rename of another package, proper Obsoletes and
     Provides are present.
[x]: Requires correct, justified where necessary.
[x]: Spec file is legible and written in American English.
[-]: Package contains systemd file(s) if in need.
[x]: Useful -debuginfo package or justification otherwise.
[x]: Package is not known to require an ExcludeArch tag.
[-]: Large documentation must go in a -doc subpackage. Large could be size
     (~1MB) or number of files.
     Note: Documentation size is 20480 bytes in 3 files.
[x]: Package complies to the Packaging Guidelines
[x]: Package successfully compiles and builds into binary rpms on at least
     one supported primary architecture.
[x]: Package installs properly.
[x]: Rpmlint is run on all rpms the build produces.
     Note: There are rpmlint messages (see attachment).
[x]: Package requires other packages for directories it uses.
[x]: Package must own all directories that it creates.
[x]: Package does not own files or directories owned by other packages.
[x]: Package uses either %{buildroot} or $RPM_BUILD_ROOT
[x]: Package does not run rm -rf %{buildroot} (or $RPM_BUILD_ROOT) at the
     beginning of %install.
[x]: Macros in Summary, %description expandable at SRPM build time.
[x]: Dist tag is present.
     Note: Multiple Release: tags found
[x]: Package does not contain duplicates in %files.
[x]: Package use %makeinstall only when make install DESTDIR=... doesn't
     work.
[x]: Package is named using only allowed ASCII characters.
[x]: Package does not use a name that already exists.
[x]: Package is not relocatable.
[x]: Sources used to build the package match the upstream source, as
     provided in the spec URL.
[x]: Spec file name must match the spec package %{name}, in the format
     %{name}.spec.
[x]: File names are valid UTF-8.
[x]: Packages must not store files under /srv, /opt or /usr/local

===== SHOULD items =====

Generic:
[-]: If the source package does not include license text(s) as a separate
     file from upstream, the packager SHOULD query upstream to include it.
[x]: Final provides and requires are sane (see attachments).
[?]: Package functions as described.
[x]: Latest version is packaged.
[x]: Package does not include license text files separate from upstream.
[x]: Patches link to upstream bugs/comments/lists or are otherwise
     justified.
[x]: Scriptlets must be sane, if used.
[-]: Description and summary sections in the package spec file contains
     translations for supported Non-English languages, if available.
[x]: Package should compile and build into binary rpms on all supported
     architectures.
[-]: %check is present and all tests pass.
[x]: Packages should try to preserve timestamps of original installed
     files.
[x]: Reviewer should test that the package builds in mock.
[x]: Buildroot is not present
[x]: Package has no %clean section with rm -rf %{buildroot} (or
     $RPM_BUILD_ROOT)
[x]: No file requires outside of /etc, /bin, /sbin, /usr/bin, /usr/sbin.
[x]: Fully versioned dependency in subpackages if applicable.
[x]: Packager, Vendor, PreReq, Copyright tags should not be in spec file
[x]: Uses parallel make %{?_smp_mflags} macro.
[x]: The placement of pkgconfig(.pc) files are correct.
[x]: Sources can be downloaded from URI in Source: tag
[x]: SourceX is a working URL.
[x]: Spec use %global instead of %define unless justified.

===== EXTRA items =====

Generic:
[!]: Package should not use obsolete m4 macros
     Note: Some obsoleted macros found, see the attachment.
     See: https://fedorahosted.org/FedoraReview/wiki/AutoTools
[x]: Rpmlint is run on debuginfo package(s).
     Note: There are rpmlint messages (see attachment).
[x]: Rpmlint is run on all installed packages.
     Note: There are rpmlint messages (see attachment).
[x]: Large data in /usr/share should live in a noarch subpackage if package
     is arched.
[x]: Spec file according to URL is the same as in SRPM.


Rpmlint
-------
Checking: libemu-0.2.0-7.20130410gitab48695.fc29.x86_64.rpm
          libemu-devel-0.2.0-7.20130410gitab48695.fc29.x86_64.rpm
          python2-libemu-0.2.0-7.20130410gitab48695.fc29.x86_64.rpm
          libemu-debuginfo-0.2.0-7.20130410gitab48695.fc29.x86_64.rpm
          libemu-debugsource-0.2.0-7.20130410gitab48695.fc29.x86_64.rpm
          libemu-0.2.0-7.20130410gitab48695.fc29.src.rpm
libemu.x86_64: W: incoherent-version-in-changelog 0.2.0-0.7.20130410gitab48695 ['0.2.0-7.20130410gitab48695.fc29', '0.2.0-7.20130410gitab48695']
libemu.x86_64: W: shared-lib-calls-exit /usr/lib64/libemu.so.2.0.0 exit.5
libemu.x86_64: W: no-manual-page-for-binary scprofiler
libemu.x86_64: W: no-manual-page-for-binary sctest
libemu-devel.x86_64: W: only-non-binary-in-usr-lib
python2-libemu.x86_64: W: private-shared-object-provides /usr/lib64/python2.7/site-packages/libemu.so libemu.so()(64bit)
python2-libemu.x86_64: W: no-documentation
libemu-debugsource.x86_64: W: no-documentation
6 packages and 0 specfiles checked; 0 errors, 8 warnings.

Comment 8 Michal Ambroz 2018-04-03 18:57:54 UTC
Hello Robert-Andre,
thankyou for review - here is the updated package:
Spec URL: http://rebus.fedorapeople.org/libemu.spec
SRPM URL: http://rebus.fedorapeople.org/libemu-0.2.0-8.20130410gitab48695.fc27.src.rpm

- use ldconfig_scriptlets                                                                                                                                                                                          
- fix release version number in the changelog
- fix the obsolete m4 macros                                                                                                                                                                      
- Exclude the private libemu.so library in python sitearch dir                                                                                                                                                                

- show all warnings to autoreconf                                                                                                                                                                                  
- use autosetup+git for troubleshooting the patches

Comment 9 Robert-André Mauchin 🐧 2018-04-03 20:30:45 UTC
Why do you git commit stuff? This is useless. You shouln't even need git.

Comment 10 Jason Tibbitts 2018-04-03 21:29:48 UTC
From a package maintainer standpoint, it can be extremely useful to use %autosetup -S git if you are applying more than a couple of patches.

Comment 11 Robert-André Mauchin 🐧 2018-04-03 22:04:12 UTC
I'm talking about:

git commit -q -a -m "unbundle libdasm"

git commit -q -a -m "downgrade autoconf for rhel6"

Comment 12 Michal Ambroz 2018-04-03 23:03:16 UTC
Hi Robert
- I am using git the same way from prep script how it is used from the autosetup.

It is same reason as already mentioned by Jason - I have all changes from patches (14 is too many to fiddle without version control) auto-commited with the autosetup -S git to be able to pinpoint the issues separately and change individual patches.

I do some unbundling changes with scripts like removing files ... so I do the commits at those points as well.

If "-S git" is recommended for autosetup ... why it should be problem to make git commits from a script ... so I have got clean slate after %prep and before %build.

Please note the git is not used for downloading stuff online or pushing to upstream. It is simply used for having more granular atomic pin-points in the process of patching.

Best regards
Michal Ambroz

Comment 13 Robert-André Mauchin 🐧 2018-04-03 23:08:47 UTC
Ok, package is approved.

Comment 14 Michal Ambroz 2018-04-03 23:19:25 UTC
Thank you Robert-Andre.

BTW just try running "rpmbuild -bp libemu.spec" then going to the build directory and using "git status", "git log" , "git diff" , "git reset --hard HEAD~1" commands. It is extremely usefull for the packaging workflow fiddling with more than couple of patches / changes.

Comment 16 Jason Tibbitts 2018-04-04 15:09:11 UTC
(fedrepo-req-admin):  The Pagure repository was created at https://src.fedoraproject.org/rpms/libemu

Comment 17 Fedora Update System 2018-04-05 02:48:09 UTC
libemu-0.2.0-8.20130410gitab48695.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2018-27aaee2a9c

Comment 18 Fedora Update System 2018-04-05 02:48:19 UTC
libemu-0.2.0-8.20130410gitab48695.fc26 has been submitted as an update to Fedora 26. https://bodhi.fedoraproject.org/updates/FEDORA-2018-ad1355662c

Comment 19 Fedora Update System 2018-04-05 02:48:26 UTC
libemu-0.2.0-8.20130410gitab48695.fc28 has been submitted as an update to Fedora 28. https://bodhi.fedoraproject.org/updates/FEDORA-2018-42ed2dfa4e

Comment 20 Fedora Update System 2018-04-05 02:48:33 UTC
libemu-0.2.0-8.20130410gitab48695.el7 has been submitted as an update to Fedora EPEL 7. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-6e774e5bc6

Comment 21 Fedora Update System 2018-04-05 15:50:06 UTC
libemu-0.2.0-8.20130410gitab48695.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-ad1355662c

Comment 22 Fedora Update System 2018-04-05 16:04:04 UTC
libemu-0.2.0-8.20130410gitab48695.fc27 has been pushed to the Fedora 27 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-27aaee2a9c

Comment 23 Fedora Update System 2018-04-05 19:13:13 UTC
libemu-0.2.0-8.20130410gitab48695.el7 has been pushed to the Fedora EPEL 7 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-6e774e5bc6

Comment 24 Fedora Update System 2018-04-06 02:32:10 UTC
libemu-0.2.0-8.20130410gitab48695.fc28 has been pushed to the Fedora 28 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-42ed2dfa4e

Comment 25 Fedora Update System 2018-04-15 02:34:20 UTC
libemu-0.2.0-8.20130410gitab48695.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this bug report.

Comment 26 Fedora Update System 2018-04-15 18:12:35 UTC
libemu-0.2.0-8.20130410gitab48695.fc26 has been pushed to the Fedora 26 stable repository. If problems still persist, please make note of it in this bug report.

Comment 27 Fedora Update System 2018-04-21 02:56:54 UTC
libemu-0.2.0-8.20130410gitab48695.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.

Comment 28 Fedora Update System 2018-04-21 03:39:02 UTC
libemu-0.2.0-8.20130410gitab48695.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.