Bug 17673 - inconsistency with verify in gnorpm-0.95-1
inconsistency with verify in gnorpm-0.95-1
Status: CLOSED ERRATA
Product: Red Hat Linux
Classification: Retired
Component: gnorpm (Show other bugs)
6.2
i386 Linux
medium Severity medium
: ---
: ---
Assigned To: Alan Cox
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2000-09-19 02:54 EDT by Jeremy Katz
Modified: 2008-05-01 11:37 EDT (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2000-09-24 12:20:51 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Jeremy Katz 2000-09-19 02:54:37 EDT
There's an inconsistency in the verification of packages in the errata test
of gnorpm.  If running as a normal user, you click the verify button on the
menu bar or the Verify option in the Packages menu, you get an error
message about requiring superuser privileges to verify packages.  In
contrast, if you select a package from one of the package groups and right
click on the package and select verify from the context menu, you are
happily allowed to verify the package.

So either verify_one() in verify.c needs an euid check added or the check
in rpm_verify_pkgs() in mainwin.c needs to be removed.  As RPM by default
allows any user to verify already installed packages, I'd lean towards the
latter.
Comment 1 Alan Cox 2000-09-23 18:53:32 EDT
Has to be the former - a user cannot verify a file they cannot read
Comment 2 Alan Cox 2000-09-24 12:20:49 EDT
Fixed in gnome cvs

Note You need to log in before you can comment on or make changes to this bug.