Bug 1771338 - Review Request: host-verification-service - RPM Package for ISecL Host Verification Service Component
Summary: Review Request: host-verification-service - RPM Package for ISecL Host Verifi...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: All
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Nobody's working on this, feel free to take it
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: FE-NEEDSPONSOR FE-DEADREVIEW
TreeView+ depends on / blocked
 
Reported: 2019-11-12 08:30 UTC by Tim Knoll
Modified: 2021-10-02 00:45 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-02 00:45:59 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Tim Knoll 2019-11-12 08:30:05 UTC
Spec URL: https://01.org/sites/default/files/downloads//verification-service-1.5.1.zip
SRPM URL: https://01.org/sites/default/files/downloads//verification-service-1.5.1.zip
Spec and SRPM are bundled into a single zip file.

Description: This package provides the Host Verification Service component of Intel Security Libraries for Datacenter.  This service is the primary server component of ISecL, used to provide a remote attestation authority for establishing platform integrity using Intel security features like Intel TXT and Intel Boot Guard.  Remote attestation provides a method by which TCG-defined measurements in a server TPM can be securely quoted and compared against expected values to determine whether the integrity of any measured component has been compromised.  The Verification Service acts as the remote attestation authority and maintains a database of user-defined expected measurements values, and provides an intelligent verification engine that allows easy centralized management of expected measurements and supports a variety of root-of-trust configurations.

Fedora Account System Username: teknoll

Comment 1 Neil Horman 2019-11-18 18:50:27 UTC
Adding FE-NEEDSPONSOR, as the submitter is not currently a packager

Submission is in incorrect format, should not be zipped into a single file, SPEC url and SRPM URL should point to those files specifically, so that fedora-review works with the BZ

package fails to build:
[exec] main:
     [exec]     [mkdir] Created dir: /home/nhorman/rpmbuild/BUILD/contrib/features/hex2bin/target/dist
     [exec]     [mkdir] Created dir: /home/nhorman/rpmbuild/BUILD/contrib/features/hex2bin/target/dist-deps
     [exec]     [touch] Creating /home/nhorman/rpmbuild/BUILD/contrib/features/hex2bin/target/dist/builder/x
     [exec]      [exec] PREFIX=/opt/mtwilson/share/hex2bin
     [exec]      [exec] mkdir: cannot create directory '/opt/mtwilson': Permission denied
     [exec]      [exec] gcc -fstack-protector-strong -fPIE -fPIC -O2 -D_FORTIFY_SOURCE=2 -Wformat -Wformat-security -o hex2bin hex2bin.c -z noexecstack -z relro -z now -pie
     [exec]      [exec] mkdir: cannot create directory '/opt/mtwilson': Permission denied
     [exec]      [exec] chmod +x hex2bin
     [exec]      [exec] mkdir: cannot create directory '/opt/mtwilson': Permission denied
     [exec]      [exec] mkdir -p /opt/mtwilson/share/hex2bin/bin
     [exec]      [exec] make: *** [Makefile:13: install] Error 1
     [exec]      [exec] Failed to make install hex2bin
     [exec]      [exec] mkdir: cannot create directory '/opt/mtwilson': Permission denied
     [exec]      [exec] make: *** [Makefile:13: install] Error 1
     [exec] [INFO] ------------------------------------------------------------------------
     [exec] [INFO] Reactor Summary:
     [exec] [INFO] 
     [exec] [INFO] hex2bin-dist 1.0 ................................... FAILURE [  1.931 s]
     [exec] [INFO] mtwilson-maven-build-contrib-features 1.1 .......... SKIPPED
     [exec] [INFO] ------------------------------------------------------------------------
     [exec] [INFO] BUILD FAILURE
     [exec] [INFO] ------------------------------------------------------------------------
     [exec] [INFO] Total time: 2.053 s
     [exec] [INFO] Finished at: 2019-11-18T13:49:48-05:00
     [exec] [INFO] ------------------------------------------------------------------------
     [exec] [ERROR] Failed to execute goal org.apache.maven.plugins:maven-antrun-plugin:1.7:run (default-cli) on project hex2bin-dist: An Ant BuildException has occured: exec returned: 2
     [exec] [ERROR] around Ant part ...<exec failonerror="true" dir="/home/nhorman/rpmbuild/BUILD/contrib/features/hex2bin/target" executable="/bin/bash">... @ 27:122 in /home/nhorman/rpmbuild/BUILD/contrib/features/hex2bin/target/antrun/build-main.xml
     [exec] [ERROR] -> [Help 1]
     [exec] [ERROR] 
     [exec] [ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch.
     [exec] [ERROR] Re-run Maven using the -X switch to enable full debug logging.
     [exec] [ERROR] 
     [exec] [ERROR] For more information about the errors and possible solutions, please read the following articles:
     [exec] [ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoExecutionException
     [exec] Result: 1

Comment 2 Petr Pisar 2019-12-11 08:45:59 UTC
A summary of this bug report is invalid. Review requests must have this format:

  Review Request: PACKAGE_NAME - PACKAGE_SUMMARY

The review request must link to _directly_ downloadable SPEC and SRPM files. Hiding them into a ZIP archive is not the right way.

Comment 3 Tim Knoll 2020-01-10 21:32:57 UTC
We have re-uploaded the source RPM and spec files to a new location:

Spec URL: https://github.com/intel-secl/verification-service/blob/v1.5.1/packages/host-verification-service-linux/src/build/host-verification-service.spec
SRPM URL: https://github.com/intel-secl/verification-service/blob/v1.5.1/packages/host-verification-service-linux/src/build/host-verification-service-4.5-1.el7.src.rpm

We are currently still working through the Koji build failures and will update once we have a resolution.

I'll also update the title to meet the format requirement.

Comment 4 Sumit 2020-02-19 13:11:16 UTC
Hi Guys,

As i am new to this can you please tell how you are trying to review this package. 
I am using fedora rawhide server (VERSION_ID=32)

1. For me it is saying package is not in correct format.

I manually downloaded the srpm file , then tried to run it, but getting below errors

Step1: wget https://github.com/intel-secl/verification-service/blob/v1.5.1/packages/host-verification-service-linux/src/build/host-verification-service-4.5-1.el7.src.rpm

[root@localhost ~]# rpm -qpl host-verification-service-4.5-1.el7.src.rpm
error: host-verification-service-4.5-1.el7.src.rpm: not an rpm package (or package manifest)

[root@localhost ~]# fedora-review --rpm-spec -n host-verification-service-4.5-1.el7.src.rpm
INFO: Processing local files: host-verification-service-4.5-1.el7.src.rpm
INFO: Getting .spec and .srpm Urls from : Local files in /root
INFO:   --> SRPM url: file:///root/host-verification-service-4.5-1.el7.src.rpm
INFO: Using review directory: /root/host-verification-service
argument is not an RPM package
cpio: premature end of archive
WARNING: Cannot unpack /root/host-verification-service/srpm/host-verification-service-4.5-1.el7.src.rpm into /root/host-verification-service/srpm-unpacked
argument is not an RPM package
cpio: premature end of archive
WARNING: Cannot unpack /root/host-verification-service/srpm/host-verification-service-4.5-1.el7.src.rpm into /root/host-verification-service/srpm-unpacked
ERROR: 'Cannot find spec file in srpm' (logs in /root/.cache/fedora-review.log)

Comment 5 Package Review 2021-10-02 00:45:59 UTC
This is an automatic action taken by review-stats script.

The ticket submitter failed to clear the NEEDINFO flag in a month.
As per https://fedoraproject.org/wiki/Policy_for_stalled_package_reviews
we consider this ticket as DEADREVIEW and proceed to close it.


Note You need to log in before you can comment on or make changes to this bug.