Bug 2043000 - cf-protection test is intentionally skipped on GO binaries but property-note test complains about cf-protection
Summary: cf-protection test is intentionally skipped on GO binaries but property-note ...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 9
Classification: Red Hat
Component: annobin
Version: 9.0
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: Nick Clifton
QA Contact: Václav Kadlčík
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-01-20 13:07 UTC by Václav Kadlčík
Modified: 2023-07-18 14:25 UTC (History)
4 users (show)

Fixed In Version: annobin-10.50-1.el9
Doc Type: No Doc Update
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-05-17 12:33:28 UTC
Type: Bug
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELPLAN-108953 0 None None None 2022-01-20 13:12:33 UTC
Red Hat Product Errata RHEA-2022:2342 0 None None None 2022-05-17 12:33:39 UTC

Description Václav Kadlčík 2022-01-20 13:07:02 UTC
Description of problem:

Because of bz1997759 annocheck skips the cf-protection test.
However it now complains about it in the property-note test.


Version-Release number of selected component (if applicable):

annobin-annocheck-10.48-1.el9


Steps to Reproduce:

1. annocheck --ignore-unknown --verbose --debug-rpm=/mnt/redhat/brewroot/packages/weldr-client/35.2/2.el9/x86_64/weldr-client-debuginfo-35.2-2.el9.x86_64.rpm /mnt/redhat/brewroot/packages/weldr-client/35.2/2.el9/x86_64/weldr-client-35.2-2.el9.x86_64.rpm |& grep cf-protection


Actual results:

Hardened: ./usr/bin/composer-cli: skip: cf-protection test because control flow protection is not needed for GO binaries 
Hardened: ./usr/bin/composer-cli: FAIL: property-note test because a property note was found but it shows that cf-protection is not enabled


Expected results:

On GO binaries, where the cf-protection isn't expected be present
for now and the cf-protection test is intentionally skipped, the 
property-note test shouldn't fail just because of cf-protection.


Additional info:

It looks to me that 10.44 our last rpm build that worked fine,
we don't have a 10.45 build and then 10.46 broke it.

Comment 1 Nick Clifton 2022-01-24 12:47:07 UTC
Fixed in annobin-10.50-1.el9.

Comment 2 Václav Kadlčík 2022-01-24 15:59:43 UTC
pre-verified: annobin-10.50-1.el9

Comment 6 errata-xmlrpc 2022-05-17 12:33:28 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (new packages: annobin), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2022:2342


Note You need to log in before you can comment on or make changes to this bug.