Bug 2253433 - why pull polkit as dependecny?
Summary: why pull polkit as dependecny?
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: chkrootkit
Version: 38
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Gwyn Ciesla
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-12-07 12:18 UTC by Harald Reindl
Modified: 2023-12-16 01:26 UTC (History)
2 users (show)

Fixed In Version: chkrootkit-0.57-4.fc39 chkrootkit-0.57-4.fc38
Clone Of:
Environment:
Last Closed: 2023-12-15 19:04:05 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Harald Reindl 2023-12-07 12:18:37 UTC
why pulling packages not needed at all on a headless server which increases the attack surface in doubt?

Upgrading:
 chkrootkit
Installing dependencies:
 duktape
 polkit
 polkit-libs
 polkit-pkla-compat

Comment 1 Gwyn Ciesla 2023-12-07 20:44:59 UTC
polkit was needed to make the chkrootkit desktop entry usable.

Comment 2 Harald Reindl 2023-12-07 21:17:45 UTC
that this should be a seperate package with a soft-dep because 98 out of 100 chkrootkit installs are on servers without any desktop and i doubt that you manage to install Fedora with a desktop environment where polkit isn't pulled by anything else

Comment 3 Gwyn Ciesla 2023-12-07 21:29:29 UTC
Actually, looking at repoquery, I think I'll keep pkexec in the desktop file but drop the polkit requirement entirely. If the machine has a DE, it will get polkit. If not, the desktop file will be present but not used.

Comment 4 Fedora Update System 2023-12-07 21:53:31 UTC
FEDORA-2023-d20bf70280 has been submitted as an update to Fedora 39. https://bodhi.fedoraproject.org/updates/FEDORA-2023-d20bf70280

Comment 5 Fedora Update System 2023-12-08 01:32:59 UTC
FEDORA-2023-d20bf70280 has been pushed to the Fedora 39 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2023-d20bf70280`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2023-d20bf70280

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2023-12-08 02:38:36 UTC
FEDORA-2023-1b4fd99e22 has been pushed to the Fedora 38 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2023-1b4fd99e22`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2023-1b4fd99e22

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Update System 2023-12-15 19:04:05 UTC
FEDORA-2023-d20bf70280 has been pushed to the Fedora 39 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 8 Fedora Update System 2023-12-16 01:26:03 UTC
FEDORA-2023-1b4fd99e22 has been pushed to the Fedora 38 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.