Bug 2517734 - aesmd.service has wrong permissions 0755 instead of 0644
Summary: aesmd.service has wrong permissions 0755 instead of 0644
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: linux-sgx
Version: 45
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Daniel Berrangé
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-18 09:08 UTC by Petr Sklenar
Modified: 2026-08-24 13:32 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-08-24 13:32:26 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Petr Sklenar 2026-08-18 09:08:43 UTC
Description of problem:
aesmd.service is shipped with mode 0755 instead of 0644.

Per Fedora Packaging Guidelines for Systemd:
"Unit files and drop-ins must be world-readable (i.e. mode 0644)"
https://docs.fedoraproject.org/en-US/packaging-guidelines/Systemd/

systemd warns about this during boot:
  Configuration file .../aesmd.service is marked executable.
  Please remove executable permission bits. Proceeding anyway.

Version-Release number:
sgx-aesm-2.29-1.fc45.x86_64

How reproducible: Always

Steps to Reproduce:
1. rpm -qlp --dump sgx-aesm-2.29-1.fc45.rpm | grep aesmd.service

Actual Results:
aesmd.service has mode 0100755

Expected Results:
aesmd.service should have mode 0100644

Additional info:
Root cause: file 5.47 classifies .service files as application/x-wine-extension-ini instead of text/plain, which breaks brp-mangle-shebangs. The spec uses install -p without -m 0644.

Fix: use install -m 0644 (or %attr(0644,...)) for unit files and rebuild.

See discussion:
https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/R43Z3MHSGOZPLHD6ORUQJUGYQ4RQ37IG/

Related bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=2513643 (file)
https://bugzilla.redhat.com/show_bug.cgi?id=2513837 (redhat-rpm-config)

Comment 1 Daniel Berrangé 2026-08-24 13:32:26 UTC
Fixed in linux-sgx-2.29-2.fc45


Note You need to log in before you can comment on or make changes to this bug.