Fedora Account System
Red Hat Associate
Red Hat Customer
Spec URL: https://asn.fedorapeople.org/localkdc.spec SRPM URL: https://asn.fedorapeople.org/localkdc-0.2.0-1.fc46.src.rpm Upstream URL: https://gitlab.com/kirmes/localkdc Description: localkdc is a local authentication hub that leverages Kerberos for managing authentication and authorization on individual machines, whether standalone or domain-enrolled. It reuses expertise accumulated through decades of work on Samba and FreeIPA. The KDC communicates over a Unix domain socket rather than network ports, allowing systemd to activate it on demand. User principals are discovered dynamically from the operating system via systemd's userdb, eliminating separate database maintenance. Credential verification is delegated to PAM, so any local system user can authenticate via Kerberos using their existing system password. There is no directory service or manual enrollment required. Fedora Account System Username: asn
This package built on koji: https://koji.fedoraproject.org/koji/taskinfo?taskID=149775818
Spec URL: https://asn.fedorapeople.org/localkdc.spec SRPM URL: https://asn.fedorapeople.org/localkdc-0.2.0-2.fc46.src.rpm
Package Review ============== Legend: [x] = Pass, [!] = Fail, [-] = Not applicable, [?] = Not evaluated Issues: ======= - systemd_post is invoked in %post, systemd_preun in %preun, and systemd_postun in %postun for Systemd service files. Note: Systemd service file(s) in localkdc See: https://docs.fedoraproject.org/en-US/packaging- guidelines/Scriptlets/#_scriptlets This is a spurious diagnostic: it appears that exactly the recommended scriptlets are invoked in the appropriate sections. - The dependency on the base package from the -selinux subpackage needs to be arch-specific. Instead of: Requires: %{name} = %{version}-%{release} Write this: Requires: %{name}%{?_isa} = %{version}-%{release} https://docs.fedoraproject.org/en-US/packaging-guidelines/#_requiring_base_package - The package doesn’t own these directories, either directly or via a dependency. See https://docs.fedoraproject.org/en-US/packaging-guidelines/#_file_and_directory_ownership. %{_libdir}/krb5/plugins/audit/ %{_libdir}/krb5/plugins/kadm5_hook/ There is a dependency on shared libraries from krb5-libs and/or krb5-server, which (co-)own: %{_libdir}/krb5/plugins/ %{_libdir}/krb5/plugins/kdb/ …but no existing package owns: %{_libdir}/krb5/plugins/audit/ %{_libdir}/krb5/plugins/kadm5_hook/ so you should own them: %dir %{_libdir}/krb5/plugins/audit/ %{_libdir}/krb5/plugins/audit/audit_json.so %dir %{_libdir}/krb5/plugins/kadm5_hook/ %{_libdir}/krb5/plugins/kadm5_hook/kadm5_chpass.so %{_libdir}/krb5/plugins/kdb/kdb_userdb.so If these are added to e.g. krb5-server or krb5-libs in the future, that’s fine: you’ll just end up co-owning them. If you want to co-own %{_libdir}/krb5/plugins/kdb/ as well for symmetry, that’s OK even if it’s not necessary. Similarly, nothing owns the %{_libexecdir}/localkdc/ directory. That’s one that should clearly belong to this package, so add: %dir %{_libexecdir}/localkdc/ - Unlike the other two shared-library plugins, %{_libdir}/krb5/plugins/kadm5_hook/kadm5_chpass.so is installed without execute permissions. Even if the plugin still works, you need to fix this because it breaks debuginfo extraction: localkdc.x86_64: W: unstripped-binary-or-object /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so - The package needs to own the two “tmpfiles” directories: localkdc.x86_64: W: tmpfile-not-in-filelist /run/localkdc localkdc.x86_64: W: tmpfile-not-in-filelist /var/log/localkdc I haven’t used this mechanism before, but looking at https://docs.fedoraproject.org/en-US/packaging-guidelines/Tmpfiles.d/#_example_spec_file, it seems like this should be something like: %dir %{_rundir}/localkdc/ %dir %attr(0750, root, root) %{_localstatedir}/log/localkdc/ - I asked about the %tmpfiles_create macro in the “Fedora Devel” matrix room, since it isn’t documented in https://docs.fedoraproject.org/en-US/packaging-guidelines/Tmpfiles.d/, and I heard, “…those macros predate the filetriggers. […] For this package, the filetriggers should be enough.” It should be adequate to use filetriggers alone, https://github.com/systemd/systemd/blob/main/src/rpm/triggers.systemd.in. I was advised that usually, it’s better to just redirect logging to the journal/syslog, but the json-formatted audit log in this package might still make sense. I was also advised that you should be able to create %{_rundir}/localkdc/ using RuntimeDirectory=localkdc without having to use the tmpfiles.d mechanism for it; see https://www.freedesktop.org/software/systemd/man/latest/systemd.exec.html#RuntimeDirectory=. It seems like the log directory could also be handled with a combination of LogsDirectory=localkdc and LogsDirectoryMode=0750, which should remove the need to use tmpfiles.d entirely. If you can remove use of the tmpfiles.d facility entirely, using settings like RuntimeDirectory and LogsDirectory instead, that would be much better, since the tmpfiles.de facility is much more general and provides much more room for error. - Since you invoke make directly for the SELinux policy, you should add BuildRequires: make This is currently satisified indirectly via (at least) cmake, but you should be explicit and avoid making assumptions about indirect dependencies. - The spec file and SRPM differ. This is mostly due to rpmautospec macro expansion, which we can ignore, but there is a discrepancy in whether Patch0: localkdc-fix-selinux.patch is present, which *is* significant. - It looks like you probably can’t run any meaningful tests, because the integration tests require root and some other things, and there’s only one unit test. The justification for not running any tests should be documented in a spec-file comment, though. Recommendations: ================ These are changes that are SHOULD items in the guidelines, or that I think you would be wise to make but aren’t addressed in the guidelines. They are not mandatory and don’t strictly block the review, but you should read and consider them. - The patch localkdc-fix-selinux.patch should have an upstream status link, briefly indicating whether it can be upstreamd and, if not, why not. https://docs.fedoraproject.org/en-US/packaging-guidelines/#_all_patches_should_have_an_upstream_bug_link_or_comment - It’s helpful to paste the raw %%{cargo_license_summary} output above your license expression: # Apache-2.0 OR BSL-1.0 # Apache-2.0 OR MIT # Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT # BSD-2-Clause # BSD-2-Clause OR Apache-2.0 OR MIT # LGPL-2.1-or-later # MIT # MIT OR Apache-2.0 # Unlicense OR MIT That way, when someone does a new build with possibly shifted Rust dependencies, they can check the comment against the new %%{cargo_license_summary} output, and update the license expression as needed. This is much lighter and less error-prone work than comparing the license expression against the %%{cargo_license_summary} output each time, especially if deduplication is involved. The license expression is properly constructed, but it might be worth noting in a comment that the license of the actual localkdc source is MIT. This is merely implied by the position of the MIT term at the beginning of the license expression, which is a convention that not everyone might recognize. - You don’t need to number Source0 and Patch0; you can just write Source and Patch instead. Numbering them doesn’t hurt anything. - You do not need this export RUSTFLAGS='%{build_rustflags}' unless you are planning to target EPEL9. In EPEL10 and all Fedoras, RUSTFLAGS are set automatically wherever CFLAGS, CXXFLAGS, LDFLAGS, and so on are. It doesn’t hurt anything. - The installation directory paths passed in CMake options should use directory macros, https://docs.fedoraproject.org/en-US/packaging-guidelines/RPMMacros/#macros_installation rather than hard-coded paths. That is, -DCMAKE_INSTALL_RUNSTATEDIR=/run \ -DCMAKE_INSTALL_LOCALSTATEDIR=/var would be better written as -DCMAKE_INSTALL_RUNSTATEDIR=%{_rundir} \ -DCMAKE_INSTALL_LOCALSTATEDIR=%{_localstatedir} or if you are being very explicit -DCMAKE_INSTALL_RUNSTATEDIR:PATH=%{_rundir} \ -DCMAKE_INSTALL_LOCALSTATEDIR:PATH=%{_localstatedir} Existing uses of %{_var} should be replaced with %{_localstatedir}; they are equivalent in practice, but %{_localstatedir} is the usual choice, and %{_var} is documented as a “seldomly used macro” in the guidelines. (Directory macros in %files already look good, except for the %{_var} recommendation above.) - Consider not building this package on i686: # https://fedoraproject.org/wiki/Changes/EncourageI686LeafRemoval ExcludeArch: %{ix86} - I didn’t evaluate the manual Requires with a fine-toothed comb. They don’t look crazy, and I’m assuming they are generally well-founded. I do think that these don’t look necessary: Requires(post): systemd-units Requires(preun): systemd-units Requires(postun): systemd-units If these were needed to simply use the %systemd_post, %systemd_preun, and %systemd_postun macros, then they would be documented in https://docs.fedoraproject.org/en-US/packaging-guidelines/Scriptlets/#_scriptlets. - Please change make -f /usr/share/selinux/devel/Makefile %{name}.pp to %make_build -f /usr/share/selinux/devel/Makefile %{name}.pp in order to benefit from possible parallelism. https://docs.fedoraproject.org/en-US/packaging-guidelines/#_parallel_make - There is inconsistent redirection of pushd/popd to /dev/null. You *need* to do this in %generate_buildrequires, where anything printed to stdout is interpreted as a dependency. (Alternatively, you could just “cd” and not bother changing back at the end of the section.) However, %build use redirection when entering src/ but not when entering selinux/. I think it would be easier to understand the spec file if you redirected the output of pushd/popd either only when required (%generate_buildrequires), or *always*. Notes: ====== These are just comments, not suggested changes. - In general, I’ve reviewed the bits of the package involving systemd and SELinux at a relatively superficial level. I’ve looked for obvious technical, practical, and policy issues, but I’ve assumed that you basically know what you’re doing here. - There are some rpmlint warnings about “overlinking,” where a shared library is linked but none of the symbols from it are used: localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/audit/audit_json.so /lib64/libk5crypto.so.3 localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so /lib64/libkadm5srv_mit.so.12 localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/kdb/kdb_userdb.so /lib64/libk5crypto.so.3 localkdc.x86_64: W: unused-direct-shlib-dependency /usr/libexec/localkdc/localkdc-pam-auth /lib64/libk5crypto.so.3 This might suggest that the upstream build system could be improved. Unnecessary shared-library dependencies can carry a small cost in time and memory, although in this case the libraries are ones that would already be loaded in any process that is loading a kerberos plugin, so it really doesn’t matter at all in practice. ===== MUST items ===== C/C++: [-]: Development (unversioned) .so files in -devel subpackage, if present. Note: Unversioned so-files in private %_libdir subdirectory (see attachment). Verify they are not in ld path. Unversioned .so files are all Kerberos plugins. They appear to be correctly installed, and are not in the default linker search path. Everything here looks correct. https://docs.fedoraproject.org/en-US/packaging-guidelines/#_unversioned_shared_objects Generic: [x]: Package is licensed with an open-source compatible license and meets other legal requirements as defined in the legal section of Packaging Guidelines. [x]: License field in the package spec file matches the actual license. Note: Checking patched sources after %prep for licenses. Licenses found: "Unknown or generated", "MIT License". 73 files have unknown license. Detailed output of licensecheck in /home/ben/fedora/review/2527288-localkdc/licensecheck.txt [x]: License file installed when any subpackage combination is installed. [x]: If the package is under multiple licenses, the licensing breakdown must be documented in the spec. [!]: Package requires other packages for directories it uses. Note: No known owner of /usr/lib64/krb5/plugins/kadm5_hook, /usr/lib64/krb5/plugins/audit, /usr/libexec/localkdc See Issues. [!]: Package must own all directories that it creates. Note: Directories without known owners: /usr/lib64/krb5/plugins/audit, /usr/lib64/krb5/plugins/kadm5_hook, /usr/share/selinux/packages, /usr/share/selinux, /usr/share/selinux/packages/targeted, /usr/libexec/localkdc See Issues. For the SELinux directories, the -selinux subpackage Requires selinux-policy-targeted, which depends on selinux-policy, which owns the directories. Normally it’s unwise to rely on indirect dependencies like this since they can change without you noticing, but this one should be reliable enough. [x]: %build honors applicable compiler flags or justifies otherwise. [x]: Package contains no bundled libraries or specifies bundled libraries with Provides: bundled(<libname>) if unbundling is not possible. [x]: Changelog in prescribed format. [x]: Sources contain only permissible code or content. [-]: Package contains desktop file if it is a GUI application. [-]: Development files must be in a -devel package [x]: Package uses nothing in %doc for runtime. [x]: Package consistently uses macros (instead of hard-coded directory names). [x]: Package is named according to the Package Naming Guidelines. [x]: Package does not generate any conflict. [x]: Package obeys FHS, except libexecdir and /usr/target. Use of /var/kerberos isn’t strictly FHS-compliant, I think, but it’s a pre-existing feature of Kerberos and not something introduced by this package. [-]: If the package is a rename of another package, proper Obsoletes and Provides are present. [x]: Requires correct, justified where necessary. [x]: Spec file is legible and written in American English. [x]: Package contains systemd file(s) if in need. [x]: Useful -debuginfo package or justification otherwise. [x]: Package is not known to require an ExcludeArch tag. [x]: Package complies to the Packaging Guidelines (except as noted) [x]: Package successfully compiles and builds into binary rpms on at least one supported primary architecture. [x]: Package installs properly. [x]: Rpmlint is run on all rpms the build produces. Note: There are rpmlint messages (see attachment). [x]: If (and only if) the source package includes the text of the license(s) in its own file, then that file, containing the text of the license(s) for the package is included in %license. [x]: The License field must be a valid SPDX expression. [x]: Package does not own files or directories owned by other packages. [x]: Package uses either %{buildroot} or $RPM_BUILD_ROOT [x]: Package does not run rm -rf %{buildroot} (or $RPM_BUILD_ROOT) at the beginning of %install. [x]: Macros in Summary, %description expandable at SRPM build time. [x]: Dist tag is present. [x]: Package does not contain duplicates in %files. [x]: Permissions on files are set properly. [x]: Package must not depend on deprecated() packages. [x]: Package use %makeinstall only when make install DESTDIR=... doesn't work. [x]: Package is named using only allowed ASCII characters. [x]: Package does not use a name that already exists. [x]: Package is not relocatable. [x]: Sources used to build the package match the upstream source, as provided in the spec URL. [x]: Spec file name must match the spec package %{name}, in the format %{name}.spec. [x]: File names are valid UTF-8. [x]: Large documentation must go in a -doc subpackage. Large could be size (~1MB) or number of files. Note: Documentation size is 982 bytes in 1 files. [x]: Packages must not store files under /srv, /opt or /usr/local ===== SHOULD items ===== Generic: [!]: Uses parallel make %{?_smp_mflags} macro. [-]: If the source package does not include license text(s) as a separate file from upstream, the packager SHOULD query upstream to include it. [x]: Final provides and requires are sane (see attachments). However, see discussion of the manual systemd-units dependency. [!]: Fully versioned dependency in subpackages if applicable. Note: No Requires: %{name}%{?_isa} = %{version}-%{release} in localkdc-selinux See Issues: this dependency needs to be arch-specific. [?]: Package functions as described. [x]: Latest version is packaged. [x]: Package does not include license text files separate from upstream. [x]: Scriptlets must be sane, if used. However, see discussion of tmpfiles.d and %tmpfiles_create. [-]: Sources are verified with gpgverify first in %prep if upstream publishes signatures. Note: gpgverify is not used. [x]: Package should compile and build into binary rpms on all supported architectures. https://koji.fedoraproject.org/koji/taskinfo?taskID=150624833 [!]: %check is present and all tests pass. See Issues: the lack of tests deserves a comment. [x]: Packages should try to preserve timestamps of original installed files. [-]: Spec use %global instead of %define unless justified. Note: %define requiring justification: %define localkdc_license %{shrink: Use of %define comes from rpmautospec, and this advice is dubious anyway, https://pagure.io/packaging-committee/issue/1449/. [x]: Reviewer should test that the package builds in mock. [x]: Buildroot is not present [x]: Package has no %clean section with rm -rf %{buildroot} (or $RPM_BUILD_ROOT) [x]: No file requires outside of /etc, /bin, /sbin, /usr/bin, /usr/sbin. [x]: Packager, Vendor, PreReq, Copyright tags should not be in spec file [x]: Sources can be downloaded from URI in Source: tag [x]: SourceX is a working URL. ===== EXTRA items ===== Generic: [!]: Spec file according to URL is the same as in SRPM. Note: Spec file as given by url is not the same as in SRPM (see attached diff). See: (this test has no URL) [x]: Rpmlint is run on debuginfo package(s). Note: No rpmlint messages. [x]: Rpmlint is run on all installed packages. Note: There are rpmlint messages (see attachment). [x]: Large data in /usr/share should live in a noarch subpackage if package is arched. Rpmlint ------- Checking: localkdc-0.2.0-2.fc46.x86_64.rpm localkdc-selinux-0.2.0-2.fc46.x86_64.rpm localkdc-0.2.0-2.fc46.src.rpm ============================ rpmlint session starts ============================ rpmlint: 2.8.0 configuration: /usr/lib/python3.14/site-packages/rpmlint/configdefaults.toml /etc/xdg/rpmlint/fedora-spdx-licenses.toml /etc/xdg/rpmlint/fedora.toml /etc/xdg/rpmlint/scoring.toml /etc/xdg/rpmlint/users-groups.toml /etc/xdg/rpmlint/warn-on-functions.toml rpmlintrc: [PosixPath('/tmp/tmpzsgyinmy')] checks: 32, packages: 3 localkdc.x86_64: W: unstripped-binary-or-object /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so localkdc.x86_64: W: tmpfile-not-in-filelist /run/localkdc localkdc.x86_64: W: tmpfile-not-in-filelist /var/log/localkdc localkdc.src: E: spelling-error ('systemd', '%description -l en_US systemd -> systems, system, system d') localkdc.src: E: spelling-error ("systemd's", "%description -l en_US systemd's -> system's, system d's, system-d's") localkdc.src: E: spelling-error ('userdb', '%description -l en_US userdb -> user db, user-db, user') localkdc.x86_64: E: spelling-error ("systemd's", "%description -l en_US systemd's -> system's, system d's, system-d's") localkdc.x86_64: E: spelling-error ('userdb', '%description -l en_US userdb -> user db, user-db, user') localkdc.x86_64: W: non-standard-dir-in-var kerberos localkdc.x86_64: W: no-manual-page-for-binary lkdcctl localkdc-selinux.x86_64: W: no-documentation localkdc-selinux.x86_64: E: no-binary localkdc.spec: W: no-%check-section localkdc.x86_64: W: empty-%postun localkdc-selinux.x86_64: W: dangerous-command-in-%pre cp localkdc-selinux.x86_64: W: dangerous-command-in-%postun rm localkdc-selinux.x86_64: W: dangerous-command-in-%posttrans rm localkdc-selinux.x86_64: W: dangerous-command-in-%post rm 3 packages and 0 specfiles checked; 6 errors, 12 warnings, 11 filtered, 6 badness; has taken 0.5 s Rpmlint (debuginfo) ------------------- Checking: localkdc-debuginfo-0.2.0-2.fc46.x86_64.rpm ============================ rpmlint session starts ============================ rpmlint: 2.8.0 configuration: /usr/lib/python3.14/site-packages/rpmlint/configdefaults.toml /etc/xdg/rpmlint/fedora-spdx-licenses.toml /etc/xdg/rpmlint/fedora.toml /etc/xdg/rpmlint/scoring.toml /etc/xdg/rpmlint/users-groups.toml /etc/xdg/rpmlint/warn-on-functions.toml rpmlintrc: [PosixPath('/tmp/tmp5d42jhzs')] checks: 32, packages: 1 1 packages and 0 specfiles checked; 0 errors, 0 warnings, 14 filtered, 0 badness; has taken 0.8 s Rpmlint (installed packages) ---------------------------- ============================ rpmlint session starts ============================ rpmlint: 2.10.0 configuration: /usr/lib/python3.15/site-packages/rpmlint/configdefaults.toml /etc/xdg/rpmlint/fedora-spdx-licenses.toml /etc/xdg/rpmlint/fedora.toml /etc/xdg/rpmlint/scoring.toml /etc/xdg/rpmlint/users-groups.toml /etc/xdg/rpmlint/warn-on-functions.toml checks: 33, packages: 3 localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/audit/audit_json.so /lib64/libk5crypto.so.3 localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so /lib64/libkadm5srv_mit.so.12 localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/kdb/kdb_userdb.so /lib64/libk5crypto.so.3 localkdc.x86_64: W: unused-direct-shlib-dependency /usr/libexec/localkdc/localkdc-pam-auth /lib64/libk5crypto.so.3 localkdc.x86_64: W: unstripped-binary-or-object /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so localkdc.x86_64: W: tmpfile-not-in-filelist /run/localkdc localkdc.x86_64: W: tmpfile-not-in-filelist /var/log/localkdc localkdc.x86_64: E: spelling-error ("systemd's", "%description -l en_US systemd's -> system's, system d's, system-d's") localkdc.x86_64: E: spelling-error ('userdb', '%description -l en_US userdb -> user db, user-db, user') localkdc.x86_64: W: non-standard-dir-in-var kerberos localkdc.x86_64: W: no-manual-page-for-binary lkdcctl localkdc-selinux.x86_64: W: no-documentation localkdc-selinux.x86_64: E: no-binary localkdc.x86_64: W: empty-%postun localkdc-selinux.x86_64: W: dangerous-command-in-%pre cp localkdc-selinux.x86_64: W: dangerous-command-in-%postun rm localkdc-selinux.x86_64: W: dangerous-command-in-%posttrans rm localkdc-selinux.x86_64: W: dangerous-command-in-%post rm 3 packages and 0 specfiles checked; 3 errors, 15 warnings, 24 filtered, 3 badness; has taken 1.0 s Unversioned so-files -------------------- localkdc: /usr/lib64/krb5/plugins/audit/audit_json.so localkdc: /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so localkdc: /usr/lib64/krb5/plugins/kdb/kdb_userdb.so Source checksums ---------------- https://gitlab.com/kirmes/localkdc/-/archive/0.2.0/localkdc-0.2.0.tar.gz : CHECKSUM(SHA256) this package : 316c83e19ea6b67e4a7769f0f0c7691bdde9df0ba9c53d7e42ac71ff7fec9239 CHECKSUM(SHA256) upstream package : 316c83e19ea6b67e4a7769f0f0c7691bdde9df0ba9c53d7e42ac71ff7fec9239 Requires -------- localkdc (rpmlib, GLIBC filtered): (localkdc-selinux if selinux-policy-targeted) (systemd-standalone-tmpfiles or systemd) /bin/sh /usr/bin/bash bash certmonger gawk hostname krb5-server krb5-workstation ld-linux-x86-64.so.2()(64bit) libc.so.6()(64bit) libgcc_s.so.1()(64bit) libgcc_s.so.1(GCC_3.0)(64bit) libgcc_s.so.1(GCC_3.3)(64bit) libgcc_s.so.1(GCC_4.2.0)(64bit) libk5crypto.so.3()(64bit) libk5crypto.so.3(k5crypto_3_MIT)(64bit) libkadm5srv_mit.so.12()(64bit) libkadm5srv_mit.so.12(kadm5srv_mit_12_MIT)(64bit) libkdb5.so.10()(64bit) libkdb5.so.10(kdb5_10_MIT)(64bit) libkrb5.so.3()(64bit) libkrb5.so.3(krb5_3_MIT)(64bit) libpam.so.0()(64bit) libpam.so.0(LIBPAM_1.0)(64bit) rtld(GNU_HASH) systemd-units localkdc-selinux (rpmlib, GLIBC filtered): /bin/sh localkdc selinux-policy-targeted Provides -------- localkdc: localkdc localkdc(x86-64) localkdc-selinux: localkdc-selinux localkdc-selinux(x86-64) Diff spec file in url and in SRPM --------------------------------- --- /home/ben/fedora/review/2527288-localkdc/srpm/localkdc.spec 2026-09-23 12:02:22.284797242 +0100 +++ /home/ben/fedora/review/2527288-localkdc/srpm-unpacked/localkdc.spec 2026-09-03 01:00:00.000000000 +0100 @@ -1,2 +1,12 @@ +## START: Set by rpmautospec +## (rpmautospec version 0.8.4) +## RPMAUTOSPEC: autorelease, autochangelog +%define autorelease(e:s:pb:n) %{?-p:0.}%{lua: + release_number = 2; + base_release_number = tonumber(rpm.expand("%{?-b*}%{!?-b:1}")); + print(release_number + base_release_number - 1); +}%{?-e:.%{-e*}}%{?-s:.%{-s*}}%{!?-n:%{?dist}} +## END: Set by rpmautospec + %bcond selinux 1 %global selinux_variants targeted @@ -26,4 +36,5 @@ URL: https://gitlab.com/kirmes/localkdc Source0: https://gitlab.com/kirmes/localkdc/-/archive/%{version}/%{name}-%{version}.tar.gz +Patch0: localkdc-fix-selinux.patch BuildRequires: cargo @@ -199,3 +210,104 @@ %changelog -%autochangelog +## START: Generated by rpmautospec +* Thu Sep 03 2026 Andreas Schneider <asn> - 0.2.0-2 +- Fix selinux logging filetransfer to localkdc directory + +* Fri Aug 14 2026 Andreas Schneider <asn> - 0.2.0-1 +- Update to version 0.2.0 + +* Thu Apr 16 2026 Andreas Schneider <asn> - 0.1.0-2 +- Fix install location of localkdc-pam-auth + +* Wed Apr 15 2026 Andreas Schneider <asn> - 0.1.0-1 +- Update to version 0.1.0 + +* Thu Nov 13 2025 Andreas Schneider <asn> - 0.0.1-36 +- Improve error handling for our tools + +* Fri Jul 11 2025 Andreas Schneider <asn> - 0.0.1-35 +- Use the right file_type for db files + +* Fri Jul 11 2025 Andreas Schneider <asn> - 0.0.1-34 +- Get selinux working + +* Fri Jun 27 2025 Andreas Schneider <asn> - 0.0.1-33 +- Fix selinux + +* Fri Jun 20 2025 Andreas Schneider <asn> - 0.0.1-32 +- Fix an infinite loop + +* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-31 +- Fix localkdc-setup + +* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-30 +- Fix possible recursion in kdb with localhost + +* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-29 +- Build with debuginfo package for kdb module + +* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-28 +- Fix build because of missing errno.h + +* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-27 +- Add support for IP and dynamic DNS aliases + +* Thu Apr 17 2025 Andreas Schneider <asn> - 0.0.1-26 +- Use app-id derived from machine-id as localkdc realm +- Added localkdc-kinit + +* Thu Apr 10 2025 Andreas Schneider <asn> - 0.0.1-25 +- Fix issues with localkdc-useradd + +* Thu Apr 10 2025 Andreas Schneider <asn> - 0.0.1-24 +- Fix localkdc-useradd +- This goes to changelog + +* Tue Apr 08 2025 Andreas Schneider <asn> - 0.0.1-23 +- Update for new localkdc realm option + +* Mon Apr 07 2025 Andreas Schneider <asn> - 0.0.1-22 +- Require preauth + +* Mon Apr 07 2025 Andreas Schneider <asn> - 0.0.1-21 +- Fix default realm + +* Wed Apr 02 2025 Andreas Schneider <asn> - 0.0.1-20 +- Add userdb support + +* Wed Apr 02 2025 Andreas Schneider <asn> - 0.0.1-19 +- gitignore + +* Wed Mar 12 2025 Andreas Schneider <asn> - 0.0.1-18 +- foo + +* Fri Jan 24 2025 Andreas Schneider <asn> - 0.0.1-15 +- New release + +* Mon Jan 20 2025 Andreas Schneider <asn> - 0.0.1-14 +- Update for alias changes + +* Thu Dec 05 2024 Andreas Schneider <asn> - 0.0.1-13 +- Updates for kdb api changes + +* Wed Dec 04 2024 Andreas Schneider <asn> - 0.0.1-12 +- Fix tarball + +* Wed Dec 04 2024 Andreas Schneider <asn> - 0.0.1-11 +- Don't use kdc_unixsock_listen anymore + +* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-10 +- update tarball + +* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-9 +- update tarball + +* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-6 +- kdb driver + +* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-4 +- selinux + +* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-1 +- The big bang! +## END: Generated by rpmautospec Generated by fedora-review 0.11.0 (05c5b26) last change: 2025-11-29 Command line :/usr/bin/fedora-review -b 2527288 Buildroot used: fedora-rawhide-x86_64 Active plugins: Generic, Shell-api Disabled plugins: Ocaml, Perl, Java, Haskell, Python, PHP, SugarActivity, R, C/C++, fonts Disabled flags: EXARCH, EPEL6, EPEL7, DISTTAG, BATCH
Thank you very much for the review! I will first fix the things upstream, do a new release and then will update the package.
The linking issue is addressed via https://forge.fedoraproject.org/freeipa/kurbu5/pulls/29
Spec URL: https://asn.fedorapeople.org/localkdc.spec SRPM URL: https://asn.fedorapeople.org/localkdc-0.2.1-1.fc46.src.rpm Update to version 0.2.1 - Require %{name}%{?_isa} in the -selinux subpackage. - Own the krb5 audit/kadm5_hook plugin dirs and libexecdir. - Drop tmpfiles.d. - Add BuildRequires: make and go-md2man, and package the new man pages. - Use %{_rundir}/%{_localstatedir} macros instead of hardcoded paths. - Use %make_build for the SELinux policy build. - Drop unneeded Requires(post/preun/postun): systemd-units. - Package the new /etc/pam.d/localkdc-otp file shipped by 0.2.1. - Drop localkdc-fix-selinux.patch, now merged upstream. - Run bats tests
The latest submission is much closer! Thanks for your work. There are a few remaining things that are new or that I missed in the first round of review. Package Review ============== Legend: [x] = Pass, [!] = Fail, [-] = Not applicable, [?] = Not evaluated Issues: ======= - systemd_post is invoked in %post, systemd_preun in %preun, and systemd_postun in %postun for Systemd service files. Note: Systemd service file(s) in localkdc See: https://docs.fedoraproject.org/en-US/packaging- guidelines/Scriptlets/#_scriptlets This is a spurious diagnostic: it appears that exactly the recommended scriptlets are invoked in the appropriate sections. - It looks like the selinux subpackage can be: BuildArch: noarch It doesn’t contain any machine code or install to any architecture-specific paths like %{_libdir}, so it should be the same on all architectures. Making it noarch saves mirror space and bandwidth. - While https://docs.fedoraproject.org/en-US/packaging-guidelines/#_requiring_base_package just talks about requiring base packages, the same logic applies to any dependencies across binary RPMs built from the same source RPMs. Thus this: %if %{with selinux} Requires: (%{name}-selinux if selinux-policy-%{selinuxtype}) %endif would better be this: %if %{with selinux} Requires: (%{name}-selinux%{?_isa} = %{version}-%{release} if selinux-policy-%{selinuxtype}) %endif except that you would not add %{?_isa} if you make the -selinux subpackage noarch as recommended above. - I see that localkdc-selinux depends on localkdc and localkdc depends (conditionally) on localkdc-selinux, creating a circular dependency. This isn’t necessarily strictly forbidden, but it can have disadvantages. In this case, it seems like it could be avoided, because localkdc-selinux merely installs a policy file into the appropriate directory, e.g. /usr/share/selinux/packages/targeted/localkdc.pp.bz2, and this doesn’t actually require anything from the base package to be installed. I think you could drop the localkdc-selinux→localkdc dependency, leaving just the conditional localkdc→localkdc-selinux dependency, and this would be an improvement. You would need to add a copy of LICENSE to the -selinux subpackage since it *could* be installed by itself. - Strictly speaking, the localkdc-selinux subpackage should have: # This subpackage does not include anything derived from the # statically-linked Rust dependencies. License: MIT - The file /etc/pam.d/localkdc-otp is a configuration file and must be marked as such. https://docs.fedoraproject.org/en-US/packaging-guidelines/#_configuration_files Change this: %{_sysconfdir}/pam.d/localkdc-otp to this: %config(noreplace) %{_sysconfdir}/pam.d/localkdc-otp - Neither this package nor any of its dependencies owns %{_sysconfdir}/pam.d. Consider whether it makes more sense to co-own the directory, %dir %{_sysconfdir}/pam.d/ or to add an explicit dependency on pam. (Currently, the package has an automatic dependency on pam-libs for libpam.so, but not on pam.) https://docs.fedoraproject.org/en-US/packaging-guidelines/#_file_and_directory_ownership Recommendations: ================ - It’s helpful to paste the raw %%{cargo_license_summary} output above your license expression: # Apache-2.0 OR BSL-1.0 # Apache-2.0 OR MIT # Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT # BSD-2-Clause # BSD-2-Clause OR Apache-2.0 OR MIT # LGPL-2.1-or-later # MIT # MIT OR Apache-2.0 # Unlicense OR MIT That way, when someone does a new build with possibly shifted Rust dependencies, they can check the comment against the new %%{cargo_license_summary} output, and update the license expression as needed. This is much lighter and less error-prone work than comparing the license expression against the %%{cargo_license_summary} output each time, especially if deduplication is involved. - You do not need this export RUSTFLAGS='%{build_rustflags}' unless you are planning to target EPEL9. In EPEL10 and all Fedoras, RUSTFLAGS are set automatically wherever CFLAGS, CXXFLAGS, LDFLAGS, and so on are. It doesn’t hurt anything. Notes: ====== - There are some rpmlint warnings about “overlinking,” where a shared library is linked but none of the symbols from it are used: localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/audit/audit_json.so /lib64/libk5crypto.so.3 localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so /lib64/libkadm5srv_mit.so.12 localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/kdb/kdb_userdb.so /lib64/libk5crypto.so.3 localkdc.x86_64: W: unused-direct-shlib-dependency /usr/libexec/localkdc/localkdc-pam-auth /lib64/libk5crypto.so.3 This might suggest that the upstream build system could be improved. Unnecessary shared-library dependencies can carry a small cost in time and memory, although in this case the libraries are ones that would already be loaded in any process that is loading a kerberos plugin, so it really doesn’t matter at all in practice. - I am not prepared to evaluate /etc/pam.d/localkdc-otp from a security perspective. - I am assuming that you basically know what you are doing with the SELinux policy compilation and installation/scriptlets, as it’s been a while since I attempted this myself and there are no relevant packaging guidelines. ===== MUST items ===== C/C++: [x]: Development (unversioned) .so files in -devel subpackage, if present. Note: Unversioned so-files in private %_libdir subdirectory (see attachment). Verify they are not in ld path. Unversioned .so files are all Kerberos plugins. They appear to be correctly installed, and are not in the default linker search path. Everything here looks correct. https://docs.fedoraproject.org/en-US/packaging-guidelines/#_unversioned_shared_objects Generic: [x]: Package is licensed with an open-source compatible license and meets other legal requirements as defined in the legal section of Packaging Guidelines. [x]: License field in the package spec file matches the actual license. Note: Checking patched sources after %prep for licenses. Licenses found: "Unknown or generated", "MIT License". 73 files have unknown license. Detailed output of licensecheck in /home/ben/fedora/review/20261003/2527288-localkdc/licensecheck.txt [x]: License file installed when any subpackage combination is installed. [x]: If the package is under multiple licenses, the licensing breakdown must be documented in the spec. [!]: Package must own all directories that it creates. Note: Directories without known owners: /etc/pam.d, /usr/share/selinux/packages/targeted, /usr/share/selinux, /usr/share/selinux/packages For /etc/pam.d, see Issues. For the SELinux directories, I think that everything is OK, and fedora-review is confused by the %{selinuxtype} macro. The -selinux subpackage has: Requires: selinux-policy-%{selinuxtype} which is actually Requires: selinux-policy-targeted and selinux-policy-targeted reliably depends on selinux-policy, which owns these directories. [x]: %build honors applicable compiler flags or justifies otherwise. [x]: Package contains no bundled libraries or specifies bundled libraries with Provides: bundled(<libname>) if unbundling is not possible. [x]: Changelog in prescribed format. [x]: Sources contain only permissible code or content. [-]: Package contains desktop file if it is a GUI application. [-]: Development files must be in a -devel package [x]: Package uses nothing in %doc for runtime. [x]: Package consistently uses macros (instead of hard-coded directory names). [x]: Package is named according to the Package Naming Guidelines. [x]: Package does not generate any conflict. [x]: Package obeys FHS, except libexecdir and /usr/target. Use of /var/kerberos isn’t strictly FHS-compliant, I think, but it’s a pre-existing feature of Kerberos and not something introduced by this package. [-]: If the package is a rename of another package, proper Obsoletes and Provides are present. [x]: Requires correct, justified where necessary. I didn’t go through these with a fine-toothed comb, but they look basically sane. [x]: Spec file is legible and written in American English. [x]: Package contains systemd file(s) if in need. [x]: Useful -debuginfo package or justification otherwise. [x]: Package is not known to require an ExcludeArch tag. [x]: Package complies to the Packaging Guidelines (except as noted) [x]: Package successfully compiles and builds into binary rpms on at least one supported primary architecture. [x]: Package installs properly. [x]: Rpmlint is run on all rpms the build produces. Note: There are rpmlint messages (see attachment). [x]: If (and only if) the source package includes the text of the license(s) in its own file, then that file, containing the text of the license(s) for the package is included in %license. [x]: The License field must be a valid SPDX expression. [x]: Package requires other packages for directories it uses. [x]: Package does not own files or directories owned by other packages. [x]: Package uses either %{buildroot} or $RPM_BUILD_ROOT [x]: Package does not run rm -rf %{buildroot} (or $RPM_BUILD_ROOT) at the beginning of %install. [x]: Macros in Summary, %description expandable at SRPM build time. [x]: Dist tag is present. [x]: Package does not contain duplicates in %files. [x]: Permissions on files are set properly. [x]: Package must not depend on deprecated() packages. [x]: Package use %makeinstall only when make install DESTDIR=... doesn't work. [x]: Package is named using only allowed ASCII characters. [x]: Package does not use a name that already exists. [x]: Package is not relocatable. [x]: Sources used to build the package match the upstream source, as provided in the spec URL. [x]: Spec file name must match the spec package %{name}, in the format %{name}.spec. [x]: File names are valid UTF-8. [x]: Large documentation must go in a -doc subpackage. Large could be size (~1MB) or number of files. Note: Documentation size is 982 bytes in 1 files. [x]: Packages must not store files under /srv, /opt or /usr/local ===== SHOULD items ===== Generic: [-]: If the source package does not include license text(s) as a separate file from upstream, the packager SHOULD query upstream to include it. [x]: Final provides and requires are sane (see attachments). [?]: Package functions as described. It’s not practical for me to test this. [x]: Latest version is packaged. [x]: Package does not include license text files separate from upstream. [x]: Scriptlets must be sane, if used. [-]: Sources are verified with gpgverify first in %prep if upstream publishes signatures. Note: gpgverify is not used. [x]: Package should compile and build into binary rpms on all supported architectures. https://koji.fedoraproject.org/koji/taskinfo?taskID=150932365 [x]: %check is present and all tests pass. The tests that can be executed are extremely minimal. [x]: Packages should try to preserve timestamps of original installed files. [x]: Spec use %global instead of %define unless justified. Note: %define requiring justification: %define localkdc_license %{shrink: Use of %define comes from rpmautospec, and this advice is dubious anyway, https://pagure.io/packaging-committee/issue/1449/. [x]: Reviewer should test that the package builds in mock. [x]: Buildroot is not present [x]: Package has no %clean section with rm -rf %{buildroot} (or $RPM_BUILD_ROOT) [x]: No file requires outside of /etc, /bin, /sbin, /usr/bin, /usr/sbin. [x]: Fully versioned dependency in subpackages if applicable. [x]: Packager, Vendor, PreReq, Copyright tags should not be in spec file [x]: Sources can be downloaded from URI in Source: tag [x]: SourceX is a working URL. ===== EXTRA items ===== Generic: [!]: Spec file according to URL is the same as in SRPM. Note: Spec file as given by url is not the same as in SRPM (see attached diff). See: (this test has no URL) [x]: Rpmlint is run on debuginfo package(s). Note: No rpmlint messages. [x]: Rpmlint is run on all installed packages. Note: There are rpmlint messages (see attachment). [x]: Large data in /usr/share should live in a noarch subpackage if package is arched. Rpmlint ------- Checking: localkdc-0.2.1-1.fc46.x86_64.rpm localkdc-selinux-0.2.1-1.fc46.x86_64.rpm localkdc-0.2.1-1.fc46.src.rpm ============================ rpmlint session starts ============================ rpmlint: 2.8.0 configuration: /usr/lib/python3.14/site-packages/rpmlint/configdefaults.toml /etc/xdg/rpmlint/fedora-spdx-licenses.toml /etc/xdg/rpmlint/fedora.toml /etc/xdg/rpmlint/scoring.toml /etc/xdg/rpmlint/users-groups.toml /etc/xdg/rpmlint/warn-on-functions.toml rpmlintrc: [PosixPath('/tmp/tmpjk8heoa2')] checks: 32, packages: 3 localkdc.src: E: spelling-error ('systemd', '%description -l en_US systemd -> systems, system, system d') localkdc.src: E: spelling-error ("systemd's", "%description -l en_US systemd's -> system's, system d's, system-d's") localkdc.src: E: spelling-error ('userdb', '%description -l en_US userdb -> user db, user-db, user') localkdc.x86_64: E: spelling-error ("systemd's", "%description -l en_US systemd's -> system's, system d's, system-d's") localkdc.x86_64: E: spelling-error ('userdb', '%description -l en_US userdb -> user db, user-db, user') localkdc.x86_64: W: non-standard-dir-in-var kerberos localkdc.x86_64: W: non-conffile-in-etc /etc/pam.d/localkdc-otp localkdc-selinux.x86_64: W: no-documentation localkdc-selinux.x86_64: E: no-binary localkdc.x86_64: W: empty-%postun localkdc-selinux.x86_64: W: dangerous-command-in-%pre cp localkdc-selinux.x86_64: W: dangerous-command-in-%postun rm localkdc-selinux.x86_64: W: dangerous-command-in-%posttrans rm localkdc-selinux.x86_64: W: dangerous-command-in-%post rm 3 packages and 0 specfiles checked; 6 errors, 8 warnings, 11 filtered, 6 badness; has taken 0.4 s Rpmlint (debuginfo) ------------------- Checking: localkdc-debuginfo-0.2.1-1.fc46.x86_64.rpm ============================ rpmlint session starts ============================ rpmlint: 2.8.0 configuration: /usr/lib/python3.14/site-packages/rpmlint/configdefaults.toml /etc/xdg/rpmlint/fedora-spdx-licenses.toml /etc/xdg/rpmlint/fedora.toml /etc/xdg/rpmlint/scoring.toml /etc/xdg/rpmlint/users-groups.toml /etc/xdg/rpmlint/warn-on-functions.toml rpmlintrc: [PosixPath('/tmp/tmplut50mrv')] checks: 32, packages: 1 1 packages and 0 specfiles checked; 0 errors, 0 warnings, 16 filtered, 0 badness; has taken 1.0 s Rpmlint (installed packages) ---------------------------- ============================ rpmlint session starts ============================ rpmlint: 2.10.0 configuration: /usr/lib/python3.15/site-packages/rpmlint/configdefaults.toml /etc/xdg/rpmlint/fedora-spdx-licenses.toml /etc/xdg/rpmlint/fedora.toml /etc/xdg/rpmlint/scoring.toml /etc/xdg/rpmlint/users-groups.toml /etc/xdg/rpmlint/warn-on-functions.toml checks: 33, packages: 3 localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/audit/audit_json.so /lib64/libk5crypto.so.3 localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so /lib64/libkadm5srv_mit.so.12 localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/kdb/kdb_userdb.so /lib64/libk5crypto.so.3 localkdc.x86_64: W: unused-direct-shlib-dependency /usr/libexec/localkdc/localkdc-pam-auth /lib64/libk5crypto.so.3 localkdc.x86_64: W: spelling-error ("systemd's", "%description -l en_US systemd's -> system's, system d's, system-d's") localkdc.x86_64: W: spelling-error ('userdb', '%description -l en_US userdb -> user db, user-db, user') localkdc.x86_64: W: non-standard-dir-in-var kerberos localkdc.x86_64: W: non-conffile-in-etc /etc/pam.d/localkdc-otp localkdc-selinux.x86_64: W: no-documentation localkdc-selinux.x86_64: E: no-binary localkdc.x86_64: W: empty-%postun localkdc-selinux.x86_64: W: dangerous-command-in-%pre cp localkdc-selinux.x86_64: W: dangerous-command-in-%postun rm localkdc-selinux.x86_64: W: dangerous-command-in-%posttrans rm localkdc-selinux.x86_64: W: dangerous-command-in-%post rm 3 packages and 0 specfiles checked; 1 errors, 14 warnings, 27 filtered, 1 badness; has taken 0.9 s Unversioned so-files -------------------- localkdc: /usr/lib64/krb5/plugins/audit/audit_json.so localkdc: /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so localkdc: /usr/lib64/krb5/plugins/kdb/kdb_userdb.so Source checksums ---------------- https://gitlab.com/kirmes/localkdc/-/archive/0.2.1/localkdc-0.2.1.tar.gz : CHECKSUM(SHA256) this package : 0e4e5fe6aa813d8b89e958a7737215534eb79f2b0863737a2abace93a0294a25 CHECKSUM(SHA256) upstream package : 0e4e5fe6aa813d8b89e958a7737215534eb79f2b0863737a2abace93a0294a25 Requires -------- localkdc (rpmlib, GLIBC filtered): (localkdc-selinux if selinux-policy-targeted) /bin/sh /usr/bin/bash bash certmonger gawk hostname krb5-server krb5-workstation ld-linux-x86-64.so.2()(64bit) libc.so.6()(64bit) libgcc_s.so.1()(64bit) libgcc_s.so.1(GCC_3.0)(64bit) libgcc_s.so.1(GCC_3.3)(64bit) libgcc_s.so.1(GCC_4.2.0)(64bit) libk5crypto.so.3()(64bit) libk5crypto.so.3(k5crypto_3_MIT)(64bit) libkadm5srv_mit.so.12()(64bit) libkadm5srv_mit.so.12(kadm5srv_mit_12_MIT)(64bit) libkdb5.so.10()(64bit) libkdb5.so.10(kdb5_10_MIT)(64bit) libkrb5.so.3()(64bit) libkrb5.so.3(krb5_3_MIT)(64bit) libpam.so.0()(64bit) libpam.so.0(LIBPAM_1.0)(64bit) rtld(GNU_HASH) localkdc-selinux (rpmlib, GLIBC filtered): /bin/sh localkdc(x86-64) selinux-policy-targeted Provides -------- localkdc: localkdc localkdc(x86-64) localkdc-selinux: localkdc-selinux localkdc-selinux(x86-64) Diff spec file in url and in SRPM --------------------------------- --- /home/ben/fedora/review/20261003/2527288-localkdc/srpm/localkdc.spec 2026-10-03 08:09:10.555640759 +0100 +++ /home/ben/fedora/review/20261003/2527288-localkdc/srpm-unpacked/localkdc.spec 2026-10-01 01:00:00.000000000 +0100 @@ -1,2 +1,12 @@ +## START: Set by rpmautospec +## (rpmautospec version 0.8.4) +## RPMAUTOSPEC: autorelease, autochangelog +%define autorelease(e:s:pb:n) %{?-p:0.}%{lua: + release_number = 1; + base_release_number = tonumber(rpm.expand("%{?-b*}%{!?-b:1}")); + print(release_number + base_release_number - 1); +}%{?-e:.%{-e*}}%{?-s:.%{-s*}}%{!?-n:%{?dist}} +## END: Set by rpmautospec + %bcond selinux 1 %global selinux_variants targeted @@ -211,3 +221,117 @@ %changelog -%autochangelog +## START: Generated by rpmautospec +* Thu Oct 01 2026 Andreas Schneider <asn> - 0.2.1-1 +- Update to version 0.2.1 +- Require %%{name}%%{?_isa} in the -selinux subpackage. +- Own the krb5 audit/kadm5_hook plugin dirs and libexecdir. +- Drop tmpfiles.d. +- Add BuildRequires: make and go-md2man, and package the new man pages. +- Use %%{_rundir}/%%{_localstatedir} macros instead of hardcoded paths. +- Use %%make_build for the SELinux policy build. +- Drop unneeded Requires(post/preun/postun): systemd-units. +- Package the new /etc/pam.d/localkdc-otp file shipped by 0.2.1. +- Drop localkdc-fix-selinux.patch, now merged upstream. +- Run bats tests + +* Thu Sep 03 2026 Andreas Schneider <asn> - 0.2.0-2 +- Fix selinux logging filetransfer to localkdc directory + +* Fri Aug 14 2026 Andreas Schneider <asn> - 0.2.0-1 +- Update to version 0.2.0 + +* Thu Apr 16 2026 Andreas Schneider <asn> - 0.1.0-2 +- Fix install location of localkdc-pam-auth + +* Wed Apr 15 2026 Andreas Schneider <asn> - 0.1.0-1 +- Update to version 0.1.0 + +* Thu Nov 13 2025 Andreas Schneider <asn> - 0.0.1-36 +- Improve error handling for our tools + +* Fri Jul 11 2025 Andreas Schneider <asn> - 0.0.1-35 +- Use the right file_type for db files + +* Fri Jul 11 2025 Andreas Schneider <asn> - 0.0.1-34 +- Get selinux working + +* Fri Jun 27 2025 Andreas Schneider <asn> - 0.0.1-33 +- Fix selinux + +* Fri Jun 20 2025 Andreas Schneider <asn> - 0.0.1-32 +- Fix an infinite loop + +* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-31 +- Fix localkdc-setup + +* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-30 +- Fix possible recursion in kdb with localhost + +* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-29 +- Build with debuginfo package for kdb module + +* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-28 +- Fix build because of missing errno.h + +* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-27 +- Add support for IP and dynamic DNS aliases + +* Thu Apr 17 2025 Andreas Schneider <asn> - 0.0.1-26 +- Use app-id derived from machine-id as localkdc realm +- Added localkdc-kinit + +* Thu Apr 10 2025 Andreas Schneider <asn> - 0.0.1-25 +- Fix issues with localkdc-useradd + +* Thu Apr 10 2025 Andreas Schneider <asn> - 0.0.1-24 +- Fix localkdc-useradd +- This goes to changelog + +* Tue Apr 08 2025 Andreas Schneider <asn> - 0.0.1-23 +- Update for new localkdc realm option + +* Mon Apr 07 2025 Andreas Schneider <asn> - 0.0.1-22 +- Require preauth + +* Mon Apr 07 2025 Andreas Schneider <asn> - 0.0.1-21 +- Fix default realm + +* Wed Apr 02 2025 Andreas Schneider <asn> - 0.0.1-20 +- Add userdb support + +* Wed Apr 02 2025 Andreas Schneider <asn> - 0.0.1-19 +- gitignore + +* Wed Mar 12 2025 Andreas Schneider <asn> - 0.0.1-18 +- foo + +* Fri Jan 24 2025 Andreas Schneider <asn> - 0.0.1-15 +- New release + +* Mon Jan 20 2025 Andreas Schneider <asn> - 0.0.1-14 +- Update for alias changes + +* Thu Dec 05 2024 Andreas Schneider <asn> - 0.0.1-13 +- Updates for kdb api changes + +* Wed Dec 04 2024 Andreas Schneider <asn> - 0.0.1-12 +- Fix tarball + +* Wed Dec 04 2024 Andreas Schneider <asn> - 0.0.1-11 +- Don't use kdc_unixsock_listen anymore + +* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-10 +- update tarball + +* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-9 +- update tarball + +* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-6 +- kdb driver + +* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-4 +- selinux + +* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-1 +- The big bang! +## END: Generated by rpmautospec Generated by fedora-review 0.12.0 (a08f0fc) last change: 2026-09-18 Command line :/usr/bin/fedora-review -b 2527288 Buildroot used: fedora-rawhide-x86_64 Active plugins: Generic, Shell-api Disabled plugins: fonts, Perl, R, Ocaml, PHP, Java, Haskell, C/C++, Python, SugarActivity Disabled flags: EXARCH, EPEL6, EPEL7, DISTTAG, BATCH, UNRETIREMENT
Spec URL: https://asn.fedorapeople.org/localkdc.spec SRPM URL: https://asn.fedorapeople.org/localkdc-0.2.1-2.fc46.src.rpm Address second round of Fedora package review feedback - Make the -selinux subpackage noarch - Drop circular Requires on the base package - Give selinux its own MIT License and ship %license LICENSE so it stays self-contained if installed standalone. - Pin the base package's conditional Requires on -selinux to %{version}-%{release}. - Mark /etc/pam.d/localkdc-otp as %config(noreplace). - Add Requires: pam since the base package relies on pam owning /etc/pam.d. - Paste the raw %{cargo_license_summary} output as a comment for future rebuilds - Drop the unneeded RUSTFLAGS export The rpmlint warnings about "overlinking" will be fixed with a new kurbu5 release. The fix has been merged upstream, but there is no new release yet. Also this isn't a big deal, the plugins are loaded with dlopen() by krb5kdc and it has all those libraries linked anyway. root@krikkit:~# ldd /usr/sbin/krb5kdc linux-vdso.so.1 (0x00007f71dd1ce000) libkadm5srv_mit.so.12 => /lib64/libkadm5srv_mit.so.12 (0x00007f71dd14d000) libkdb5.so.10 => /lib64/libkdb5.so.10 (0x00007f71dd137000) libgssrpc.so.4 => /lib64/libgssrpc.so.4 (0x00007f71dd116000) libkrb5.so.3 => /lib64/libkrb5.so.3 (0x00007f71dd044000) libk5crypto.so.3 => /lib64/libk5crypto.so.3 (0x00007f71dd02c000) libcom_err.so.2 => /lib64/libcom_err.so.2 (0x00007f71dd026000) libkrb5support.so.0 => /lib64/libkrb5support.so.0 (0x00007f71dd013000) libverto.so.1 => /lib64/libverto.so.1 (0x00007f71dd00c000) libc.so.6 => /lib64/libc.so.6 (0x00007f71dce13000) libgssapi_krb5.so.2 => /lib64/libgssapi_krb5.so.2 (0x00007f71dcdb8000) libkeyutils.so.1 => /lib64/libkeyutils.so.1 (0x00007f71dcdb2000) libcrypto.so.3 => /lib64/libcrypto.so.3 (0x00007f71dc800000) libresolv.so.2 => /lib64/libresolv.so.2 (0x00007f71dcd9d000) libselinux.so.1 => /lib64/libselinux.so.1 (0x00007f71dcd69000) /lib64/ld-linux-x86-64.so.2 (0x00007f71dd1d0000) libz.so.1 => /lib64/libz.so.1 (0x00007f71dc7d6000) libpcre2-8.so.0 => /lib64/libpcre2-8.so.0 (0x00007f71dc725000) libgcc_s.so.1 => /lib64/libgcc_s.so.1 (0x00007f71dc6f8000)