Bug 2527288 - Review Request: localkdc - A local KDC based on MIT Kerberos
Summary: Review Request: localkdc - A local KDC based on MIT Kerberos
Keywords:
Status: ASSIGNED
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Ben Beasley
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-02 09:02 UTC by Andreas Schneider
Modified: 2026-10-05 15:47 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:
code: fedora-review?


Attachments (Terms of Use)

Description Andreas Schneider 2026-09-02 09:02:17 UTC
Spec URL: https://asn.fedorapeople.org/localkdc.spec
SRPM URL: https://asn.fedorapeople.org/localkdc-0.2.0-1.fc46.src.rpm
Upstream URL: https://gitlab.com/kirmes/localkdc

Description:
localkdc is a local authentication hub that leverages Kerberos for managing
authentication and authorization on individual machines, whether standalone or
domain-enrolled. It reuses expertise accumulated through decades of work on
Samba and FreeIPA.

The KDC communicates over a Unix domain socket rather than network ports,
allowing systemd to activate it on demand. User principals are discovered
dynamically from the operating system via systemd's userdb, eliminating separate
database maintenance. Credential verification is delegated to PAM, so any local
system user can authenticate via Kerberos using their existing system
password. There is no directory service or manual enrollment required.

Fedora Account System Username: asn

Comment 1 Andreas Schneider 2026-09-02 09:02:20 UTC
This package built on koji:  https://koji.fedoraproject.org/koji/taskinfo?taskID=149775818

Comment 3 Ben Beasley 2026-09-28 09:11:23 UTC
Package Review
==============

Legend:
[x] = Pass, [!] = Fail, [-] = Not applicable, [?] = Not evaluated


Issues:
=======
- systemd_post is invoked in %post, systemd_preun in %preun, and
  systemd_postun in %postun for Systemd service files.
  Note: Systemd service file(s) in localkdc
  See: https://docs.fedoraproject.org/en-US/packaging-
  guidelines/Scriptlets/#_scriptlets

  This is a spurious diagnostic: it appears that exactly the recommended
  scriptlets are invoked in the appropriate sections.

- The dependency on the base package from the -selinux subpackage needs to be
  arch-specific.

  Instead of:

    Requires:       %{name} = %{version}-%{release}

  Write this:

    Requires:       %{name}%{?_isa} = %{version}-%{release}

  https://docs.fedoraproject.org/en-US/packaging-guidelines/#_requiring_base_package

- The package doesn’t own these directories, either directly or via a
  dependency. See
  https://docs.fedoraproject.org/en-US/packaging-guidelines/#_file_and_directory_ownership.

    %{_libdir}/krb5/plugins/audit/
    %{_libdir}/krb5/plugins/kadm5_hook/

  There is a dependency on shared libraries from krb5-libs and/or krb5-server,
  which (co-)own:

    %{_libdir}/krb5/plugins/
    %{_libdir}/krb5/plugins/kdb/

  …but no existing package owns: 

    %{_libdir}/krb5/plugins/audit/
    %{_libdir}/krb5/plugins/kadm5_hook/

  so you should own them:

    %dir %{_libdir}/krb5/plugins/audit/
    %{_libdir}/krb5/plugins/audit/audit_json.so
    %dir %{_libdir}/krb5/plugins/kadm5_hook/
    %{_libdir}/krb5/plugins/kadm5_hook/kadm5_chpass.so
    %{_libdir}/krb5/plugins/kdb/kdb_userdb.so

  If these are added to e.g. krb5-server or krb5-libs in the future, that’s
  fine: you’ll just end up co-owning them. If you want to co-own
  %{_libdir}/krb5/plugins/kdb/ as well for symmetry, that’s OK even if it’s not
  necessary.

  Similarly, nothing owns the %{_libexecdir}/localkdc/ directory. That’s one
  that should clearly belong to this package, so add:

    %dir %{_libexecdir}/localkdc/

- Unlike the other two shared-library plugins,
  %{_libdir}/krb5/plugins/kadm5_hook/kadm5_chpass.so is installed without
  execute permissions. Even if the plugin still works, you need to fix this
  because it breaks debuginfo extraction:

    localkdc.x86_64: W: unstripped-binary-or-object
                        /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so

- The package needs to own the two “tmpfiles” directories:

    localkdc.x86_64: W: tmpfile-not-in-filelist /run/localkdc
    localkdc.x86_64: W: tmpfile-not-in-filelist /var/log/localkdc

  I haven’t used this mechanism before, but looking at
  https://docs.fedoraproject.org/en-US/packaging-guidelines/Tmpfiles.d/#_example_spec_file,
  it seems like this should be something like:

    %dir %{_rundir}/localkdc/
    %dir %attr(0750, root, root) %{_localstatedir}/log/localkdc/


- I asked about the %tmpfiles_create macro in the “Fedora Devel” matrix room,
  since it isn’t documented in
  https://docs.fedoraproject.org/en-US/packaging-guidelines/Tmpfiles.d/, and I
  heard, “…those macros predate the filetriggers. […] For this package, the
  filetriggers should be enough.” It should be adequate to use filetriggers
  alone,
  https://github.com/systemd/systemd/blob/main/src/rpm/triggers.systemd.in. 

  I was advised that usually, it’s better to just redirect logging to the
  journal/syslog, but the json-formatted audit log in this package might still
  make sense.

  I was also advised that you should be able to create %{_rundir}/localkdc/
  using RuntimeDirectory=localkdc without having to use the tmpfiles.d
  mechanism for it; see
  https://www.freedesktop.org/software/systemd/man/latest/systemd.exec.html#RuntimeDirectory=.

  It seems like the log directory could also be handled with a combination of
  LogsDirectory=localkdc and LogsDirectoryMode=0750, which should remove the
  need to use tmpfiles.d entirely.

  If you can remove use of the tmpfiles.d facility entirely, using settings
  like RuntimeDirectory and LogsDirectory instead, that would be much better,
  since the tmpfiles.de facility is much more general and provides much more
  room for error.

- Since you invoke make directly for the SELinux policy, you should add

    BuildRequires:  make

  This is currently satisified indirectly via (at least) cmake, but you should
  be explicit and avoid making assumptions about indirect dependencies.

- The spec file and SRPM differ. This is mostly due to rpmautospec macro
  expansion, which we can ignore, but there is a discrepancy in whether

    Patch0:         localkdc-fix-selinux.patch

  is present, which *is* significant.

- It looks like you probably can’t run any meaningful tests, because the
  integration tests require root and some other things, and there’s only one
  unit test. The justification for not running any tests should be documented
  in a spec-file comment, though.

Recommendations:
================

These are changes that are SHOULD items in the guidelines, or that I think you
would be wise to make but aren’t addressed in the guidelines. They are not
mandatory and don’t strictly block the review, but you should read and consider
them.

- The patch localkdc-fix-selinux.patch should have an upstream status link,
  briefly indicating whether it can be upstreamd and, if not, why not.

  https://docs.fedoraproject.org/en-US/packaging-guidelines/#_all_patches_should_have_an_upstream_bug_link_or_comment

- It’s helpful to paste the raw %%{cargo_license_summary} output above your
  license expression:

    # Apache-2.0 OR BSL-1.0
    # Apache-2.0 OR MIT
    # Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT
    # BSD-2-Clause
    # BSD-2-Clause OR Apache-2.0 OR MIT
    # LGPL-2.1-or-later
    # MIT
    # MIT OR Apache-2.0
    # Unlicense OR MIT 

  That way, when someone does a new build with possibly shifted Rust
  dependencies, they can check the comment against the new
  %%{cargo_license_summary} output, and update the license expression as
  needed. This is much lighter and less error-prone work than comparing the
  license expression against the %%{cargo_license_summary} output each time,
  especially if deduplication is involved.

  The license expression is properly constructed, but it might be worth noting
  in a comment that the license of the actual localkdc source is MIT. This is
  merely implied by the position of the MIT term at the beginning of the
  license expression, which is a convention that not everyone might recognize.

- You don’t need to number Source0 and Patch0; you can just write Source and
  Patch instead. Numbering them doesn’t hurt anything.

- You do not need this

    export RUSTFLAGS='%{build_rustflags}'

  unless you are planning to target EPEL9. In EPEL10 and all Fedoras, RUSTFLAGS
  are set automatically wherever CFLAGS, CXXFLAGS, LDFLAGS, and so on are.

  It doesn’t hurt anything.

- The installation directory paths passed in CMake options should use directory
  macros,

    https://docs.fedoraproject.org/en-US/packaging-guidelines/RPMMacros/#macros_installation

  rather than hard-coded paths. That is,

    -DCMAKE_INSTALL_RUNSTATEDIR=/run \
    -DCMAKE_INSTALL_LOCALSTATEDIR=/var

  would be better written as

    -DCMAKE_INSTALL_RUNSTATEDIR=%{_rundir} \
    -DCMAKE_INSTALL_LOCALSTATEDIR=%{_localstatedir}

  or if you are being very explicit

    -DCMAKE_INSTALL_RUNSTATEDIR:PATH=%{_rundir} \
    -DCMAKE_INSTALL_LOCALSTATEDIR:PATH=%{_localstatedir}

  Existing uses of %{_var} should be replaced with %{_localstatedir}; they are
  equivalent in practice, but %{_localstatedir} is the usual choice, and
  %{_var} is documented as a “seldomly used macro” in the guidelines.

  (Directory macros in %files already look good, except for the %{_var}
  recommendation above.)

- Consider not building this package on i686:

    # https://fedoraproject.org/wiki/Changes/EncourageI686LeafRemoval
    ExcludeArch:    %{ix86}

- I didn’t evaluate the manual Requires with a fine-toothed comb. They don’t
  look crazy, and I’m assuming they are generally well-founded.

  I do think that these don’t look necessary:

    Requires(post): systemd-units
    Requires(preun): systemd-units
    Requires(postun): systemd-units

  If these were needed to simply use the %systemd_post, %systemd_preun, and
  %systemd_postun macros, then they would be documented in
  https://docs.fedoraproject.org/en-US/packaging-guidelines/Scriptlets/#_scriptlets.

- Please change

    make -f /usr/share/selinux/devel/Makefile %{name}.pp

  to

    %make_build -f /usr/share/selinux/devel/Makefile %{name}.pp

  in order to benefit from possible parallelism.

  https://docs.fedoraproject.org/en-US/packaging-guidelines/#_parallel_make

- There is inconsistent redirection of pushd/popd to /dev/null. You *need* to
  do this in %generate_buildrequires, where anything printed to stdout is
  interpreted as a dependency. (Alternatively, you could just “cd” and not
  bother changing back at the end of the section.) However, %build use
  redirection when entering src/ but not when entering selinux/. I think it
  would be easier to understand the spec file if you redirected the output of
  pushd/popd either only when required (%generate_buildrequires), or *always*.

Notes:
======

These are just comments, not suggested changes.

- In general, I’ve reviewed the bits of the package involving systemd and
  SELinux at a relatively superficial level. I’ve looked for obvious technical,
  practical, and policy issues, but I’ve assumed that you basically know what
  you’re doing here.

- There are some rpmlint warnings about “overlinking,” where a shared library
  is linked but none of the symbols from it are used:

    localkdc.x86_64: W: unused-direct-shlib-dependency
			/usr/lib64/krb5/plugins/audit/audit_json.so
			/lib64/libk5crypto.so.3
    localkdc.x86_64: W: unused-direct-shlib-dependency
			/usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so
			/lib64/libkadm5srv_mit.so.12
    localkdc.x86_64: W: unused-direct-shlib-dependency
			/usr/lib64/krb5/plugins/kdb/kdb_userdb.so
			/lib64/libk5crypto.so.3
    localkdc.x86_64: W: unused-direct-shlib-dependency
			/usr/libexec/localkdc/localkdc-pam-auth
			/lib64/libk5crypto.so.3

  This might suggest that the upstream build system could be improved.
  Unnecessary shared-library dependencies can carry a small cost in time and
  memory, although in this case the libraries are ones that would already be
  loaded in any process that is loading a kerberos plugin, so it really doesn’t
  matter at all in practice.

===== MUST items =====

C/C++:
[-]: Development (unversioned) .so files in -devel subpackage, if present.
     Note: Unversioned so-files in private %_libdir subdirectory (see
     attachment). Verify they are not in ld path.

     Unversioned .so files are all Kerberos plugins. They appear to be
     correctly installed, and are not in the default linker search path.
     Everything here looks correct.

     https://docs.fedoraproject.org/en-US/packaging-guidelines/#_unversioned_shared_objects

Generic:
[x]: Package is licensed with an open-source compatible license and meets
     other legal requirements as defined in the legal section of Packaging
     Guidelines.
[x]: License field in the package spec file matches the actual license.
     Note: Checking patched sources after %prep for licenses. Licenses
     found: "Unknown or generated", "MIT License". 73 files have unknown
     license. Detailed output of licensecheck in
     /home/ben/fedora/review/2527288-localkdc/licensecheck.txt
[x]: License file installed when any subpackage combination is installed.
[x]: If the package is under multiple licenses, the licensing breakdown
     must be documented in the spec.
[!]: Package requires other packages for directories it uses.
     Note: No known owner of /usr/lib64/krb5/plugins/kadm5_hook,
     /usr/lib64/krb5/plugins/audit, /usr/libexec/localkdc

     See Issues.

[!]: Package must own all directories that it creates.
     Note: Directories without known owners: /usr/lib64/krb5/plugins/audit,
     /usr/lib64/krb5/plugins/kadm5_hook, /usr/share/selinux/packages,
     /usr/share/selinux, /usr/share/selinux/packages/targeted,
     /usr/libexec/localkdc

     See Issues.

     For the SELinux directories, the -selinux subpackage Requires
     selinux-policy-targeted, which depends on selinux-policy, which owns the
     directories. Normally it’s unwise to rely on indirect dependencies like
     this since they can change without you noticing, but this one should be
     reliable enough.

[x]: %build honors applicable compiler flags or justifies otherwise.
[x]: Package contains no bundled libraries or specifies bundled libraries
     with Provides: bundled(<libname>) if unbundling is not possible.
[x]: Changelog in prescribed format.
[x]: Sources contain only permissible code or content.
[-]: Package contains desktop file if it is a GUI application.
[-]: Development files must be in a -devel package
[x]: Package uses nothing in %doc for runtime.
[x]: Package consistently uses macros (instead of hard-coded directory
     names).
[x]: Package is named according to the Package Naming Guidelines.
[x]: Package does not generate any conflict.
[x]: Package obeys FHS, except libexecdir and /usr/target.

     Use of /var/kerberos isn’t strictly FHS-compliant, I think, but it’s a
     pre-existing feature of Kerberos and not something introduced by this
     package.

[-]: If the package is a rename of another package, proper Obsoletes and
     Provides are present.
[x]: Requires correct, justified where necessary.
[x]: Spec file is legible and written in American English.
[x]: Package contains systemd file(s) if in need.
[x]: Useful -debuginfo package or justification otherwise.
[x]: Package is not known to require an ExcludeArch tag.
[x]: Package complies to the Packaging Guidelines

     (except as noted)

[x]: Package successfully compiles and builds into binary rpms on at least
     one supported primary architecture.
[x]: Package installs properly.
[x]: Rpmlint is run on all rpms the build produces.
     Note: There are rpmlint messages (see attachment).
[x]: If (and only if) the source package includes the text of the
     license(s) in its own file, then that file, containing the text of the
     license(s) for the package is included in %license.
[x]: The License field must be a valid SPDX expression.
[x]: Package does not own files or directories owned by other packages.
[x]: Package uses either %{buildroot} or $RPM_BUILD_ROOT
[x]: Package does not run rm -rf %{buildroot} (or $RPM_BUILD_ROOT) at the
     beginning of %install.
[x]: Macros in Summary, %description expandable at SRPM build time.
[x]: Dist tag is present.
[x]: Package does not contain duplicates in %files.
[x]: Permissions on files are set properly.
[x]: Package must not depend on deprecated() packages.
[x]: Package use %makeinstall only when make install DESTDIR=... doesn't
     work.
[x]: Package is named using only allowed ASCII characters.
[x]: Package does not use a name that already exists.
[x]: Package is not relocatable.
[x]: Sources used to build the package match the upstream source, as
     provided in the spec URL.
[x]: Spec file name must match the spec package %{name}, in the format
     %{name}.spec.
[x]: File names are valid UTF-8.
[x]: Large documentation must go in a -doc subpackage. Large could be size
     (~1MB) or number of files.
     Note: Documentation size is 982 bytes in 1 files.
[x]: Packages must not store files under /srv, /opt or /usr/local

===== SHOULD items =====

Generic:
[!]: Uses parallel make %{?_smp_mflags} macro.
[-]: If the source package does not include license text(s) as a separate
     file from upstream, the packager SHOULD query upstream to include it.
[x]: Final provides and requires are sane (see attachments).

     However, see discussion of the manual systemd-units dependency.

[!]: Fully versioned dependency in subpackages if applicable.
     Note: No Requires: %{name}%{?_isa} = %{version}-%{release} in
     localkdc-selinux

     See Issues: this dependency needs to be arch-specific.

[?]: Package functions as described.
[x]: Latest version is packaged.
[x]: Package does not include license text files separate from upstream.
[x]: Scriptlets must be sane, if used.

     However, see discussion of tmpfiles.d and %tmpfiles_create.

[-]: Sources are verified with gpgverify first in %prep if upstream
     publishes signatures.
     Note: gpgverify is not used.
[x]: Package should compile and build into binary rpms on all supported
     architectures.

     https://koji.fedoraproject.org/koji/taskinfo?taskID=150624833

[!]: %check is present and all tests pass.

     See Issues: the lack of tests deserves a comment.

[x]: Packages should try to preserve timestamps of original installed
     files.
[-]: Spec use %global instead of %define unless justified.
     Note: %define requiring justification: %define localkdc_license
     %{shrink:

     Use of %define comes from rpmautospec, and this advice is dubious anyway,
     https://pagure.io/packaging-committee/issue/1449/.

[x]: Reviewer should test that the package builds in mock.
[x]: Buildroot is not present
[x]: Package has no %clean section with rm -rf %{buildroot} (or
     $RPM_BUILD_ROOT)
[x]: No file requires outside of /etc, /bin, /sbin, /usr/bin, /usr/sbin.
[x]: Packager, Vendor, PreReq, Copyright tags should not be in spec file
[x]: Sources can be downloaded from URI in Source: tag
[x]: SourceX is a working URL.

===== EXTRA items =====

Generic:
[!]: Spec file according to URL is the same as in SRPM.
     Note: Spec file as given by url is not the same as in SRPM (see
     attached diff).
     See: (this test has no URL)
[x]: Rpmlint is run on debuginfo package(s).
     Note: No rpmlint messages.
[x]: Rpmlint is run on all installed packages.
     Note: There are rpmlint messages (see attachment).
[x]: Large data in /usr/share should live in a noarch subpackage if package
     is arched.


Rpmlint
-------
Checking: localkdc-0.2.0-2.fc46.x86_64.rpm
          localkdc-selinux-0.2.0-2.fc46.x86_64.rpm
          localkdc-0.2.0-2.fc46.src.rpm
============================ rpmlint session starts ============================
rpmlint: 2.8.0
configuration:
    /usr/lib/python3.14/site-packages/rpmlint/configdefaults.toml
    /etc/xdg/rpmlint/fedora-spdx-licenses.toml
    /etc/xdg/rpmlint/fedora.toml
    /etc/xdg/rpmlint/scoring.toml
    /etc/xdg/rpmlint/users-groups.toml
    /etc/xdg/rpmlint/warn-on-functions.toml
rpmlintrc: [PosixPath('/tmp/tmpzsgyinmy')]
checks: 32, packages: 3

localkdc.x86_64: W: unstripped-binary-or-object /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so
localkdc.x86_64: W: tmpfile-not-in-filelist /run/localkdc
localkdc.x86_64: W: tmpfile-not-in-filelist /var/log/localkdc
localkdc.src: E: spelling-error ('systemd', '%description -l en_US systemd -> systems, system, system d')
localkdc.src: E: spelling-error ("systemd's", "%description -l en_US systemd's -> system's, system d's, system-d's")
localkdc.src: E: spelling-error ('userdb', '%description -l en_US userdb -> user db, user-db, user')
localkdc.x86_64: E: spelling-error ("systemd's", "%description -l en_US systemd's -> system's, system d's, system-d's")
localkdc.x86_64: E: spelling-error ('userdb', '%description -l en_US userdb -> user db, user-db, user')
localkdc.x86_64: W: non-standard-dir-in-var kerberos
localkdc.x86_64: W: no-manual-page-for-binary lkdcctl
localkdc-selinux.x86_64: W: no-documentation
localkdc-selinux.x86_64: E: no-binary
localkdc.spec: W: no-%check-section
localkdc.x86_64: W: empty-%postun
localkdc-selinux.x86_64: W: dangerous-command-in-%pre cp
localkdc-selinux.x86_64: W: dangerous-command-in-%postun rm
localkdc-selinux.x86_64: W: dangerous-command-in-%posttrans rm
localkdc-selinux.x86_64: W: dangerous-command-in-%post rm
 3 packages and 0 specfiles checked; 6 errors, 12 warnings, 11 filtered, 6 badness; has taken 0.5 s 




Rpmlint (debuginfo)
-------------------
Checking: localkdc-debuginfo-0.2.0-2.fc46.x86_64.rpm
============================ rpmlint session starts ============================
rpmlint: 2.8.0
configuration:
    /usr/lib/python3.14/site-packages/rpmlint/configdefaults.toml
    /etc/xdg/rpmlint/fedora-spdx-licenses.toml
    /etc/xdg/rpmlint/fedora.toml
    /etc/xdg/rpmlint/scoring.toml
    /etc/xdg/rpmlint/users-groups.toml
    /etc/xdg/rpmlint/warn-on-functions.toml
rpmlintrc: [PosixPath('/tmp/tmp5d42jhzs')]
checks: 32, packages: 1

 1 packages and 0 specfiles checked; 0 errors, 0 warnings, 14 filtered, 0 badness; has taken 0.8 s 





Rpmlint (installed packages)
----------------------------
============================ rpmlint session starts ============================
rpmlint: 2.10.0
configuration:
    /usr/lib/python3.15/site-packages/rpmlint/configdefaults.toml
    /etc/xdg/rpmlint/fedora-spdx-licenses.toml
    /etc/xdg/rpmlint/fedora.toml
    /etc/xdg/rpmlint/scoring.toml
    /etc/xdg/rpmlint/users-groups.toml
    /etc/xdg/rpmlint/warn-on-functions.toml
checks: 33, packages: 3

localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/audit/audit_json.so /lib64/libk5crypto.so.3
localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so /lib64/libkadm5srv_mit.so.12
localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/kdb/kdb_userdb.so /lib64/libk5crypto.so.3
localkdc.x86_64: W: unused-direct-shlib-dependency /usr/libexec/localkdc/localkdc-pam-auth /lib64/libk5crypto.so.3
localkdc.x86_64: W: unstripped-binary-or-object /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so
localkdc.x86_64: W: tmpfile-not-in-filelist /run/localkdc
localkdc.x86_64: W: tmpfile-not-in-filelist /var/log/localkdc
localkdc.x86_64: E: spelling-error ("systemd's", "%description -l en_US systemd's -> system's, system d's, system-d's")
localkdc.x86_64: E: spelling-error ('userdb', '%description -l en_US userdb -> user db, user-db, user')
localkdc.x86_64: W: non-standard-dir-in-var kerberos
localkdc.x86_64: W: no-manual-page-for-binary lkdcctl
localkdc-selinux.x86_64: W: no-documentation
localkdc-selinux.x86_64: E: no-binary
localkdc.x86_64: W: empty-%postun
localkdc-selinux.x86_64: W: dangerous-command-in-%pre cp
localkdc-selinux.x86_64: W: dangerous-command-in-%postun rm
localkdc-selinux.x86_64: W: dangerous-command-in-%posttrans rm
localkdc-selinux.x86_64: W: dangerous-command-in-%post rm
 3 packages and 0 specfiles checked; 3 errors, 15 warnings, 24 filtered, 3 badness; has taken 1.0 s 



Unversioned so-files
--------------------
localkdc: /usr/lib64/krb5/plugins/audit/audit_json.so
localkdc: /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so
localkdc: /usr/lib64/krb5/plugins/kdb/kdb_userdb.so

Source checksums
----------------
https://gitlab.com/kirmes/localkdc/-/archive/0.2.0/localkdc-0.2.0.tar.gz :
  CHECKSUM(SHA256) this package     : 316c83e19ea6b67e4a7769f0f0c7691bdde9df0ba9c53d7e42ac71ff7fec9239
  CHECKSUM(SHA256) upstream package : 316c83e19ea6b67e4a7769f0f0c7691bdde9df0ba9c53d7e42ac71ff7fec9239


Requires
--------
localkdc (rpmlib, GLIBC filtered):
    (localkdc-selinux if selinux-policy-targeted)
    (systemd-standalone-tmpfiles or systemd)
    /bin/sh
    /usr/bin/bash
    bash
    certmonger
    gawk
    hostname
    krb5-server
    krb5-workstation
    ld-linux-x86-64.so.2()(64bit)
    libc.so.6()(64bit)
    libgcc_s.so.1()(64bit)
    libgcc_s.so.1(GCC_3.0)(64bit)
    libgcc_s.so.1(GCC_3.3)(64bit)
    libgcc_s.so.1(GCC_4.2.0)(64bit)
    libk5crypto.so.3()(64bit)
    libk5crypto.so.3(k5crypto_3_MIT)(64bit)
    libkadm5srv_mit.so.12()(64bit)
    libkadm5srv_mit.so.12(kadm5srv_mit_12_MIT)(64bit)
    libkdb5.so.10()(64bit)
    libkdb5.so.10(kdb5_10_MIT)(64bit)
    libkrb5.so.3()(64bit)
    libkrb5.so.3(krb5_3_MIT)(64bit)
    libpam.so.0()(64bit)
    libpam.so.0(LIBPAM_1.0)(64bit)
    rtld(GNU_HASH)
    systemd-units

localkdc-selinux (rpmlib, GLIBC filtered):
    /bin/sh
    localkdc
    selinux-policy-targeted



Provides
--------
localkdc:
    localkdc
    localkdc(x86-64)

localkdc-selinux:
    localkdc-selinux
    localkdc-selinux(x86-64)



Diff spec file in url and in SRPM
---------------------------------
--- /home/ben/fedora/review/2527288-localkdc/srpm/localkdc.spec	2026-09-23 12:02:22.284797242 +0100
+++ /home/ben/fedora/review/2527288-localkdc/srpm-unpacked/localkdc.spec	2026-09-03 01:00:00.000000000 +0100
@@ -1,2 +1,12 @@
+## START: Set by rpmautospec
+## (rpmautospec version 0.8.4)
+## RPMAUTOSPEC: autorelease, autochangelog
+%define autorelease(e:s:pb:n) %{?-p:0.}%{lua:
+    release_number = 2;
+    base_release_number = tonumber(rpm.expand("%{?-b*}%{!?-b:1}"));
+    print(release_number + base_release_number - 1);
+}%{?-e:.%{-e*}}%{?-s:.%{-s*}}%{!?-n:%{?dist}}
+## END: Set by rpmautospec
+
 %bcond selinux 1
 %global selinux_variants targeted
@@ -26,4 +36,5 @@
 URL:            https://gitlab.com/kirmes/localkdc
 Source0:        https://gitlab.com/kirmes/localkdc/-/archive/%{version}/%{name}-%{version}.tar.gz
+Patch0:         localkdc-fix-selinux.patch
 
 BuildRequires:  cargo
@@ -199,3 +210,104 @@
 
 %changelog
-%autochangelog
+## START: Generated by rpmautospec
+* Thu Sep 03 2026 Andreas Schneider <asn> - 0.2.0-2
+- Fix selinux logging filetransfer to localkdc directory
+
+* Fri Aug 14 2026 Andreas Schneider <asn> - 0.2.0-1
+- Update to version 0.2.0
+
+* Thu Apr 16 2026 Andreas Schneider <asn> - 0.1.0-2
+- Fix install location of localkdc-pam-auth
+
+* Wed Apr 15 2026 Andreas Schneider <asn> - 0.1.0-1
+- Update to version 0.1.0
+
+* Thu Nov 13 2025 Andreas Schneider <asn> - 0.0.1-36
+- Improve error handling for our tools
+
+* Fri Jul 11 2025 Andreas Schneider <asn> - 0.0.1-35
+- Use the right file_type for db files
+
+* Fri Jul 11 2025 Andreas Schneider <asn> - 0.0.1-34
+- Get selinux working
+
+* Fri Jun 27 2025 Andreas Schneider <asn> - 0.0.1-33
+- Fix selinux
+
+* Fri Jun 20 2025 Andreas Schneider <asn> - 0.0.1-32
+- Fix an infinite loop
+
+* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-31
+- Fix localkdc-setup
+
+* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-30
+- Fix possible recursion in kdb with localhost
+
+* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-29
+- Build with debuginfo package for kdb module
+
+* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-28
+- Fix build because of missing errno.h
+
+* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-27
+- Add support for IP and dynamic DNS aliases
+
+* Thu Apr 17 2025 Andreas Schneider <asn> - 0.0.1-26
+- Use app-id derived from machine-id as localkdc realm
+- Added localkdc-kinit
+
+* Thu Apr 10 2025 Andreas Schneider <asn> - 0.0.1-25
+- Fix issues with localkdc-useradd
+
+* Thu Apr 10 2025 Andreas Schneider <asn> - 0.0.1-24
+- Fix localkdc-useradd
+- This goes to changelog
+
+* Tue Apr 08 2025 Andreas Schneider <asn> - 0.0.1-23
+- Update for new localkdc realm option
+
+* Mon Apr 07 2025 Andreas Schneider <asn> - 0.0.1-22
+- Require preauth
+
+* Mon Apr 07 2025 Andreas Schneider <asn> - 0.0.1-21
+- Fix default realm
+
+* Wed Apr 02 2025 Andreas Schneider <asn> - 0.0.1-20
+- Add userdb support
+
+* Wed Apr 02 2025 Andreas Schneider <asn> - 0.0.1-19
+- gitignore
+
+* Wed Mar 12 2025 Andreas Schneider <asn> - 0.0.1-18
+- foo
+
+* Fri Jan 24 2025 Andreas Schneider <asn> - 0.0.1-15
+- New release
+
+* Mon Jan 20 2025 Andreas Schneider <asn> - 0.0.1-14
+- Update for alias changes
+
+* Thu Dec 05 2024 Andreas Schneider <asn> - 0.0.1-13
+- Updates for kdb api changes
+
+* Wed Dec 04 2024 Andreas Schneider <asn> - 0.0.1-12
+- Fix tarball
+
+* Wed Dec 04 2024 Andreas Schneider <asn> - 0.0.1-11
+- Don't use kdc_unixsock_listen anymore
+
+* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-10
+- update tarball
+
+* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-9
+- update tarball
+
+* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-6
+- kdb driver
+
+* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-4
+- selinux
+
+* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-1
+- The big bang!
+## END: Generated by rpmautospec


Generated by fedora-review 0.11.0 (05c5b26) last change: 2025-11-29
Command line :/usr/bin/fedora-review -b 2527288
Buildroot used: fedora-rawhide-x86_64
Active plugins: Generic, Shell-api
Disabled plugins: Ocaml, Perl, Java, Haskell, Python, PHP, SugarActivity, R, C/C++, fonts
Disabled flags: EXARCH, EPEL6, EPEL7, DISTTAG, BATCH

Comment 4 Andreas Schneider 2026-09-28 17:28:02 UTC
Thank you very much for the review!

I will first fix the things upstream, do a new release and then will update the package.

Comment 5 Andreas Schneider 2026-09-29 08:48:26 UTC
The linking issue is addressed via https://forge.fedoraproject.org/freeipa/kurbu5/pulls/29

Comment 6 Andreas Schneider 2026-10-02 07:06:11 UTC
Spec URL: https://asn.fedorapeople.org/localkdc.spec
SRPM URL: https://asn.fedorapeople.org/localkdc-0.2.1-1.fc46.src.rpm



Update to version 0.2.1

- Require %{name}%{?_isa} in the -selinux subpackage.
- Own the krb5 audit/kadm5_hook plugin dirs and libexecdir.
- Drop tmpfiles.d.
- Add BuildRequires: make and go-md2man, and package the new man pages.
- Use %{_rundir}/%{_localstatedir} macros instead of hardcoded paths.
- Use %make_build for the SELinux policy build.
- Drop unneeded Requires(post/preun/postun): systemd-units.
- Package the new /etc/pam.d/localkdc-otp file shipped by 0.2.1.
- Drop localkdc-fix-selinux.patch, now merged upstream.
- Run bats tests

Comment 7 Ben Beasley 2026-10-05 10:26:04 UTC
The latest submission is much closer! Thanks for your work. There are a few remaining things that are new or that I missed in the first round of review.

Package Review
==============

Legend:
[x] = Pass, [!] = Fail, [-] = Not applicable, [?] = Not evaluated

Issues:
=======
- systemd_post is invoked in %post, systemd_preun in %preun, and
  systemd_postun in %postun for Systemd service files.
  Note: Systemd service file(s) in localkdc
  See: https://docs.fedoraproject.org/en-US/packaging-
  guidelines/Scriptlets/#_scriptlets

  This is a spurious diagnostic: it appears that exactly the recommended
  scriptlets are invoked in the appropriate sections.

- It looks like the selinux subpackage can be:

    BuildArch:      noarch

  It doesn’t contain any machine code or install to any architecture-specific
  paths like %{_libdir}, so it should be the same on all architectures. Making
  it noarch saves mirror space and bandwidth.

- While
  https://docs.fedoraproject.org/en-US/packaging-guidelines/#_requiring_base_package
  just talks about requiring base packages, the same logic applies to any
  dependencies across binary RPMs built from the same source RPMs. Thus this:

    %if %{with selinux}
    Requires:       (%{name}-selinux if selinux-policy-%{selinuxtype})
    %endif
    
  would better be this:

    %if %{with selinux}
    Requires:       (%{name}-selinux%{?_isa} = %{version}-%{release} if selinux-policy-%{selinuxtype})
    %endif

  except that you would not add %{?_isa} if you make the -selinux subpackage
  noarch as recommended above.

- I see that localkdc-selinux depends on localkdc and localkdc depends
  (conditionally) on localkdc-selinux, creating a circular dependency. This
  isn’t necessarily strictly forbidden, but it can have disadvantages.

  In this case, it seems like it could be avoided, because localkdc-selinux
  merely installs a policy file into the appropriate directory, e.g.
  /usr/share/selinux/packages/targeted/localkdc.pp.bz2, and this doesn’t
  actually require anything from the base package to be installed.

  I think you could drop the localkdc-selinux→localkdc dependency, leaving just
  the conditional localkdc→localkdc-selinux dependency, and this would be an
  improvement. You would need to add a copy of LICENSE to the -selinux
  subpackage since it *could* be installed by itself.

- Strictly speaking, the localkdc-selinux subpackage should have:

    # This subpackage does not include anything derived from the
    # statically-linked Rust dependencies.
    License:        MIT

- The file /etc/pam.d/localkdc-otp is a configuration file and must be marked
  as such.

  https://docs.fedoraproject.org/en-US/packaging-guidelines/#_configuration_files

  Change this:

    %{_sysconfdir}/pam.d/localkdc-otp

  to this:

    %config(noreplace) %{_sysconfdir}/pam.d/localkdc-otp

- Neither this package nor any of its dependencies owns %{_sysconfdir}/pam.d.
  Consider whether it makes more sense to co-own the directory,

    %dir %{_sysconfdir}/pam.d/

  or to add an explicit dependency on pam.

  (Currently, the package has an automatic dependency on pam-libs for
  libpam.so, but not on pam.)
 
  https://docs.fedoraproject.org/en-US/packaging-guidelines/#_file_and_directory_ownership

Recommendations:
================

- It’s helpful to paste the raw %%{cargo_license_summary} output above your
  license expression:

    # Apache-2.0 OR BSL-1.0
    # Apache-2.0 OR MIT
    # Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT
    # BSD-2-Clause
    # BSD-2-Clause OR Apache-2.0 OR MIT
    # LGPL-2.1-or-later
    # MIT
    # MIT OR Apache-2.0
    # Unlicense OR MIT

  That way, when someone does a new build with possibly shifted Rust
  dependencies, they can check the comment against the new
  %%{cargo_license_summary} output, and update the license expression as
  needed. This is much lighter and less error-prone work than comparing the
  license expression against the %%{cargo_license_summary} output each time,
  especially if deduplication is involved.

- You do not need this

    export RUSTFLAGS='%{build_rustflags}'

  unless you are planning to target EPEL9. In EPEL10 and all Fedoras, RUSTFLAGS
  are set automatically wherever CFLAGS, CXXFLAGS, LDFLAGS, and so on are.

  It doesn’t hurt anything.

Notes:
======

- There are some rpmlint warnings about “overlinking,” where a shared library
  is linked but none of the symbols from it are used:

    localkdc.x86_64: W: unused-direct-shlib-dependency
			/usr/lib64/krb5/plugins/audit/audit_json.so
			/lib64/libk5crypto.so.3
    localkdc.x86_64: W: unused-direct-shlib-dependency
			/usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so
			/lib64/libkadm5srv_mit.so.12
    localkdc.x86_64: W: unused-direct-shlib-dependency
			/usr/lib64/krb5/plugins/kdb/kdb_userdb.so
			/lib64/libk5crypto.so.3
    localkdc.x86_64: W: unused-direct-shlib-dependency
			/usr/libexec/localkdc/localkdc-pam-auth
			/lib64/libk5crypto.so.3

  This might suggest that the upstream build system could be improved.
  Unnecessary shared-library dependencies can carry a small cost in time and
  memory, although in this case the libraries are ones that would already be
  loaded in any process that is loading a kerberos plugin, so it really doesn’t
  matter at all in practice.

- I am not prepared to evaluate /etc/pam.d/localkdc-otp from a security
  perspective.

- I am assuming that you basically know what you are doing with the SELinux
  policy compilation and installation/scriptlets, as it’s been a while since I
  attempted this myself and there are no relevant packaging guidelines.


===== MUST items =====

C/C++:
[x]: Development (unversioned) .so files in -devel subpackage, if present.
     Note: Unversioned so-files in private %_libdir subdirectory (see
     attachment). Verify they are not in ld path.

     Unversioned .so files are all Kerberos plugins. They appear to be
     correctly installed, and are not in the default linker search path.
     Everything here looks correct.

     https://docs.fedoraproject.org/en-US/packaging-guidelines/#_unversioned_shared_objects

Generic:
[x]: Package is licensed with an open-source compatible license and meets
     other legal requirements as defined in the legal section of Packaging
     Guidelines.
[x]: License field in the package spec file matches the actual license.
     Note: Checking patched sources after %prep for licenses. Licenses
     found: "Unknown or generated", "MIT License". 73 files have unknown
     license. Detailed output of licensecheck in
     /home/ben/fedora/review/20261003/2527288-localkdc/licensecheck.txt
[x]: License file installed when any subpackage combination is installed.
[x]: If the package is under multiple licenses, the licensing breakdown
     must be documented in the spec.
[!]: Package must own all directories that it creates.
     Note: Directories without known owners: /etc/pam.d,
     /usr/share/selinux/packages/targeted, /usr/share/selinux,
     /usr/share/selinux/packages

     For /etc/pam.d, see Issues.

     For the SELinux directories, I think that everything is OK, and
     fedora-review is confused by the %{selinuxtype} macro. The -selinux
     subpackage has:

       Requires:       selinux-policy-%{selinuxtype}

     which is actually

       Requires:       selinux-policy-targeted

     and selinux-policy-targeted reliably depends on selinux-policy, which owns
     these directories.

[x]: %build honors applicable compiler flags or justifies otherwise.
[x]: Package contains no bundled libraries or specifies bundled libraries
     with Provides: bundled(<libname>) if unbundling is not possible.
[x]: Changelog in prescribed format.
[x]: Sources contain only permissible code or content.
[-]: Package contains desktop file if it is a GUI application.
[-]: Development files must be in a -devel package
[x]: Package uses nothing in %doc for runtime.
[x]: Package consistently uses macros (instead of hard-coded directory
     names).
[x]: Package is named according to the Package Naming Guidelines.
[x]: Package does not generate any conflict.
[x]: Package obeys FHS, except libexecdir and /usr/target.

     Use of /var/kerberos isn’t strictly FHS-compliant, I think, but it’s a
     pre-existing feature of Kerberos and not something introduced by this
     package.

[-]: If the package is a rename of another package, proper Obsoletes and
     Provides are present.
[x]: Requires correct, justified where necessary.

     I didn’t go through these with a fine-toothed comb, but they look
     basically sane.

[x]: Spec file is legible and written in American English.
[x]: Package contains systemd file(s) if in need.
[x]: Useful -debuginfo package or justification otherwise.
[x]: Package is not known to require an ExcludeArch tag.
[x]: Package complies to the Packaging Guidelines

     (except as noted)

[x]: Package successfully compiles and builds into binary rpms on at least
     one supported primary architecture.
[x]: Package installs properly.
[x]: Rpmlint is run on all rpms the build produces.
     Note: There are rpmlint messages (see attachment).
[x]: If (and only if) the source package includes the text of the
     license(s) in its own file, then that file, containing the text of the
     license(s) for the package is included in %license.
[x]: The License field must be a valid SPDX expression.
[x]: Package requires other packages for directories it uses.
[x]: Package does not own files or directories owned by other packages.
[x]: Package uses either %{buildroot} or $RPM_BUILD_ROOT
[x]: Package does not run rm -rf %{buildroot} (or $RPM_BUILD_ROOT) at the
     beginning of %install.
[x]: Macros in Summary, %description expandable at SRPM build time.
[x]: Dist tag is present.
[x]: Package does not contain duplicates in %files.
[x]: Permissions on files are set properly.
[x]: Package must not depend on deprecated() packages.
[x]: Package use %makeinstall only when make install DESTDIR=... doesn't
     work.
[x]: Package is named using only allowed ASCII characters.
[x]: Package does not use a name that already exists.
[x]: Package is not relocatable.
[x]: Sources used to build the package match the upstream source, as
     provided in the spec URL.
[x]: Spec file name must match the spec package %{name}, in the format
     %{name}.spec.
[x]: File names are valid UTF-8.
[x]: Large documentation must go in a -doc subpackage. Large could be size
     (~1MB) or number of files.
     Note: Documentation size is 982 bytes in 1 files.
[x]: Packages must not store files under /srv, /opt or /usr/local

===== SHOULD items =====

Generic:
[-]: If the source package does not include license text(s) as a separate
     file from upstream, the packager SHOULD query upstream to include it.
[x]: Final provides and requires are sane (see attachments).
[?]: Package functions as described.

     It’s not practical for me to test this.

[x]: Latest version is packaged.
[x]: Package does not include license text files separate from upstream.
[x]: Scriptlets must be sane, if used.
[-]: Sources are verified with gpgverify first in %prep if upstream
     publishes signatures.
     Note: gpgverify is not used.
[x]: Package should compile and build into binary rpms on all supported
     architectures.

     https://koji.fedoraproject.org/koji/taskinfo?taskID=150932365

[x]: %check is present and all tests pass.

     The tests that can be executed are extremely minimal.

[x]: Packages should try to preserve timestamps of original installed
     files.
[x]: Spec use %global instead of %define unless justified.
     Note: %define requiring justification: %define localkdc_license
     %{shrink:

     Use of %define comes from rpmautospec, and this advice is dubious anyway,
     https://pagure.io/packaging-committee/issue/1449/.

[x]: Reviewer should test that the package builds in mock.
[x]: Buildroot is not present
[x]: Package has no %clean section with rm -rf %{buildroot} (or
     $RPM_BUILD_ROOT)
[x]: No file requires outside of /etc, /bin, /sbin, /usr/bin, /usr/sbin.
[x]: Fully versioned dependency in subpackages if applicable.
[x]: Packager, Vendor, PreReq, Copyright tags should not be in spec file
[x]: Sources can be downloaded from URI in Source: tag
[x]: SourceX is a working URL.

===== EXTRA items =====

Generic:
[!]: Spec file according to URL is the same as in SRPM.
     Note: Spec file as given by url is not the same as in SRPM (see
     attached diff).
     See: (this test has no URL)
[x]: Rpmlint is run on debuginfo package(s).
     Note: No rpmlint messages.
[x]: Rpmlint is run on all installed packages.
     Note: There are rpmlint messages (see attachment).
[x]: Large data in /usr/share should live in a noarch subpackage if package
     is arched.


Rpmlint
-------
Checking: localkdc-0.2.1-1.fc46.x86_64.rpm
          localkdc-selinux-0.2.1-1.fc46.x86_64.rpm
          localkdc-0.2.1-1.fc46.src.rpm
============================ rpmlint session starts ============================
rpmlint: 2.8.0
configuration:
    /usr/lib/python3.14/site-packages/rpmlint/configdefaults.toml
    /etc/xdg/rpmlint/fedora-spdx-licenses.toml
    /etc/xdg/rpmlint/fedora.toml
    /etc/xdg/rpmlint/scoring.toml
    /etc/xdg/rpmlint/users-groups.toml
    /etc/xdg/rpmlint/warn-on-functions.toml
rpmlintrc: [PosixPath('/tmp/tmpjk8heoa2')]
checks: 32, packages: 3

localkdc.src: E: spelling-error ('systemd', '%description -l en_US systemd -> systems, system, system d')
localkdc.src: E: spelling-error ("systemd's", "%description -l en_US systemd's -> system's, system d's, system-d's")
localkdc.src: E: spelling-error ('userdb', '%description -l en_US userdb -> user db, user-db, user')
localkdc.x86_64: E: spelling-error ("systemd's", "%description -l en_US systemd's -> system's, system d's, system-d's")
localkdc.x86_64: E: spelling-error ('userdb', '%description -l en_US userdb -> user db, user-db, user')
localkdc.x86_64: W: non-standard-dir-in-var kerberos
localkdc.x86_64: W: non-conffile-in-etc /etc/pam.d/localkdc-otp
localkdc-selinux.x86_64: W: no-documentation
localkdc-selinux.x86_64: E: no-binary
localkdc.x86_64: W: empty-%postun
localkdc-selinux.x86_64: W: dangerous-command-in-%pre cp
localkdc-selinux.x86_64: W: dangerous-command-in-%postun rm
localkdc-selinux.x86_64: W: dangerous-command-in-%posttrans rm
localkdc-selinux.x86_64: W: dangerous-command-in-%post rm
 3 packages and 0 specfiles checked; 6 errors, 8 warnings, 11 filtered, 6 badness; has taken 0.4 s 




Rpmlint (debuginfo)
-------------------
Checking: localkdc-debuginfo-0.2.1-1.fc46.x86_64.rpm
============================ rpmlint session starts ============================
rpmlint: 2.8.0
configuration:
    /usr/lib/python3.14/site-packages/rpmlint/configdefaults.toml
    /etc/xdg/rpmlint/fedora-spdx-licenses.toml
    /etc/xdg/rpmlint/fedora.toml
    /etc/xdg/rpmlint/scoring.toml
    /etc/xdg/rpmlint/users-groups.toml
    /etc/xdg/rpmlint/warn-on-functions.toml
rpmlintrc: [PosixPath('/tmp/tmplut50mrv')]
checks: 32, packages: 1

 1 packages and 0 specfiles checked; 0 errors, 0 warnings, 16 filtered, 0 badness; has taken 1.0 s 





Rpmlint (installed packages)
----------------------------
============================ rpmlint session starts ============================
rpmlint: 2.10.0
configuration:
    /usr/lib/python3.15/site-packages/rpmlint/configdefaults.toml
    /etc/xdg/rpmlint/fedora-spdx-licenses.toml
    /etc/xdg/rpmlint/fedora.toml
    /etc/xdg/rpmlint/scoring.toml
    /etc/xdg/rpmlint/users-groups.toml
    /etc/xdg/rpmlint/warn-on-functions.toml
checks: 33, packages: 3

localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/audit/audit_json.so /lib64/libk5crypto.so.3
localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so /lib64/libkadm5srv_mit.so.12
localkdc.x86_64: W: unused-direct-shlib-dependency /usr/lib64/krb5/plugins/kdb/kdb_userdb.so /lib64/libk5crypto.so.3
localkdc.x86_64: W: unused-direct-shlib-dependency /usr/libexec/localkdc/localkdc-pam-auth /lib64/libk5crypto.so.3
localkdc.x86_64: W: spelling-error ("systemd's", "%description -l en_US systemd's -> system's, system d's, system-d's")
localkdc.x86_64: W: spelling-error ('userdb', '%description -l en_US userdb -> user db, user-db, user')
localkdc.x86_64: W: non-standard-dir-in-var kerberos
localkdc.x86_64: W: non-conffile-in-etc /etc/pam.d/localkdc-otp
localkdc-selinux.x86_64: W: no-documentation
localkdc-selinux.x86_64: E: no-binary
localkdc.x86_64: W: empty-%postun
localkdc-selinux.x86_64: W: dangerous-command-in-%pre cp
localkdc-selinux.x86_64: W: dangerous-command-in-%postun rm
localkdc-selinux.x86_64: W: dangerous-command-in-%posttrans rm
localkdc-selinux.x86_64: W: dangerous-command-in-%post rm
 3 packages and 0 specfiles checked; 1 errors, 14 warnings, 27 filtered, 1 badness; has taken 0.9 s 



Unversioned so-files
--------------------
localkdc: /usr/lib64/krb5/plugins/audit/audit_json.so
localkdc: /usr/lib64/krb5/plugins/kadm5_hook/kadm5_chpass.so
localkdc: /usr/lib64/krb5/plugins/kdb/kdb_userdb.so

Source checksums
----------------
https://gitlab.com/kirmes/localkdc/-/archive/0.2.1/localkdc-0.2.1.tar.gz :
  CHECKSUM(SHA256) this package     : 0e4e5fe6aa813d8b89e958a7737215534eb79f2b0863737a2abace93a0294a25
  CHECKSUM(SHA256) upstream package : 0e4e5fe6aa813d8b89e958a7737215534eb79f2b0863737a2abace93a0294a25


Requires
--------
localkdc (rpmlib, GLIBC filtered):
    (localkdc-selinux if selinux-policy-targeted)
    /bin/sh
    /usr/bin/bash
    bash
    certmonger
    gawk
    hostname
    krb5-server
    krb5-workstation
    ld-linux-x86-64.so.2()(64bit)
    libc.so.6()(64bit)
    libgcc_s.so.1()(64bit)
    libgcc_s.so.1(GCC_3.0)(64bit)
    libgcc_s.so.1(GCC_3.3)(64bit)
    libgcc_s.so.1(GCC_4.2.0)(64bit)
    libk5crypto.so.3()(64bit)
    libk5crypto.so.3(k5crypto_3_MIT)(64bit)
    libkadm5srv_mit.so.12()(64bit)
    libkadm5srv_mit.so.12(kadm5srv_mit_12_MIT)(64bit)
    libkdb5.so.10()(64bit)
    libkdb5.so.10(kdb5_10_MIT)(64bit)
    libkrb5.so.3()(64bit)
    libkrb5.so.3(krb5_3_MIT)(64bit)
    libpam.so.0()(64bit)
    libpam.so.0(LIBPAM_1.0)(64bit)
    rtld(GNU_HASH)

localkdc-selinux (rpmlib, GLIBC filtered):
    /bin/sh
    localkdc(x86-64)
    selinux-policy-targeted



Provides
--------
localkdc:
    localkdc
    localkdc(x86-64)

localkdc-selinux:
    localkdc-selinux
    localkdc-selinux(x86-64)



Diff spec file in url and in SRPM
---------------------------------
--- /home/ben/fedora/review/20261003/2527288-localkdc/srpm/localkdc.spec	2026-10-03 08:09:10.555640759 +0100
+++ /home/ben/fedora/review/20261003/2527288-localkdc/srpm-unpacked/localkdc.spec	2026-10-01 01:00:00.000000000 +0100
@@ -1,2 +1,12 @@
+## START: Set by rpmautospec
+## (rpmautospec version 0.8.4)
+## RPMAUTOSPEC: autorelease, autochangelog
+%define autorelease(e:s:pb:n) %{?-p:0.}%{lua:
+    release_number = 1;
+    base_release_number = tonumber(rpm.expand("%{?-b*}%{!?-b:1}"));
+    print(release_number + base_release_number - 1);
+}%{?-e:.%{-e*}}%{?-s:.%{-s*}}%{!?-n:%{?dist}}
+## END: Set by rpmautospec
+
 %bcond selinux 1
 %global selinux_variants targeted
@@ -211,3 +221,117 @@
 
 %changelog
-%autochangelog
+## START: Generated by rpmautospec
+* Thu Oct 01 2026 Andreas Schneider <asn> - 0.2.1-1
+- Update to version 0.2.1
+- Require %%{name}%%{?_isa} in the -selinux subpackage.
+- Own the krb5 audit/kadm5_hook plugin dirs and libexecdir.
+- Drop tmpfiles.d.
+- Add BuildRequires: make and go-md2man, and package the new man pages.
+- Use %%{_rundir}/%%{_localstatedir} macros instead of hardcoded paths.
+- Use %%make_build for the SELinux policy build.
+- Drop unneeded Requires(post/preun/postun): systemd-units.
+- Package the new /etc/pam.d/localkdc-otp file shipped by 0.2.1.
+- Drop localkdc-fix-selinux.patch, now merged upstream.
+- Run bats tests
+
+* Thu Sep 03 2026 Andreas Schneider <asn> - 0.2.0-2
+- Fix selinux logging filetransfer to localkdc directory
+
+* Fri Aug 14 2026 Andreas Schneider <asn> - 0.2.0-1
+- Update to version 0.2.0
+
+* Thu Apr 16 2026 Andreas Schneider <asn> - 0.1.0-2
+- Fix install location of localkdc-pam-auth
+
+* Wed Apr 15 2026 Andreas Schneider <asn> - 0.1.0-1
+- Update to version 0.1.0
+
+* Thu Nov 13 2025 Andreas Schneider <asn> - 0.0.1-36
+- Improve error handling for our tools
+
+* Fri Jul 11 2025 Andreas Schneider <asn> - 0.0.1-35
+- Use the right file_type for db files
+
+* Fri Jul 11 2025 Andreas Schneider <asn> - 0.0.1-34
+- Get selinux working
+
+* Fri Jun 27 2025 Andreas Schneider <asn> - 0.0.1-33
+- Fix selinux
+
+* Fri Jun 20 2025 Andreas Schneider <asn> - 0.0.1-32
+- Fix an infinite loop
+
+* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-31
+- Fix localkdc-setup
+
+* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-30
+- Fix possible recursion in kdb with localhost
+
+* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-29
+- Build with debuginfo package for kdb module
+
+* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-28
+- Fix build because of missing errno.h
+
+* Fri May 16 2025 Andreas Schneider <asn> - 0.0.1-27
+- Add support for IP and dynamic DNS aliases
+
+* Thu Apr 17 2025 Andreas Schneider <asn> - 0.0.1-26
+- Use app-id derived from machine-id as localkdc realm
+- Added localkdc-kinit
+
+* Thu Apr 10 2025 Andreas Schneider <asn> - 0.0.1-25
+- Fix issues with localkdc-useradd
+
+* Thu Apr 10 2025 Andreas Schneider <asn> - 0.0.1-24
+- Fix localkdc-useradd
+- This goes to changelog
+
+* Tue Apr 08 2025 Andreas Schneider <asn> - 0.0.1-23
+- Update for new localkdc realm option
+
+* Mon Apr 07 2025 Andreas Schneider <asn> - 0.0.1-22
+- Require preauth
+
+* Mon Apr 07 2025 Andreas Schneider <asn> - 0.0.1-21
+- Fix default realm
+
+* Wed Apr 02 2025 Andreas Schneider <asn> - 0.0.1-20
+- Add userdb support
+
+* Wed Apr 02 2025 Andreas Schneider <asn> - 0.0.1-19
+- gitignore
+
+* Wed Mar 12 2025 Andreas Schneider <asn> - 0.0.1-18
+- foo
+
+* Fri Jan 24 2025 Andreas Schneider <asn> - 0.0.1-15
+- New release
+
+* Mon Jan 20 2025 Andreas Schneider <asn> - 0.0.1-14
+- Update for alias changes
+
+* Thu Dec 05 2024 Andreas Schneider <asn> - 0.0.1-13
+- Updates for kdb api changes
+
+* Wed Dec 04 2024 Andreas Schneider <asn> - 0.0.1-12
+- Fix tarball
+
+* Wed Dec 04 2024 Andreas Schneider <asn> - 0.0.1-11
+- Don't use kdc_unixsock_listen anymore
+
+* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-10
+- update tarball
+
+* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-9
+- update tarball
+
+* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-6
+- kdb driver
+
+* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-4
+- selinux
+
+* Fri Nov 29 2024 Andreas Schneider <asn> - 0.0.1-1
+- The big bang!
+## END: Generated by rpmautospec


Generated by fedora-review 0.12.0 (a08f0fc) last change: 2026-09-18
Command line :/usr/bin/fedora-review -b 2527288
Buildroot used: fedora-rawhide-x86_64
Active plugins: Generic, Shell-api
Disabled plugins: fonts, Perl, R, Ocaml, PHP, Java, Haskell, C/C++, Python, SugarActivity
Disabled flags: EXARCH, EPEL6, EPEL7, DISTTAG, BATCH, UNRETIREMENT

Comment 8 Andreas Schneider 2026-10-05 15:47:30 UTC
Spec URL: https://asn.fedorapeople.org/localkdc.spec
SRPM URL: https://asn.fedorapeople.org/localkdc-0.2.1-2.fc46.src.rpm


    Address second round of Fedora package review feedback

    - Make the -selinux subpackage noarch
    - Drop circular Requires on the base package
    - Give selinux its own MIT License and ship %license LICENSE
      so it stays self-contained if installed standalone.
    - Pin the base package's conditional Requires on -selinux to
      %{version}-%{release}.
    - Mark /etc/pam.d/localkdc-otp as %config(noreplace).
    - Add Requires: pam since the base package relies on pam owning
      /etc/pam.d.
    - Paste the raw %{cargo_license_summary} output as a comment for future
      rebuilds
    - Drop the unneeded RUSTFLAGS export


The rpmlint warnings about "overlinking" will be fixed with a new kurbu5 release. The fix has been merged upstream, but there is no new release yet. Also this isn't a big deal, the plugins are loaded with dlopen() by krb5kdc and it has all those libraries linked anyway.

root@krikkit:~# ldd /usr/sbin/krb5kdc
        linux-vdso.so.1 (0x00007f71dd1ce000)
        libkadm5srv_mit.so.12 => /lib64/libkadm5srv_mit.so.12 (0x00007f71dd14d000)
        libkdb5.so.10 => /lib64/libkdb5.so.10 (0x00007f71dd137000)
        libgssrpc.so.4 => /lib64/libgssrpc.so.4 (0x00007f71dd116000)
        libkrb5.so.3 => /lib64/libkrb5.so.3 (0x00007f71dd044000)
        libk5crypto.so.3 => /lib64/libk5crypto.so.3 (0x00007f71dd02c000)
        libcom_err.so.2 => /lib64/libcom_err.so.2 (0x00007f71dd026000)
        libkrb5support.so.0 => /lib64/libkrb5support.so.0 (0x00007f71dd013000)
        libverto.so.1 => /lib64/libverto.so.1 (0x00007f71dd00c000)
        libc.so.6 => /lib64/libc.so.6 (0x00007f71dce13000)
        libgssapi_krb5.so.2 => /lib64/libgssapi_krb5.so.2 (0x00007f71dcdb8000)
        libkeyutils.so.1 => /lib64/libkeyutils.so.1 (0x00007f71dcdb2000)
        libcrypto.so.3 => /lib64/libcrypto.so.3 (0x00007f71dc800000)
        libresolv.so.2 => /lib64/libresolv.so.2 (0x00007f71dcd9d000)
        libselinux.so.1 => /lib64/libselinux.so.1 (0x00007f71dcd69000)
        /lib64/ld-linux-x86-64.so.2 (0x00007f71dd1d0000)
        libz.so.1 => /lib64/libz.so.1 (0x00007f71dc7d6000)
        libpcre2-8.so.0 => /lib64/libpcre2-8.so.0 (0x00007f71dc725000)
        libgcc_s.so.1 => /lib64/libgcc_s.so.1 (0x00007f71dc6f8000)


Note You need to log in before you can comment on or make changes to this bug.