Bug 461781 - repopatch will fail if /tmp/kusu does not exist
repopatch will fail if /tmp/kusu does not exist
Product: Red Hat HPC Solution
Classification: Red Hat
Component: kusu-repoman (Show other bugs)
All Linux
high Severity high
: ---
: ---
Assigned To: OCS Support
Depends On:
  Show dependency treegraph
Reported: 2008-09-10 11:21 EDT by Daniel Riek
Modified: 2008-09-29 15:12 EDT (History)
2 users (show)

See Also:
Fixed In Version: ocs-5.1-5
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2008-09-29 15:12:16 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Daniel Riek 2008-09-10 11:21:55 EDT
Description of problem:

repopatch will fail to upgrade the repositories if the directory /tmp/kusu does nto exist. The program should check for the existence and recreate if the dir was e.g. deleted during a cleanup script.

[root@installer ~]# repopatch -r rhel5_x86_64
Getting updates for rhel-5-x86_64. This may take a while...
New kernel(s) found:
Do you wish to include them? (Yes or No): yes
Making new update kit.
Unable to add update kit. Reason: [Errno 2] No such file or directory: '/tmp/kusu/repopatch_buildkit2L1Lad'
[root@installer ~]#
Comment 1 Nils Philippsen 2008-09-11 05:51:40 EDT
The mere existence/use of a hard-coded path in /tmp sounds very ominous to me from a security standpoint. Has this already been reviewed? NB: I don't know how many packages are affected by this (if this is a problem).
Comment 2 Daniel Riek 2008-09-11 13:04:38 EDT
If I understand right, the 3rd level directory (in this case repopatch_buildkit2L1Lad) is created with a unique name for each run. It is just the higher level directory that needs to exist. For /tmp that can not be assumed as cleanup-scripts often delete such directories.
Comment 3 Nils Philippsen 2008-09-12 04:02:21 EDT
I don't know if the second level directory being random makes much difference. The first could be a symlink to somewhere else and that needs reviewing IMO.
Comment 4 Daniel Riek 2008-09-12 14:44:44 EDT
Good point. Perhaps it would be easy to just remove the second level directory: it does not add any real value, does it?
Comment 5 OCS Support 2008-09-18 11:52:36 EDT
The solution has two parts:
1. Update the kusu-core package.  It needs to be 5.1-9.  Prior to that it was using /tmp/kusu for the KUSU_TMP.  Updating this package has been verified to work.

2. The second part of the solution will be in kusu-repoman 5.1-7  and this changes the value used when KUSU_TMP is undefined.  A new srpm will be provided shortly.
Comment 6 OCS Support 2008-09-29 09:33:29 EDT
Fix passes QA

Note You need to log in before you can comment on or make changes to this bug.