Bug 701038 - tomcat user shell /sbin/nologin regression in F15
Summary: tomcat user shell /sbin/nologin regression in F15
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: tomcat6
Version: 18
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: David Knox
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-04-30 14:26 UTC by John Dennis
Modified: 2015-11-02 00:16 UTC (History)
5 users (show)

Fixed In Version: tomcat6-6.0.30-8.fc15
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2014-02-05 23:16:30 UTC
Type: ---


Attachments (Terms of Use)

Description John Dennis 2011-04-30 14:26:34 UTC
F15 lost the fix to the tomcat user shell, it was supposed to have been changed from /bin/sh to /sbin/nologin and it was in several of the different distribution spec files, but in F15 it apparently got lost.

Here is the git commit where it was supposedly fixed, but notice the fix is not in the commit, the only thing in the commit is the release number bump and the changelog comment. 

commit 0ea0a2aed3ff9af83acb6d64023a9ebd634d9888
Author: david knox <dknox@78-97-42-72.skybeam.com>
Date:   Fri Mar 4 14:12:15 2011 -0700

    In useradd, set daemon shell to nologin

diff --git a/tomcat6.spec b/tomcat6.spec
index 63f745a..b66b9e3 100644
--- a/tomcat6.spec
+++ b/tomcat6.spec
@@ -53,7 +53,7 @@
 Name:          tomcat6
 Epoch:         0
 Version:       %{major_version}.%{minor_version}.%{micro_version}
-Release:       5%{?dist}
+Release:       6%{?dist}
 Summary:       Apache Servlet/JSP Engine, RI for Servlet %{servletspec}/JSP %{jspspec} API
 
 Group:         Networking/Daemons
@@ -561,6 +561,9 @@ fi
 %{appdir}/sample
 
 %changelog
+* Fri Mar 04 2011 David Knox <dknox@redhat.com> - 0:6.0.30-6
+- In useradd, set daemon shell to nologin
+
 * Mon Feb 28 2011 David Knox <dknox@redhat.com> - 0:6.0.30-5
 - Fixes typo in tomcat6-conf.

Comment 1 Fedora Update System 2011-05-02 19:55:36 UTC
tomcat6-6.0.30-8.fc15 has been submitted as an update for Fedora 15.
https://admin.fedoraproject.org/updates/tomcat6-6.0.30-8.fc15

Comment 2 Fedora Update System 2011-05-03 04:26:26 UTC
Package tomcat6-6.0.30-8.fc15:
* should fix your issue,
* was pushed to the Fedora 15 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing tomcat6-6.0.30-8.fc15'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/tomcat6-6.0.30-8.fc15
then log in and leave karma (feedback).

Comment 3 Fedora Update System 2011-05-16 18:53:17 UTC
tomcat6-6.0.32-1.fc15 has been submitted as an update for Fedora 15.
https://admin.fedoraproject.org/updates/tomcat6-6.0.32-1.fc15

Comment 4 Joshua Roys 2011-11-02 13:19:51 UTC
http://pkgs.fedoraproject.org/gitweb/?p=tomcat6.git;a=commitdiff;h=0dbc02af3dbcc34d7977d165e35c12835cfcb139

Nitpick: this should be /sbin/nologin instead of /bin/nologin .

Comment 5 Wayne Pollock 2012-01-14 23:14:58 UTC
This bug is in Fedora 16 too:
tomcat6-6.0.32-17.fc16.noarch uses bin/nologin, not /sbin/nologin as it should.

Comment 6 Fedora End Of Life 2012-08-06 20:01:07 UTC
This message is a notice that Fedora 15 is now at end of life. Fedora 
has stopped maintaining and issuing updates for Fedora 15. It is 
Fedora's policy to close all bug reports from releases that are no 
longer maintained.  At this time, all open bugs with a Fedora 'version'
of '15' have been closed as WONTFIX.

(Please note: Our normal process is to give advanced warning of this 
occurring, but we forgot to do that. A thousand apologies.)

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, feel free to reopen 
this bug and simply change the 'version' to a later Fedora version.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we were unable to fix it before Fedora 15 reached end of life. If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora, you are encouraged to click on 
"Clone This Bug" (top right of this page) and open it against that 
version of Fedora.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events.  Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

Comment 7 Fedora End Of Life 2012-08-06 20:01:35 UTC
This message is a notice that Fedora 15 is now at end of life. Fedora 
has stopped maintaining and issuing updates for Fedora 15. It is 
Fedora's policy to close all bug reports from releases that are no 
longer maintained.  At this time, all open bugs with a Fedora 'version'
of '15' have been closed as WONTFIX.

(Please note: Our normal process is to give advanced warning of this 
occurring, but we forgot to do that. A thousand apologies.)

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, feel free to reopen 
this bug and simply change the 'version' to a later Fedora version.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we were unable to fix it before Fedora 15 reached end of life. If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora, you are encouraged to click on 
"Clone This Bug" (top right of this page) and open it against that 
version of Fedora.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events.  Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

Comment 8 David Knox 2013-03-25 16:11:05 UTC
reopening for f18

Comment 9 Fedora Update System 2013-03-29 20:26:54 UTC
tomcat6-6.0.36-2.fc18 has been submitted as an update for Fedora 18.
https://admin.fedoraproject.org/updates/tomcat6-6.0.36-2.fc18

Comment 10 Fedora End Of Life 2013-12-21 15:40:08 UTC
This message is a reminder that Fedora 18 is nearing its end of life.
Approximately 4 (four) weeks from now Fedora will stop maintaining
and issuing updates for Fedora 18. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as WONTFIX if it remains open with a Fedora 
'version' of '18'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version prior to Fedora 18's end of life.

Thank you for reporting this issue and we are sorry that we may not be 
able to fix it before Fedora 18 is end of life. If you would still like 
to see this bug fixed and are able to reproduce it against a later version 
of Fedora, you are encouraged  change the 'version' to a later Fedora 
version prior to Fedora 18's end of life.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events. Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

Comment 11 Fedora End Of Life 2014-02-05 23:16:30 UTC
Fedora 18 changed to end-of-life (EOL) status on 2014-01-14. Fedora 18 is
no longer maintained, which means that it will not receive any further
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of
Fedora please feel free to reopen this bug against that version. If you
are unable to reopen this bug, please file a new report against the
current release. If you experience problems, please add a comment to this
bug.

Thank you for reporting this bug and we are sorry it could not be fixed.


Note You need to log in before you can comment on or make changes to this bug.