https://bugzilla.redhat.com/show_bug.cgi?id=2367684
Bug ID: 2367684
Summary: matrix-synapse is missing restrictions in systemd unit
Product: Fedora
Version: 42
OS: Linux
Status: NEW
Component: matrix-synapse
Keywords: Security
Severity: medium
Assignee: V02460(a)gmail.com
Reporter: js-fedora(a)nil.im
QA Contact: extras-qa(a)fedoraproject.org
CC: djc(a)djc.id.au,
epel-packagers-sig(a)lists.fedoraproject.org,
fedora(a)alex-m.co.uk, jonathan(a)almalinux.org,
V02460(a)gmail.com
Target Milestone: ---
Classification: Fedora
Surprisingly, the systemd unit for synapse doesn't restrict any access at all.
That is quite unexpected for a daemon packaged in Fedora.
The following can probably all be added:
ReadWritePaths=/var/lib/synapse
NoNewPrivileges=yes
PrivateDevices=yes
PrivateTmp=yes
ProtectHome=yes
ProtectSystem=strict
ProtectControlGroups=true
RestrictSUIDSGID=true
RestrictRealtime=true
LockPersonality=true
ProtectKernelLogs=true
ProtectKernelTunables=true
ProtectHostname=true
ProtectKernelModules=true
PrivateUsers=true
ProtectClock=true
SystemCallArchitectures=native
SystemCallErrorNumber=EPERM
SystemCallFilter=@system-service
Reproducible: Always
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2367684
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2363017
Bug ID: 2363017
Summary: rocksdb-10.2.1 is available
Product: Fedora
Version: rawhide
Status: NEW
Component: rocksdb
Keywords: FutureFeature, Triaged
Assignee: hegjon(a)gmail.com
Reporter: upstream-release-monitoring(a)fedoraproject.org
QA Contact: extras-qa(a)fedoraproject.org
CC: davide(a)cavalca.name,
epel-packagers-sig(a)lists.fedoraproject.org,
hegjon(a)gmail.com, kkeithle(a)redhat.com,
lemenkov(a)gmail.com, mmuzila(a)redhat.com
Target Milestone: ---
Classification: Fedora
Releases retrieved: 10.2.1
Upstream release that is considered latest: 10.2.1
Current version/release in rawhide: 10.1.3-1.fc43
URL: https://github.com/facebook/rocksdb
Please consult the package updates policy before you issue an update to a
stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/
More information about the service that created this bug can be found at:
https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_M…
Please keep in mind that with any upstream change, there may also be packaging
changes that need to be made. Specifically, please remember that it is your
responsibility to review the new version to ensure that the licensing is still
correct and that no non-free or legally problematic items have been added
upstream.
Based on the information from Anitya:
https://release-monitoring.org/project/15560/
To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/rocksdb
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2363017
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2365166
Bug ID: 2365166
Summary: zbarcam-qt does not start
Product: Fedora
Version: 42
OS: Linux
Status: NEW
Component: zbar
Keywords: Desktop, Regression
Severity: medium
Assignee: gwync(a)protonmail.com
Reporter: dreua(a)posteo.de
QA Contact: extras-qa(a)fedoraproject.org
CC: dougsland(a)redhat.com,
epel-packagers-sig(a)lists.fedoraproject.org,
gwync(a)protonmail.com, mchehab(a)infradead.org,
multimedia-sig(a)lists.fedoraproject.org,
negativo17(a)gmail.com
Target Milestone: ---
Classification: Fedora
$ dnf list zbar-qt
Updating and loading repositories:
Repositories loaded.
Installed packages
zbar-qt.x86_64 0.23.93-6.fc42 fedora
Available packages
zbar-qt.i686 0.23.93-6.fc42 fedora
$ zbarcam-qt --version
QSocketNotifier: Can only be used with threads started with QThread
zbarcam_qt: Unknown option 'version'.
Reproducible: Always
Steps to Reproduce:
1. Run zbarcam-qt
Actual Results:
$ zbarcam-qt
QSocketNotifier: Can only be used with threads started with QThread
Segmentation fault (core dumped)
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2365166
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2369074
Bug ID: 2369074
Summary: znc-1.10.0-rc1 is available
Product: Fedora
Version: rawhide
Status: NEW
Component: znc
Keywords: FutureFeature, Triaged
Assignee: neil(a)shrug.pw
Reporter: upstream-release-monitoring(a)fedoraproject.org
QA Contact: extras-qa(a)fedoraproject.org
CC: davide(a)cavalca.name,
epel-packagers-sig(a)lists.fedoraproject.org,
nb(a)fedoraproject.org, neil(a)shrug.pw
Target Milestone: ---
Classification: Fedora
Releases retrieved: 1.10.0-rc1
Upstream release that is considered latest: 1.10.0-rc1
Current version/release in rawhide: 1.9.1-7.fc43
URL: https://github.com/znc/znc
Please consult the package updates policy before you issue an update to a
stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/
More information about the service that created this bug can be found at:
https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_M…
Please keep in mind that with any upstream change, there may also be packaging
changes that need to be made. Specifically, please remember that it is your
responsibility to review the new version to ensure that the licensing is still
correct and that no non-free or legally problematic items have been added
upstream.
Based on the information from Anitya:
https://release-monitoring.org/project/5305/
To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/znc
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2369074
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2279102
Bug ID: 2279102
Summary: Change upstream to
https://github.com/callowayproject/bump-my-version
Product: Fedora
Version: rawhide
Status: NEW
Component: bumpversion
Assignee: jonathan(a)almalinux.org
Reporter: awilliam(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: davide(a)cavalca.name,
epel-packagers-sig(a)lists.fedoraproject.org,
fede(a)evolware.org, jonathan(a)almalinux.org
Target Milestone: ---
Classification: Fedora
bump2version is now unmaintained and points to bump-my-version:
https://github.com/c4urself/bump2version
so we should probably switch upstreams again. only problem is they didn't
continue the versioning, so current bump-my-version is 0.21.0, lower than
1.0.1. So either we'd have to lie about the version or add an epoch.
We could package bump-my-version as a new package and have it obsolete
bumpversion, I guess, but that's more work...
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2279102
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…
https://bugzilla.redhat.com/show_bug.cgi?id=2268443
Bug ID: 2268443
Summary: Package README.md instead of an empty README
Product: Fedora
Version: rawhide
Status: NEW
Component: sdbus-cpp
Assignee: mblaha(a)redhat.com
Reporter: ppisar(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: epel-packagers-sig(a)lists.fedoraproject.org,
mblaha(a)redhat.com
Target Milestone: ---
Classification: Fedora
sdbus-cpp-1.5.0-1.fc41.x86_64 packages /usr/share/doc/sdbus-c++/README which is
useless because it only points to an unpackaged README.md:
$ cat /usr/share/doc/sdbus-c++/README
See README.md
$ cat /usr/share/doc/sdbus-c++/README.md
cat: /usr/share/doc/sdbus-c++/README.md: No such file or directory
I recommend replacing README with README.md in the package. I verified that
READM.md exists in sdbus-cpp-1.5.0.tar.gz.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2268443
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…