https://bugzilla.redhat.com/show_bug.cgi?id=1379553
Bug ID: 1379553
Summary: perl-XML-Twig: expand_external_ents option fails to
work as documented
Product: Security Response
Component: vulnerability
Keywords: Security
Severity: medium
Priority: medium
Assignee: security-response-team(a)redhat.com
Reporter: dmoppert(a)redhat.com
CC: cweyl(a)alumni.drew.edu, jplesnik(a)redhat.com,
perl-devel(a)lists.fedoraproject.org,
perl-maint-list(a)redhat.com, ppisar(a)redhat.com,
psabata(a)redhat.com
The option to `expand_external_ents`, documented as controlling external entity
expansion in XML::Twig does not work. External entities are always expanded,
regardless of the option's setting.
Upstream bug:
https://rt.cpan.org/Public/Bug/Display.html?id=118097
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=1259386
Bug ID: 1259386
Summary: perl-XML-Merge-1.2.565EgGd-20.fc24 FTBFS: Can't
convert '1.12.B55J2qn': Invalid version format
(non-numeric data)
Product: Fedora
Version: rawhide
Component: perl-XML-Merge
Assignee: xavier(a)bachelot.org
Reporter: ppisar(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: perl-devel(a)lists.fedoraproject.org,
xavier(a)bachelot.org
perl-XML-Merge-1.2.565EgGd-20.fc24 fails to build in F24:
Executing(%build): /bin/sh -e /var/tmp/rpm-tmp.oC1E58
+ umask 022
+ cd /builddir/build/BUILD
+ cd XML-Merge-1.2.565EgGd
+ /usr/bin/perl Makefile.PL INSTALLDIRS=vendor
Can't convert '1.12.B55J2qn': Invalid version format (non-numeric data)
Checking if your kit is complete...
Looks good
error: Bad exit status from /var/tmp/rpm-tmp.oC1E58 (%build)
RPM build errors:
Bad exit status from /var/tmp/rpm-tmp.oC1E58 (%build)
Difference between working and failing build root:
perl-ExtUtils-MakeMaker 7.04-346.fc23 > 7.06-2.fc24
perl-ExtUtils-Command 1.20-346.fc23 > 7.06-2.fc24
glib2 2.45.6-1.fc24 > 2.45.7-1.fc24
python3-dnf-plugins-core 0.1.10-1.fc24 > 0.1.11-1.fc24
dnf-plugins-core 0.1.10-1.fc24 > 0.1.11-1.fc24
libgpg-error 1.19-2.fc23 > 1.20-1.fc24
gdb 7.10-15.fc24 > 7.10-16.fc24
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=1224294
Bug ID: 1224294
Summary: perl-OpenGL-0.6702-4.fc23 FTBFS: undefined symbol:
glWindowPos4dMESA
Product: Fedora
Version: rawhide
Component: perl-OpenGL
Assignee: lkundrak(a)v3.sk
Reporter: ppisar(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: filip(a)andresovi.net, lkundrak(a)v3.sk,
perl-devel(a)lists.fedoraproject.org, scenek(a)gmail.com
perl-OpenGL-0.6702-4.fc23 fails to build in F23 because tests fail on linking
with Mesa OpenGL library:
+ make test
"/usr/bin/perl" "-MExtUtils::Command::MM" "-MTest::Harness" "-e" "undef
*Test::Harness::Switches; test_harness(0, 'blib/lib', 'blib/arch')" t/*.t
# Failed test 'require OpenGL;'
# at t/00_require.t line 3.
# Tried to require 'OpenGL'.
# Error: Can't load
'/builddir/build/BUILD/OpenGL-0.6702/blib/arch/auto/OpenGL/OpenGL.so' for
module OpenGL:
/builddir/build/BUILD/OpenGL-0.6702/blib/arch/auto/OpenGL/OpenGL.so: undefined
symbol: glWindowPos4dMESA at /usr/lib64/perl5/DynaLoader.pm line 193.
# at (eval 4) line 2.
# Compilation failed in require at (eval 4) line 2.
# Looks like you failed 1 test of 1.
t/00_require.t .......
Dubious, test returned 1 (wstat 256, 0x100)
Failed 1/1 subtests
This is caused by upgrading mesa-libGL-devel from 10.6.0-0.devel.5.51e3453 to
10.6.0-0.devel.6.5a55f68.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=984185
Bug ID: 984185
Summary: perl should be a hardened build
Product: Fedora
Version: 18
Component: perl
Severity: unspecified
Priority: unspecified
Assignee: mmaslano(a)redhat.com
Reporter: h.reindl(a)thelounge.net
QA Contact: extras-qa(a)fedoraproject.org
CC: cweyl(a)alumni.drew.edu, iarnell(a)gmail.com,
jplesnik(a)redhat.com, kasal(a)ucw.cz,
mmaslano(a)redhat.com,
perl-devel(a)lists.fedoraproject.org, ppisar(a)redhat.com,
psabata(a)redhat.com, rc040203(a)freenet.de,
tcallawa(a)redhat.com
perl is often used for long running services (mailgraph, smokeping, postgrey..)
as well as called from webservers with untrusted input
so it should be "Full RELRO" and PIE
http://fedoraproject.org/wiki/Packaging:Guidelines#PIE
______________________________________________________
If your package meets any of the following criteria you MUST enable the PIE
compiler flags:
Your package is long running. This means it's likely to be started and keep
running until the machine is rebooted, not start on demand and quit on idle.
Your package has suid binaries, or binaries with capabilities.
Your package runs as root.
If your package meets the following criteria you should consider enabling the
PIE compiler flags:
Your package accepts/processes untrusted input.
______________________________________________________
[root@srv-rhsoft:~]$ checksec --file /usr/bin/perl
RELRO STACK CANARY NX PIE RPATH
RUNPATH FILE
Partial RELRO Canary found NX enabled No PIE RPATH
RUNPATH /usr/bin/perl
--
You are receiving this mail because:
You are on the CC list for the bug.
Unsubscribe from this bug https://bugzilla.redhat.com/token.cgi?t=YABEZK214w&a=cc_unsubscribe
https://bugzilla.redhat.com/show_bug.cgi?id=1373410
Bug ID: 1373410
Summary: Please port to WebKit2
Product: Fedora
Version: rawhide
Component: perl-Gtk3-WebKit
Assignee: ddick(a)cpan.org
Reporter: rhbz(a)genodeftest.de
QA Contact: extras-qa(a)fedoraproject.org
CC: ddick(a)cpan.org, perl-devel(a)lists.fedoraproject.org
Description of problem:
Currently, perl-Gtk3-WebKit is based on webkitgtk3, which is WebKit1 on Gtk3.
There are plans to remove WebKit1 from Fedora 27+ [1].
Version-Release number of selected component (if applicable):
all current versions
How reproducible:
always
Actual results:
perl-Gtk3-WebKit is compiled against webkitgtk3(-devel)
Expected results:
perl-Gtk3-WebKit should be compiled against webkitgtk4(-devel)
Additional info:
In case the API differs too much you might want to add another package, e.g.
named perl-Gtk3-WebKit2, which is compiled against webkitgtk4(-devel) and
deprecate the old one.
[1] See
https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org…
and a mass bug filing announcement on
https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org…
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=1265922
Bug ID: 1265922
Summary: amavisd and clamav dependencies
Product: Fedora EPEL
Version: epel7
Component: amavisd-new
Severity: low
Assignee: j.orti.alcaine(a)gmail.com
Reporter: sistemisti-posta(a)csi.it
QA Contact: extras-qa(a)fedoraproject.org
CC: janfrode(a)tanso.net, j.orti.alcaine(a)gmail.com,
perl-devel(a)lists.fedoraproject.org, steve(a)silug.org,
vanmeeuwen+fedora(a)kolabsys.com
Description of problem:
I have amavisd-new without local clamd server, because I configured it remotely
through instream protocol.
I very appreciate if you could leave clamav and altermime dependencies.
Version-Release number of selected component (if applicable):
amavisd-new-2.10.1-4.el7
Now I forcedly removed clamav, but it is not good:
** Found 3 pre-existing rpmdb problem(s), 'yum check' output follows:
amavisd-new-2.10.1-4.el7.noarch has missing requires of altermime
amavisd-new-2.10.1-4.el7.noarch has missing requires of clamav-server
amavisd-new-2.10.1-4.el7.noarch has missing requires of clamav-server-systemd
Thanks a lot
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=1399246
Bug ID: 1399246
Summary: wrong permission on
/usr/share/doc/perl-Mail-SPF/bin/spfquery
Product: Fedora
Version: 24
Component: perl-Mail-SPF
Severity: medium
Assignee: jpazdziora(a)redhat.com
Reporter: customercare(a)resellerdesktop.de
QA Contact: extras-qa(a)fedoraproject.org
CC: jpazdziora(a)redhat.com, nb(a)fedoraproject.org,
perl-devel(a)lists.fedoraproject.org, steve(a)silug.org
Description of problem:
/usr/share/doc/perl-Mail-SPF/bin/spfquery comes with root executeable
permissions.
If it shall be used by exim or any other non-root mailserver, it needs o+x or
g+x and a new group with exim etc.
Eitherway those "temporary" Solutions by admins get deleted with an
update/upgrade of the package.
Suggested Solution:
chmod o+x /usr/share/doc/perl-Mail-SPF/bin/spfquery
Version-Release number of selected component (if applicable):
perl-Mail-SPF-2.9.0-7.fc23.noarch
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=1331825
Bug ID: 1331825
Summary: perl-Net-Server should depend on perl-IO-Socket-INET6
Product: Fedora EPEL
Version: epel7
Component: perl-Net-Server
Assignee: lkundrak(a)v3.sk
Reporter: roy(a)karlsbakk.net
QA Contact: extras-qa(a)fedoraproject.org
CC: kevin(a)scrye.com, lkundrak(a)v3.sk,
perl-devel(a)lists.fedoraproject.org
Description of problem:
With systems like munin-node, it's unable to listen to IPv6 unless
perl-IO-Socket-INET6 is installed manually. There really isn't a good reason to
keep this out, since IPv6 is getting rather common these days
Version-Release number of selected component (if applicable):
Current RHEL/CentOS 7 as of 2016-04-29
How reproducible:
Every time
Steps to Reproduce:
1. Try to bind to IPv6 with perl-Net-Server
2.
3.
Actual results:
Fails
Expected results:
Succeeds
Additional info:
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=1268828
Bug ID: 1268828
Summary: RFE: On 32 bit platforms, enable -Duse64bitint and
maybe also -Duselongdouble
Product: Fedora
Version: rawhide
Component: perl
Assignee: jplesnik(a)redhat.com
Reporter: rjones(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: cweyl(a)alumni.drew.edu, iarnell(a)gmail.com,
jplesnik(a)redhat.com, kasal(a)ucw.cz,
perl-devel(a)lists.fedoraproject.org, ppisar(a)redhat.com,
psabata(a)redhat.com, rc040203(a)freenet.de,
tcallawa(a)redhat.com
Description of problem:
Perl on Fedora 32 bit platforms uses 32 bit ints, and on 64 bit
platforms uses 64 bit ints.
This causes some problems when we express size-in-bytes in some
programs -- it is easy for these kind of programs to work fine on
the common 64 bit platform, but to fail to work in bad ways (rounding
errors or overflows) on 32 bit. Since 32 bit is comparatively rare,
these bugs can go unnoticed. An example of a program that will fail
like this is: http://git.annexia.org/?p=import-to-ovirt.git;a=tree
Also, Debian (since Wheezy) has enabled this option, so by making
this change we would be consistent with Debian & Ubuntu.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=310995
Some pros and cons described here:
http://www.nntp.perl.org/group/perl.perl5.porters/2010/04/msg158984.html
There is also interaction with another option (-Duselongdouble).
Version-Release number of selected component (if applicable):
perl-5.22.0-350.fc24
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=1309675
Bug ID: 1309675
Summary: perl-DBD-SQLite-1.50-1.fc24 FTBFS: t/43_fts3.t test
fails
Product: Fedora
Version: rawhide
Component: perl-DBD-SQLite
Assignee: jplesnik(a)redhat.com
Reporter: ppisar(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: jplesnik(a)redhat.com, mmaslano(a)redhat.com,
perl-devel(a)lists.fedoraproject.org, ppisar(a)redhat.com,
steve(a)silug.org
perl-DBD-SQLite-1.50-1.fc24 fails to build in F24 because of rebased sqlite
that disabled ENABLE_FTS3_TOKENIZER:
t/42_primary_key_info.t ............................... ok
DBD::SQLite::db do failed: unknown tokenizer: perl at t/43_fts3.t line 87.
# Failed test 'no warnings'
# at inc/Test/NoWarnings.pm line 38.
# There were 1 warning(s)
# Previous test 1 'An object of class 'DBI::db' isa 'DBI::db''
# DBD::SQLite::db do failed: unknown tokenizer: perl at t/43_fts3.t line
87.
# at t/43_fts3.t line 87.
#
# Looks like you planned 35 tests but ran 2.
# Looks like you failed 1 test of 2 run.
# Looks like your test exited with 255 just after 2.
t/43_fts3.t ...........................................
Dubious, test returned 255 (wstat 65280, 0xff00)
Failed 34/35 subtests
Difference between working and failing build root:
sqlite-devel 3.10.2-3.fc24 > 3.11.0-1.fc24
glibc 2.22.90-35.fc24 > 2.22.90-36.fc24
sqlite 3.10.2-3.fc24 > 3.11.0-1.fc24
sqlite-libs 3.10.2-3.fc24 > 3.11.0-1.fc24
glibc-common 2.22.90-35.fc24 > 2.22.90-36.fc24
krb5-libs 1.14-20.fc24 > 1.14-21.fc24
glibc-devel 2.22.90-35.fc24 > 2.22.90-36.fc24
systemd-libs 229-1.fc24 > 229-2.fc24
gdb 7.10.90.20160211-52.fc24 > 7.10.90.20160216-54.fc24
libicu 56.1-1.fc24 > 56.1-3.fc24
kernel-headers 4.5.0-0.rc3.git3.1.... > 4.5.0-0.rc4.git0.1....
binutils 2.26-10.fc24 > 2.26-11.fc24
glibc-headers 2.22.90-35.fc24 > 2.22.90-36.fc24
lzo 2.08-6.fc24 > 2.08-7.fc24
systemd 229-1.fc24 > 229-2.fc24
gnupg2 2.1.10-4.fc24 > 2.1.11-1.fc24
python3-pyparsing 2.1.0-1.fc24 > 2.1.0-2.fc24
--
You are receiving this mail because:
You are on the CC list for the bug.