Bug 6309

Summary: rpm -V does not verify packages
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Mark Hatle <mark.hatle>
Component: devtools / tool chainAssignee: Mark Hatle <mark.hatle>
Status: VERIFIED FIXED QA Contact: Alexandru Georgescu <alexandru.c.georgescu>
Severity: major    
Priority: Medium+ CC: alexandru.c.georgescu, diego.sueiro, meta.mr.watcher, meta.watcher, sgw
Version: 1.5   
Target Milestone: 1.7   
Hardware: x86   
OS: Multiple   
Whiteboard: TC needed
OS type for building Yocto: --- Type of Regression: Regression (Used to work)
Verified: Documentation change: No (bug/feature does not impact docs)

Description Mark Hatle 2014-05-09 23:30:21 UTC
rpm -V <package> should validation the filesystem contents of a particular package.  This is not working properly.

Good way to test this:

rpm -V grep
<no error>

echo 'foo' >> /bin/grep.grep

rpm -V grep
S.5....T    /bin/grep.grep


(S - size, 5 - MD5SUM, T - time)
Comment 1 Mark Hatle 2014-05-09 23:34:24 UTC
This appears to be a logic issue:

lib/verify.c:

-if (!(FF_ISSET(qva->qva_fflags, GHOST) && FF_ISSET(fflags, GHOST)))
+if (!(FF_ISSET(qva->qva_fflags, GHOST)) && FF_ISSET(fflags, GHOST))


The offending line of code was found by diego.sueiro@gmail.com, and sent to the YP mailing list.
Comment 2 Mark Hatle 2014-05-12 15:36:14 UTC
I have sent the patch to the list for this item.  I believe it affects 1.6 and 1.5 as well.
Comment 3 Mark Hatle 2014-05-12 18:54:21 UTC
Fixed in master. 

commit e99a2aa28ac1b4299647e2f667380f33a2913746


Maintainers for 1.6 (daisy) and 1.5 (dora) have been asked to backport.
Comment 4 Mark Hatle 2014-06-25 00:16:28 UTC
Daisy:

commit 0fe6974b3a4bd4d4fc1d8d4398650c1313840f01


Dora:

commit 9f9bcad51381887819d58ffdde2e41307d342473
Comment 5 Alexandru Georgescu 2014-07-30 14:37:38 UTC
verified with qemux86 on 1.7_m1

root@qemux86:~# rpm --verify qt4-demos
S.5.....    /usr/bin/qt4/demos/affine/affine
S.5.....    /usr/bin/qt4/demos/books/books
S.5.....    /usr/bin/qt4/demos/boxes/boxes
S.5.....    /usr/bin/qt4/demos/browser/browser
S.5.....    /usr/bin/qt4/demos/chip/chip
S.5.....    /usr/bin/qt4/demos/composition/composition
S.5.....    /usr/bin/qt4/demos/declarative/calculator/calculator
S.5.....    /usr/bin/qt4/demos/declarative/flickr/flickr
S.5.....    /usr/bin/qt4/demos/declarative/minehunt/minehunt
S.5.....    /usr/bin/qt4/demos/declarative/photoviewer/photoviewer
S.5.....    /usr/bin/qt4/demos/declarative/rssnews/rssnews
S.5.....    /usr/bin/qt4/demos/declarative/samegame/samegame
S.5.....    /usr/bin/qt4/demos/declarative/snake/snake
S.5.....    /usr/bin/qt4/demos/declarative/twitter/twitter
S.5.....    /usr/bin/qt4/demos/declarative/webbrowser/webbrowser
S.5.....    /usr/bin/qt4/demos/deform/deform
S.5.....    /usr/bin/qt4/demos/embeddeddialogs/embeddeddialogs
S.5.....    /usr/bin/qt4/demos/glhypnotizer/glhypnotizer
S.5.....    /usr/bin/qt4/demos/gradients/gradients
S.5.....    /usr/bin/qt4/demos/interview/interview
S.5.....    /usr/bin/qt4/demos/mainwindow/mainwindow
S.5.....    /usr/bin/qt4/demos/pathstroke/pathstroke
S.5.....    /usr/bin/qt4/demos/qmediaplayer/qmediaplayer
S.5.....    /usr/bin/qt4/demos/spreadsheet/spreadsheet
S.5.....    /usr/bin/qt4/demos/sqlbrowser/sqlbrowser
S.5.....    /usr/bin/qt4/demos/sub-attaq/sub-attaq
S.5.....    /usr/bin/qt4/demos/textedit/textedit
S.5.....    /usr/bin/qt4/demos/undo/undo
S.5.....    /usr/bin/qtdemo
root@qemux86:~#
Comment 6 Mark Hatle 2014-08-06 15:23:42 UTC
Test Case is partially described in the first comment.  (That test is system 'destructive', as we intentionally damage a binary.)

Run 'rpm -V <package>' on the target and verify that the changes are properly identified.

With 'prelink' enabled, and the prelinker -not- installed on the target, expect almost all executables to return an md5sum mismatch.  If the prelinker -is- installed on the target, it will be used to verify the md5sum.
Comment 7 Alexandru Georgescu 2014-08-06 17:04:40 UTC
(In reply to comment #6)
> Test Case is partially described in the first comment.  (That test is system
> 'destructive', as we intentionally damage a binary.)
> 
> Run 'rpm -V <package>' on the target and verify that the changes are
> properly identified.
> 
> With 'prelink' enabled, and the prelinker -not- installed on the target,
> expect almost all executables to return an md5sum mismatch.  If the
> prelinker -is- installed on the target, it will be used to verify the md5sum.

Hi Mark,
Thank you for your kind explanation. I actually added TC needed into the whiteboard just so I know later that it needs a TC added.

Thanks!