rpm -V <package> should validation the filesystem contents of a particular package. This is not working properly. Good way to test this: rpm -V grep <no error> echo 'foo' >> /bin/grep.grep rpm -V grep S.5....T /bin/grep.grep (S - size, 5 - MD5SUM, T - time)
This appears to be a logic issue: lib/verify.c: -if (!(FF_ISSET(qva->qva_fflags, GHOST) && FF_ISSET(fflags, GHOST))) +if (!(FF_ISSET(qva->qva_fflags, GHOST)) && FF_ISSET(fflags, GHOST)) The offending line of code was found by diego.sueiro@gmail.com, and sent to the YP mailing list.
I have sent the patch to the list for this item. I believe it affects 1.6 and 1.5 as well.
Fixed in master. commit e99a2aa28ac1b4299647e2f667380f33a2913746 Maintainers for 1.6 (daisy) and 1.5 (dora) have been asked to backport.
Daisy: commit 0fe6974b3a4bd4d4fc1d8d4398650c1313840f01 Dora: commit 9f9bcad51381887819d58ffdde2e41307d342473
verified with qemux86 on 1.7_m1 root@qemux86:~# rpm --verify qt4-demos S.5..... /usr/bin/qt4/demos/affine/affine S.5..... /usr/bin/qt4/demos/books/books S.5..... /usr/bin/qt4/demos/boxes/boxes S.5..... /usr/bin/qt4/demos/browser/browser S.5..... /usr/bin/qt4/demos/chip/chip S.5..... /usr/bin/qt4/demos/composition/composition S.5..... /usr/bin/qt4/demos/declarative/calculator/calculator S.5..... /usr/bin/qt4/demos/declarative/flickr/flickr S.5..... /usr/bin/qt4/demos/declarative/minehunt/minehunt S.5..... /usr/bin/qt4/demos/declarative/photoviewer/photoviewer S.5..... /usr/bin/qt4/demos/declarative/rssnews/rssnews S.5..... /usr/bin/qt4/demos/declarative/samegame/samegame S.5..... /usr/bin/qt4/demos/declarative/snake/snake S.5..... /usr/bin/qt4/demos/declarative/twitter/twitter S.5..... /usr/bin/qt4/demos/declarative/webbrowser/webbrowser S.5..... /usr/bin/qt4/demos/deform/deform S.5..... /usr/bin/qt4/demos/embeddeddialogs/embeddeddialogs S.5..... /usr/bin/qt4/demos/glhypnotizer/glhypnotizer S.5..... /usr/bin/qt4/demos/gradients/gradients S.5..... /usr/bin/qt4/demos/interview/interview S.5..... /usr/bin/qt4/demos/mainwindow/mainwindow S.5..... /usr/bin/qt4/demos/pathstroke/pathstroke S.5..... /usr/bin/qt4/demos/qmediaplayer/qmediaplayer S.5..... /usr/bin/qt4/demos/spreadsheet/spreadsheet S.5..... /usr/bin/qt4/demos/sqlbrowser/sqlbrowser S.5..... /usr/bin/qt4/demos/sub-attaq/sub-attaq S.5..... /usr/bin/qt4/demos/textedit/textedit S.5..... /usr/bin/qt4/demos/undo/undo S.5..... /usr/bin/qtdemo root@qemux86:~#
Test Case is partially described in the first comment. (That test is system 'destructive', as we intentionally damage a binary.) Run 'rpm -V <package>' on the target and verify that the changes are properly identified. With 'prelink' enabled, and the prelinker -not- installed on the target, expect almost all executables to return an md5sum mismatch. If the prelinker -is- installed on the target, it will be used to verify the md5sum.
(In reply to comment #6) > Test Case is partially described in the first comment. (That test is system > 'destructive', as we intentionally damage a binary.) > > Run 'rpm -V <package>' on the target and verify that the changes are > properly identified. > > With 'prelink' enabled, and the prelinker -not- installed on the target, > expect almost all executables to return an md5sum mismatch. If the > prelinker -is- installed on the target, it will be used to verify the md5sum. Hi Mark, Thank you for your kind explanation. I actually added TC needed into the whiteboard just so I know later that it needs a TC added. Thanks!