https://bugzilla.novell.com/show_bug.cgi?id=803642 https://bugzilla.novell.com/show_bug.cgi?id=803642#c0 Summary: security issue / scariness: init_buildsystem touches files on *host* /var/lib/rpm Classification: Internal Novell Products Product: openSUSE Build Service Version: 2.3 Platform: Other OS/Version: Other Status: NEW Severity: Critical Priority: P5 - None Component: build process AssignedTo: mls@suse.com ReportedBy: jnelson-suse@jamponi.net QAContact: adrian@suse.com Found By: --- Blocker: --- User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:18.0) Gecko/20100101 Firefox/18.0 When preparing a build, init_buildsystem touches files on the *host's* /var/lib/rpm. All invocations of rpm that do not use chroot should use the rpm flag --root. This appears to cause occasional rpm data corruption issues (for both the build and - potentially - the host). Reproducible: Sometimes Steps to Reproduce: 1. 2. 3. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.