[Bug 770040] New: gnome-java-bridge.jar has wrong permissions
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c0 Summary: gnome-java-bridge.jar has wrong permissions Classification: openSUSE Product: openSUSE 12.1 Version: Final Platform: x86-64 OS/Version: openSUSE 12.1 Status: NEW Severity: Normal Priority: P5 - None Component: Java AssignedTo: bnc-team-java@forge.provo.novell.com ReportedBy: R.Vickers@cs.rhul.ac.uk QAContact: qa-bugs@suse.de Found By: --- Blocker: --- User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5 The file /usr/lib64/jvm/java-1.6.0-openjdk-1.6.0/jre/lib/ext/gnome-java-bridge.jar is not readable by anybody except root...persumably this is not intentional? This problem occurs in the package java-1_6_0-openjdk-1.6.0.0_b24.1.11.3-6.2.x86_64 but does not happen with java-1_6_0-openjdk-1.6.0.0_b24.1.11.1-3.1.x86_64 For some reason some of my 12.1 machines have the good one whilst some have the other. The problem also occurs with java-1_6_0-openjdk-1.6.0.0_b24.1.11.3-0.11.2.x86_64 under opensuse 11.4 Reproducible: Always Steps to Reproduce: 1. ls -l /usr/lib64/jvm/java-1.6.0-openjdk-1.6.0/jre/lib/ext/gnome-java-bridge.jar Actual Results: -rw------- 1 root root 449000 Jun 19 23:24 /usr/lib64/jvm/java-1.6.0-openjdk-1.6.0/jre/lib/ext/gnome-java-bridge.jar Expected Results: -rw-r--r-- 1 root root 449000 Jun 19 23:24 /usr/lib64/jvm/java-1.6.0-openjdk-1.6.0/jre/lib/ext/gnome-java-bridge.jar -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c1 Henry Laurent <laurent.henry@ehess.fr> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |laurent.henry@ehess.fr --- Comment #1 from Henry Laurent <laurent.henry@ehess.fr> 2012-07-06 12:52:00 UTC --- hi, i am getting the same just after my weekly online update too juste today. This made my tomcat jam: GRAVE: Failure loading extension /usr/lib64/jvm/java-1.6.0-openjdk-1.6.0/jre/lib/ext/gnome-java-bridge.jar java.io.FileNotFoundException: /usr/lib64/jvm/java-1.6.0-openjdk-1.6.0/jre/lib/ext/gnome-java-bridge.jar (Permission denied) at java.io.FileInputStream.open(Native Method) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c2 Foolish Ewe <foolishewe@hotmail.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |foolishewe@hotmail.com --- Comment #2 from Foolish Ewe <foolishewe@hotmail.com> 2012-07-08 19:27:32 UTC --- I also see that in with in the current install (i.e. Tumbleweed). -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c3 Michal Vyskocil <mvyskocil@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |NEEDINFO CC| |mvyskocil@suse.com InfoProvider| |meissner@suse.com --- Comment #3 from Michal Vyskocil <mvyskocil@suse.com> 2012-07-12 12:39:05 UTC --- That's quite unfortunate - please type chmod 0644 /usr/lib64/jvm/java-1.6.0-openjdk-1.6.0/jre/lib/ext/gnome-java-bridge.jar as a root as a workaround. I doubt we will release any new maintenance update of openjdk6 in the future. @marcus I think about some workaround. For instance package openjdk6-perms, which will have Supplements: java-1_6_0-openjdk and do the chmod in %pre. Do you think it will work with our update stack? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c4 Marcus Meissner <meissner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |NEW CC| |meissner@suse.com InfoProvider|meissner@suse.com | --- Comment #4 from Marcus Meissner <meissner@suse.com> 2012-07-12 14:31:32 UTC --- why cant we just update java-1_6_0-openjdk again and fix this? this wpould be better than adding a new package just for this. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c5 --- Comment #5 from Javier Llorente <javier@opensuse.org> 2012-08-19 18:11:01 UTC --- This also affects Eclipse: Archive for required library: '/usr/lib64/jvm/java-1.6.0-openjdk-1.6.0/jre/lib/ext/gnome-java-bridge.jar' in project 'Pío-pío' cannot be read or is not a valid ZIP file -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c6 Michal Vyskocil <mvyskocil@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |NEEDINFO InfoProvider| |meissner@suse.com --- Comment #6 from Michal Vyskocil <mvyskocil@suse.com> 2012-08-20 07:54:16 UTC --- (In reply to comment #4)
why cant we just update java-1_6_0-openjdk again and fix this?
this wpould be better than adding a new package just for this.
The problem is openjdk needs openjdk6 for build and this is not fixable from %prep, or %build phase of rpm. What have worked for me is to have a package openjdk6-perms, which did the fix in %prep, because that code runs as a root. If there is some other solution (temporary allow buildforroot?), please share it. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c7 --- Comment #7 from Marcus Meissner <meissner@suse.com> 2012-08-20 08:15:57 UTC --- so this is an issue with 12.1 updates? I thought only for factory? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c8 --- Comment #8 from Michal Vyskocil <mvyskocil@suse.com> 2012-08-20 08:52:05 UTC --- factory do not have openjdk6, so only released distros are affected -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c9 --- Comment #9 from Marcus Meissner <meissner@suse.com> 2012-08-20 08:59:01 UTC --- for 11.4 and 12.1 i can untangle this with an online update. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c10 Marcus Meissner <meissner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |NEW InfoProvider|meissner@suse.com | --- Comment #10 from Marcus Meissner <meissner@suse.com> 2012-08-20 13:00:03 UTC --- openSUSE:Maintenance:796 has a fixed package which will be released in a week (7 days of waiting-qa) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c Swamp Workflow Management <swamp@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard| |obs:running:860:critical -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c Swamp Workflow Management <swamp@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard|obs:running:860:critical | -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c11 --- Comment #11 from Swamp Workflow Management <swamp@suse.de> 2012-09-12 17:08:47 UTC --- openSUSE-SU-2012:1154-1: An update that fixes four vulnerabilities is now available. Category: security (critical) Bug References: 770040,777499 CVE References: CVE-2012-0547,CVE-2012-1682,CVE-2012-3136,CVE-2012-4681 Sources used: openSUSE 12.2 (src): java-1_7_0-openjdk-1.7.0.6-3.12.1 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c12 --- Comment #12 from Bernhard Wiedemann <bwiedemann@suse.com> 2012-09-20 11:00:40 CEST --- This is an autogenerated message for OBS integration: This bug (770040) was mentioned in https://build.opensuse.org/request/show/135110 Evergreen:11.2 / java-1_6_0-openjdk -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c13 --- Comment #13 from Bernhard Wiedemann <bwiedemann@suse.com> 2012-09-21 14:00:13 CEST --- This is an autogenerated message for OBS integration: This bug (770040) was mentioned in https://build.opensuse.org/request/show/135243 Evergreen:11.2 / java-1_6_0-openjdk -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=770040 https://bugzilla.novell.com/show_bug.cgi?id=770040#c14 Michal Vyskocil <mvyskocil@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution| |FIXED --- Comment #14 from Michal Vyskocil <mvyskocil@suse.com> 2012-10-29 12:22:15 UTC --- already released -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com