/usr/lib/rpm
NameSizeModeActions
fileattrs/-0755rm
macros.d/-0755rm
platform/-0755rm
redhat/-0755rm
brp-compress15020755editdlrm
brp-java-gcjcompile14180755editdlrm
brp-python-bytecompile38680755editdlrm
brp-python-hardlink6320755editdlrm
brp-scl-compress18090755editdlrm
brp-scl-python-bytecompile31090755editdlrm
brp-strip4280755editdlrm
brp-strip-comment-note7410755editdlrm
brp-strip-shared7060755editdlrm
brp-strip-static-archive4940755editdlrm
check-buildroot12850755editdlrm
check-files10430755editdlrm
check-prereqs4180755editdlrm
check-rpaths10390755editdlrm
check-rpaths-worker50550755editdlrm
config.guess441660755editdlrm
config.sub364080755editdlrm
debugedit476880755editdlrm
debuginfo.prov3750755editdlrm
desktop-file.prov6020755editdlrm
elfdeps167680755editdlrm
find-debuginfo.sh200540755editdlrm
find-lang.sh82350755editdlrm
find-provides910755editdlrm
find-requires910755editdlrm
fontconfig.prov4890755editdlrm
kabi.sh4680755editdlrm
kmod.prov6820755editdlrm
libtooldeps.sh7180755editdlrm
macros439880644editdlrm
macros.perl4730644editdlrm
macros.php1920644editdlrm
macros.python9060644editdlrm
metainfo.prov4380755editdlrm
mkinstalldirs35390755editdlrm
mono-find-provides11070755editdlrm
mono-find-requires19160755editdlrm
ocaml-find-provides.sh16590755editdlrm
ocaml-find-requires.sh21350755editdlrm
pkgconfigdeps.sh13710755editdlrm
python-macro-helper6340644editdlrm
pythondeps.sh9210755editdlrm
pythondistdeps.py111840755editdlrm
rpm.daily2960644editdlrm
rpm.log610644editdlrm
rpm.supp6880644editdlrm
rpm2cpio.sh12490755editdlrm
rpmdb_dump169040755editdlrm
rpmdb_load292960755editdlrm
rpmdb_loadcvt14670755editdlrm
rpmdb_recover169040755editdlrm
rpmdb_stat168720755editdlrm
rpmdb_upgrade127520755editdlrm
rpmdb_verify168560755editdlrm
rpmdeps173440755editdlrm
rpmpopt-4.14.3114700644editdlrm
rpmrc171540644editdlrm
scldeps.sh2540755editdlrm
script.req3220755editdlrm
sepdebugcrcfix162320755editdlrm
tgpg9290755editdlrm
Edit: /usr/lib/rpm/check-rpaths-worker (5055B)
#! /bin/bash # Copyright (C) 2004 Enrico Scholz # # This program is free software; you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by # the Free Software Foundation; version 2 of the License. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with this program; if not, write to the Free Software # Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA fail= already_shown=0 # effect of this expression is obviously: # * match paths beginning with: # - $SOMETHING//.. # - //.. # * but not paths beginning with # - $SOMETHING/.. # - $SOMETHING/../../../..... BADNESS_EXPR_32='\(\(\$[^/]\+\)\?\(/.*\)\?/\(\([^.][^/]*\)\|\(\.[^./][^/]*\)\|\(\.\.[^/]\+\)\)\)/\.\.\(/.*\)\?$' function showHint() { test "$already_shown" -eq 0 || return already_shown=1 cat <&2 ******************************************************************************* * * WARNING: 'check-rpaths' detected a broken RPATH and will cause 'rpmbuild' * to fail. To ignore these errors, you can set the '\$QA_RPATHS' * environment variable which is a bitmask allowing the values * below. The current value of QA_RPATHS is $(printf '0x%04x' $QA_RPATHS). * * 0x0001 ... standard RPATHs (e.g. /usr/lib); such RPATHs are a minor * issue but are introducing redundant searchpaths without * providing a benefit. They can also cause errors in multilib * environments. * 0x0002 ... invalid RPATHs; these are RPATHs which are neither absolute * nor relative filenames and can therefore be a SECURITY risk * 0x0004 ... insecure RPATHs; these are relative RPATHs which are a * SECURITY risk * 0x0008 ... the special '\$ORIGIN' RPATHs are appearing after other * RPATHs; this is just a minor issue but usually unwanted * 0x0010 ... the RPATH is empty; there is no reason for such RPATHs * and they cause unneeded work while loading libraries * 0x0020 ... an RPATH references '..' of an absolute path; this will break * the functionality when the path before '..' is a symlink * * * Examples: * - to ignore standard and empty RPATHs, execute 'rpmbuild' like * \$ QA_RPATHS=\$(( 0x0001|0x0010 )) rpmbuild my-package.src.rpm * - to check existing files, set \$RPM_BUILD_ROOT and execute check-rpaths like * \$ RPM_BUILD_ROOT= /usr/lib/rpm/check-rpaths * ******************************************************************************* EOF } function msg() { local val=$1 local cmp=$2 local msg= local fail= local code test $[ $val & $cmp ] -ne 0 || return 0 code=$(printf '%04x' $cmp) if test $[ $val & ~$QA_RPATHS ] -eq 0; then msg="WARNING" else showHint msg="ERROR " fail=1 fi shift 2 echo "$msg $code: $@" >&2 test -z "$fail" } : ${QA_RPATHS:=0} old_IFS=$IFS for i; do pos=0 rpath=$(readelf -d "$i" 2>/dev/null | LANG=C grep '(RPATH).*:') || continue rpath=$(echo "$rpath" | LANG=C sed -e 's!.*(RPATH).*: \[\(.*\)\]!\1!p;d') tmp=aux:$rpath:/lib/aux || : IFS=: set -- $tmp IFS=$old_IFS shift allow_ORIGIN=1 for j; do new_allow_ORIGIN=0 if test -z "$j"; then badness=16 elif expr match "$j" "$BADNESS_EXPR_32" >/dev/null; then badness=32 else case "$j" in (/lib/*|/usr/lib/*|/usr/X11R6/lib/*|/usr/local/lib/*) badness=0;; (/lib64/*|/usr/lib64/*|/usr/X11R6/lib64/*|/usr/local/lib64/*) badness=0;; (\$ORIGIN|\$\{ORIGINX\}|\$ORIGIN/*|\$\{ORIGINX\}/*) test $allow_ORIGIN -eq 0 && badness=8 || { badness=0 new_allow_ORIGIN=1 } ;; (/*\$PLATFORM*|/*\$\{PLATFORM\}*|/*\$LIB*|/*\$\{LIB\}*) badness=0;; (/lib|/usr/lib|/usr/X11R6/lib) badness=1;; (/lib64|/usr/lib64|/usr/X11R6/lib64) badness=1;; (.*) badness=4;; (*) badness=2;; esac fi allow_ORIGIN=$new_allow_ORIGIN base=${i##$RPM_BUILD_ROOT} msg "$badness" 1 "file '$base' contains a standard rpath '$j' in [$rpath]" || fail=1 msg "$badness" 2 "file '$base' contains an invalid rpath '$j' in [$rpath]" || fail=1 msg "$badness" 4 "file '$base' contains an insecure rpath '$j' in [$rpath]" || fail=1 msg "$badness" 8 "file '$base' contains the \$ORIGIN rpath specifier at the wrong position in [$rpath]" || fail=1 msg "$badness" 16 "file '$base' contains an empty rpath in [$rpath]" || fail=1 msg "$badness" 32 "file '$base' contains an rpath referencing '..' of an absolute path [$rpath]" || fail=2 let ++pos done done test -z "$fail"