[Bug 183089] Review Request: ularn - a text-based roguelike game

bugzilla at redhat.com bugzilla at redhat.com
Fri Mar 17 15:11:54 UTC 2006


Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug report.

Summary: Review Request: ularn - a text-based roguelike game


https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=183089





------- Additional Comments From wart at kobold.org  2006-03-17 10:11 EST -------
(In reply to comment #9)
> MUST
> ====
[...]
> * Successfully compiles and builds on at least one platform (FC-5 x86_64)
>   (lots of warnings though!)

Odd.  I don't get many warnings on FC-4, mostly a few harmless "ignoring return
value" warnings.  Must be from the new gcc.  I'll look at fixing these up after
I import the package and upgrade my desktop to FC-5.

[...] 
> MUSTFIX
> =======
> * Package should own /usr/share/ularn, just use %{_datadir}/%{name} instead
>   of the 3 seperate lines for the 3 files under this dir.

Done.

> * You currently use setegid to drop the games group, that however wont affect
> the saved gid and thus an attacker can regain these rights by a simpel
> setgid(games-gid). I've been reading a lot if setxxxgid man pages, and this is
> the solution:
[...]

Fixed.

New package, contains an updated -drop-setgid patch and 0wns %{_datadir}/ularn:

http://www.kobold.org/~wart/fedora/ularn-1.5p4-4.src.rpm
http://www.kobold.org/~wart/fedora/ularn.spec

-- 
Configure bugmail: https://bugzilla.redhat.com/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the QA contact for the bug, or are watching the QA contact.




More information about the fedora-extras-list mailing list