Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 546578 - sci-libs/plplot-5.11.1-r1: stable request
Summary: sci-libs/plplot-5.11.1-r1: stable request
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal QA (vote)
Assignee: Gentoo Science Related Packages
URL:
Whiteboard: WAS: Security problem NULL DT_RUNPATH...
Keywords: STABLEREQ
: 515964 572368 (view as bug list)
Depends on:
Blocks: 555460
  Show dependency tree
 
Reported: 2015-04-14 13:24 UTC by Martin Mokrejš
Modified: 2016-03-16 11:51 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Martin Mokrejš 2015-04-14 13:24:38 UTC
>>> Completed installing plplot-5.10.0-r1 into /mnt/1TB/var/tmp/portage/sci-libs/plplot-5.10.0-r1/image/

scanelf: rpath_security_checks(): Security problem NULL DT_RUNPATH in /mnt/1TB/var/tmp/portage/sci-libs/plplot-5.10.0-r1/image/usr/lib64/plplot/plplotjavac_wrap.so
Auto fixing rpaths for /mnt/1TB/var/tmp/portage/sci-libs/plplot-5.10.0-r1/image/usr/lib64/plplot/plplotjavac_wrap.so

 * QA Notice: The following files contain insecure RUNPATHs
 *  Please file a bug about this at http://bugs.gentoo.org/
 *  with the maintaining herd of the package.
 *   /mnt/1TB/var/tmp/portage/sci-libs/plplot-5.10.0-r1/image/usr/lib64/plplot/plplotjavac_wrap.so
 *
Comment 1 Martin Mokrejš 2015-04-14 13:32:29 UTC
Opened https://sourceforge.net/p/plplot/bugs/160/
Comment 2 Martin Mokrejš 2015-04-14 13:36:43 UTC
Maybe plplot-5.11.0 will be better? Makes no sense to open yet another bug report for the version bump, right? ;-)

http://sourceforge.net/p/plplot/news/2015/04/plplot-5110-has-been-released/
Comment 3 Martin Mokrejš 2015-04-14 18:07:53 UTC
Somebody please answer Alan's comment:


assigned_to: Alan W. Irwin
Group: -->
Comment:

Is the issue that you forgot to set -DUSE_RPATH=OFF as a cmake option? That option means that rpath is not set for installed libraries and executables. That option has been used for years by Debian and Fedora packagers so that might be all you need to solve the above problem.
Comment 4 Justin Lecher (RETIRED) gentoo-dev 2015-04-20 08:55:17 UTC
*** Bug 515964 has been marked as a duplicate of this bug. ***
Comment 5 Justin Lecher (RETIRED) gentoo-dev 2015-04-20 15:32:33 UTC
We are using -DUSE_RPATH=OFF for long but somehow java is no respecting it.
Comment 6 Martin Mokrejš 2016-01-19 11:33:24 UTC
Hi,
  would somebody please answer at https://sourceforge.net/p/plplot/bugs/160/ the recent activity on this issue (on behalf of Gentoo)? Thank you.
Comment 7 David Seifert gentoo-dev 2016-01-19 12:25:33 UTC
Dear Martin, I've corresponded with Alan and found the issue (it's purely a Gentoo issue). I'll push the fix this evening.
Comment 8 David Seifert gentoo-dev 2016-01-19 18:04:39 UTC
commit 86b02d33cd1e4fe22c92754467b376d9f3e76f2c
Author: David Seifert <soap@gentoo.org>
Date:   Tue Jan 19 19:03:33 2016 +0100

    sci-libs/plplot: Do not copy plplotjavac_wrap.so from BUILD_DIR
    
    Gentoo-Bug: 546578
    Instead, we use the installed .so file instead, which has
    RPATH removed by cmake and register the .so file with the
    Java environment.
Comment 9 Martin Mokrejš 2016-01-19 18:52:23 UTC
Thank you David.
Comment 10 Justin Lecher (RETIRED) gentoo-dev 2016-01-20 07:25:28 UTC
*** Bug 572368 has been marked as a duplicate of this bug. ***
Comment 11 Justin Lecher (RETIRED) gentoo-dev 2016-01-20 07:29:27 UTC
@arches, please stable

=sci-libs/plplot-5.11.1-r1
Comment 12 Justin Lecher (RETIRED) gentoo-dev 2016-01-20 07:30:45 UTC
@security, is this something which belongs into your hands?
Comment 13 Kristian Fiskerstrand (RETIRED) gentoo-dev 2016-01-20 08:30:17 UTC
(In reply to Justin Lecher from comment #12)
> @security, is this something which belongs into your hands?

From a quick glance, no, this is something that can be fixed by maintainer without security involvement. Thanks for asking :)
Comment 14 Agostino Sarubbo gentoo-dev 2016-02-01 08:16:50 UTC
amd64 stable
Comment 15 Agostino Sarubbo gentoo-dev 2016-02-14 10:25:22 UTC
x86 stable
Comment 16 Agostino Sarubbo gentoo-dev 2016-03-16 11:51:43 UTC
ppc stable. Closing.