[autobackport: sssd-2-11] Use macro rather than shell expansion for string processing in spec file#8523
Open
sssd-bot wants to merge 2 commits intoSSSD:sssd-2-11from
Open
Conversation
There was a problem hiding this comment.
Code Review
This pull request improves security by replacing a shell expansion used for string processing in the spec file with a safer RPM macro. It also adds a default value for the Samba package version, making the build more robust.
However, the PR's stated goal of rejecting shell expansions is not fully met, as other instances of shell execution remain in the spec file (e.g., for determining samba_package_version and ldb_modulesdir). My review includes a comment with a suggestion to remove the remaining shell expansion for samba_package_version by determining the version during the configure step, which would fully align with the security hardening objective.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is an automatic backport of PR#8511 Use macro rather than shell expansion for string processing in spec file to branch sssd-2-11, created by @nforro.
Please make sure this backport is correct.
Note
The commits were cherry-picked without conflicts.
You can push changes to this pull request
Original commits
f9697d4 - Use macro rather than shell expansion for string processing in spec file
caa0ec2 - Add a default for %samba_package_version
Backported commits
Original Pull Request Body
We've hardened security in Packit Service and shell expansions in spec files are now rejected as they can be used to execute arbitrary code. There is no need to use shell expansion for string processing, there is an existing macro for this very purpose.