l***@poczta.onet.pl
2007-02-20 10:36:36 UTC
Hello. I have packaged thinkfinger for Fedora Extras. It has already passed the review, so users should be able to install it with yum install thinkfinger really soon. I have some suggestions as well.
1. Could you please drop a patch that removes executable permissions from pam_thinkfinger.so? It causes rpm not to strip the library, and as a result some rpmlint warnings.
2. The reviewer has suggested the following: “Would it be worth filing a RFE against pam to include the line needed in /etc/pam.d/system-auth? It should ignore it if the module isn't available I think, and will only work for users that setup a fingerprint. Perhaps something to think about when this package is more mature.”
3. I have made a quick browse through SVN and I haven't noticed that the patch for 1654013 buffer overflow is included. Please include it, for me the overflow is not only possible, it is actually happening. Patch fixes the problem. Apart from that, thinkfinger works very well in Fedora. I'm attaching the patch for your convenience (to avoid tabs/spaces pain).
Regards,
JS
1. Could you please drop a patch that removes executable permissions from pam_thinkfinger.so? It causes rpm not to strip the library, and as a result some rpmlint warnings.
2. The reviewer has suggested the following: “Would it be worth filing a RFE against pam to include the line needed in /etc/pam.d/system-auth? It should ignore it if the module isn't available I think, and will only work for users that setup a fingerprint. Perhaps something to think about when this package is more mature.”
3. I have made a quick browse through SVN and I haven't noticed that the patch for 1654013 buffer overflow is included. Please include it, for me the overflow is not only possible, it is actually happening. Patch fixes the problem. Apart from that, thinkfinger works very well in Fedora. I'm attaching the patch for your convenience (to avoid tabs/spaces pain).
Regards,
JS