============================ rpmlint session starts ============================ rpmlint: 2.5.0 configuration: /opt/testing/lib64/python3.11/rpmlint/configdefaults.toml /opt/testing/share/rpmlint/cron-whitelist.toml /opt/testing/share/rpmlint/dbus-services.toml /opt/testing/share/rpmlint/device-files-whitelist.toml /opt/testing/share/rpmlint/licenses.toml /opt/testing/share/rpmlint/opensuse.toml /opt/testing/share/rpmlint/pam-modules.toml /opt/testing/share/rpmlint/permissions-whitelist.toml /opt/testing/share/rpmlint/pie-executables.toml /opt/testing/share/rpmlint/polkit-rules-whitelist.toml /opt/testing/share/rpmlint/scoring.toml /opt/testing/share/rpmlint/security.toml /opt/testing/share/rpmlint/sudoers-whitelist.toml /opt/testing/share/rpmlint/sysctl-whitelist.toml /opt/testing/share/rpmlint/systemd-tmpfiles.toml /opt/testing/share/rpmlint/users-groups.toml /opt/testing/share/rpmlint/world-writable-whitelist.toml /opt/testing/share/rpmlint/zypper-plugins.toml /etc/xdg/rpmlint/scoring-strict.override.toml checks: 41, packages: 2 rr.x86_64: W: unstripped-binary-or-object /usr/lib64/rr/librrpage.so rr.x86_64: W: unstripped-binary-or-object /usr/lib64/rr/librrpage_32.so This executable should be stripped from debugging symbols, in order to take less space and be loaded faster. This is usually done automatically at buildtime by rpm. rr.x86_64: E: statically-linked-binary /usr/bin/rr_exec_stub rr.x86_64: E: statically-linked-binary /usr/bin/rr_exec_stub_32 The package installs a statically linked binary or object file. rr.x86_64: E: script-without-shebang /usr/share/bash-completion/completions/rr This text file has executable bits set or is located in a path dedicated for executables, but lacks a shebang and cannot thus be executed. If the file is meant to be an executable script, add the shebang, otherwise remove the executable bits or move the file elsewhere. rr.x86_64: W: position-independent-executable-suggested /usr/bin/rr_exec_stub rr.x86_64: W: position-independent-executable-suggested /usr/bin/rr_exec_stub_32 This executable should be position independent (all binaries should). Check that it is built with -fPIE/-fpie in compiler flags and -pie in linker flags. rr.spec: W: no-%check-section The spec file does not contain an %check section. Please check if the package has a testsuite and what it takes to enable the testsuite as part of the package build. If it is not possible to run it in the build environment (OBS/koji) or no testsuite exists, then please ignore this warning. You should not insert an empty %check section. rr.x86_64: E: missing-call-to-setgroups-before-setuid /usr/bin/rr This executable is calling setuid and setgid without setgroups or initgroups. This means it didn't relinquish all groups, and this would be a potential security issue. rr.x86_64: E: missing-PT_GNU_STACK-section /usr/lib64/rr/librrpage.so rr.x86_64: E: missing-PT_GNU_STACK-section /usr/lib64/rr/librrpage_32.so The binary lacks a PT_GNU_STACK section. This forces the dynamic linker to make the stack executable. rr.x86_64: W: files-duplicate /usr/share/rr/64bit-pkeys.xml /usr/share/rr/32bit-pkeys.xml Your package contains duplicated files that are not hard- or symlinks. You should use the %fdupes macro to link the files to one. rr.x86_64: E: env-script-interpreter (Badness: 9) /usr/bin/signal-rr-recording.sh /usr/bin/env bash This script uses 'env' as an interpreter. For the rpm runtime dependency detection to work, the shebang #!/usr/bin/env needs to be patched into #!/usr/bin/ otherwise the package dependency generator merely adds a dependency on /usr/bin/env rather than the actual interpreter /usr/bin/. Alternatively, if the file should not be executed, then ensure that it is not marked as executable or don't install it in a path that is reserved for executables. rr.x86_64: E: devel-file-in-non-devel-package (Badness: 50) /usr/share/rr/src/preload/overrides.c rr.x86_64: E: devel-file-in-non-devel-package (Badness: 50) /usr/share/rr/src/preload/preload_interface.h rr.x86_64: E: devel-file-in-non-devel-package (Badness: 50) /usr/share/rr/src/preload/rrcalls.h rr.x86_64: E: devel-file-in-non-devel-package (Badness: 50) /usr/share/rr/src/preload/syscallbuf.c rr.x86_64: E: devel-file-in-non-devel-package (Badness: 50) /usr/share/rr/src/preload/syscallbuf.h A file that is needed only e.g. when developing or building software is included in a non-devel package. These files should go in devel packages. Check time report (>1% & >0.1s): Check Duration (in s) Fraction (in %) Checked files BinariesCheck 0.1 56.7 TOTAL 0.2 100.0 2 packages and 0 specfiles checked; 12 errors, 6 warnings, 8 filtered, 265 badness; has taken 0.2 s