============================ rpmlint session starts ============================ rpmlint: 2.8.0 configuration: /opt/testing/lib/python3.13/rpmlint/configdefaults.toml /opt/testing/share/rpmlint/cron-whitelist.toml /opt/testing/share/rpmlint/dbus-services.toml /opt/testing/share/rpmlint/device-files-whitelist.toml /opt/testing/share/rpmlint/licenses.toml /opt/testing/share/rpmlint/opensuse.toml /opt/testing/share/rpmlint/pam-modules.toml /opt/testing/share/rpmlint/permissions-whitelist.toml /opt/testing/share/rpmlint/pie-executables.toml /opt/testing/share/rpmlint/polkit-rules-whitelist.toml /opt/testing/share/rpmlint/scoring.toml /opt/testing/share/rpmlint/security.toml /opt/testing/share/rpmlint/sudoers-whitelist.toml /opt/testing/share/rpmlint/sysctl-whitelist.toml /opt/testing/share/rpmlint/systemd-tmpfiles.toml /opt/testing/share/rpmlint/users-groups.toml /opt/testing/share/rpmlint/world-writable-whitelist.toml /opt/testing/share/rpmlint/zypper-plugins.toml /etc/xdg/rpmlint/scoring-strict.override.toml rpmlintrc: /home/abuild/rpmbuild/SOURCES/sssd-rpmlintrc checks: 42, packages: 26 sssd.armv7hl: W: post-without-tmpfile-creation /usr/lib/tmpfiles.d/sssd.conf Please use the %tmpfiles_create macro in %post for each of your tmpfiles.d files if you expect this file or directory to be available after package installation (and before reboot). sssd.armv7hl: E: permissions-fscaps /usr/libexec/sssd/selinux_child has fscaps 'cap_setgid,cap_setuid=p' sssd.armv7hl: E: permissions-fscaps /usr/libexec/sssd/sssd_pam has fscaps 'cap_dac_read_search=p' sssd-krb5-common.armv7hl: E: permissions-fscaps /usr/libexec/sssd/krb5_child has fscaps 'cap_dac_read_search,cap_setgid,cap_setuid=p' sssd-krb5-common.armv7hl: E: permissions-fscaps /usr/libexec/sssd/ldap_child has fscaps 'cap_dac_read_search=p' Packaging file capabilities is currently not supported. Please use normal permissions instead. You may contact the security team to request an entry that sets capabilities in /usr/share/permissions/permissions instead. libipa_hbac-devel.armv7hl: E: no-binary libsss_certmap-devel.armv7hl: E: no-binary libsss_idmap-devel.armv7hl: E: no-binary libsss_nss_idmap-devel.armv7hl: E: no-binary The package should be of the noarch architecture because it doesn't contain any binaries. sssd.armv7hl: W: dir-or-file-outside-snapshot /var/lib/sss sssd.armv7hl: W: dir-or-file-outside-snapshot /var/lib/sss/db sssd.armv7hl: W: dir-or-file-outside-snapshot /var/lib/sss/gpo_cache sssd.armv7hl: W: dir-or-file-outside-snapshot /var/lib/sss/keytabs sssd.armv7hl: W: dir-or-file-outside-snapshot /var/lib/sss/mc sssd.armv7hl: W: dir-or-file-outside-snapshot /var/lib/sss/pipes sssd.armv7hl: W: dir-or-file-outside-snapshot /var/lib/sss/pipes/private sssd.armv7hl: W: dir-or-file-outside-snapshot /var/lib/sss/pubconf sssd.armv7hl: W: dir-or-file-outside-snapshot /var/log/sssd sssd-krb5-common.armv7hl: W: dir-or-file-outside-snapshot /var/lib/sss/pubconf/krb5.include.d The package contains files outside the snapshot, e.g. outside /etc and /usr or inside /usr/local. Check time report (>1% & >0.1s): Check Duration (in s) Fraction (in %) Checked files ExtractRpm 2.1 42.3 BinariesCheck 1.7 33.5 SignatureCheck 0.4 7.5 BashismsCheck 0.3 5.6 SharedLibraryPolicyCheck 0.1 2.2 TOTAL 5.0 100.0 26 packages and 0 specfiles checked; 8 errors, 11 warnings, 199 filtered, 8 badness; has taken 5.1 s