[MIR] opal-prd

Bug #1691557 reported by Adam Conrad
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
The Ubuntu-power-systems project
Fix Released
High
Canonical Foundations Team
skiboot (Ubuntu)
Fix Released
High
Canonical Foundations Team

Bug Description

[ Availability ]
opal-prd has been in universe since xenial

[ Rationale ]
IBM is requesting opal-prd be installed by hw-detect on OpenPower systems to provide "acpid-like" functionality on OpenPower systems.

[ Security ]
I can find no CVEs relating to skiboot or opal-prd, which could mean it's perfect, but probably means it's just not been abused thoroughly by anyone yet. Given a root daemon is involved, it could probably use a quick once-over.

[ Quality ]
skiboot is maintained in Debian by Frederic Bonnard, an IBM employee, has 0 open bugs in Debian, and 0 open bugs in Ubuntu.

opal-prd installs a single daemon, asks no debconf questions, has systemd support, and comes configured correctly out of the box.

[ Dependencies ]
opal-prd has no dependencies outside main.

[ Maintenance ]
skiboot uses dh(1) style packaging, is lintian-clean, and the packaging is pretty clear and simple.

Revision history for this message
Mathieu Trudel-Lapierre (cyphermox) wrote :

As discussed, this needs a security review.

Also, it's missing a bug subscriber.

Changed in skiboot (Ubuntu):
status: New → Incomplete
assignee: nobody → Ubuntu Security Team (ubuntu-security)
Revision history for this message
Emily Ratliff (emilyr) wrote :

Would IBM be willing to provide backported patches in the event a CVE is found in this code base?

Revision history for this message
Vasant Hegde (hegdevasant) wrote :

Yes. We (IBM) will try to provide required fixes.

-Vasant

Revision history for this message
Mathieu Trudel-Lapierre (cyphermox) wrote :

There's a team subscriber now for the package; has it been acked by the security team yet?

Revision history for this message
Emily Ratliff (emilyr) wrote :

The Security Team acks this unreviewed. We reserve the right to perform a security review at a later date. We are operating under the assumptions that 1) IBM will try to provide backported security fixes (per comment #3), 2) Server/Foundations teams will perform testing of the security updates (per email discussion); 3)the opal-prd package is built only for the ppc64el architecture; 4) opal-prd operates on trusted input provided by the Power firmware.

Changed in skiboot (Ubuntu):
assignee: Ubuntu Security Team (ubuntu-security) → nobody
Manoj Iyer (manjo)
Changed in skiboot (Ubuntu):
importance: Undecided → High
Changed in ubuntu-power-systems:
importance: Undecided → High
status: New → Triaged
Revision history for this message
Andrew Cloke (andrew-cloke) wrote :

Referencing source bug for ease of navigation: https://bugs.launchpad.net/ubuntu-power-systems/+bug/1555904 .

Revision history for this message
Manoj Iyer (manjo) wrote :

comment #3 says that IBM will provide necessary patches for this bug, could you please review this bug and post any links to patches that are upstream?

Revision history for this message
Vasant Hegde (hegdevasant) wrote :

Manoj,

Comment #3 is in response to #2. In case if there is any CVE reported, then IBM will try to provide necessary fixes.

No additional patch is required to address this bug.

-Vasant

Revision history for this message
Mathieu Trudel-Lapierre (cyphermox) wrote :

I did a quick review of the package for the MIR and it looks fine to me; MIR approved.

Changed in skiboot (Ubuntu):
status: Incomplete → Fix Committed
Revision history for this message
Steve Langasek (vorlon) wrote :

Override component to main
skiboot 5.4.3-1 in artful: universe/admin -> main
1 publication overridden.
Override component to main
opal-prd 5.4.3-1 in artful ppc64el: universe/admin/optional/100% -> main
1 publication overridden.

Changed in skiboot (Ubuntu):
status: Fix Committed → Fix Released
Manoj Iyer (manjo)
Changed in ubuntu-power-systems:
status: Triaged → Fix Released
assignee: nobody → Canonical Foundations Team (canonical-foundations)
Changed in skiboot (Ubuntu):
assignee: nobody → Canonical Foundations Team (canonical-foundations)
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.