Querying and Packaging With rpm
Goal
You query and verify with rpm, and build a package yourself from a spec file and install it.
Why it matters
rpm -V is an audit tool that compares the hash at install time with the current file and tells you what has changed. It is normal for a configuration file to have changed, but if a binary has changed, you must investigate. And if you build a package yourself, you know for certain what is inside it — the strictness of rpmbuild, where a build fails if a file is not listed in %files, keeps the package contents accurate.
Steps
- Create the
/root/rpmlabdirectory and write the number of installed packages as a single numeric line in/root/rpmlab/count.txt. - Save the list of documentation files of the
coreutils-commonpackage to/root/rpmlab/docs.txt. - Write only the name of the package that owns
/usr/bin/lson one line in/root/rpmlab/owner.txt. - Pick one configuration file from the installed packages, append one line to its content, run the verification, and save the lines showing tampering to
/root/rpmlab/verify.txt. (Pick a safe file such as/etc/nanorcor/etc/DIR_COLORS.) - Query the install scripts of any installed package and save them to
/root/rpmlab/scripts.txt. If the package has no scripts, that fact is printed. - Create the
~/rpmbuildbuild tree, bundle/opt/fixtures/rpmbuild/labhub-tool-1.0intolabhub-tool-1.0.tar.gzand put it inSOURCES/, put/opt/fixtures/rpmbuild/labhub-tool.specinSPECS/, and build. An.rpmmust appear under~/rpmbuild/RPMS/noarch/. - Query the
.rpmyou built without installing it, and save the information and the file list to/root/rpmlab/pkg-info.txtand/root/rpmlab/pkg-files.txtrespectively. - Install that package and make
/root/rpmlab/report.txtwith the following 4 lines.NAME=labhub-tool/VERSION=<설치된 버전-릴리스>/ARCH=noarch/RUN=<labhub-tool 명령 실행 결과 첫 줄>(that is, the installed version-release, and the first line of the output of running the labhub-tool command)
Notes
- You create the build tree with
mkdir -p ~/rpmbuild/{SPECS,SOURCES,BUILD,BUILDROOT,RPMS,SRPMS}. - The tar takes the form
tar -czf ~/rpmbuild/SOURCES/labhub-tool-1.0.tar.gz -C /opt/fixtures/rpmbuild labhub-tool-1.0. - The build is
rpmbuild -ba ~/rpmbuild/SPECS/labhub-tool.spec. - To query an rpm that is not installed, add
-qp. - Common mistake 1: if the top-level directory name inside the tar in step 6 differs from
%{name}-%{version},%setupfails. - Common mistake 2: if you edit a binary instead of a configuration file in step 4, the system breaks. Check the configuration file list first with
rpm -qc.
Installed list and detailed information
Create the /root/rpmlab directory and write the number of installed packages as a single numeric line in /root/rpmlab/count.txt.
rpm -qa prints one per line. You only need to count them.
Distinguishing files, configuration, and documentation
Save the list of documentation files of the coreutils-common package to /root/rpmlab/docs.txt.
The three options -ql, -qc, and -qd each give a different list.
Finding the owner of a file
Write only the name of the package that owns /usr/bin/ls on one line in /root/rpmlab/owner.txt.
-qf takes a path and tells you the package. If you need only the name, cut it out.
Detecting tampering
Pick one configuration file from the installed packages, append one line to its content, run the verification, and save the lines showing tampering to /root/rpmlab/verify.txt. (Pick a safe file such as /etc/nanorc or /etc/DIR_COLORS.)
If you verify after editing a configuration file, particular characters appear. Save that line as it is.
Checking install scripts
Query the install scripts of any installed package and save them to /root/rpmlab/scripts.txt. If the package has no scripts, that fact is printed.
There is a query option that lets you see what a package runs before and after installation.
Building an rpm
Create the ~/rpmbuild build tree, bundle /opt/fixtures/rpmbuild/labhub-tool-1.0 into labhub-tool-1.0.tar.gz and put it in SOURCES/, put /opt/fixtures/rpmbuild/labhub-tool.spec in SPECS/, and build. An .rpm must appear under ~/rpmbuild/RPMS/noarch/.
Create the build tree, bundle the source into a tar and put it in SOURCES. The spec is in the fixture.
Taking the built package apart
Query the .rpm you built without installing it, and save the information and the file list to /root/rpmlab/pkg-info.txt and /root/rpmlab/pkg-files.txt respectively.
To query a file that is not installed, you need one more option.
Summary report
Install that package and make /root/rpmlab/report.txt with the following 4 lines.
NAME=labhub-tool / VERSION=<설치된 버전-릴리스> / ARCH=noarch / RUN=<labhub-tool 명령 실행 결과 첫 줄> (that is, the installed version-release, and the first line of the output of running the labhub-tool command)
Gather the information of the package you built and installed. The values must be actual query results.