WelcomeWelcome | FAQFAQ | DownloadsDownloads | WikiWiki

Author Topic: hostile takeover of TCL15 x86_64 repo?  (Read 1236 times)

Offline GNUser

  • Wiki Author
  • Hero Member
  • *****
  • Posts: 1511
hostile takeover of TCL15 x86_64 repo?
« on: March 02, 2024, 08:11:55 PM »
Today when I tried to sync my mirror of the repo, I noticed that abiword-dev.tcz.tree was taking a long time to download. Turns out the file is multiple GB in size now--up from around 400 KB. I aborted the sync.

Something does not seem right. Please take a look at the repo to make sure someone malicious hasn't altered it.

Offline Rich

  • Administrator
  • Hero Member
  • *****
  • Posts: 11630
Re: hostile takeover of TCL15 x86_64 repo?
« Reply #1 on: March 02, 2024, 08:33:23 PM »
Hi GNUser
... Turns out the file is multiple GB in size now--up from around 400 KB. ...
There's a circular dependency that needs to be resolved. That's
the cause of the huge file. Only -dev extensions appear to be
affected. Juanito is looking into it.

Offline GNUser

  • Wiki Author
  • Hero Member
  • *****
  • Posts: 1511
Re: hostile takeover of TCL15 x86_64 repo?
« Reply #2 on: March 02, 2024, 08:44:05 PM »
Thanks, Rich. Glad to hear it's a known issue and not a security breach.

EDIT: When problem is resolved, would someone kindly make it known (e.g., on this thread)?
« Last Edit: March 02, 2024, 08:48:51 PM by GNUser »

Offline Rich

  • Administrator
  • Hero Member
  • *****
  • Posts: 11630
Re: hostile takeover of TCL15 x86_64 repo?
« Reply #3 on: March 02, 2024, 09:08:15 PM »
Hi GNUser
One of us will update this thread.

Offline Juanito

  • Administrator
  • Hero Member
  • *****
  • Posts: 14817
Re: hostile takeover of TCL15 x86_64 repo?
« Reply #4 on: March 03, 2024, 04:28:59 AM »
The main problem of a circular dependency between elogind and polkit is fixed, there may be some other, minor, tidying up to do.

Offline GNUser

  • Wiki Author
  • Hero Member
  • *****
  • Posts: 1511
Re: hostile takeover of TCL15 x86_64 repo?
« Reply #5 on: March 03, 2024, 06:54:08 AM »
Good to hear. Thanks for the update.

Offline hiro

  • Hero Member
  • *****
  • Posts: 1229
Re: hostile takeover of TCL15 x86_64 repo?
« Reply #6 on: March 04, 2024, 09:49:13 AM »
abiword would need elogind or polkit? for what?

Offline Rich

  • Administrator
  • Hero Member
  • *****
  • Posts: 11630
Re: hostile takeover of TCL15 x86_64 repo?
« Reply #7 on: March 04, 2024, 10:17:30 AM »
Hi hiro
According to the tree file, elogind gets pulled in by dbus as follows:
Code: [Select]
abiword.tcz->goffice.tcz->gtk3.tcz->at-spi2-core.tcz->dbus.tcz->elogind.tcz->acl.tcz->attr.tczFound here:
http://tinycorelinux.net/15.x/x86_64/tcz/abiword.tcz.tree

I don't see polkit showing up in there.