Bug 1214053 - Wrong Permissions for Package xmrig-6.18.1-bp155.1.8.x86_64.rpm (Download Error)
Summary: Wrong Permissions for Package xmrig-6.18.1-bp155.1.8.x86_64.rpm (Download Error)
Status: NEW
Alias: None
Product: openSUSE Backports
Classification: openSUSE
Component: Packages (show other bugs)
Version: SLE-15-SP5
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: E-Mail List
QA Contact: E-Mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-08-08 06:19 UTC by Stephan Kreuz
Modified: 2023-08-22 11:28 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
VirusTotal check for xmrig (65.01 KB, image/png)
2023-08-11 12:07 UTC, Stephan Kreuz
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Stephan Kreuz 2023-08-08 06:19:55 UTC
Sine 07/01/23 (not sure when problem occure first Time) I get Permission denied for Package xmrig-6.18.1-bp155.1.8.x86_64.rpm from suse-packagehub-15-sp5-backports-pool-x86_64(-sap).
Please verify that the correct Permisions set for that Package.

kind regards
Stephan
Comment 1 Wolfgang Engel 2023-08-09 14:58:19 UTC
Hello Stephan, can you please copy and paste the error message here into the bug so we are able to identify the issue ?
Comment 2 Wolfgang Engel 2023-08-09 15:05:56 UTC
Ah, you mentioned Download Error in the description so it looks like you where not able to download and install the package.

On my testing system (SLES-15-SP5) I was able to install the package with "zypper in xmrig"

Can you please attach a zypper logfile (/var/log/zypper.log and /var/log/zypper/history) ?
Comment 3 Stephan Kreuz 2023-08-10 05:24:29 UTC
Hi Wolfgang,

I attach the Error Messages but I think I have to clear/change the token.

Error syncing the channel: SUSE-PackageHub-15-SP5-Backports-Pool for x86_64

Command '[/usr/bin/spacewalk-repo-sync, --channel, suse-packagehub-15-sp5-backports-pool-x86_64, --type, yum, --non-interactive]' exited with error code 1: 04:41:42 ERROR: Download failed: https://updates.suse.com/SUSE/Backports/SLE-15-SP5_x86_64/standard/rpm/x86_64_GA/xmrig-6.18.1-bp155.1.8.x86_64.rpm?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX3FXn-6ssSgLE_StpO9rlPDQxU9wetphQEZmHY1M_x5au4snRos7xSOwYhe_aCA2vEuhMJ-gM4_XS9F0-WgUDqI6npfc_QJXCJOgutQdtZAojKbpU - [Errno 14] HTTPS Error 403 - Forbidden.
04:41:42     1/1 : xmrig-6.18.1-bp155.1.8.x86_64.rpm (failed)

with Token per PM if wanted ;-)

kind regards

Stephan
Comment 4 Wolfgang Engel 2023-08-10 08:56:39 UTC
(In reply to Stephan Kreuz from comment #3)
> Hi Wolfgang,
> 
> I attach the Error Messages but I think I have to clear/change the token.
> 
> Error syncing the channel: SUSE-PackageHub-15-SP5-Backports-Pool for x86_64
> 
> Command '[/usr/bin/spacewalk-repo-sync, --channel,
> suse-packagehub-15-sp5-backports-pool-x86_64, --type, yum,
> --non-interactive]' exited with error code 1: 04:41:42 ERROR: Download
> failed:
> https://updates.suse.com/SUSE/Backports/SLE-15-SP5_x86_64/standard/rpm/
> x86_64_GA/xmrig-6.18.1-bp155.1.8.x86_64.
> rpm?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX3FXn-
> 6ssSgLE_StpO9rlPDQxU9wetphQEZmHY1M_x5au4snRos7xSOwYhe_aCA2vEuhMJ-gM4_XS9F0-
> WgUDqI6npfc_QJXCJOgutQdtZAojKbpU - [Errno 14] HTTPS Error 403 - Forbidden.
> 04:41:42     1/1 : xmrig-6.18.1-bp155.1.8.x86_64.rpm (failed)
> 
> with Token per PM if wanted ;-)
> 
> kind regards
> 
> Stephan


Hello Stephan,

I'm not able to send you a license or subscription for your SLES version. 
Please get in touch with your local IT or SUSE-Support to get one.

The package xmrig itself also can be freely downloaded from here:
https://download.opensuse.org/repositories/openSUSE:/Backports:/SLE-15-SP5/standard/x86_64/xmrig-6.18.1-bp155.1.8.x86_64.rpm

Regards,

Wolfgang
Comment 5 Stephan Kreuz 2023-08-10 09:26:28 UTC
Hi Wolfgang,

please read the Bug Description !!
I have a Download Error not an Installation Problem.

Also I have a Subscription, I can download all Packages only if I download the Package xmrig-6.18.1-bp155.1.8.x86_64.rpm, i get the Error !!

Alternative Download Links can not be set in SuSeManager for SuSe Products !

kind regards
Stephan
Comment 6 Stephan Kreuz 2023-08-11 12:07:13 UTC
Created attachment 868765 [details]
VirusTotal check  for xmrig
Comment 7 Stephan Kreuz 2023-08-11 12:09:05 UTC
Hi Wolfgang,

now it ist clear why I can`t download the Package.

Checked with VirusTotal.

Atttached Screenshot

kind regards

Stephan
Comment 8 Wolfgang Engel 2023-08-17 10:47:08 UTC
Hello Stephan,

(In reply to Stephan Kreuz from comment #7)
> Hi Wolfgang,
> 
> now it ist clear why I can`t download the Package.
> 
> Checked with VirusTotal.
> 
> Atttached Screenshot

Thank you for the update, sharing the screenshot.

I also tested download and installation using an RMT-Server and on my test system directly connected to SCC. Both worked.

I also checked the rpm with clamscan but with no results regarding an infection. My guess is that it is a false positive with your virus scanner since xmrig contains code for mining :)

Regards,

Wolfgang
Comment 9 Stephan Kreuz 2023-08-17 12:09:51 UTC
Hi Wolfgang,

thats right , our Security Gateway dropped the Package.
Im working for the Department of Defense in Germany and it is not possible to whitelist  xmrig.

So we must live with the daily Error Messages.

BTW

Why should anybody use a Crypto Miner in a Enterprise Environment ?

kind regards

Stephan
Comment 10 Wolfgang Engel 2023-08-17 14:29:45 UTC
Hi Stephan,

(In reply to Stephan Kreuz from comment #9)
> Hi Wolfgang,
> 
> thats right , our Security Gateway dropped the Package.
> Im working for the Department of Defense in Germany and it is not possible
> to whitelist  xmrig.
> 
> So we must live with the daily Error Messages.

Thanks for letting me know. 

> 
> BTW
> 
> Why should anybody use a Crypto Miner in a Enterprise Environment ?

Package Hub consists of additional community packages that we share with openSUSE Leap (we are sharing the sources and so the binaries) so there are many additional packages that are not specific to typical enterprise usage.
On the other hand it gives the freedom for the user to also use those packages on a enterprise platform. But I see your point since especially for xmrig the user base on the enteprise sector might be quite small.

Regards,

Wolfgang