Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-72034

[RFE] openjdk is pulling flatpak as a dependency.

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • No
    • None
    • rhel-sst-java
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None

      What were you trying to do that didn't work?

      [RFE] From RHEL 7.9 up through the current RHEL 9, if any non-headless (i.e. GUI) openjdk is installed, not only is all the X11 dependencies installed, but so is `flatpak`. If you install other select GUI packages, `flatpak` is brought in.

      Customer states that `flatpak` should never be an installation dependency, even for the X11/GUI experience.

      What is the impact of this issue to you?

      When `flatpak` is installed on a Server (which always happens when installing openjdk), any user with a bash or sftp capability can install (sideload) and run any non-privileged GUI application by leveraging its USB Export per
      https://docs.flatpak.org/en/latest/usb-drives.html

      It will live in their homedir with all necessary dependencies, along with its data.

      Please provide the package NVR for which the bug is seen:

      1. `java-1.8.0-openjdk`

      How reproducible is this bug?:

      Everytime.

      Steps to reproduce

      1. # Install java-openjdk
      2. Along with all other dependencies 'Flatpak' is also installed.

      Expected results

      By default, weak dependencies should never be installed

      flatpak should be explicitly installed – not even defined as a weak-dependency. Nothing ever has flatpak as a mandatory dependency for its operation (like shared libs are.)

      Actual results

      Flatpak is getting pulled and installed as a dependency for java-openjdk installs.

              rhn-engineering-ahughes Andrew Hughes
              rhn-support-mijjapur Murali Prudhvi Dhar Rao Ijjapureddi
              Andrew Hughes Andrew Hughes
              David Kutalek David Kutalek
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: