kpackagekit install security update in automatic mode without authorization

Bug #586497 reported by kico
68
This bug affects 11 people
Affects Status Importance Assigned to Milestone
kpackagekit (Ubuntu)
Fix Released
High
Jonathan Thomas
Lucid
Fix Released
High
Jonathan Thomas
Maverick
Fix Released
High
Jonathan Thomas

Bug Description

Binary package hint: kpackagekit

kubuntu lucid 10.04

kpackagekit installs security update in automatic mode without authorization

settings are "security update: ask for download and installation", but kpakagekit doesn't ask it and installs security update package in automatic mode.

Changed in kpackagekit (Ubuntu):
importance: Undecided → High
Revision history for this message
Scott Kitterman (kitterman) wrote :

This is actually managed by the packagekit backend, not kpackagekit. It looks like the packagekit backend is not following the apt cron stuff you set in software-properties-{kde,gtk}.

affects: kpackagekit (Ubuntu) → packagekit (Ubuntu)
Revision history for this message
Scott Kitterman (kitterman) wrote :

Marking confirmed based on it affecting multiple people.

Changed in packagekit (Ubuntu):
status: New → Confirmed
Revision history for this message
CMReigrut (chris-reigrut) wrote :

As additional information, I had my KPackageKit settings at:
Check for updates: Daily
Only notify about available updates

And it still continued to download and install. This is a critical bug, and has forced me to disable automatic update notification.

Revision history for this message
Radko Dinev (radko-dinev) wrote :

I can confirm too (using Kubuntu 10.04 Lucid LTS, KDE 4.4.4).

My settings are:
Important security updates, Recommended updates
Check for updates: Daily
Only notify about available updates

It just notified me that it is updating my system and downloaded and installed updates without any confirmation. Then notified me again that the process completed.

The only way to possibly stop it is to click the system tray icon of KPackageKit that shows during the update process, click on the topmost menu item to show the update progress window and click Cancel there to interrupt it, possibly at download stage if you are fast enough.

Revision history for this message
Scott Kitterman (kitterman) wrote :

sudo apt-get remove packagekit will do it too (that's my solution).

Changed in packagekit (Ubuntu Lucid):
status: New → Confirmed
importance: Undecided → High
milestone: none → ubuntu-10.04.1
tags: added: regression-release
Revision history for this message
Scott Kitterman (kitterman) wrote :

Happened on a second machine for me today.

Revision history for this message
Sebastian Heinlein (glatzor) wrote :

Kpackagekit is patched to use the software-properties-kde dialog instead of the packagekit preferences. furthermore the packagekit cron parts aren't shipped. So it seems that you can keep packagekit installed, Scott.

affects: packagekit (Ubuntu) → unattended-upgrades (Ubuntu)
Changed in unattended-upgrades (Ubuntu):
assignee: nobody → Jonathan Thomas (echidnaman)
Changed in unattended-upgrades (Ubuntu Lucid):
assignee: nobody → Jonathan Thomas (echidnaman)
Revision history for this message
Jonathan Riddell (jr) wrote :

This is caused by the "smart icon" in KPackageKit using the KPackageKit settings for automatic updates. Since we don't use KPackageKit settings and Apt already has its own setting and ability for automatic updates we can just remove the feature from the smart icon. This patch does so. I have uploaded to lucid-proposed awaiting approval from ubuntu-sru. Unfortunately I can't work out how to change the package for this Launchpad bug to kpackagekit.

Revision history for this message
Jonathan Riddell (jr) wrote :

TEST CASE
Run Kubuntu for a few days and note that security updates are automatically installed.

Install the new package, run Kubuntu for a few days and note that they aren't.

affects: unattended-upgrades (Ubuntu Lucid) → kpackagekit (Ubuntu Lucid)
Revision history for this message
Colin Watson (cjwatson) wrote : Please test proposed package

Accepted kpackagekit into lucid-proposed, the package will build now and be available in a few hours. Please test and give feedback here. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation how to enable and use -proposed. Thank you in advance!

Changed in kpackagekit (Ubuntu Lucid):
status: Confirmed → Fix Committed
tags: added: verification-needed
Revision history for this message
Colin Watson (cjwatson) wrote :

(Please make sure this SRU patch gets into maverick too.)

Revision history for this message
Scott Kitterman (kitterman) wrote :

It works correctly now. In addition to the test case for the regression, I also manually enabled automatic security updates and verified that those still work when the user has enabled them.

tags: added: verification-done
removed: verification-needed
Revision history for this message
Martin Pitt (pitti) wrote :

Accepted 0.5.4-0ubuntu4.3 which should fix the FTBFS. Please test.

tags: added: verification-needed
removed: verification-done
Revision history for this message
Clay Weber (claydoh) wrote :

This has fixed the issue for me.

Revision history for this message
Scott Kitterman (kitterman) wrote :

Works for me too.

tags: added: verification-done
removed: verification-needed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package kpackagekit - 0.5.4-0ubuntu4.3

---------------
kpackagekit (0.5.4-0ubuntu4.3) lucid-proposed; urgency=low

  * Fix patch kubuntu_06_no_automatic_updates.diff to make it apply
    Closes LP: #586497
 -- Jonathan Riddell <email address hidden> Wed, 23 Jun 2010 10:58:50 +0100

Changed in kpackagekit (Ubuntu Lucid):
status: Fix Committed → Fix Released
Revision history for this message
Martin Pitt (pitti) wrote :

Can we please get this fixed in maverick ASAP, too? Thanks.

Changed in kpackagekit (Ubuntu Maverick):
milestone: none → maverick-alpha-3
status: Confirmed → In Progress
Revision history for this message
Dominic Ong (ong-dominic) wrote :

Version 0.5.4-0ubuntu4.3:

  * Fix patch kubuntu_06_no_automatic_updates.diff to make it apply
    Closes LP: #586497

Version 0.5.4-0ubuntu4.2:

  * Add kubuntu_06_no_automatic_updates.diff, don't run automatic
    install updates from KPackageKit settings. Apt already has its
    own settings and ability to do this. Closes LP: #586497

Revision history for this message
Martin Pitt (pitti) wrote :

Fixed in maverick in 0.6.0-0ubuntu1.

Changed in kpackagekit (Ubuntu Maverick):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.