hello, could you please revoke watchcommits rights for packaging-team for components 'hawkey' and 'dnf'? it's sending undeliverable mails around when I push to fedpkg.
This user (packaging-team) is the owner of the packages, and thus cannot be revoked watchcommits.
The email address is an redhat controlled mailing list.
We could either change the email address in FAS of the account, ask RH to make the mailing list available again, or just ignore the bounces.
So, looking on the other side of the firewall, there is no ml by that name. The only thing that would be a candidate is a internal ml with a slightly different name and things are like this since more than 1 year.
I think this was a error when the account was created, and FAS should be changed, or the external account should be created.
The first one would be done by Fedora admin, the 2nd one should be seen with RH IT.
misc, there definitely is a ml by that name, we just don't let it be listed. If watchcommits can not be disabled for the owner please do not make any changes.
Could we get a password reset for the packaging-team FAS account so the team can manage these things ourselves?
Here's the real problem with the emails sent as watchcommits: their 'From' field is a nonexistent address derived from the name of the committing FAS account. For instance when I push to the 'hawkey' component, an email is sent to packaging-team-maint@redhat.com (the component owner) with 'From:' field set to 'akozumpl@fedoraproject.org'. I have never used this address, don't have access to the inbox. Moreover: we should not simply add 'akozumpl@fedoraproject.org' as a subscriber of the ML, because if this account actually exists it can not be trusted with RH-internal stuff the ML receives.
Ah,
actually I can add addresses allowed to post without making them subscribers. This could be the solution.
I'd still like the FAS password to packaging-team user reset please.
Bot accounts purposefully do not have a password so that no one can log into them. This is a security measure for accounts which never expire and that could potentially go for a long period without someone noticing that they have been compromised.
Is there anything further we can do here?
Please re-open if you need anything else.