https://bugzilla.redhat.com/show_bug.cgi?id=2524750

            Bug ID: 2524750
           Summary: Review Request: azure-protected-vm-secrets - Decrypts
                    host-protected secrets in Azure Confidential VMs
           Product: Fedora
           Version: 43
                OS: Linux
            Status: NEW
         Component: Package Review
          Severity: medium
          Assignee: [email protected]
          Reporter: [email protected]
        QA Contact: [email protected]
                CC: [email protected]
  Target Milestone: ---
    Classification: Fedora



Spec URL:
https://raw.githubusercontent.com/ash93jha/azure-protected-vm-secrets-review/main/azure-protected-vm-secrets.spec
SRPM URL:
https://github.com/ash93jha/azure-protected-vm-secrets-review/raw/main/azure-protected-vm-secrets-1.0.9-1.fc44.src.rpm

Description:
azure-protected-vm-secrets detects the confidential-computing environment and
decrypts host-provisioned secrets on Azure Confidential VMs (AMD SEV-SNP,
Intel TDX). The package contains the
azure-protected-secrets-tool CLI for invoking the supported operations
(is-cvm, is-secrets-provisioning-enabled, unprotect-secret,
validate-imds-metadata); the runtime shared library is in the -libs
subpackage and the C header for linking against it is in the -devel
subpackage.

Fedora Account System Username: aashishjha

Notes for the reviewer:
- Successful COPR builds (Fedora 43 + rawhide, x86_64):
  https://copr.fedorainfracloud.org/coprs/aashishjha/sspl/
- rpmlint reports 0 errors with the bundled rpmlintrc (filters spelling-error
  false-positives on domain terms and literal CLI subcommand names that must
  appear verbatim in %description); the 4 spelling errors without it are the
  standard ignorable ones.
- fedora-review / full local build: passes. rpmbuild -ba builds all
  subpackages; %check runs the GoogleTest suite (100% tests passed, 65/65);
  rpmlint 0 errors with the bundled rpmlintrc.
- Upstream is the azure-protected-vm-secrets/ subdirectory of a multi-component
  monorepo (Azure/confidential-computing-cvm-guest-attestation). Source0 uses
  the GitHub auto-archive tag tarball, re-rooted into the subdir via
  %autosetup -n (SourceURL.adoc §Git Tags pattern, extended for the subdir).
  ~52 MB whole-repo tarball (mostly a checked-in video asset).
- Mixed-use split: CLI in main pkg, runtime .so in -libs (SOVERSION 1 →
  .so/.so.1/.so.1.0.9 triplet), header + unversioned .so in -devel.
- A static .a is built for unit-test linking only and is never installed.
- %check runs the GoogleTest suite via %ctest (no TPM/hardware needed).
- License: MIT (top-level LICENSE); dead BSD-3-Clause ctypesgen bindings
removed.

Reproducible: Always


-- 
You are receiving this mail because:
You are on the CC list for the bug.
You are always notified about changes to this product and component
https://bugzilla.redhat.com/show_bug.cgi?id=2524750

Report this comment as SPAM: 
https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-spam&short_desc=Report%20of%20Bug%202524750%23c0

-- 
_______________________________________________
package-review mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to