Bug#823190: lintian: Please error out on orig tarball sigs for source 1.0

2018-01-29 Thread Mattia Rizzolo
On Mon, Jan 29, 2018 at 09:01:48PM +0100, Mattia Rizzolo wrote:
> Since 1.18.something dpkg can handle unpacking of 1.18.15, and since
> dpkg 1.19.0 it also creates them.  yes it was a issue back then but now
> it's correctly handled, and dak accepts them since last week.

More info in this ftp.debian.org's bug: https://bugs.debian.org/888448

-- 
regards,
Mattia Rizzolo

GPG Key: 66AE 2B4A FCCF 3F52 DA18  4D18 4B04 3FCD B944 4540  .''`.
more about me:  https://mapreri.org : :'  :
Launchpad user: https://launchpad.net/~mapreri  `. `'`
Debian QA page: https://qa.debian.org/developer.php?login=mattia  `-


signature.asc
Description: PGP signature


Bug#823190: lintian: Please error out on orig tarball sigs for source 1.0

2018-01-29 Thread Mattia Rizzolo
On Tue, Jan 30, 2018 at 12:45:56AM +0530, Chris Lamb wrote:
> tags 823190 + pending
> thanks
> 
> Fixed in Git, pending upload:

Errr, no.

Since 1.18.something dpkg can handle unpacking of 1.18.15, and since
dpkg 1.19.0 it also creates them.  yes it was a issue back then but now
it's correctly handled, and dak accepts them since last week.

>   
> https://anonscm.debian.org/git/lintian/lintian.git/commit/?id=2f1efb44994b066c22a985c09a853fc9583aacf8

Please revert this commit and close this bug as no action needed
anymore.

-- 
regards,
Mattia Rizzolo

GPG Key: 66AE 2B4A FCCF 3F52 DA18  4D18 4B04 3FCD B944 4540  .''`.
more about me:  https://mapreri.org : :'  :
Launchpad user: https://launchpad.net/~mapreri  `. `'`
Debian QA page: https://qa.debian.org/developer.php?login=mattia  `-


signature.asc
Description: PGP signature


Bug#823190: lintian: Please error out on orig tarball sigs for source 1.0

2018-01-29 Thread Chris Lamb
tags 823190 + pending
thanks

Fixed in Git, pending upload:

  
https://anonscm.debian.org/git/lintian/lintian.git/commit/?id=2f1efb44994b066c22a985c09a853fc9583aacf8


Regards,

-- 
  ,''`.
 : :'  : Chris Lamb
 `. `'`  la...@debian.org / chris-lamb.co.uk
   `-



Bug#823190: lintian: Please error out on orig tarball sigs for source 1.0

2017-07-13 Thread Chris Lamb
Hi Guillem,

> […]

Thanks for the explanation :)

> The report would still make sense for anything targetting a stable
> release though, so it perhaps still has some merit?

I'll leave the question of closing it up to you but I'll at least bump
this bug down my own "priority" list.

Thanks again. o/


Regards,

-- 
  ,''`.
 : :'  : Chris Lamb, Debian Project Leader
 `. `'`  la...@debian.org / chris-lamb.co.uk
   `-



Bug#823190: lintian: Please error out on orig tarball sigs for source 1.0

2017-07-12 Thread Mattia Rizzolo
On Thu, Jul 13, 2017 at 01:17:05AM +0200, Guillem Jover wrote:
> But at this point I'm not sure if the report makes sense anymore, as
> I might as well enable signatures for format 1.0, given that stable
> supports unpacking those now. Thanks for the "accidental" reminder. :)

Except that IIRC the problem was about ftp-master, that TTBOMK is still
not updated to stretch.  You probably should check with ftp-masters/DSA
before proposing such change again.
Or wait another release to have the support propagate even further (as
at that point only uploads targeting oldstable and LTS would matter).

-- 
regards,
Mattia Rizzolo

GPG Key: 66AE 2B4A FCCF 3F52 DA18  4D18 4B04 3FCD B944 4540  .''`.
more about me:  https://mapreri.org : :'  :
Launchpad user: https://launchpad.net/~mapreri  `. `'`
Debian QA page: https://qa.debian.org/developer.php?login=mattia  `-


signature.asc
Description: PGP signature


Bug#823190: lintian: Please error out on orig tarball sigs for source 1.0

2017-07-12 Thread Guillem Jover
Hi!

On Wed, 2017-07-12 at 23:00:44 +0100, Chris Lamb wrote:
> > It would be nice if lintian could error out when finding an orig
> > tarball signature on source format 1.0 packages.
> >
> > The pattern for the signature is «.orig.tar.gz.asc».
> 
> Where are these files stored? Am I confusing this with
> debian/upstream-signing-key.asc … ?

They are part of the source package, referenced by the .dsc. You can
see existing instances of this in the archive, such as:

  $ apt-cache showsrc libbsd | grep '\.asc$'

But at this point I'm not sure if the report makes sense anymore, as
I might as well enable signatures for format 1.0, given that stable
supports unpacking those now. Thanks for the "accidental" reminder. :)

The report would still make sense for anything targetting a stable
release though, so it perhaps still has some merit? Otherwise it can
be closed.

Thanks,
Guillem



Bug#823190: lintian: Please error out on orig tarball sigs for source 1.0

2017-07-12 Thread Chris Lamb
Hi Guillem,

> It would be nice if lintian could error out when finding an orig
> tarball signature on source format 1.0 packages.
>
> The pattern for the signature is «.orig.tar.gz.asc».

Where are these files stored? Am I confusing this with
debian/upstream-signing-key.asc … ?


Regards,

-- 
  ,''`.
 : :'  : Chris Lamb, Debian Project Leader
 `. `'`  la...@debian.org / chris-lamb.co.uk
   `-



Bug#823190: lintian: Please error out on orig tarball sigs for source 1.0

2016-05-01 Thread Guillem Jover
Package: lintian
Version: 2.5.44
Severity: wishlist

Hi!

With dpkg 1.18.5, orig tarball signatures for format 1.0 will be
accepted for extraction and building, which means stable systems will
not be able to extract them. Extraction of orig taball signatures for
format >= 2.0 have been accepted since dpkg 1.17.20, so these are
safe to use.

It would be nice if lintian could error out when finding an orig
tarball signature on source format 1.0 packages.

The pattern for the signature is «.orig.tar.gz.asc».

Thanks,
Guillem