Bug#940070: RFS: wolfssl/4.1.0+dfsg-1 [RC] -- wolfSSL encryption library

2019-09-12 Thread Chris Lamb
Hi Felix,

> 'license-file-needs-no-entry-in-debian-copyright'. I will send you a
> Lintian merge request with a suggestion.

Thanks. I think it is often a sign of people just blindly grepping for
"Copyright". I've even seen some d/copyright with placeholder "Acme,
Inc", "Yoyodyne, Inc." or even "FIXME"...
 
Let me know when you have a new package ready.


Regards,

-- 
  ,''`.
 : :'  : Chris Lamb
 `. `'`  la...@debian.org  chris-lamb.co.uk
   `-



Bug#940070: RFS: wolfssl/4.1.0+dfsg-1 [RC] -- wolfSSL encryption library

2019-09-12 Thread Felix Lechner
Hi Chris,

On Thu, Sep 12, 2019 at 12:19 AM Chris Lamb  wrote:
>
> Did you spot the unused-file-paragraph-in-dep5-copyright Lintian
> warning?

I could not figure out where that message came from. I adjusted the
package, which is on Mentors.

> Indeed, remarking of the copyright of the copyright notice
> itself is really superfluous and just introduces noise into debian/
> copyright IMHO.

Mentioning COPYING in d/copyright is probably superfluous, but the
current tag unfairly blames the maintainer for an error when there was
none. With 971 source packages in unstable triggering at least one tag
'unused-file-paragraph-in-dep5-copyright', I may not be alone.

I spent an hour reading up on DEP-5 and repositioning paragraphs. I
could not figure out why my package, after four years, provoked this
tag. In the end I gave up and blamed the generally poor, or perhaps
developing, specificity of DEP-5.

A more direct nudge would be better, I think, such as
'license-file-needs-no-entry-in-debian-copyright'. I will send you a
Lintian merge request with a suggestion.

As for the other tag about lack of a test suite, wolfSSL has two. One
uses the network (but could perhaps be limited to loopback) while the
other, relying on libtool, cannot test the installed version. With a
first user, having some kind of testing is on top of my list. I will
see the wolfSSL guys later today at the ST conference [1] and discuss
it with them.

> Happy to upload once this is resolved.

Thanks for uploading wolfssl.

Kind regards
Felix

[1] 
https://www.st.com/content/st_com/en/campaigns/developers-conference-2019/agenda.html



Bug#940070: RFS: wolfssl/4.1.0+dfsg-1 [RC] -- wolfSSL encryption library

2019-09-12 Thread Chris Lamb
Hi Felix,

> https://mentors.debian.net/debian/pool/main/w/wolfssl/wolfssl_4.1.0+dfsg-1.dsc

Did you spot the unused-file-paragraph-in-dep5-copyright Lintian
warning? Indeed, remarking of the copyright of the copyright notice
itself is really superfluous and just introduces noise into debian/
copyright IMHO.

Happy to upload once this is resolved.


Regards,

-- 
  ,''`.
 : :'  : Chris Lamb
 `. `'`  la...@debian.org  chris-lamb.co.uk
   `-



Bug#940070: RFS: wolfssl/4.1.0+dfsg-1 [RC] -- wolfSSL encryption library

2019-09-11 Thread Felix Lechner
Package: sponsorship-requests
Severity: important
X-Debbugs-CC: la...@debian.org

Dear mentors,

This has to go through NEW due to a bump in the shared object version.

I am looking for a sponsor for my package "wolfssl"

 * Package name: wolfssl
   Version : 4.1.0+dfsg-1
   Upstream Author : David Garske 
 * URL : https://www.wolfssl.com/products/wolfssl/
 * License : GPL-2+
 * Vcs : None
   Section : libs

It builds those binary packages:

  libwolfssl19 - wolfSSL encryption library
  libwolfssl-dev - Development files for the wolfSSL encryption library

To access further information about this package, please visit the
following URL:

  https://mentors.debian.net/package/wolfssl

Alternatively, one can download the package with dget using this command:

  dget -x 
https://mentors.debian.net/debian/pool/main/w/wolfssl/wolfssl_4.1.0+dfsg-1.dsc

Changes since the last upload:

   * In 'telegram-cli', wolfSSL may have found its first user in Debian
   * Thank you to Liu Ying-Chun  for helping with packaging
   * New upstream release
 - Fixes CVE-2019-11873
   "Buffer Overflow in DoPreSharedKeys in tls13.c"
   (Closes: #929468)
 - Fixed CVE-2018-16870 in 3.15.7
   "Bleichenbacher downgrade attack TLS"
   (Closes: #918952)
   * Bumped library major number to 19
   * Updated shared object symbols
   * Updated Debian patches
   * Bumped Standards-Version to 4.4.0
   * Bumped debhelper compat to 12, via debhelper-compat (= 12) in d/control
   * Excluded resource.h and generated html in d/copyright
   * Updated some dates in d/copyright

Regards,

--
  Felix Lechner