Making Fedora secure - Package exit policy for security

2018-07-30 Thread Huzaifa Sidhpurwala
Hi All, I was asked to bring this issue[1] to the developer community before FESCO makes a decision. In several instances[2] there exists packages in Fedora, in which package-maintainers did not patch security issues, for multiple reasons including 1. non-responsive maintainer 2. issue hard to

[Bug 1610065] New: perl-HTTP-Tiny-0.074 is available

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1610065 Bug ID: 1610065 Summary: perl-HTTP-Tiny-0.074 is available Product: Fedora Version: rawhide Component: perl-HTTP-Tiny Keywords: FutureFeature, Triaged Assignee:

Re: Intent to retire python-svg

2018-07-30 Thread Robert Brown
Julien, I'd be happy to take some ownership. Any info? Thanks On Mon, Jul 30, 2018, 4:15 PM Julien Enselme wrote: > Hi all, > > I intend to retire python-svg. Tests are failing on Python 3.7 for a > reason I cannot figure, there was no commit during the last year and > according to

[Fedocal] Reminder meeting : Modularity Office Hours

2018-07-30 Thread nils
Dear all, You are kindly invited to the meeting: Modularity Office Hours on 2018-07-31 from 10:00:00 to 11:00:00 US/Eastern At fedora-modular...@chat.freenode.net The meeting will be about: This is where you ask the Fedora Modularity Team questions (and we try to answer them)! Join us on

Re: dokuwiki packagers unresponsive

2018-07-30 Thread Sérgio Basto
On Mon, 2018-07-30 at 23:07 +0200, Peter 'Pessoft' Kolínek wrote: > On 2018-07-27 17:08, Matthias Runge wrote: > > On Fri, Jul 27, 2018 at 02:51:25AM +0100, Sérgio Basto wrote: > > > On Thu, 2018-07-26 at 21:43 -0400, Solomon Peachy wrote: > > > > On Thu, Jul 26, 2018 at 09:09:25PM +0200, Peter

Re: dokuwiki packagers unresponsive

2018-07-30 Thread Peter 'Pessoft' Kolínek
On 2018-07-27 17:08, Matthias Runge wrote: On Fri, Jul 27, 2018 at 02:51:25AM +0100, Sérgio Basto wrote: On Thu, 2018-07-26 at 21:43 -0400, Solomon Peachy wrote: > On Thu, Jul 26, 2018 at 09:09:25PM +0200, Peter 'Pessoft' Kolínek > wrote: > > I'd like to fix some issues (including security

Fedora testing-20180730.0 compose check report

2018-07-30 Thread Fedora compose checker
No missing expected images. Passed openQA tests: 2/2 (x86_64) -- Mail generated by check-compose: https://pagure.io/fedora-qa/check-compose ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to

[Bug 1609256] perl-CPAN-Perl-Releases-3.72 is available

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1609256 --- Comment #4 from Fedora Update System --- perl-CPAN-Perl-Releases-3.72-1.fc28 has been pushed to the Fedora 28 testing repository. If problems still persist, please make note of it in this bug report. See

[Bug 1606925] perl-CPAN-Perl-Releases-3.70 is available

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1606925 --- Comment #8 from Fedora Update System --- perl-CPAN-Perl-Releases-3.72-1.fc28 has been pushed to the Fedora 28 testing repository. If problems still persist, please make note of it in this bug report. See

Intent to retire python-svg

2018-07-30 Thread Julien Enselme
Hi all, I intend to retire python-svg. Tests are failing on Python 3.7 for a reason I cannot figure, there was no commit during the last year and according to `repoquery --whatrequires python2-svgwrite` and `repoquery --whatrequires python3-svgwrite` nothing uses it anymore. If you want to

[Bug 1609221] License 'public domain' is not valid

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1609221 --- Comment #5 from Tom "spot" Callaway --- (In reply to Dave Olsthoorn from comment #4) > Maybe the confusion is because of this: > https://metacpan.org/changes/distribution/DBIx-Simple#L26 > > It seems the versions after 1.32 are not

[Bug 1609221] License 'public domain' is not valid

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1609221 --- Comment #4 from Dave Olsthoorn --- Maybe the confusion is because of this: https://metacpan.org/changes/distribution/DBIx-Simple#L26 It seems the versions after 1.32 are not released into the public domain anymore, but released under

[Bug 1609221] License 'public domain' is not valid

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1609221 Tom "spot" Callaway changed: What|Removed |Added Status|CLOSED |ASSIGNED

Fedora Rawhide-20180730.n.0 compose check report

2018-07-30 Thread Fedora compose checker
No missing expected images. Failed openQA tests: 10/138 (x86_64), 23/24 (i386), 1/2 (arm) New failures (same test did not fail in Rawhide-20180729.n.0): ID: 261800 Test: x86_64 universal install_scsi_updates_img URL: https://openqa.fedoraproject.org/tests/261800 ID: 261802 Test:

Fedora updates-20180730.1 compose check report

2018-07-30 Thread Fedora compose checker
No missing expected images. Passed openQA tests: 2/2 (x86_64) Installed system changes in test x86_64 AtomicHost-dvd_ostree-iso install_default: System load changed from 0.07 to 0.38 Previous test data: https://openqa.fedoraproject.org/tests/261624#downloads Current test data:

[Bug 1609221] License 'public domain' is not valid

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1609221 --- Comment #2 from Dave Olsthoorn --- Okay, but how does this work qualify as "Public Domain"? There is a license text that mentions any OSI approved license is valid, not that it was released to the public domain:

[EPEL-devel] Fedora EPEL 7 updates-testing report

2018-07-30 Thread updates
The following Fedora EPEL 7 Security updates need testing: Age URL 50 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-3835d39d1a unrtf-0.21.9-8.el7 45 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-15b7dc35af pass-1.7.2-1.el7 26

Re: Guideline change: glibc malloc as the C/C++/Rust allocator

2018-07-30 Thread Andrew Lutomirski
On Jul 27, 2018, at 9:58 AM, Owen Taylor wrote: On Fri, Jul 27, 2018 at 9:44 AM, Florian Weimer wrote: > On 07/27/2018 03:33 PM, John Reiser wrote:The key principle is that > sizeof(foo) must be the stride of an array of foo, > > and the array must guarantee alignment of each element in the

Re: F28: Mismatch between the program and library build versions detected, gcc-c++, wxGTK3

2018-07-30 Thread Jonathan Wakely
On 25/07/18 13:25 -0400, Scott Talbert wrote: On Wed, 25 Jul 2018, Wolfgang Stoeggl wrote: Hello, a recent F28 update build of poedit [1] shows the following message after starting: Warning: Mismatch between the program and library build versions detected. The library used 3.0

Re: Guideline change: glibc malloc as the C/C++/Rust allocator

2018-07-30 Thread R P Herrold
On Mon, 30 Jul 2018, Jonathan Wakely wrote: > On 26/07/18 12:45 -0400, R P Herrold wrote: > > The use here of 'interpose' is unclear to me -- are you saying > > 'substitute a different' ? > > The usual way to replace 'malloc' is via ELF symbol interposition: >

Re: Guideline change: glibc malloc as the C/C++/Rust allocator

2018-07-30 Thread Jonathan Wakely
On 26/07/18 22:34 +0200, Florian Weimer wrote: http://www.erahm.org/2016/03/24/minimum-alignment-of-allocation-across-platforms/ Oh dear, this is worrying. I'm adding more places in libstdc++ where the std::lib assumes that memory obtained from malloc will always be aligned to

Re: [atomic-devel] Starting a Container SIG

2018-07-30 Thread Clement Verna
On Mon, 30 Jul 2018 at 17:59, Giuseppe Scrivano wrote: > > I'm also interested. > > Regards, > Giuseppe > > > Jeff Ligon writes: > > > I too would like to be a part of this but I’m not sure how much I’d be able > > to help. > > > > On Fri, Jul 27, 2018 at 1:29 PM Owen Taylor wrote: > > > >

[Bug 1609256] perl-CPAN-Perl-Releases-3.72 is available

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1609256 Fedora Update System changed: What|Removed |Added Status|MODIFIED|ON_QA --- Comment #3 from

[Bug 1606925] perl-CPAN-Perl-Releases-3.70 is available

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1606925 --- Comment #7 from Fedora Update System --- perl-CPAN-Perl-Releases-3.72-1.fc27 has been pushed to the Fedora 27 testing repository. If problems still persist, please make note of it in this bug report. See

[Bug 1609221] License 'public domain' is not valid

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1609221 Tom "spot" Callaway changed: What|Removed |Added Status|NEW |CLOSED CC|

Re: Guideline change: glibc malloc as the C/C++/Rust allocator

2018-07-30 Thread Jonathan Wakely
On 26/07/18 12:45 -0400, R P Herrold wrote: On Thu, 26 Jul 2018, Florian Weimer wrote: I would like to request a change of the Packaging Guidelines, advising packagers not to interpose malloc. The use here of 'interpose' is unclear to me -- are you saying 'substitute a different' ? The

Fedora rawhide compose report: 20180730.n.0 changes

2018-07-30 Thread Fedora Rawhide Report
OLD: Fedora-Rawhide-20180729.n.0 NEW: Fedora-Rawhide-20180730.n.0 = SUMMARY = Added images:0 Dropped images: 0 Added packages: 1 Dropped packages:4 Upgraded packages: 268 Downgraded packages: 0 Size of added packages: 20.33 MiB Size of dropped packages

Summary/Minutes from today's FESCo Meeting (2018-07-30)

2018-07-30 Thread Petr Šabata
= #fedora-meeting-1: FESCO (2018-07-30) = Meeting started by contyk at 15:00:01 UTC. The full logs are available at https://meetbot.fedoraproject.org/fedora-meeting-1/2018-07-30/fesco.2018-07-30-15.00.log.html . Meeting

Re: Rust SIG

2018-07-30 Thread Brian (bex) Exelbierd
On Mon, Jul 30, 2018 at 5:49 PM, Clement Verna wrote: > On Mon, 30 Jul 2018 at 17:45, Brian (bex) Exelbierd > wrote: > > > > > > > > On Mon, Jul 30, 2018 at 2:31 PM, Martin Sehnoutka > wrote: > >> > >> Do you plan any hackfest during Flock? > > > > > > We are booked out for schedule hacks

Re: Rust SIG

2018-07-30 Thread Clement Verna
On Mon, 30 Jul 2018 at 17:45, Brian (bex) Exelbierd wrote: > > > > On Mon, Jul 30, 2018 at 2:31 PM, Martin Sehnoutka wrote: >> >> Do you plan any hackfest during Flock? > > > We are booked out for schedule hacks during Flock, however there is usually > some space on the edges for impromptu

Re: What to BuildRequire for libstdc++.so __cxa_demangle?

2018-07-30 Thread Jonathan Wakely
On 21/07/18 18:52 +0200, Mark Wielaard wrote: Hi, The elfutils tools can demangle C++ symbols through the standard _cxa_demangle interface. The elfutils tools are written in C and so simply link with -lstdc++ to get access to __cxa_demangle. You should be able to use -lsupc++ if you only want

Re: Rust SIG

2018-07-30 Thread Brian (bex) Exelbierd
On Mon, Jul 30, 2018 at 2:31 PM, Martin Sehnoutka wrote: > Do you plan any hackfest during Flock? > We are booked out for schedule hacks during Flock, however there is usually some space on the edges for impromptu meetings. regards, bex > > On 07/27/2018 04:04 PM, Igor Gnatenko wrote: > >

Re: Self Introduction: Rob Brown

2018-07-30 Thread Randy Barlow
On 07/29/2018 08:59 PM, Robert Brown wrote: > I'm new to fedora 28, and I am interested in participating in the > package authoring and maintenance. I'm coming from Debian. Welcome aboard! You can read about becoming a packager here:

Re: Active but unresponsive maintainer: Peter Lemenkov

2018-07-30 Thread Peter Lemenkov
Hey, Sorry for the absence - I'm still around. 2018-07-30 15:34 GMT+02:00 Timothée Floure : > > Hello, > > Peter Lemenkov [0] is an active packager (he submitted a new erlang > build to bodhi an hour ago) but I was unable to contact him for the last > two months. > > I first "encountered" him

Self Introduction

2018-07-30 Thread Iñaki Úcar
Hi everyone, My name is Iñaki Ucar, and I am based in Madrid, Spain. I have been a happy Fedora user and advocate for many many years (since Fedora Core 2). Now I would love to start contributing to the project as a package maintainer, so I am seeking a sponsor. I am package maintainer for the R

Re: Packages which use the BuildRoot: directive

2018-07-30 Thread Panu Matilainen
On 07/14/2018 12:47 AM, Kevin Fenzi wrote: On 07/12/2018 07:45 AM, Miro Hrončok wrote: I second that. When we mass filled PRs with python2 related changes it was always a Red Hat maintained software, where people were basically telling us: "no, we won't accept your PR here, we maintain the

Active but unresponsive maintainer: Peter Lemenkov

2018-07-30 Thread Timothée Floure
Hello, Peter Lemenkov [0] is an active packager (he submitted a new erlang build to bodhi an hour ago) but I was unable to contact him for the last two months. I first "encountered" him when he used his rights as provenpackager to merge some PRs on the elixir package, without thoughts for

Re: Packages which needlessly use %defattr

2018-07-30 Thread Igor Gnatenko
On Mon, Jul 30, 2018 at 11:01 AM Miroslav Suchý wrote: > Dne 4.7.2018 v 12:18 Zbigniew Jędrzejewski-Szmek napsal(a): > > What about just doing a mass specfile update now? I think asking > > individual maintainers to fix their packages isn't worth their > > time. > > -1 > > I like the Jason

Re: Rust SIG

2018-07-30 Thread Martin Sehnoutka
Do you plan any hackfest during Flock? On 07/27/2018 04:04 PM, Igor Gnatenko wrote: > Hello, > > it seems to be a week of SIG announcements, so why shouldn't I share that > we also have Rust SIG . > > At this point we have over 400 crates packaged, few

Re: Golang SIG for Fedora

2018-07-30 Thread Nicolas Mailhot
Hi, I'm obviously interested, even though I'm not available all year round -- Nicolas Mailhot ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct:

Re: koschei build gone?

2018-07-30 Thread Miro Hrončok
On 30.7.2018 13:54, Mikolaj Izdebski wrote: I would found it less confusiong if they are kept in the DB but marked them "stalled -> canceled"? For example here at least one architecture failed and even the fact that the build was stalled is interesting. Agreed. Can you file upstream issue at

Re: koschei build gone?

2018-07-30 Thread Mikolaj Izdebski
On 07/30/2018 01:49 PM, Miro Hrončok wrote: > On 30.7.2018 12:42, Mikolaj Izdebski wrote: >> On 07/30/2018 11:19 AM, Miro Hrončok wrote: >>> Hi, >>> >>> I've filled this bugzilla: [0] and I clearly remember seeing a failed >>> build in koschei - I've even linked it in the BZ [1]. >>> >>> Yet the

Re: koschei build gone?

2018-07-30 Thread Miro Hrončok
On 30.7.2018 12:42, Mikolaj Izdebski wrote: On 07/30/2018 11:19 AM, Miro Hrončok wrote: Hi, I've filled this bugzilla: [0] and I clearly remember seeing a failed build in koschei - I've even linked it in the BZ [1]. Yet the URL now returns 404. Last build in koschei for python3 is 3 days

Re: koschei build gone?

2018-07-30 Thread Mikolaj Izdebski
On 07/30/2018 11:19 AM, Miro Hrončok wrote: > Hi, > > I've filled this bugzilla: [0] and I clearly remember seeing a failed > build in koschei - I've even linked it in the BZ [1]. > > Yet the URL now returns 404. > > Last build in koschei for python3 is 3 days older than the bugreport. > >

koschei build gone?

2018-07-30 Thread Miro Hrončok
Hi, I've filled this bugzilla: [0] and I clearly remember seeing a failed build in koschei - I've even linked it in the BZ [1]. Yet the URL now returns 404. Last build in koschei for python3 is 3 days older than the bugreport. What happens? Are certain builds deleted for various reasons? Or

Re: Packages which needlessly use %defattr

2018-07-30 Thread Miroslav Suchý
Dne 4.7.2018 v 12:18 Zbigniew Jędrzejewski-Szmek napsal(a): > What about just doing a mass specfile update now? I think asking > individual maintainers to fix their packages isn't worth their > time. -1 I like the Jason attitude much more. It gives time to discuss it. To find false positives.

Re: Auto-filing of FTBFS bugs gone wild

2018-07-30 Thread Hans de Goede
Hi, On 19-07-18 17:42, Igor Gnatenko wrote: On Thu, Jul 19, 2018 at 5:33 PM Hans de Goede mailto:hdego...@redhat.com>> wrote: Hi All, I've just got 20 bugs auto-filed against packages which I co-maintain and that is just for packages starting with the letter 'a'. A quick

[EPEL-devel] Re: libbibutils 6.6 update with soname bump in epel7

2018-07-30 Thread Tuomo Soini
On Sat, 28 Jul 2018 12:29:56 +0900 Jens-Ulrik Petersen wrote: > Vasiliy, I have decoupled ghc-hs-bibutils from bibutils in epel7 now > too, so you shouldn't need to worry about it anymore. Please, add ghc-rpm-macros to update too. That's build dependency of ghc-hs-bibutils. And while package is

[Bug 1609587] perl-App-cpm-0.977 is available

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1609587 Jitka Plesnikova changed: What|Removed |Added Status|NEW |CLOSED Fixed In Version|

[Bug 1606926] perl-Alien-pkgconf-0.14 is available

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1606926 Petr Pisar changed: What|Removed |Added Status|ASSIGNED|CLOSED Fixed In Version|

[Bug 1609443] perl-Net-Netmask-1.9104 is available

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1609443 Jitka Plesnikova changed: What|Removed |Added Status|NEW |CLOSED Fixed In Version|

Re: dokuwiki packagers unresponsive

2018-07-30 Thread Matthias Runge
On Fri, Jul 27, 2018 at 02:51:25AM +0100, Sérgio Basto wrote: > On Thu, 2018-07-26 at 21:43 -0400, Solomon Peachy wrote: > > On Thu, Jul 26, 2018 at 09:09:25PM +0200, Peter 'Pessoft' Kolínek > > wrote: > > > I'd like to fix some issues (including security problems) which are > > > for > > > a long

[Bug 1606925] perl-CPAN-Perl-Releases-3.70 is available

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1606925 --- Comment #6 from Fedora Update System --- perl-CPAN-Perl-Releases-3.72-1.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2018-aa743e4784 -- You are receiving this mail because: You are on

[Bug 1609256] perl-CPAN-Perl-Releases-3.72 is available

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1609256 --- Comment #2 from Fedora Update System --- perl-CPAN-Perl-Releases-3.72-1.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2018-aa743e4784 -- You are receiving this mail because: You are on

[Bug 1609256] perl-CPAN-Perl-Releases-3.72 is available

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1609256 --- Comment #1 from Fedora Update System --- perl-CPAN-Perl-Releases-3.72-1.fc28 has been submitted as an update to Fedora 28. https://bodhi.fedoraproject.org/updates/FEDORA-2018-29e957c41c -- You are receiving this mail because: You are on

[Bug 1606925] perl-CPAN-Perl-Releases-3.70 is available

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1606925 --- Comment #5 from Fedora Update System --- perl-CPAN-Perl-Releases-3.72-1.fc28 has been submitted as an update to Fedora 28. https://bodhi.fedoraproject.org/updates/FEDORA-2018-29e957c41c -- You are receiving this mail because: You are on

[Bug 1609256] perl-CPAN-Perl-Releases-3.72 is available

2018-07-30 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1609256 Jitka Plesnikova changed: What|Removed |Added Status|NEW |MODIFIED Fixed In Version|

[Test-Announce] Proposal to CANCEL: 2018-07-30 Fedora QA Meeting

2018-07-30 Thread Adam Williamson
Hi folks! I'm proposing we cancel the QA meeting tomorrow (today?). I don't see anything urgent to discuss, so let's take the time off. If you're aware of anything important we have to discuss this week, please do reply to this mail and we can go ahead and run the meeting. Thanks! -- Adam