Description Luca BRUNO 2018-11-13 14:55:58 UTC
Description of problem:

bind-utils package currently provides a few utilities that depends on python3 and a bunch of other python modules. From a quick look on F29, the set of those utilities is quite small and consist of:
 * /usr/sbin/dnssec-checkds
 * /usr/sbin/dnssec-coverage
 * /usr/sbin/dnssec-keymgr

In order to trim down the web of python dependencies on fedora-coreos images, it would be nice if those utilities could be split to their own dedicated binary package (bind-python-utils perhaps?).

Comment 1 Petr Menšík 2018-11-13 20:26:01 UTC
Sure, I thought about that more than once. I think splitting would be useful, especially because those utilities are way less used than most common dig and host.

Anyway, it is possible dependencies may grow because of bug #1564776. Not a python dependencies however.

Comment 2 Luca BRUNO 2018-11-13 21:49:00 UTC
In our specific case, native dependencies (I'm thinking of libprotobuf here) are a bit less of problem compare to user-exposed interpreters.

Anyway, thanks for the quick followup. If you need any kind of review/feedback/help on this, feel free to reach to any of the people in the current CC set.

Comment 3 Tomáš Hozza 2018-11-14 08:09:28 UTC
Please don't name them bind-python-utils. It will make much more sense to have utilities split by use case and named them by use case, not by the language they are written in. These are not python modules.

Comment 4 Dusty Mabe 2018-12-12 15:59:40 UTC
Hi Petr. Do you know if the splitting out of python deps will make it into Fedora 30? We'd like to use this in Fedora CoreOS for Fedora 30 if possible.

Comment 5 Petr Menšík 2019-01-16 19:57:16 UTC
Tomas is right, these are not tools to work in python. I checked how they have it organized in Debian. There are dnssec tools in bind9utils [1] package and dnsutils [2] with basic client commands like host, dig etc. I think most packages that depend on bind-utils require host or dig.

It is a question what to move outside. I think bind-dnssec-utils with most of tools in /usr/sbin would make sense. They are related more to named service and working with zone files and their keys. 

Packages that require bind-utils are on f29:


I did check that:
bash-argsparse uses host
bontmia uses host
inxi uses dig
lbd uses host
nagios-plugins-dig uses dig
nagios-plugins-dns uses nslookup (!)
neofetch uses dig
gnome-nettool uses dig

I am confident at least freeipa-server-dns would require some dnssec tools or key generation tools. Not sure about freeipa-client. It would be simple to move some tools into separate subpackage, but not so without breaking something.
Alternative would be forking two separate utils and bind-utils would still require both of them, so backward compatibility is rock-solid. I admit I do not have enough time for communicating all these changes with all dependent packages. Not yet sure how to solve it. I may fork simple utilities into bind-dnsutils and leave bind-utils to require both bind-dnsutils and bind-dnssec-utils. Seems overcomplicated but safe enough.

1. https://packages.debian.org/sid/amd64/bind9utils/filelist
2. https://packages.debian.org/sid/amd64/dnsutils/filelist

Comment 6 Petr Menšík 2019-01-17 13:09:15 UTC
I think I have found some solution, bind-utils would Suggest bind-dnssec-utils for some time. It allows to not install bind-dnssec-utils, but should install both for all existing users [1]. I would drop the suggests when I am confident requires for bind-utils require just what has left inside. Have it in my test repository for now, because I have to first rebase to BIND 9.11.5 and it is not yet prepared. It should build inside COPR after while [2] (note some other features are enabled too).

1. https://src.fedoraproject.org/fork/pemensik/rpms/bind/c/2830e00b88ea8bb956e0cdeb6f205fc72741b167?branch=master-beta
2. https://copr.fedorainfracloud.org/coprs/pemensik/bind/

Comment 7 Dusty Mabe 2019-01-17 14:40:04 UTC
thanks for working on this petr

Comment 8 Petr Menšík 2019-01-31 15:33:17 UTC
Ok, checked packages in more automated way.

Used these commands on rawhide:
dnf install $(dnf repoquery --whatrequires bind-utils)
rpm -ql bind-utils | grep '/usr/s\?bin' | while read BINARY; do BS=$(basename -- "$BINARY"); echo "$BS"; [ "$BINARY" != "/usr/bin/host" ] && BINARY=$(basename -- "$BINARY"); grep -w "$BINARY" -r /usr/bin /usr/sbin /usr/lib*; done | tee found.log

According to that, FreeIPA requires just nsupdate and dnsec-keyfromlabel-pkcs11. Because freeipa uses dnsec-keyfromlabel-pkcs11 binary, it does not require bind-dnssec-utils that provides dnssec-keyfromlabel. It could require it later if *-pkcs11 variants are deprecated, but that is not yet comming.

It seems no other tool tries to use any command from /usr/sbin. I think it is safe to just split dnssec tools away.

Comment 9 Sinny Kumari 2019-02-13 11:53:02 UTC
Thanks a lot Petr for creating bind-dnssec-utils sub-package and moving Python utilities from bind-utils to the new sub-pacakge! I see that latest bind-utils-9.11.5-8.P1.fc30 sub-package available in Fedora 30 doesn't contain Python dependent utilities now.

Comment 10 Fedora Update System 2019-05-06 14:55:27 UTC
bind-9.11.6-5.P1.fc30 has been submitted as an update to Fedora 30. https://bodhi.fedoraproject.org/updates/FEDORA-2019-493dfcda55

Comment 11 Fedora Update System 2019-05-06 21:04:07 UTC
bind-9.11.6-5.P1.fc30 has been pushed to the Fedora 30 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2019-493dfcda55

Comment 12 Fedora Update System 2019-05-10 00:47:27 UTC
bind-9.11.6-5.P1.fc30 has been pushed to the Fedora 30 stable repository. If problems still persist, please make note of it in this bug report.

