Bug 1662565 - Review Request: libsignal-protocol-c - Signal Protocol C library
Summary: Review Request: libsignal-protocol-c - Signal Protocol C library
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Peter Lemenkov
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-12-30 04:01 UTC by Randy Barlow
Modified: 2019-02-04 17:01 UTC (History)
4 users (show)

Fixed In Version: libsignal-protocol-c-2.3.2-1.fc30
Clone Of:
Environment:
Last Closed: 2019-02-04 17:01:05 UTC
Type: ---
Embargoed:
lemenkov: fedora-review+


Attachments (Terms of Use)

Description Randy Barlow 2018-12-30 04:01:24 UTC
Spec URL: https://bowlofeggs.fedorapeople.org/libsignal-protocol-c.spec
SRPM URL: https://bowlofeggs.fedorapeople.org/libsignal-protocol-c-2.3.2-1.fc30.src.rpm
Description: This is a ratcheting forward secrecy protocol that works in synchronous and asynchronous messaging environments.
Fedora Account System Username: bowlofeggs

Comment 1 Michael Schwendt 2018-12-30 23:41:55 UTC
> License:    GPLv3+

Files say "GPLv3" only. No "or later" in any source files.

[!] Source tarball contains bundled projects covered by different license terms. Such as protobuf-c. This will need a close look.


> BuildRequires: gcc-c++

Doesn't seem to be true, since a plain C lib is built from C code.


> Requires:   libsignal-protocol-c == %{version}

The base package guidelines haven't been changed:
https://fedoraproject.org/wiki/Packaging:Guidelines#Requiring_Base_Package


> Requires:   pkgconf-pkg-config

Very unusual and should be removed in favor of rpmbuild's automatic dependency on pkg-config.


> %changelog

Out of sync.

Comment 2 Randy Barlow 2019-01-05 14:42:39 UTC
Good catch on the bundled lib, I hadn't noticed that. I found an issue about it:

https://github.com/signalapp/libsignal-protocol-c/issues/103

Looking at their CMake code, it does not seem they provide a way to use the system library. Unfortunately, they also don't seem to document the version of protobuf-c, so I asked in that ticket which version is bundled so I can mark it in the spec file. Looking at the commit history makes it seem like a fork of 1.1.1:

https://github.com/signalapp/libsignal-protocol-c/commits/master/src/protobuf-c

The BR on gcc-c++ was done because the cmake tool does look for the C++ compiler even though it doesn't seem to use it. We could probably make a patch for upstream to stop this, but for now I just installed it since it was harmless and easy.

Here's a patch to address some of the problems:

--- libsignal-protocol-c.spec.old       2019-01-05 09:30:40.885309220 -0500
+++ libsignal-protocol-c.spec   2019-01-05 09:29:52.800721370 -0500
@@ -2,7 +2,7 @@
 Version:    2.3.2
 Release:    1%{?dist}
 
-License:    GPLv3+
+License:    GPLv3
 Summary:    Signal Protocol C library
 URL:        https://github.com/signalapp/libsignal-protocol-c
 Source0:    %{url}/archive/v%{version}/%{name}-%{version}.tar.gz
@@ -12,6 +12,9 @@
 BuildRequires: gcc-c++
 BuildRequires: openssl-devel
 
+# https://github.com/signalapp/libsignal-protocol-c/issues/103
+Provides: bundled(protobuf-c) = 1.1.1
+
 
 %description
 This is a ratcheting forward secrecy protocol that works in synchronous and asynchronous messaging
@@ -21,8 +24,7 @@
 %package devel
 Summary:    Development files for libsignal-protocol-c
 
-Requires:   libsignal-protocol-c == %{version}
-Requires:   pkgconf-pkg-config
+Requires:   %{name}%{?_isa} = %{version}-%{release}
 
 
 %description devel
@@ -59,5 +61,5 @@
 
 
 %changelog
-* Sat Dec 29 2018 Randy Barlow <bowlofeggs> - 2.3.0-1
+* Sat Jan 05 2019 Randy Barlow <bowlofeggs> - 2.3.2-1
 - Initial release.


New spec and SRPM:

Spec URL: https://bowlofeggs.fedorapeople.org/libsignal-protocol-c.spec
SRPM URL: https://bowlofeggs.fedorapeople.org/libsignal-protocol-c-2.3.2-1.fc30.src.rpm

Comment 3 Randy Barlow 2019-01-08 15:17:00 UTC
Hi Michael!

Would you be willing to take another look at this?

Comment 4 Peter Lemenkov 2019-01-31 19:42:05 UTC
I'll review it

Comment 5 Peter Lemenkov 2019-01-31 20:07:25 UTC
REVIEW:

Legend: + = PASSED, - = FAILED, 0 = Not Applicable

+ rpmlint is almost silent:

Auriga ~/rpmbuild/SPECS: rpmlint ../SRPMS/libsignal-protocol-c-2.3.2-1.fc29.src.rpm ../RPMS/x86_64/libsignal-protocol-c-*
libsignal-protocol-c.src: E: description-line-too-long C This is a ratcheting forward secrecy protocol that works in synchronous and asynchronous messaging
libsignal-protocol-c.x86_64: E: description-line-too-long C This is a ratcheting forward secrecy protocol that works in synchronous and asynchronous messaging

^^^ These two looks cosmetic. But anyway consider shortening it.

libsignal-protocol-c-devel.x86_64: W: no-documentation

^^^ It does not contain any docs.

5 packages and 0 specfiles checked; 2 errors, 1 warnings.
Auriga ~/rpmbuild/SPECS:

+ The package is named according to the  Package Naming Guidelines.
+ The spec file name matches the base package %{name}, in the format %{name}.spec.
+ The package meets the Packaging Guidelines.
+ The package is licensed with a Fedora approved license and meets the Licensing Guidelines.
+ The License field in the package spec file matches the actual license (GPLv3 exactly).
+ The file, containing the text of the license(s) for the package, is included as %license.
+ The spec file is written in American English.
+ The spec file for the package is legible.
+ The sources used to build the package, match the upstream source, as provided in the spec URL.

Auriga ~/rpmbuild/SOURCES: sha256sum libsignal-protocol-c-2.3.2.tar.gz*
f3826f3045352e14027611c95449bfcfe39bfd3d093d578c70f70eee0c85000d  libsignal-protocol-c-2.3.2.tar.gz
f3826f3045352e14027611c95449bfcfe39bfd3d093d578c70f70eee0c85000d  libsignal-protocol-c-2.3.2.tar.gz.1
Auriga ~/rpmbuild/SOURCES: 

+ The package successfully compiles and builds into binary rpms on at least one primary architecture.
+ All build dependencies are listed in BuildRequires.
0 No need to handle locales.

+/- The package bundle copies of system libraries (protobuf compiler and curve25519 library, which isn't included in Fedora repos yet). A necessary provides is added.
0 The package is not designed to be relocatable.
+ The package owns all directories that it creates.
+ The package does not list a file more than once in the spec file's %files listings.
+ Permissions on files are set properly.
+ The package consistently uses macros.
+ The package contains code, or permissible content.
0 No extremely large documentation files.
+ Anything, the package includes as %doc, does not affect the runtime of the application.
+ Header files are stored in a -devel package.
0 No static libraries.
+ The pkgconfig(.pc) files are stored in a -devel package and necessary runtime requirement added automatically.
+ The library file(s) that end in .so (without suffix) is(are) stored in a -devel package.
+ The -devel package requires the base package using a fully versioned dependency: Requires: %{name}%{?_isa} = %{version}-%{release}
+ The package does NOT contain any .la libtool archives.
0 Not a GUI application.
+ The package does not own files or directories already owned by other packages.
+ All filenames in rpm packages are valid UTF-8.


APPROVED.

Comment 7 Gwyn Ciesla 2019-02-04 14:31:39 UTC
(fedscm-admin):  The Pagure repository was created at https://src.fedoraproject.org/rpms/libsignal-protocol-c

Comment 8 Randy Barlow 2019-02-04 16:52:48 UTC
Thanks for the review Peter!

I fixed the description line length in https://src.fedoraproject.org/rpms/libsignal-protocol-c/c/c5350156cdc862625725a6fdedadd486921844f1?branch=master and I silenced the doc warning on the -devel package in https://src.fedoraproject.org/rpms/libsignal-protocol-c/c/a289ca7ffc99661b2f69d086aaa08998a4d8c973?branch=master.


Note You need to log in before you can comment on or make changes to this bug.