Fedora Account System
Red Hat Associate
Red Hat Customer
Spec URL: https://bowlofeggs.fedorapeople.org/libsignal-protocol-c.spec SRPM URL: https://bowlofeggs.fedorapeople.org/libsignal-protocol-c-2.3.2-1.fc30.src.rpm Description: This is a ratcheting forward secrecy protocol that works in synchronous and asynchronous messaging environments. Fedora Account System Username: bowlofeggs
> License: GPLv3+ Files say "GPLv3" only. No "or later" in any source files. [!] Source tarball contains bundled projects covered by different license terms. Such as protobuf-c. This will need a close look. > BuildRequires: gcc-c++ Doesn't seem to be true, since a plain C lib is built from C code. > Requires: libsignal-protocol-c == %{version} The base package guidelines haven't been changed: https://fedoraproject.org/wiki/Packaging:Guidelines#Requiring_Base_Package > Requires: pkgconf-pkg-config Very unusual and should be removed in favor of rpmbuild's automatic dependency on pkg-config. > %changelog Out of sync.
Good catch on the bundled lib, I hadn't noticed that. I found an issue about it: https://github.com/signalapp/libsignal-protocol-c/issues/103 Looking at their CMake code, it does not seem they provide a way to use the system library. Unfortunately, they also don't seem to document the version of protobuf-c, so I asked in that ticket which version is bundled so I can mark it in the spec file. Looking at the commit history makes it seem like a fork of 1.1.1: https://github.com/signalapp/libsignal-protocol-c/commits/master/src/protobuf-c The BR on gcc-c++ was done because the cmake tool does look for the C++ compiler even though it doesn't seem to use it. We could probably make a patch for upstream to stop this, but for now I just installed it since it was harmless and easy. Here's a patch to address some of the problems: --- libsignal-protocol-c.spec.old 2019-01-05 09:30:40.885309220 -0500 +++ libsignal-protocol-c.spec 2019-01-05 09:29:52.800721370 -0500 @@ -2,7 +2,7 @@ Version: 2.3.2 Release: 1%{?dist} -License: GPLv3+ +License: GPLv3 Summary: Signal Protocol C library URL: https://github.com/signalapp/libsignal-protocol-c Source0: %{url}/archive/v%{version}/%{name}-%{version}.tar.gz @@ -12,6 +12,9 @@ BuildRequires: gcc-c++ BuildRequires: openssl-devel +# https://github.com/signalapp/libsignal-protocol-c/issues/103 +Provides: bundled(protobuf-c) = 1.1.1 + %description This is a ratcheting forward secrecy protocol that works in synchronous and asynchronous messaging @@ -21,8 +24,7 @@ %package devel Summary: Development files for libsignal-protocol-c -Requires: libsignal-protocol-c == %{version} -Requires: pkgconf-pkg-config +Requires: %{name}%{?_isa} = %{version}-%{release} %description devel @@ -59,5 +61,5 @@ %changelog -* Sat Dec 29 2018 Randy Barlow <bowlofeggs> - 2.3.0-1 +* Sat Jan 05 2019 Randy Barlow <bowlofeggs> - 2.3.2-1 - Initial release. New spec and SRPM: Spec URL: https://bowlofeggs.fedorapeople.org/libsignal-protocol-c.spec SRPM URL: https://bowlofeggs.fedorapeople.org/libsignal-protocol-c-2.3.2-1.fc30.src.rpm
Hi Michael! Would you be willing to take another look at this?
I'll review it
REVIEW: Legend: + = PASSED, - = FAILED, 0 = Not Applicable + rpmlint is almost silent: Auriga ~/rpmbuild/SPECS: rpmlint ../SRPMS/libsignal-protocol-c-2.3.2-1.fc29.src.rpm ../RPMS/x86_64/libsignal-protocol-c-* libsignal-protocol-c.src: E: description-line-too-long C This is a ratcheting forward secrecy protocol that works in synchronous and asynchronous messaging libsignal-protocol-c.x86_64: E: description-line-too-long C This is a ratcheting forward secrecy protocol that works in synchronous and asynchronous messaging ^^^ These two looks cosmetic. But anyway consider shortening it. libsignal-protocol-c-devel.x86_64: W: no-documentation ^^^ It does not contain any docs. 5 packages and 0 specfiles checked; 2 errors, 1 warnings. Auriga ~/rpmbuild/SPECS: + The package is named according to the Package Naming Guidelines. + The spec file name matches the base package %{name}, in the format %{name}.spec. + The package meets the Packaging Guidelines. + The package is licensed with a Fedora approved license and meets the Licensing Guidelines. + The License field in the package spec file matches the actual license (GPLv3 exactly). + The file, containing the text of the license(s) for the package, is included as %license. + The spec file is written in American English. + The spec file for the package is legible. + The sources used to build the package, match the upstream source, as provided in the spec URL. Auriga ~/rpmbuild/SOURCES: sha256sum libsignal-protocol-c-2.3.2.tar.gz* f3826f3045352e14027611c95449bfcfe39bfd3d093d578c70f70eee0c85000d libsignal-protocol-c-2.3.2.tar.gz f3826f3045352e14027611c95449bfcfe39bfd3d093d578c70f70eee0c85000d libsignal-protocol-c-2.3.2.tar.gz.1 Auriga ~/rpmbuild/SOURCES: + The package successfully compiles and builds into binary rpms on at least one primary architecture. + All build dependencies are listed in BuildRequires. 0 No need to handle locales. +/- The package bundle copies of system libraries (protobuf compiler and curve25519 library, which isn't included in Fedora repos yet). A necessary provides is added. 0 The package is not designed to be relocatable. + The package owns all directories that it creates. + The package does not list a file more than once in the spec file's %files listings. + Permissions on files are set properly. + The package consistently uses macros. + The package contains code, or permissible content. 0 No extremely large documentation files. + Anything, the package includes as %doc, does not affect the runtime of the application. + Header files are stored in a -devel package. 0 No static libraries. + The pkgconfig(.pc) files are stored in a -devel package and necessary runtime requirement added automatically. + The library file(s) that end in .so (without suffix) is(are) stored in a -devel package. + The -devel package requires the base package using a fully versioned dependency: Requires: %{name}%{?_isa} = %{version}-%{release} + The package does NOT contain any .la libtool archives. 0 Not a GUI application. + The package does not own files or directories already owned by other packages. + All filenames in rpm packages are valid UTF-8. APPROVED.
https://pagure.io/releng/fedora-scm-requests/issue/9578
(fedscm-admin): The Pagure repository was created at https://src.fedoraproject.org/rpms/libsignal-protocol-c
Thanks for the review Peter! I fixed the description line length in https://src.fedoraproject.org/rpms/libsignal-protocol-c/c/c5350156cdc862625725a6fdedadd486921844f1?branch=master and I silenced the doc warning on the -devel package in https://src.fedoraproject.org/rpms/libsignal-protocol-c/c/a289ca7ffc99661b2f69d086aaa08998a4d8c973?branch=master.