Bug 1719956 - Review Request: python-argon2-cffi - The secure Argon2 password hashing algorithm
Summary: Review Request: python-argon2-cffi - The secure Argon2 password hashing algo...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Robert-André Mauchin 🐧
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
: 1750579 (view as bug list)
Depends On:
Blocks: 1750590
TreeView+ depends on / blocked
 
Reported: 2019-06-12 19:46 UTC by Pavlo Rudyi
Modified: 2019-10-06 05:17 UTC (History)
4 users (show)

Fixed In Version: python-argon2-cffi-19.1.0-1.fc31
Clone Of:
Environment:
Last Closed: 2019-10-06 05:17:49 UTC
Type: ---
Embargoed:
eclipseo: fedora-review+


Attachments (Terms of Use)

Comment 1 Robert-André Mauchin 🐧 2019-06-13 16:03:36 UTC
 - You need to include changelog entries

 - you shouldn't need to include extras/libargon2/LICENSE since you're using system libargon

 - docs/license.rst isn't a license file either, don't include it

 - Use "Documentation for argon2-cffi" with a capital

python-argon2-cffi-doc.x86_64: W: summary-not-capitalized C argon2-cffi documentation

 - 

Source0: https://files.pythonhosted.org/packages/source/a/%{pypi_name}/argon2_cffi-%{version}.tar.gz

→

Source0: %{pypi_source}


Package Review
==============

Legend:
[x] = Pass, [!] = Fail, [-] = Not applicable, [?] = Not evaluated
[ ] = Manual review needed


Issues:
=======
- Package does not contain duplicates in %files.
  Note: BUILDSTDERR: warning: File listed twice:
  /usr/share/licenses/python3-argon2-cffi/LICENSE
  See: https://docs.fedoraproject.org/en-US/packaging-
  guidelines/#_duplicate_files


===== MUST items =====

C/C++:
[x]: Package does not contain kernel modules.
[x]: Package contains no static executables.
[x]: Development (unversioned) .so files in -devel subpackage, if present.
     Note: Unversioned so-files in private %_libdir subdirectory (see
     attachment). Verify they are not in ld path.
[x]: If your application is a C or C++ application you must list a
     BuildRequires against gcc, gcc-c++ or clang.
[x]: Package does not contain any libtool archives (.la)
[x]: Rpath absent or only used for internal libs.

Generic:
[x]: Package is licensed with an open-source compatible license and meets
     other legal requirements as defined in the legal section of Packaging
     Guidelines.
[x]: License field in the package spec file matches the actual license.
     Note: Checking patched sources after %prep for licenses. Licenses
     found: "Unknown or generated", "Expat License BSD 3-clause "New" or
     "Revised" License", "Expat License", "Apache License (v2.0) Creative
     Commons CC0 Public License (v1.0)", "Creative Commons CC0 Public
     License (v1.0)", "BSD 3-clause "New" or "Revised" License". 101 files
     have unknown license. Detailed output of licensecheck in
     /home/bob/packaging/review/python-argon2-cffi/review-python-
     argon2-cffi/licensecheck.txt
[x]: License file installed when any subpackage combination is installed.
[x]: %build honors applicable compiler flags or justifies otherwise.
[x]: Package contains no bundled libraries without FPC exception.
[x]: Changelog in prescribed format.
[x]: Sources contain only permissible code or content.
[-]: Package contains desktop file if it is a GUI application.
[-]: Development files must be in a -devel package
[x]: Package uses nothing in %doc for runtime.
[x]: Package consistently uses macros (instead of hard-coded directory
     names).
[x]: Package is named according to the Package Naming Guidelines.
[x]: Package does not generate any conflict.
[x]: Package obeys FHS, except libexecdir and /usr/target.
[-]: If the package is a rename of another package, proper Obsoletes and
     Provides are present.
[x]: Requires correct, justified where necessary.
[x]: Spec file is legible and written in American English.
[-]: Package contains systemd file(s) if in need.
[x]: Useful -debuginfo package or justification otherwise.
[-]: Package is not known to require an ExcludeArch tag.
[x]: Large documentation must go in a -doc subpackage. Large could be size
     (~1MB) or number of files.
     Note: Documentation size is 20480 bytes in 2 files.
[x]: Package complies to the Packaging Guidelines
[x]: Package successfully compiles and builds into binary rpms on at least
     one supported primary architecture.
[x]: Package installs properly.
[x]: Rpmlint is run on all rpms the build produces.
     Note: There are rpmlint messages (see attachment).
[x]: Package requires other packages for directories it uses.
[x]: Package does not own files or directories owned by other packages.
[x]: Package uses either %{buildroot} or $RPM_BUILD_ROOT
[x]: Package does not run rm -rf %{buildroot} (or $RPM_BUILD_ROOT) at the
     beginning of %install.
[x]: Macros in Summary, %description expandable at SRPM build time.
[x]: Dist tag is present.
[x]: Package use %makeinstall only when make install DESTDIR=... doesn't
     work.
[x]: Package is named using only allowed ASCII characters.
[x]: Package does not use a name that already exists.
[x]: Package is not relocatable.
[x]: Sources used to build the package match the upstream source, as
     provided in the spec URL.
[x]: Spec file name must match the spec package %{name}, in the format
     %{name}.spec.
[x]: File names are valid UTF-8.
[x]: Packages must not store files under /srv, /opt or /usr/local

Python:
[x]: Python eggs must not download any dependencies during the build
     process.
[x]: A package which is used by another package via an egg interface should
     provide egg info.
[x]: Package meets the Packaging Guidelines::Python
[x]: Package contains BR: python2-devel or python3-devel
[x]: Packages MUST NOT have dependencies (either build-time or runtime) on
     packages named with the unversioned python- prefix unless no properly
     versioned package exists. Dependencies on Python packages instead MUST
     use names beginning with python2- or python3- as appropriate.
[x]: Python packages must not contain %{pythonX_site(lib|arch)}/* in %files
[x]: Binary eggs must be removed in %prep

===== SHOULD items =====

Generic:
[-]: If the source package does not include license text(s) as a separate
     file from upstream, the packager SHOULD query upstream to include it.
[x]: Final provides and requires are sane (see attachments).
[-]: Fully versioned dependency in subpackages if applicable.
     Note: No Requires: %{name}%{?_isa} = %{version}-%{release} in
     python3-argon2-cffi
[?]: Package functions as described.
[x]: Latest version is packaged.
[x]: Package does not include license text files separate from upstream.
[-]: Description and summary sections in the package spec file contains
     translations for supported Non-English languages, if available.
[x]: Package should compile and build into binary rpms on all supported
     architectures.
[x]: %check is present and all tests pass.
[x]: Packages should try to preserve timestamps of original installed
     files.
[x]: Reviewer should test that the package builds in mock.
[x]: Buildroot is not present
[x]: Package has no %clean section with rm -rf %{buildroot} (or
     $RPM_BUILD_ROOT)
[x]: No file requires outside of /etc, /bin, /sbin, /usr/bin, /usr/sbin.
[x]: Packager, Vendor, PreReq, Copyright tags should not be in spec file
[x]: Sources can be downloaded from URI in Source: tag
[x]: SourceX is a working URL.
[x]: Spec use %global instead of %define unless justified.

===== EXTRA items =====

Generic:
[x]: Rpmlint is run on all installed packages.
     Note: There are rpmlint messages (see attachment).
[x]: Large data in /usr/share should live in a noarch subpackage if package
     is arched.
[x]: Spec file according to URL is the same as in SRPM.


Rpmlint
-------
Checking: python3-argon2-cffi-19.1.0-1.fc31.x86_64.rpm
          python-argon2-cffi-doc-19.1.0-1.fc31.x86_64.rpm
          python-argon2-cffi-debugsource-19.1.0-1.fc31.x86_64.rpm
          python-argon2-cffi-19.1.0-1.fc31.src.rpm
python3-argon2-cffi.x86_64: E: no-changelogname-tag
python-argon2-cffi-doc.x86_64: W: summary-not-capitalized C argon2-cffi documentation
python-argon2-cffi-doc.x86_64: E: no-changelogname-tag
python-argon2-cffi-doc.x86_64: W: wrong-file-end-of-line-encoding /usr/share/doc/python-argon2-cffi-doc/html/objects.inv
python-argon2-cffi-doc.x86_64: W: file-not-utf8 /usr/share/doc/python-argon2-cffi-doc/html/objects.inv
python-argon2-cffi-debugsource.x86_64: E: no-changelogname-tag
python-argon2-cffi.src: E: no-changelogname-tag
4 packages and 0 specfiles checked; 4 errors, 3 warnings.

Comment 2 Pavlo Rudyi 2019-06-14 14:00:10 UTC
https://gist.github.com/paulcarroty/5cceff6b0abf8b55c73c9e5cb5145213#file-python-argon2-cffi-spec

stderr: warning: Downloading https://files.pythonhosted.org/packages/source/a/argon2-cffi/argon2-cffi-19.1.0.tar.gz to /var/lib/copr-rpmbuild/resultstwzp7f1b/argon2-cffi-19.1.0.tar.gz
curl: (22) The requested URL returned error: 404 
error: Couldn't download https://files.pythonhosted.org/packages/source/a/argon2-cffi/argon2-cffi-19.1.0.tar.gz
Failed to execute command.

Comment 3 Robert-André Mauchin 🐧 2019-06-14 14:41:02 UTC
Summary: argon2-cffi documentation

→

Summary: Documentation for argon2-cffi

 - Not needed:

extras/libargon2/README.md


Package approved, please fix the aforementioned issues.

Comment 4 Robert-André Mauchin 🐧 2019-06-14 14:42:21 UTC
Your changelog entry must include Version-Release info:

* Fri Jun 14 2019 Pavlo Rudyi <paulcarroty> - 19.1.0-1

Comment 5 Pavlo Rudyi 2019-06-14 15:37:33 UTC
Done.

Comment 6 Robert-André Mauchin 🐧 2019-09-22 15:49:02 UTC
Refreshing flag.

Comment 7 Gwyn Ciesla 2019-09-23 13:13:59 UTC
(fedscm-admin):  The Pagure repository was created at https://src.fedoraproject.org/rpms/python-argon2-cffi

Comment 8 Elliott Sales de Andrade 2019-10-06 05:15:59 UTC
*** Bug 1750579 has been marked as a duplicate of this bug. ***

Comment 9 Elliott Sales de Andrade 2019-10-06 05:17:49 UTC
Please add your bug reports to your Bodhi updates.

https://bodhi.fedoraproject.org/updates/FEDORA-2019-5fc014f121


Note You need to log in before you can comment on or make changes to this bug.