Fedora Account System
Red Hat Associate
Red Hat Customer
Spec URL: https://gitlab.com/musicinmybrain/fedora-rpm/-/raw/54139bb15a7376a2ec2538bb2e442739c5c9385a/topojson-server.spec SRPM URL: https://kojipkgs.fedoraproject.org//work/tasks/9293/61839293/fx-20.0.2-1.fc35.src.rpm Description: Command-line JSON processing tool Features: * Easy to use * Standalone binary * Interactive mode * Streaming support Fedora Account System Username: music Note that this package is for Fedora 34+ only, and is under the brand-new Node.js packaging guidelines at https://docs.fedoraproject.org/en-US/packaging-guidelines/Node.js. If you are not familiar with the recent significant changes (most notably, bundling of all dependencies), then please read through the guidelines carefully before reviewing. Thanks! Koji scratch builds: F35: https://koji.fedoraproject.org/koji/taskinfo?taskID=61839292 F34: https://koji.fedoraproject.org/koji/taskinfo?taskID=61839610
It appears gitlab is serving a 403 error to the fedora-review tool even though the spec URL is otherwise good, perhaps by blocking user-agents not on a whitelist. This is obnoxious. The following URL should work for everyone: https://music.fedorapeople.org/fx.spec
- Please don't use Koji to link to SRPM packages as they have a limited duration. Current SRPM is 404. Please reupload it.
Thanks, updated. Same spec URL: https://music.fedorapeople.org/fx.spec New SRPM URL: https://music.fedorapeople.org/fx-20.0.2-1.fc33.src.rpm
- Why are node_modules symbolic links to node_modules_prod? Why not put them directly at node_modules? - Why do you convert the Markdown files to HTML? for md in *.md do pandoc -o "$(basename "${md}" .md).html" -s "${md}" done
Package Review ============== Legend: [x] = Pass, [!] = Fail, [-] = Not applicable, [?] = Not evaluated [ ] = Manual review needed ===== MUST items ===== Generic: [x]: Package is licensed with an open-source compatible license and meets other legal requirements as defined in the legal section of Packaging Guidelines. [!]: License field in the package spec file matches the actual license. Note: Checking patched sources after %prep for licenses. Licenses found: "Unknown or generated", "Expat License", "*No copyright* Expat License", "SIL Open Font License 1.1", "SIL Open Font License 1.1 GNU General Public License v2.0 or later". 138 files have unknown license. Detailed output of licensecheck in /home/bob/packaging/review/fx/review-fx/licensecheck.txt [x]: If the package is under multiple licenses, the licensing breakdown must be documented in the spec. [x]: Package contains no bundled libraries without FPC exception. [x]: Changelog in prescribed format. [x]: Sources contain only permissible code or content. [-]: Package contains desktop file if it is a GUI application. [-]: Development files must be in a -devel package [x]: Package uses nothing in %doc for runtime. [x]: Package consistently uses macros (instead of hard-coded directory names). [x]: Package is named according to the Package Naming Guidelines. [x]: Package does not generate any conflict. [x]: Package obeys FHS, except libexecdir and /usr/target. [-]: If the package is a rename of another package, proper Obsoletes and Provides are present. [x]: Requires correct, justified where necessary. [x]: Spec file is legible and written in American English. [-]: Package contains systemd file(s) if in need. [x]: Package is not known to require an ExcludeArch tag. [-]: Large documentation must go in a -doc subpackage. Large could be size (~1MB) or number of files. Note: Documentation size is 61440 bytes in 4 files. [x]: Package complies to the Packaging Guidelines [x]: Package successfully compiles and builds into binary rpms on at least one supported primary architecture. [x]: Package installs properly. [x]: Rpmlint is run on all rpms the build produces. Note: There are rpmlint messages (see attachment). [x]: Package requires other packages for directories it uses. [x]: Package does not own files or directories owned by other packages. [x]: Package uses either %{buildroot} or $RPM_BUILD_ROOT [x]: Package does not run rm -rf %{buildroot} (or $RPM_BUILD_ROOT) at the beginning of %install. [x]: Macros in Summary, %description expandable at SRPM build time. [x]: Dist tag is present. [x]: Package does not contain duplicates in %files. [x]: Permissions on files are set properly. [x]: Package use %makeinstall only when make install DESTDIR=... doesn't work. [x]: Package is named using only allowed ASCII characters. [x]: Package does not use a name that already exists. [x]: Package is not relocatable. [x]: Sources used to build the package match the upstream source, as provided in the spec URL. [x]: Spec file name must match the spec package %{name}, in the format %{name}.spec. [x]: File names are valid UTF-8. [x]: Packages must not store files under /srv, /opt or /usr/local ===== SHOULD items ===== Generic: [-]: If the source package does not include license text(s) as a separate file from upstream, the packager SHOULD query upstream to include it. [x]: Final provides and requires are sane (see attachments). [?]: Package functions as described. [x]: Latest version is packaged. [x]: Package does not include license text files separate from upstream. [-]: Sources are verified with gpgverify first in %prep if upstream publishes signatures. Note: gpgverify is not used. [-]: Description and summary sections in the package spec file contains translations for supported Non-English languages, if available. [x]: %check is present and all tests pass. [x]: Packages should try to preserve timestamps of original installed files. [x]: Reviewer should test that the package builds in mock. [x]: Buildroot is not present [x]: Package has no %clean section with rm -rf %{buildroot} (or $RPM_BUILD_ROOT) [x]: No file requires outside of /etc, /bin, /sbin, /usr/bin, /usr/sbin. [x]: Packager, Vendor, PreReq, Copyright tags should not be in spec file [x]: Sources can be downloaded from URI in Source: tag [x]: SourceX is a working URL. [x]: Package should compile and build into binary rpms on all supported architectures. [x]: Spec use %global instead of %define unless justified. ===== EXTRA items ===== Generic: [x]: Rpmlint is run on all installed packages. Note: There are rpmlint messages (see attachment). [x]: Spec file according to URL is the same as in SRPM. Rpmlint ------- Checking: fx-20.0.2-1.fc35.noarch.rpm fx-20.0.2-1.fc35.src.rpm fx.noarch: W: only-non-binary-in-usr-lib fx.noarch: W: hidden-file-or-dir /usr/lib/node_modules/fx/node_modules/.bin fx.noarch: W: hidden-file-or-dir /usr/lib/node_modules/fx/node_modules_prod/.bin fx.noarch: W: hidden-file-or-dir /usr/lib/node_modules/fx/node_modules_prod/.bin fx.src: W: strange-permission check-null-licenses 755 fx.src: W: invalid-url Source3: fx-20.0.2-nm-dev.tgz fx.src: W: invalid-url Source2: fx-20.0.2-nm-prod.tgz 2 packages and 0 specfiles checked; 0 errors, 7 warnings.
- Install the main package's license with %license in %files
(In reply to Robert-André Mauchin 🐧 from comment #7) > - Install the main package's license with %license in %files Disregard this.
> - Why are node_modules symbolic links to node_modules_prod? Why not put them directly at node_modules? This is taken directly from the template at https://docs.fedoraproject.org/en-US/packaging-guidelines/Node.js/#_using_tarballs_for_bundling. I do not know the original rationale. ----- > - Why do you convert the Markdown files to HTML? It seemed like it would be useful to have them available in a browser-friendly format. In retrospect, this is probably excessive for a couple of simple files. I have removed the conversion: New spec URL: https://music.fedorapeople.org/fx-20.0.2-2/fx.spec New SRPM URL: https://music.fedorapeople.org/fx-20.0.2-2/fx-20.0.2-2.fc33.src.rpm ----- > [!]: License field in the package spec file matches the actual license. > Note: Checking patched sources after %prep for licenses. Licenses > found: "Unknown or generated", "Expat License", "*No copyright* Expat > License", "SIL Open Font License 1.1", "SIL Open Font License 1.1 GNU > General Public License v2.0 or later". 138 files have unknown license. > Detailed output of licensecheck in > /home/bob/packaging/review/fx/review-fx/licensecheck.txt Are you sure? node_modules_prod/@medv/blessed/usr/fonts/README says: > The files configure, configure.help, bdftopsf.pl and ucstoany.pl are > distributed under the GNU General Public License version 2.0 or (at your > choice) any later version. but these files are not present in the bundle. So with GPLv2+ out of the mix, I think all licenses are covered by “MIT and OFL”.
(In reply to code from comment #8) > > - Why are node_modules symbolic links to node_modules_prod? Why not put them directly at node_modules? > > This is taken directly from the template at > https://docs.fedoraproject.org/en-US/packaging-guidelines/Node.js/ > #_using_tarballs_for_bundling. I do not know the original rationale. > > ----- > > > - Why do you convert the Markdown files to HTML? > > It seemed like it would be useful to have them available in a > browser-friendly format. In retrospect, this is probably excessive for a > couple of simple files. I have removed the conversion: > > New spec URL: https://music.fedorapeople.org/fx-20.0.2-2/fx.spec > New SRPM URL: > https://music.fedorapeople.org/fx-20.0.2-2/fx-20.0.2-2.fc33.src.rpm > > ----- > > > [!]: License field in the package spec file matches the actual license. > > Note: Checking patched sources after %prep for licenses. Licenses > > found: "Unknown or generated", "Expat License", "*No copyright* Expat > > License", "SIL Open Font License 1.1", "SIL Open Font License 1.1 GNU > > General Public License v2.0 or later". 138 files have unknown license. > > Detailed output of licensecheck in > > /home/bob/packaging/review/fx/review-fx/licensecheck.txt > > Are you sure? > No it's ok, I initially thought you add forgotten OFL, I removed my comment but forgot to remove the ! in the fedora-review. Package approved.
Thanks for the review. Repository requested: https://pagure.io/releng/fedora-scm-requests/issue/32926
(fedscm-admin): The Pagure repository was created at https://src.fedoraproject.org/rpms/fx
FEDORA-2021-0eddd66b75 has been submitted as an update to Fedora 34. https://bodhi.fedoraproject.org/updates/FEDORA-2021-0eddd66b75
FEDORA-2021-0eddd66b75 has been pushed to the Fedora 34 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf install --enablerepo=updates-testing --advisory=FEDORA-2021-0eddd66b75 \*` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2021-0eddd66b75 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2021-67aa84d8f4 has been pushed to the Fedora 34 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2021-67aa84d8f4` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2021-67aa84d8f4 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2021-67aa84d8f4 has been pushed to the Fedora 34 stable repository. If problem still persists, please make note of it in this bug report.