Bug 2331188 - Review Request: firetools - graphical user interface for the Firejail security sandbox
Summary: Review Request: firetools - graphical user interface for the Firejail securit...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: All
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Nobody's working on this, feel free to take it
QA Contact: Fedora Extras Quality Assurance
URL: https://firejail.wordpress.com
Whiteboard:
Depends On:
Blocks: FE-NEEDSPONSOR
TreeView+ depends on / blocked
 
Reported: 2024-12-09 17:15 UTC by Brandon Nielsen
Modified: 2024-12-10 19:59 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Brandon Nielsen 2024-12-09 17:15:34 UTC
Spec URL: https://download.copr.fedorainfracloud.org/results/nielsenb/firejail/fedora-rawhide-x86_64/08232246-firetools/firetools.spec
SRPM URL: https://download.copr.fedorainfracloud.org/results/nielsenb/firejail/fedora-rawhide-x86_64/08232246-firetools/firetools-0.9.72-3.fc42.src.rpm
Description: A simple Qt5 based interface for the Firejail security sandbox.
Fedora Account System Username: nielsenb

Note that I have a long stalled review / sponsorship request open[0], not sure if that is relevant or not.

The patch in the specfile has been submitted upstream[1].

[0] - https://bugzilla.redhat.com/show_bug.cgi?id=1350884
[1] - https://github.com/netblue30/firetools/pull/76

Comment 1 solomoncyj 2024-12-10 02:21:38 UTC
lgt5m. but you stated it is a gui application. pluse install desktop-file-utils and generate a .desktop file [0], to gether with a metainfo.xml file[1]

[0] https://docs.fedoraproject.org/en-US/packaging-guidelines/#_desktop_files
[1] https://docs.fedoraproject.org/en-US/packaging-guidelines/AppData/

Comment 2 Fedora Review Service 2024-12-10 05:15:30 UTC
Copr build:
https://copr.fedorainfracloud.org/coprs/build/8371525
(succeeded)

Review template:
https://download.copr.fedorainfracloud.org/results/@fedora-review/fedora-review-2331188-firetools/fedora-rawhide-x86_64/08371525-firetools/fedora-review/review.txt

Please take a look if any issues were found.


---
This comment was created by the fedora-review-service
https://github.com/FrostyX/fedora-review-service

If you want to trigger a new Copr build, add a comment containing new
Spec and SRPM URLs or [fedora-review-service-build] string.

Comment 3 Brandon Nielsen 2024-12-10 19:48:09 UTC
(In reply to solomoncyj from comment #1)
> lgt5m. but you stated it is a gui application. pluse install
> desktop-file-utils and generate a .desktop file [0], to gether with a
> metainfo.xml file[1]
> 
> [0] https://docs.fedoraproject.org/en-US/packaging-guidelines/#_desktop_files
> [1] https://docs.fedoraproject.org/en-US/packaging-guidelines/AppData/

Spec URL: https://download.copr.fedorainfracloud.org/results/nielsenb/firejail/fedora-rawhide-x86_64/08373257-firetools/firetools.spec
SRPM URL: https://download.copr.fedorainfracloud.org/results/nielsenb/firejail/fedora-rawhide-x86_64/08373257-firetools/firetools-0.9.72-4.fc42.src.rpm

Added the desktop file check, as well as appdata checks. Changes to make both checks happy have been submitted upstream[0][1].

[0] - https://github.com/netblue30/firetools/pull/77
[1] - https://github.com/netblue30/firetools/pull/78

Comment 4 Brandon Nielsen 2024-12-10 19:54:05 UTC
(In reply to Fedora Review Service from comment #2)
> Copr build:
> https://copr.fedorainfracloud.org/coprs/build/8371525
> (succeeded)
> 
> Review template:
> https://download.copr.fedorainfracloud.org/results/@fedora-review/fedora-
> review-2331188-firetools/fedora-rawhide-x86_64/08371525-firetools/fedora-
> review/review.txt
> 
> Please take a look if any issues were found.
> 
> 
> ---
> This comment was created by the fedora-review-service
> https://github.com/FrostyX/fedora-review-service
> 
> If you want to trigger a new Copr build, add a comment containing new
> Spec and SRPM URLs or [fedora-review-service-build] string.

Regarding "Sources are verified with gpgverify first in %prep if upstream publishes signatures. Note: gpgverify is not used." I would love to add a gpgverify step[0] as upstream does provide a key[1] and signed hashes. But the published asc[2] file isn't a detached signature so the macro doesn't understand it.

I could feasibly "unarmor" the asc file and then run sha256 sum. Given the security nature of the package, it might be an avenue worth pursuing.

[0] - https://docs.fedoraproject.org/en-US/packaging-guidelines/#_verifying_signatures
[1] - https://firejailtools.wordpress.com/downloads/
[2] - https://sourceforge.net/projects/firejail/files/firetools/firetools-0.9.72.asc/download

Comment 5 Fedora Review Service 2024-12-10 19:56:10 UTC
Copr build:
https://copr.fedorainfracloud.org/coprs/build/8373539
(succeeded)

Review template:
https://download.copr.fedorainfracloud.org/results/@fedora-review/fedora-review-2331188-firetools/fedora-rawhide-x86_64/08373539-firetools/fedora-review/review.txt

Please take a look if any issues were found.


---
This comment was created by the fedora-review-service
https://github.com/FrostyX/fedora-review-service

If you want to trigger a new Copr build, add a comment containing new
Spec and SRPM URLs or [fedora-review-service-build] string.

Comment 6 Fedora Review Service 2024-12-10 19:59:30 UTC
Copr build:
https://copr.fedorainfracloud.org/coprs/build/8373555
(succeeded)

Review template:
https://download.copr.fedorainfracloud.org/results/@fedora-review/fedora-review-2331188-firetools/fedora-rawhide-x86_64/08373555-firetools/fedora-review/review.txt

Please take a look if any issues were found.


---
This comment was created by the fedora-review-service
https://github.com/FrostyX/fedora-review-service

If you want to trigger a new Copr build, add a comment containing new
Spec and SRPM URLs or [fedora-review-service-build] string.


Note You need to log in before you can comment on or make changes to this bug.