Bug 575504 (metagoofil) - Review Request: metagoofil - Metadata analyzer, information gathering tool
Summary: Review Request: metagoofil - Metadata analyzer, information gathering tool
Keywords:
Status: CLOSED ERRATA
Alias: metagoofil
Product: Fedora
Classification: Fedora
Component: Package Review
Version: 12
Hardware: All
OS: Linux
low
medium
Target Milestone: ---
Assignee: Tomas Mraz
QA Contact: Fedora Extras Quality Assurance
URL: http://www.edge-security.com/metagoof...
Whiteboard:
Depends On:
Blocks: FE-SECLAB
TreeView+ depends on / blocked
 
Reported: 2010-03-21 03:07 UTC by Michal Ambroz
Modified: 2010-09-02 02:27 UTC (History)
7 users (show)

Fixed In Version: metagoofil-1.4a-5.el5
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2010-04-23 22:52:21 UTC
Type: ---
Embargoed:
tmraz: fedora-review+
kevin: fedora-cvs+


Attachments (Terms of Use)

Description Michal Ambroz 2010-03-21 03:07:57 UTC
Spec URL: http://rebus.webz.cz/d/metagoofil.spec
SRPM URL: http://rebus.webz.cz/d/metagoofil-1.4a-1.fc12.src.rpm2
License: GPLv2

Description: 
Metagoofil is an information gathering tool designed for extracting metadata
of public documents (pdf,doc,xls,ppt,odp,ods) availables in the target/victim
websites.


Hello, 
please would be someone so kind and willing to do review 
of the metagoofil package for fedora? 
I do not have any package in Fedora sofar so I would 
humbly ask for sponsoring as well.

Output from the rpmlint :
$rpmlint /home/rebus/rpmbuild/SRPMS/metagoofil-1.4a-1.fc12.src.rpm /home/rebus/rpmbuild/RPMS/noarch/metagoofil-1.4a-1.fc12.noarch.rpm
metagoofil.src: W: spelling-error %description -l en_US pdf -> pd, pf, pd f
metagoofil.src: W: spelling-error %description -l en_US xls -> ls, xis, x ls
metagoofil.src: W: spelling-error %description -l en_US ppt -> opt, pot, ppr
metagoofil.src: W: spelling-error %description -l en_US odp -> op, pod, ode
metagoofil.src: W: spelling-error %description -l en_US ods -> dos, ids, odd
- list of supported document types in the description

metagoofil.noarch: E: explicit-lib-dependency libextractor
- explicit dependency is needed because it is executed from the perl script and is not detected automatically

metagoofil.noarch: W: spelling-error %description -l en_US pdf -> pd, pf, pd f
metagoofil.noarch: W: spelling-error %description -l en_US xls -> ls, xis, x ls
metagoofil.noarch: W: spelling-error %description -l en_US ppt -> opt, pot, ppr
metagoofil.noarch: W: spelling-error %description -l en_US odp -> op, pod, ode
metagoofil.noarch: W: spelling-error %description -l en_US ods -> dos, ids, odd
- list of supported document types in the description

2 packages and 0 specfiles checked; 1 errors, 10 warnings.

Thank you.    
Michal Ambroz

Comment 1 Alex Orlandi 2010-03-21 10:48:51 UTC
(In reply to comment #0)

Informal review

> SRPM URL: http://rebus.webz.cz/d/metagoofil-1.4a-1.fc12.src.rpm2
 - there's a typo in the url of the src.rpm (trailing "2")

> [...] 
> 
> Output from the rpmlint :
> $rpmlint /home/rebus/rpmbuild/SRPMS/metagoofil-1.4a-1.fc12.src.rpm
> /home/rebus/rpmbuild/RPMS/noarch/metagoofil-1.4a-1.fc12.noarch.rpm
> metagoofil.src: W: spelling-error %description -l en_US pdf -> pd, pf, pd f
> [...]
> metagoofil.src: W: spelling-error %description -l en_US ods -> dos, ids, odd
> - list of supported document types in the description

   - use CAPITALS for file extensions (i.e.: use PDF instead of pdf)

> metagoofil.noarch: E: explicit-lib-dependency libextractor
> - explicit dependency is needed because it is executed from the perl script and is not detected automatically

   - In general rpmlint suggests that "You must let rpm find the library dependencies by itself. Do not put unneeded explicit Requires: tags."
    Anyway in this case it is quite probable that rpm can't find the dependency, so should be ok.


> metagoofil.noarch: W: spelling-error %description -l en_US pdf -> pd, pf, pd f
> [...]
> metagoofil.noarch: W: spelling-error %description -l en_US ods -> dos, ids, odd
> - list of supported document types in the description

   - same of above (capitalize)

Comment 2 Michal Ambroz 2010-03-21 12:40:26 UTC
Hello Alex,
thanks for the tips - with capitalizations rpmlint doesn't complain about the abreviations of format extensions
Here is the rebuild package.

SPEC URL: http://rebus.webz.cz/d/metagoofil.spec
SRPM URL: http://rebus.webz.cz/d/metagoofil-1.4a-2.fc12.src.rpm

> Anyway in this case it is quite probable that rpm can't find the
> dependency, so should be ok.
yes that is the point - rpm didn't find the dependency and was ready to install the package when libextractor is not present.

Best regards
Michal Ambroz

Comment 3 Ralf Corsepius 2010-03-21 12:47:44 UTC
(In reply to comment #1)
> > metagoofil.src: W: spelling-error %description -l en_US ods -> dos, ids, odd
> > - list of supported document types in the description
> 
>    - use CAPITALS for file extensions (i.e.: use PDF instead of pdf)
Not quite. This is a bug in rpmlint, which is safe to be ignored.

Comment 4 Michal Ambroz 2010-04-11 00:20:55 UTC
Hello Alex, Ralf,
please are there some outstanding issues you would like me to fix?
Thank you.

Michal Ambroz

Comment 5 Michal Ambroz 2010-04-11 16:45:48 UTC
Output from rpmlint
$rpmlint metagoofil-1.4a-2.fc12.src.rpm metagoofil-1.4a-2.fc12.noarch.rpm
metagoofil.noarch: E: explicit-lib-dependency libextractor
2 packages and 0 specfiles checked; 1 errors, 0 warnings.

Explicit dependency is needed because it is executed from the perl script and
it is not detected automatically

Koji build F12: http://koji.fedoraproject.org/koji/taskinfo?taskID=2108436
Koji build F13: http://koji.fedoraproject.org/koji/taskinfo?taskID=2108500
Koji build rawhide: http://koji.fedoraproject.org/koji/taskinfo?taskID=2108502

Comment 6 Alex Orlandi 2010-04-11 19:04:01 UTC
(In reply to comment #5)
> Output from rpmlint
> $rpmlint metagoofil-1.4a-2.fc12.src.rpm metagoofil-1.4a-2.fc12.noarch.rpm
> metagoofil.noarch: E: explicit-lib-dependency libextractor
> 2 packages and 0 specfiles checked; 1 errors, 0 warnings.
> 
> Explicit dependency is needed because it is executed from the perl script and
> it is not detected automatically
> 
> [...]

You are right. Dependency cannot be resolved automatically so explicit lib dependency is required, in this case.

Anyway it is a python script (not perl): you should add 
"Requires: python..." in spec file

See https://fedoraproject.org/wiki/Packaging:Python for details.

Comment 7 Michal Ambroz 2010-04-12 00:16:37 UTC
Added Requires: python(abi) = 2.6

SPEC URL: http://rebus.fedorapeople.org/fedora/12/SPECS/metagoofil.spec
SRPM URL: http://rebus.fedorapeople.org/fedora/12/SRPMS/metagoofil-1.4a-3.fc12.src.rpm

Best regards
Michal Ambroz

Comment 8 Thomas Spura 2010-04-19 07:48:03 UTC
(In reply to comment #0)
> I do not have any package in Fedora sofar so I would 
> humbly ask for sponsoring as well.

-> blocking FE-NEEDSPONSOR

Comment 9 Michal Ambroz 2010-04-19 09:43:53 UTC
Thomas - I have been sponsored already so I am removing this blocking again.
You can check the status in FAS.
Best regards
Michal Ambroz

Comment 10 Tomas Mraz 2010-04-20 09:57:01 UTC
You could change the Requires: libextractor to Requires: /usr/bin/libextractor-extract, file dependencies on files in bin dirs are fine.

rpmlint -v metagoofil-1.4a-3.fc12.noarch.rpm 
metagoofil.noarch: I: checking
metagoofil.noarch: E: explicit-lib-dependency libextractor
1 packages and 0 specfiles checked; 1 errors, 0 warnings.

You can fix the error by following the suggestion above. However it is not a real error as you use the requires for one of the libextractor files and not for the library itself. So it is up to you if you want to change the requires or not.

rpmlint -v metagoofil-1.4a-3.fc12.src.rpm 
metagoofil.src: I: checking
1 packages and 0 specfiles checked; 0 errors, 0 warnings.

The package is really simple and I reviewed that it conforms to the guidelines.

APPROVED

Comment 11 Michal Ambroz 2010-04-20 13:34:33 UTC
Thank you Tomasi for review.
If it clears the rpmlint and is not against guidelines I will modify dependency to file rather than whole lib. Name of binary is still self-explaining which package is it comming from so no-harm to use it.
Thanks for hint.
Michal Ambroz

Comment 13 Michal Ambroz 2010-04-20 23:47:59 UTC
New Package CVS Request
=======================
Package Name: metagoofil
Short Description: Metadata analyzer, information gathering tool
Owners: rebus
Branches: F-12 F-13 EL-4 EL-5 devel
InitialCC: 

Thank you
Michal Ambroz

Comment 14 Kevin Fenzi 2010-04-21 04:02:04 UTC
CVS done (by process-cvs-requests.py).

Comment 15 Fedora Update System 2010-04-23 08:28:17 UTC
metagoofil-1.4a-4.el4 has been submitted as an update for Fedora EPEL 4.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-4.el4

Comment 16 Fedora Update System 2010-04-23 08:28:23 UTC
metagoofil-1.4a-4.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-4.fc12

Comment 17 Fedora Update System 2010-04-23 08:28:27 UTC
metagoofil-1.4a-4.el5 has been submitted as an update for Fedora EPEL 5.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-4.el5

Comment 18 Fedora Update System 2010-04-23 08:28:35 UTC
metagoofil-1.4a-4.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-4.fc13

Comment 19 Fedora Update System 2010-04-23 22:52:16 UTC
metagoofil-1.4a-4.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 20 Fedora Update System 2010-04-23 22:53:43 UTC
metagoofil-1.4a-4.fc13 has been pushed to the Fedora 13 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 21 Fedora Update System 2010-04-24 21:20:21 UTC
metagoofil-1.4a-5.el4 has been submitted as an update for Fedora EPEL 4.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-5.el4

Comment 22 Fedora Update System 2010-04-24 21:20:26 UTC
metagoofil-1.4a-5.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-5.fc13

Comment 23 Fedora Update System 2010-04-24 21:20:31 UTC
metagoofil-1.4a-5.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-5.fc12

Comment 24 Fedora Update System 2010-04-24 21:20:35 UTC
metagoofil-1.4a-5.el5 has been submitted as an update for Fedora EPEL 5.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-5.el5

Comment 25 Fedora Update System 2010-04-25 13:51:32 UTC
metagoofil-1.4a-5.fc13 has been pushed to the Fedora 13 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 26 Fedora Update System 2010-04-27 02:26:03 UTC
metagoofil-1.4a-5.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 27 Fedora Update System 2010-05-14 01:06:46 UTC
metagoofil-1.4a-5.el4 has been pushed to the Fedora EPEL 4 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 28 Fedora Update System 2010-05-14 01:08:08 UTC
metagoofil-1.4a-5.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 29 Fedora Update System 2010-08-15 20:19:05 UTC
metagoofil-1.4b-1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/metagoofil-1.4b-1.fc12

Comment 30 Fedora Update System 2010-08-15 20:19:10 UTC
metagoofil-1.4b-1.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/metagoofil-1.4b-1.fc13

Comment 31 Fedora Update System 2010-08-15 20:19:16 UTC
metagoofil-1.4b-1.el5 has been submitted as an update for Fedora EPEL 5.
http://admin.fedoraproject.org/updates/metagoofil-1.4b-1.el5

Comment 32 Fedora Update System 2010-08-26 01:01:12 UTC
metagoofil-1.4b-1.fc13 has been pushed to the Fedora 13 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 33 Fedora Update System 2010-08-26 01:05:34 UTC
metagoofil-1.4b-1.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 34 Fedora Update System 2010-09-02 02:27:58 UTC
metagoofil-1.4b-1.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.