Bug 575504 - (metagoofil) Review Request: metagoofil - Metadata analyzer, information gathering tool
Review Request: metagoofil - Metadata analyzer, information gathering tool
Status: CLOSED ERRATA
Product: Fedora
Classification: Fedora
Component: Package Review (Show other bugs)
12
All Linux
low Severity medium
: ---
: ---
Assigned To: Tomas Mraz
Fedora Extras Quality Assurance
http://www.edge-security.com/metagoof...
:
Depends On:
Blocks: FE-SECLAB
  Show dependency treegraph
 
Reported: 2010-03-20 23:07 EDT by Michal Ambroz
Modified: 2010-09-01 22:27 EDT (History)
7 users (show)

See Also:
Fixed In Version: metagoofil-1.4a-5.el5
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2010-04-23 18:52:21 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
tmraz: fedora‑review+
kevin: fedora‑cvs+


Attachments (Terms of Use)

  None (edit)
Description Michal Ambroz 2010-03-20 23:07:57 EDT
Spec URL: http://rebus.webz.cz/d/metagoofil.spec
SRPM URL: http://rebus.webz.cz/d/metagoofil-1.4a-1.fc12.src.rpm2
License: GPLv2

Description: 
Metagoofil is an information gathering tool designed for extracting metadata
of public documents (pdf,doc,xls,ppt,odp,ods) availables in the target/victim
websites.


Hello, 
please would be someone so kind and willing to do review 
of the metagoofil package for fedora? 
I do not have any package in Fedora sofar so I would 
humbly ask for sponsoring as well.

Output from the rpmlint :
$rpmlint /home/rebus/rpmbuild/SRPMS/metagoofil-1.4a-1.fc12.src.rpm /home/rebus/rpmbuild/RPMS/noarch/metagoofil-1.4a-1.fc12.noarch.rpm
metagoofil.src: W: spelling-error %description -l en_US pdf -> pd, pf, pd f
metagoofil.src: W: spelling-error %description -l en_US xls -> ls, xis, x ls
metagoofil.src: W: spelling-error %description -l en_US ppt -> opt, pot, ppr
metagoofil.src: W: spelling-error %description -l en_US odp -> op, pod, ode
metagoofil.src: W: spelling-error %description -l en_US ods -> dos, ids, odd
- list of supported document types in the description

metagoofil.noarch: E: explicit-lib-dependency libextractor
- explicit dependency is needed because it is executed from the perl script and is not detected automatically

metagoofil.noarch: W: spelling-error %description -l en_US pdf -> pd, pf, pd f
metagoofil.noarch: W: spelling-error %description -l en_US xls -> ls, xis, x ls
metagoofil.noarch: W: spelling-error %description -l en_US ppt -> opt, pot, ppr
metagoofil.noarch: W: spelling-error %description -l en_US odp -> op, pod, ode
metagoofil.noarch: W: spelling-error %description -l en_US ods -> dos, ids, odd
- list of supported document types in the description

2 packages and 0 specfiles checked; 1 errors, 10 warnings.

Thank you.    
Michal Ambroz
Comment 1 Alex Orlandi 2010-03-21 06:48:51 EDT
(In reply to comment #0)

Informal review

> SRPM URL: http://rebus.webz.cz/d/metagoofil-1.4a-1.fc12.src.rpm2
 - there's a typo in the url of the src.rpm (trailing "2")

> [...] 
> 
> Output from the rpmlint :
> $rpmlint /home/rebus/rpmbuild/SRPMS/metagoofil-1.4a-1.fc12.src.rpm
> /home/rebus/rpmbuild/RPMS/noarch/metagoofil-1.4a-1.fc12.noarch.rpm
> metagoofil.src: W: spelling-error %description -l en_US pdf -> pd, pf, pd f
> [...]
> metagoofil.src: W: spelling-error %description -l en_US ods -> dos, ids, odd
> - list of supported document types in the description

   - use CAPITALS for file extensions (i.e.: use PDF instead of pdf)

> metagoofil.noarch: E: explicit-lib-dependency libextractor
> - explicit dependency is needed because it is executed from the perl script and is not detected automatically

   - In general rpmlint suggests that "You must let rpm find the library dependencies by itself. Do not put unneeded explicit Requires: tags."
    Anyway in this case it is quite probable that rpm can't find the dependency, so should be ok.


> metagoofil.noarch: W: spelling-error %description -l en_US pdf -> pd, pf, pd f
> [...]
> metagoofil.noarch: W: spelling-error %description -l en_US ods -> dos, ids, odd
> - list of supported document types in the description

   - same of above (capitalize)
Comment 2 Michal Ambroz 2010-03-21 08:40:26 EDT
Hello Alex,
thanks for the tips - with capitalizations rpmlint doesn't complain about the abreviations of format extensions
Here is the rebuild package.

SPEC URL: http://rebus.webz.cz/d/metagoofil.spec
SRPM URL: http://rebus.webz.cz/d/metagoofil-1.4a-2.fc12.src.rpm

> Anyway in this case it is quite probable that rpm can't find the
> dependency, so should be ok.
yes that is the point - rpm didn't find the dependency and was ready to install the package when libextractor is not present.

Best regards
Michal Ambroz
Comment 3 Ralf Corsepius 2010-03-21 08:47:44 EDT
(In reply to comment #1)
> > metagoofil.src: W: spelling-error %description -l en_US ods -> dos, ids, odd
> > - list of supported document types in the description
> 
>    - use CAPITALS for file extensions (i.e.: use PDF instead of pdf)
Not quite. This is a bug in rpmlint, which is safe to be ignored.
Comment 4 Michal Ambroz 2010-04-10 20:20:55 EDT
Hello Alex, Ralf,
please are there some outstanding issues you would like me to fix?
Thank you.

Michal Ambroz
Comment 5 Michal Ambroz 2010-04-11 12:45:48 EDT
Output from rpmlint
$rpmlint metagoofil-1.4a-2.fc12.src.rpm metagoofil-1.4a-2.fc12.noarch.rpm
metagoofil.noarch: E: explicit-lib-dependency libextractor
2 packages and 0 specfiles checked; 1 errors, 0 warnings.

Explicit dependency is needed because it is executed from the perl script and
it is not detected automatically

Koji build F12: http://koji.fedoraproject.org/koji/taskinfo?taskID=2108436
Koji build F13: http://koji.fedoraproject.org/koji/taskinfo?taskID=2108500
Koji build rawhide: http://koji.fedoraproject.org/koji/taskinfo?taskID=2108502
Comment 6 Alex Orlandi 2010-04-11 15:04:01 EDT
(In reply to comment #5)
> Output from rpmlint
> $rpmlint metagoofil-1.4a-2.fc12.src.rpm metagoofil-1.4a-2.fc12.noarch.rpm
> metagoofil.noarch: E: explicit-lib-dependency libextractor
> 2 packages and 0 specfiles checked; 1 errors, 0 warnings.
> 
> Explicit dependency is needed because it is executed from the perl script and
> it is not detected automatically
> 
> [...]

You are right. Dependency cannot be resolved automatically so explicit lib dependency is required, in this case.

Anyway it is a python script (not perl): you should add 
"Requires: python..." in spec file

See https://fedoraproject.org/wiki/Packaging:Python for details.
Comment 7 Michal Ambroz 2010-04-11 20:16:37 EDT
Added Requires: python(abi) = 2.6

SPEC URL: http://rebus.fedorapeople.org/fedora/12/SPECS/metagoofil.spec
SRPM URL: http://rebus.fedorapeople.org/fedora/12/SRPMS/metagoofil-1.4a-3.fc12.src.rpm

Best regards
Michal Ambroz
Comment 8 Thomas Spura 2010-04-19 03:48:03 EDT
(In reply to comment #0)
> I do not have any package in Fedora sofar so I would 
> humbly ask for sponsoring as well.

-> blocking FE-NEEDSPONSOR
Comment 9 Michal Ambroz 2010-04-19 05:43:53 EDT
Thomas - I have been sponsored already so I am removing this blocking again.
You can check the status in FAS.
Best regards
Michal Ambroz
Comment 10 Tomas Mraz 2010-04-20 05:57:01 EDT
You could change the Requires: libextractor to Requires: /usr/bin/libextractor-extract, file dependencies on files in bin dirs are fine.

rpmlint -v metagoofil-1.4a-3.fc12.noarch.rpm 
metagoofil.noarch: I: checking
metagoofil.noarch: E: explicit-lib-dependency libextractor
1 packages and 0 specfiles checked; 1 errors, 0 warnings.

You can fix the error by following the suggestion above. However it is not a real error as you use the requires for one of the libextractor files and not for the library itself. So it is up to you if you want to change the requires or not.

rpmlint -v metagoofil-1.4a-3.fc12.src.rpm 
metagoofil.src: I: checking
1 packages and 0 specfiles checked; 0 errors, 0 warnings.

The package is really simple and I reviewed that it conforms to the guidelines.

APPROVED
Comment 11 Michal Ambroz 2010-04-20 09:34:33 EDT
Thank you Tomasi for review.
If it clears the rpmlint and is not against guidelines I will modify dependency to file rather than whole lib. Name of binary is still self-explaining which package is it comming from so no-harm to use it.
Thanks for hint.
Michal Ambroz
Comment 13 Michal Ambroz 2010-04-20 19:47:59 EDT
New Package CVS Request
=======================
Package Name: metagoofil
Short Description: Metadata analyzer, information gathering tool
Owners: rebus
Branches: F-12 F-13 EL-4 EL-5 devel
InitialCC: 

Thank you
Michal Ambroz
Comment 14 Kevin Fenzi 2010-04-21 00:02:04 EDT
CVS done (by process-cvs-requests.py).
Comment 15 Fedora Update System 2010-04-23 04:28:17 EDT
metagoofil-1.4a-4.el4 has been submitted as an update for Fedora EPEL 4.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-4.el4
Comment 16 Fedora Update System 2010-04-23 04:28:23 EDT
metagoofil-1.4a-4.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-4.fc12
Comment 17 Fedora Update System 2010-04-23 04:28:27 EDT
metagoofil-1.4a-4.el5 has been submitted as an update for Fedora EPEL 5.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-4.el5
Comment 18 Fedora Update System 2010-04-23 04:28:35 EDT
metagoofil-1.4a-4.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-4.fc13
Comment 19 Fedora Update System 2010-04-23 18:52:16 EDT
metagoofil-1.4a-4.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 20 Fedora Update System 2010-04-23 18:53:43 EDT
metagoofil-1.4a-4.fc13 has been pushed to the Fedora 13 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 21 Fedora Update System 2010-04-24 17:20:21 EDT
metagoofil-1.4a-5.el4 has been submitted as an update for Fedora EPEL 4.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-5.el4
Comment 22 Fedora Update System 2010-04-24 17:20:26 EDT
metagoofil-1.4a-5.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-5.fc13
Comment 23 Fedora Update System 2010-04-24 17:20:31 EDT
metagoofil-1.4a-5.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-5.fc12
Comment 24 Fedora Update System 2010-04-24 17:20:35 EDT
metagoofil-1.4a-5.el5 has been submitted as an update for Fedora EPEL 5.
http://admin.fedoraproject.org/updates/metagoofil-1.4a-5.el5
Comment 25 Fedora Update System 2010-04-25 09:51:32 EDT
metagoofil-1.4a-5.fc13 has been pushed to the Fedora 13 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 26 Fedora Update System 2010-04-26 22:26:03 EDT
metagoofil-1.4a-5.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 27 Fedora Update System 2010-05-13 21:06:46 EDT
metagoofil-1.4a-5.el4 has been pushed to the Fedora EPEL 4 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 28 Fedora Update System 2010-05-13 21:08:08 EDT
metagoofil-1.4a-5.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 29 Fedora Update System 2010-08-15 16:19:05 EDT
metagoofil-1.4b-1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/metagoofil-1.4b-1.fc12
Comment 30 Fedora Update System 2010-08-15 16:19:10 EDT
metagoofil-1.4b-1.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/metagoofil-1.4b-1.fc13
Comment 31 Fedora Update System 2010-08-15 16:19:16 EDT
metagoofil-1.4b-1.el5 has been submitted as an update for Fedora EPEL 5.
http://admin.fedoraproject.org/updates/metagoofil-1.4b-1.el5
Comment 32 Fedora Update System 2010-08-25 21:01:12 EDT
metagoofil-1.4b-1.fc13 has been pushed to the Fedora 13 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 33 Fedora Update System 2010-08-25 21:05:34 EDT
metagoofil-1.4b-1.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 34 Fedora Update System 2010-09-01 22:27:58 EDT
metagoofil-1.4b-1.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.