Bug 912816 - Review Request: kyua-testers - Scriptable tester interfaces
Summary: Review Request: kyua-testers - Scriptable tester interfaces
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Mario Blättermann
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-02-19 18:25 UTC by Julio Merino
Modified: 2013-12-28 23:37 UTC (History)
3 users (show)

Fixed In Version: kyua-testers-0.2-1.fc20
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-12-28 23:37:44 UTC
Type: Bug
Embargoed:
mario.blaettermann: fedora-review+
gwync: fedora-cvs+


Attachments (Terms of Use)

Description Julio Merino 2013-02-19 18:25:18 UTC
Spec URL: http://www.NetBSD.org/~jmmv/kyua-testers.spec
SRPM URL: http://www.NetBSD.org/~jmmv/kyua-testers-0.1-1.fc18.src.rpm

This will be necessary for the update of kyua-cli to 0.6 that is forthcoming.

Description:

Kyua (pronounced Q.A.) is a testing framework for both developers and
users.  Kyua is different from most other testing frameworks in that it
puts the end user experience before anything else.  There are multiple
reasons for users to run the tests themselves, and Kyua ensures that
they can do so in the most convenient way.

This module, kyua-testers, provides scriptable interfaces to interact
with test programs of various kinds.  The interface of such testers
allows the caller to execute a single test case of a single test program
in a controlled and homogeneous manner.

Comment 1 Mario Blättermann 2013-06-06 17:59:30 UTC
Scratch build:
http://koji.fedoraproject.org/koji/taskinfo?taskID=5476746

$ rpmlint -i -v *
kyua-testers.src: I: checking
kyua-testers.src: W: spelling-error %description -l en_US scriptable -> scrip table, scrip-table, script able
The value of this tag appears to be misspelled. Please double-check.

kyua-testers.src: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers.src: I: checking-url http://kyua.googlecode.com/files/kyua-testers-0.1.tar.gz (timeout 10 seconds)
kyua-testers.src: W: invalid-url Source0: http://kyua.googlecode.com/files/kyua-testers-0.1.tar.gz HTTP Error 404: Not Found
The value should be a valid, public HTTP, HTTPS, or FTP URL.

kyua-testers.i686: I: checking
kyua-testers.i686: W: spelling-error %description -l en_US scriptable -> scrip table, scrip-table, script able
The value of this tag appears to be misspelled. Please double-check.

kyua-testers.i686: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers.i686: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/cli_test
kyua-testers.i686: E: missing-call-to-setgroups /usr/libexec/kyua-atf-tester
kyua-testers.i686: E: missing-call-to-setgroups /usr/libexec/kyua-plain-tester
kyua-testers.i686: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/run_test
kyua-testers.i686: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/stacktrace_test
kyua-testers.x86_64: I: checking
kyua-testers.x86_64: W: spelling-error %description -l en_US scriptable -> scrip table, scrip-table, script able
The value of this tag appears to be misspelled. Please double-check.

kyua-testers.x86_64: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/cli_test
kyua-testers.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-atf-tester
kyua-testers.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-plain-tester
kyua-testers.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/run_test
kyua-testers.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/stacktrace_test
kyua-testers-debuginfo.i686: I: checking
kyua-testers-debuginfo.i686: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-debuginfo.x86_64: I: checking
kyua-testers-debuginfo.x86_64: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-devel.i686: I: checking
kyua-testers-devel.i686: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-devel.i686: W: no-documentation
The package contains no documentation (README, doc, etc). You have to include
documentation files.

kyua-testers-devel.x86_64: I: checking
kyua-testers-devel.x86_64: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-devel.x86_64: W: no-documentation
The package contains no documentation (README, doc, etc). You have to include
documentation files.

kyua-testers.spec: I: checking-url http://kyua.googlecode.com/files/kyua-testers-0.1.tar.gz (timeout 10 seconds)
kyua-testers.spec: W: invalid-url Source0: http://kyua.googlecode.com/files/kyua-testers-0.1.tar.gz HTTP Error 404: Not Found
The value should be a valid, public HTTP, HTTPS, or FTP URL.

kyua-testers-tests.i686: I: checking
kyua-testers-tests.i686: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-tests.i686: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/cli_test
kyua-testers-tests.i686: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/run_test
kyua-testers-tests.i686: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/stacktrace_test
kyua-testers-tests.x86_64: I: checking
kyua-testers-tests.x86_64: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-tests.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/cli_test
kyua-testers-tests.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/run_test
kyua-testers-tests.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/stacktrace_test
9 packages and 1 specfiles checked; 16 errors, 7 warnings.


Unavailable Googlecode URLs are a common problem. Don't bother with it, the tarball is downloadable using wget.

Spelling errors are ignorable.

"missing-call-to-setgroups"
Don't know what this means, it is not mentioned in the wiki. Needs to be investigated.

README.fedora is superfluous in the -tests package. The main package is present when installing the tests, so the file is available anyway.

%{name} = %{version}-%{release}
has to be
%{name}%{?_isa} = %{version}-%{release}
for multiarch packages.

Comment 2 Julio Merino 2013-06-15 20:51:00 UTC
Mario, thanks for taking a look.

The changes I have done:

- Removed the README.Fedora file from the main package as its contents are specific to the -tests subpackage.
- Added the %{?_isa} chunk to all dependency specifications on libraries.  Not sure if that's what you meant, but that's what I seem to understand from the packaging guidelines.

However:

- I don't know what to do about missing-call-to-setgroups.  I cannot find any documentation on this check.  FWIW, rebuilding other packages that are already checked in results in this same warning even when such warning did not show up months ago.  It seems a new rule.

I've had to move the new files here:

ftp://ftp.NetBSD.org/pub/NetBSD/misc/jmmv/fedora/kyua-testers.spec
ftp://ftp.NetBSD.org/pub/NetBSD/misc/jmmv/fedora/kyua-testers-0.1-1.fc18.src.rpm

Can you please take another look?  Thanks!

Comment 3 Mario Blättermann 2013-06-20 18:05:26 UTC
(In reply to Julio Merino from comment #2)
> - I don't know what to do about missing-call-to-setgroups.  I cannot find
> any documentation on this check.  FWIW, rebuilding other packages that are
> already checked in results in this same warning even when such warning did
> not show up months ago.  It seems a new rule.
> 
You should ask in the packagers list <packaging.org> what this means and how to handle it. It's an error, not a warning, so it should be considered as serious for the time being.

I take this for a full review.

Comment 4 Christopher Meng 2013-07-22 02:58:51 UTC
missing-call-to-setgroups has been renamed to missing-call-to-setgroups-before-setuid.

This will be available in the next version.

And the explanation is:

This executable is calling setuid and setgid without setgroups or initgroups.
There is a high probability this mean it didn't relinquish all groups, and this
would be a potential security issue to be fixed. Seek POS36-C on the web for
details about the problem.

Ref POS36-C:

https://www.securecoding.cert.org/confluence/display/seccode/POS36-C.+Observe+correct+revocation+order+while+relinquishing+privileges

Comment 5 Mario Blättermann 2013-09-15 18:36:17 UTC
Any progress here?

Comment 6 Mario Blättermann 2013-10-31 19:08:21 UTC
No response from the package submitter for more than three months. If nothing happens next two weeks, I consider to close this ticket.

Comment 7 Julio Merino 2013-11-24 04:05:44 UTC
Wow, sorry for the looooong delay in replying.  I haven't been paying attention to neither Kyua nor Fedora for a long time for various personal reasons... and recently just got back to them.

Regarding the missing-call-to-setgroups-before-setuid warning: it's true that the code does not call setgroups, but this is not a real "problem".  The code in the "tester" binaries implements logic to drop privileges for test cases that request it, but this is _NOT_ intended to be a security feature and is documented as such.  (Mind you, it's the test that chooses to request lower privileges, not the user, so this really is not about security.)  Adding a call to setgroups() would only silence this specific warning but would do nothing to improve security.  I think this warning just needs to be ignored here.

Comment 8 Christopher Meng 2013-11-24 09:42:14 UTC
(In reply to Julio Merino from comment #7)

Yes, it's more like a warning now for packagers.

Hope will Mario will do the review soon.

Thanks.

Comment 9 Mario Blättermann 2013-11-24 16:55:58 UTC
Scratch build fails:
http://koji.fedoraproject.org/koji/taskinfo?taskID=6219513

It is due to an unresolvable dependency in Rawhide:
DEBUG util.py:266:  Error: Package: kyua-cli-0.5-3.fc19.i686 (build)
DEBUG util.py:266:             Requires: liblutok.so.0

New attempt for f20:
http://koji.fedoraproject.org/koji/taskinfo?taskID=6219521

Same dependency problem there. The current lutok-0.3 package has liblutok.so.2, the mentioned liblutok.so.0 is in the f19 package only. Seems to be a problem in kyua-cli, which pulls lutok. It has to be resolved before we can continue on this review. There are still f19 packages for kyua-cli in Rawhide, so I assume it has build problems.

And last but not least an issue from build.log:
»warning: bogus date in %changelog: Mon Feb 19 2013 Julio Merino <julio> 0.1-1«

Comment 10 Julio Merino 2013-11-24 18:29:56 UTC
So the issue with kyua-cli is that somebody attempted to upgrade it to 0.6, committed the results, but I guess didn't even try to build the package.  kyua-cli-0.6 requires kyua-testers, so no new versions can be built against the right version of liblutok at the moment.

Question: Is it an OK procedure if I revert the bogus update of kyua-cli to 0.5 and rebuild a working version?  Because no binaries have been built for 0.6 yet, I suppose this is fine.  Alternatively I'd tweak the initial addition of kyua-testers to not require kyua-cli.

Comment 11 Mario Blättermann 2013-11-24 19:29:32 UTC
Don't understand completely. The kyua-testers package is needed for updating kyua to 0.6, but we require kyua-cli. This is an unresolvable ping-pong dependency, as far as I can evaluate. As you see in the scratch builds, they fail already with kyua-cli-0.5. I'm a bit confused about this situation.

Comment 12 Julio Merino 2013-11-24 19:46:02 UTC
kyua-testers _only_ needs kyua-cli because of the %check target in the spec file.  Getting rid of that would also let us kill the BuildRequires stanza on kyua-cli and not introduce any cycles.  But doing so means we lose the execution of the tests for kyua-testers during the build of a package; not a huge deal given that these can be run later via the -tests subpackage.

The reason I sent it this way is because I thought that this could be OK as long as at least one build for kyua-cli existed in the tree.  (This build could exist with kyua-cli-0.5 if fixed.) 

What do you suggest?

Comment 13 Mario Blättermann 2013-11-24 20:00:09 UTC
I suggest to disable the %check section for the time being so that I can do a proper scratch build and approve your package, unless some other blocker issues come up. This way we get the package at least into Rawhide and you might re-enable the tests once kyua-cli has the right version. Well, we would have a ping-pong-scenario similar to that one I already mentioned, but it would work as long as both packages are available from the repos. Currently, with one repo package and one which has to be scratch-built it wouldn't work. Is this imagineable for you to do so?

BTW, instead of disabling the checks you could add a condition which makes it more simple to switch them on and off:

%global with_checks 1

Then, in the %check section itself, you use the if/then constructs to enable/disable it.

Moreover, you are using the %define macro. In most cases, %global is the better choice. See http://fedoraproject.org/wiki/Packaging:Guidelines#.25global_preferred_over_.25define.

Comment 14 Julio Merino 2013-11-25 01:34:31 UTC
Alright, so:

- Changed %define with %global.
- Added a %_with_checks global, defaulting to 0 for now.
- Updated the changelog entry, which apparently also fixes the date.

Because of the new %_with_checks, it is not worth attempting to fix the current kyua-cli package.  It's just easier and better to finish this package and properly update kyua-cli to 0.7 which should "just work".

New URLs (because of the SRPM name change):

Spec URL: http://www.NetBSD.org/~jmmv/kyua-testers.spec
SRPM URL: http://www.NetBSD.org/~jmmv/kyua-testers-0.1-1.fc20.src.rpm

Thanks!

Comment 15 Mario Blättermann 2013-11-25 19:24:15 UTC
(In reply to Julio Merino from comment #14)
> SRPM URL: http://www.NetBSD.org/~jmmv/kyua-testers-0.1-1.fc20.src.rpm

"Not Found

The requested URL /~jmmv/kyua-testers-0.1-1.fc20.src.rpm was not found on this server."

And as far as I can see, the spec file is the previous one.

Comment 16 Julio Merino 2013-11-25 19:50:26 UTC
Oops, my fault... I confused the servers in which these live due to copy/paste and did not validate the links after hand-editing them:

Spec URL: ftp://ftp.NetBSD.org/pub/NetBSD/misc/jmmv/fedora/kyua-testers.spec
SRPM URL: ftp://ftp.NetBSD.org/pub/NetBSD/misc/jmmv/fedora/kyua-testers-0.1-1.fc20.src.rpm

Comment 17 Mario Blättermann 2013-11-25 20:13:42 UTC
Scratch build:
http://koji.fedoraproject.org/koji/taskinfo?taskID=6224362

$ rpmlint -i -v *
kyua-testers.src: I: checking
kyua-testers.src: W: spelling-error %description -l en_US scriptable -> scrip table, scrip-table, script able
The value of this tag appears to be misspelled. Please double-check.

kyua-testers.src: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers.src: I: checking-url http://kyua.googlecode.com/files/kyua-testers-0.1.tar.gz (timeout 10 seconds)
kyua-testers.src: W: invalid-url Source0: http://kyua.googlecode.com/files/kyua-testers-0.1.tar.gz HTTP Error 404: Not Found
The value should be a valid, public HTTP, HTTPS, or FTP URL.

kyua-testers.armv7hl: I: checking
kyua-testers.armv7hl: W: spelling-error %description -l en_US scriptable -> scrip table, scrip-table, script able
The value of this tag appears to be misspelled. Please double-check.

kyua-testers.armv7hl: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers.armv7hl: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/cli_test
kyua-testers.armv7hl: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/run_test
kyua-testers.armv7hl: E: missing-call-to-setgroups /usr/libexec/kyua-atf-tester
kyua-testers.armv7hl: E: missing-call-to-setgroups /usr/libexec/kyua-plain-tester
kyua-testers.armv7hl: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/stacktrace_test
kyua-testers.i686: I: checking
kyua-testers.i686: W: spelling-error %description -l en_US scriptable -> scrip table, scrip-table, script able
The value of this tag appears to be misspelled. Please double-check.

kyua-testers.i686: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers.i686: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/cli_test
kyua-testers.i686: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/run_test
kyua-testers.i686: E: missing-call-to-setgroups /usr/libexec/kyua-atf-tester
kyua-testers.i686: E: missing-call-to-setgroups /usr/libexec/kyua-plain-tester
kyua-testers.i686: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/stacktrace_test
kyua-testers.x86_64: I: checking
kyua-testers.x86_64: W: spelling-error %description -l en_US scriptable -> scrip table, scrip-table, script able
The value of this tag appears to be misspelled. Please double-check.

kyua-testers.x86_64: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/cli_test
kyua-testers.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/run_test
kyua-testers.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-atf-tester
kyua-testers.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-plain-tester
kyua-testers.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/stacktrace_test
kyua-testers-debuginfo.armv7hl: I: checking
kyua-testers-debuginfo.armv7hl: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-debuginfo.i686: I: checking
kyua-testers-debuginfo.i686: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-debuginfo.x86_64: I: checking
kyua-testers-debuginfo.x86_64: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-devel.armv7hl: I: checking
kyua-testers-devel.armv7hl: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-devel.armv7hl: W: no-documentation
The package contains no documentation (README, doc, etc). You have to include
documentation files.

kyua-testers-devel.i686: I: checking
kyua-testers-devel.i686: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-devel.i686: W: no-documentation
The package contains no documentation (README, doc, etc). You have to include
documentation files.

kyua-testers-devel.x86_64: I: checking
kyua-testers-devel.x86_64: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-devel.x86_64: W: no-documentation
The package contains no documentation (README, doc, etc). You have to include
documentation files.

kyua-testers.spec: I: checking-url http://kyua.googlecode.com/files/kyua-testers-0.1.tar.gz (timeout 10 seconds)
kyua-testers.spec: W: invalid-url Source0: http://kyua.googlecode.com/files/kyua-testers-0.1.tar.gz HTTP Error 404: Not Found
The value should be a valid, public HTTP, HTTPS, or FTP URL.

kyua-testers-tests.armv7hl: I: checking
kyua-testers-tests.armv7hl: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-tests.armv7hl: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/cli_test
kyua-testers-tests.armv7hl: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/run_test
kyua-testers-tests.armv7hl: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/stacktrace_test
kyua-testers-tests.i686: I: checking
kyua-testers-tests.i686: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-tests.i686: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/cli_test
kyua-testers-tests.i686: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/run_test
kyua-testers-tests.i686: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/stacktrace_test
kyua-testers-tests.x86_64: I: checking
kyua-testers-tests.x86_64: I: checking-url http://code.google.com/p/kyua/ (timeout 10 seconds)
kyua-testers-tests.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/cli_test
kyua-testers-tests.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/run_test
kyua-testers-tests.x86_64: E: missing-call-to-setgroups /usr/libexec/kyua-testers/tests/stacktrace_test
13 packages and 1 specfiles checked; 24 errors, 9 warnings.


The missing-call-to-setgroups warning was already discussed. So there remain a Googlecode package which can't be downloaded, some ignorable spelling errors and a -devel package without docs. The Googlecode stuff is known for not being downloadable by rpmlint (whatever it uses for), I can fetch it using wget. We don't have any docs which we could ship in the -devel package.


OK, here we go:

---------------------------------
key:

[+] OK
[.] OK, not applicable
[X] needs work
---------------------------------

[+] MUST: rpmlint must be run on the source rpm and all binary rpms the build produces. The output should be posted in the review.
[+] MUST: The package must be named according to the Package Naming Guidelines.
[+] MUST: The spec file name must match the base package %{name}, in the format %{name}.spec unless your package has an exemption.
[+] MUST: The package must meet the Packaging Guidelines.
[+] MUST: The package must be licensed with a Fedora approved license and meet the Licensing Guidelines.
[+] MUST: The License field in the package spec file must match the actual license.
    BSD
[+] MUST: If (and only if) the source package includes the text of the license(s) in its own file, then that file, containing the text of the license(s) for the package must be included in %doc.
[+] MUST: The spec file must be written in American English.
[+] MUST: The spec file for the package MUST be legible.
[+] MUST: The sources used to build the package must match the upstream source, as provided in the spec URL. Reviewers should use sha256sum for this task as it is used by the sources file once imported into git. If no upstream URL can be specified for this package, please see the Source URL Guidelines for how to deal with this.
    $ sha256sum *
    08f30eef2c967c5451f858ed63c0c4647899d634fcb32dc5fe5fbdb3e0170e49  kyua-testers-0.1.tar.gz
    08f30eef2c967c5451f858ed63c0c4647899d634fcb32dc5fe5fbdb3e0170e49  kyua-testers-0.1.tar.gz.orig

[+] MUST: The package MUST successfully compile and build into binary rpms on at least one primary architecture.
[.] MUST: If the package does not successfully compile, build or work on an architecture, then those architectures should be listed in the spec in ExcludeArch. Each architecture listed in ExcludeArch MUST have a bug filed in bugzilla, describing the reason that the package does not compile/build/work on that architecture. The bug number MUST be placed in a comment, next to the corresponding ExcludeArch line.
[+] MUST: All build dependencies must be listed in BuildRequires, except for any that are listed in the exceptions section of the Packaging Guidelines ; inclusion of those as BuildRequires is optional. Apply common sense.
[.] MUST: The spec file MUST handle locales properly. This is done by using the %find_lang macro. Using %{_datadir}/locale/* is strictly forbidden.
[.] MUST: Every binary RPM package (or subpackage) which stores shared library files (not just symlinks) in any of the dynamic linker's default paths, must call ldconfig in %post and %postun.
[.] MUST: Packages must NOT bundle copies of system libraries.
[.] MUST: If the package is designed to be relocatable, the packager must state this fact in the request for review, along with the rationalization for relocation of that specific package. Without this, use of Prefix: /usr is considered a blocker.
[+] MUST: A package must own all directories that it creates. If it does not create a directory that it uses, then it should require a package which does create that directory.
[+] MUST: A Fedora package must not list a file more than once in the spec file's %files listings. (Notable exception: license texts in specific situations)
[+] MUST: Permissions on files must be set properly. Executables should be set with executable permissions, for example.
[+] MUST: Each package must consistently use macros.
[+] MUST: The package must contain code, or permissable content.
[.] MUST: Large documentation files must go in a -doc subpackage. (The definition of large is left up to the packager's best judgement, but is not restricted to size. Large can refer to either size or quantity).
[+] MUST: If a package includes something as %doc, it must not affect the runtime of the application. To summarize: If it is in %doc, the program must run properly if it is not present.
[.] MUST: Static libraries must be in a -static package.
[+] MUST: Development files must be in a -devel package.
[+] MUST: In the vast majority of cases, devel packages must require the base package using a fully versioned dependency: Requires: %{name}%{?_isa} = %{version}-%{release}
[.] MUST: Packages must NOT contain any .la libtool archives, these must be removed in the spec if they are built.
[.] MUST: Packages containing GUI applications must include a %{name}.desktop file, and that file must be properly installed with desktop-file-install in the %install section. If you feel that your packaged GUI application does not need a .desktop file, you must put a comment in the spec file with your explanation.
[+] MUST: Packages must not own files or directories already owned by other packages. The rule of thumb here is that the first package to be installed should own the files or directories that other packages may rely upon. This means, for example, that no package in Fedora should ever share ownership with any of the files or directories owned by the filesystem or man package. If you feel that you have a good reason to own a file or directory that another package owns, then please present that at package review time. 
[+] MUST: All filenames in rpm packages must be valid UTF-8.


[.] SHOULD: If the source package does not include license text(s) as a separate file from upstream, the packager SHOULD query upstream to include it.
[.] SHOULD: The description and summary sections in the package spec file should contain translations for supported Non-English languages, if available.
[+] SHOULD: The reviewer should test that the package builds in mock.
    See Koji build above (which uses Mock anyway).
[+] SHOULD: The package should compile and build into binary rpms on all supported architectures.
[.] SHOULD: The reviewer should test that the package functions as described. A package should not segfault instead of running, for example.
[+] SHOULD: If scriptlets are used, those scriptlets must be sane. This is vague, and left up to the reviewers judgement to determine sanity.
[+] SHOULD: Usually, subpackages other than devel should require the base package using a fully versioned dependency.
[+] SHOULD: The placement of pkgconfig(.pc) files depends on their usecase, and this is usually for development purposes, so should be placed in a -devel pkg. A reasonable exception is that the main pkg itself is a devel tool not installed in a user runtime, e.g. gcc or gdb.
[.] SHOULD: If the package has file dependencies outside of /etc, /bin, /sbin, /usr/bin, or /usr/sbin consider requiring the package which provides the file instead of the file itself.
[.] SHOULD: your package should contain man pages for binaries/scripts. If it doesn't, work with upstream to add them where they make sense.


----------------

PACKAGE APPROVED

----------------

Comment 18 Julio Merino 2013-11-25 20:21:27 UTC
Thank you Mario, and apologies for the long delays in the process.

New Package SCM Request
=======================
Package Name: kyua-testers
Short Description: Automated testing framework (Scriptable tester interfaces)
Owners: jmmv
Branches: f20
InitialCC:

Comment 19 Gwyn Ciesla 2013-11-26 13:21:13 UTC
Git done (by process-git-requests).

Comment 20 Fedora Update System 2013-11-26 14:14:03 UTC
kyua-testers-0.1-1.fc20 has been submitted as an update for Fedora 20.
https://admin.fedoraproject.org/updates/kyua-testers-0.1-1.fc20

Comment 21 Julio Merino 2013-11-26 14:15:40 UTC
Package committed, new builds pushed to rawhide and f20 and update to f20 requested.  Will leave it up to bodhi to close this bug when the latter happens.

Thanks all!

Now, to fix the build of kyua-cli...

Comment 22 Fedora Update System 2013-11-26 18:02:29 UTC
kyua-testers-0.1-1.fc20 has been pushed to the Fedora 20 testing repository.

Comment 23 Fedora Update System 2013-12-08 14:14:14 UTC
kyua-testers-0.2-1.fc20 has been submitted as an update for Fedora 20.
https://admin.fedoraproject.org/updates/kyua-testers-0.2-1.fc20

Comment 24 Fedora Update System 2013-12-28 23:37:44 UTC
kyua-testers-0.2-1.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.