Re: Self Introduction: Yunmei Li

2022-02-20 Thread Yunmei LI
Hi, Thanks for your suggestion, and I will rework my package based on your comments. A question by the way: I built an epel package on CentOS7, my package will depend on cmake 3.18 when it is building___ devel mailing list --

Re: Preventing account takeovers through expired domains

2022-02-20 Thread Kevin Fenzi
On Sun, Feb 20, 2022 at 04:43:13PM -0800, Gary Buhrmaster wrote: > On Sun, Feb 20, 2022, 16:09 Adam Williamson > wrote: > > > It used to support these, but the support was lost with the recent > > rewrite. However, it supports Google Authenticator-style OTPs. Folks > > with infra privileges on

email / IRC notifications (FMN)

2022-02-20 Thread Ryan Lerch
Hi all, I am currently trying to open a UI / UX review of the FMN / Notifications system and just chasing isome raw feedback on how you all get notifications (email / IRC / or otherwise) when developing / packaging / working on Fedora. Please check out the following discussion thread to log your

[Bug 2032428] perl-RDF-Trine for EPEL 9

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2032428 Bug 2032428 depends on bug 2048959, which changed state. Bug 2048959 Summary: Add perl-GraphViz to EPEL9 https://bugzilla.redhat.com/show_bug.cgi?id=2048959 What|Removed |Added

[Bug 2048959] Add perl-GraphViz to EPEL9

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2048959 Fedora Update System changed: What|Removed |Added Fixed In Version||perl-GraphViz-2.24-19.el9

Re: Preventing account takeovers through expired domains

2022-02-20 Thread Gary Buhrmaster
On Sun, Feb 20, 2022, 16:09 Adam Williamson wrote: > It used to support these, but the support was lost with the recent > rewrite. However, it supports Google Authenticator-style OTPs. Folks > with infra privileges on their accounts (like me) are already required > to use these. It works fine. I

Re: Preventing account takeovers through expired domains

2022-02-20 Thread Adam Williamson
On Sun, 2022-02-20 at 16:42 +, Gary Buhrmaster wrote: > Unfortunately, last I checked, the FAS account > system did not support adding something > like a FIDO2 security key to an account(**). > Even if it did, I suspect not all the other parts > of the system would support FIDO keys. It used

Re: Failed OpenQA tests for zchunk update - how to troubleshoot?

2022-02-20 Thread Adam Williamson
On Sun, 2022-02-20 at 20:26 +, Jonathan Dieter wrote: > I've just pushed zchunk-1.2.0 to all active Fedora branches, and it's > passed the (admittedly non-comprehensive) zchunk test suite, but I'm > seeing 2 OpenQA failed tests in Bodhi: > >

[Bug 2056250] perl-CPAN-Perl-Releases-5.20220220 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056250 --- Comment #1 from Fedora Update System --- FEDORA-2022-41f918f7db has been submitted as an update to Fedora 35. https://bodhi.fedoraproject.org/updates/FEDORA-2022-41f918f7db -- You are receiving this mail because: You are on the CC list

[Bug 2056250] perl-CPAN-Perl-Releases-5.20220220 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056250 --- Comment #2 from Fedora Update System --- FEDORA-2022-75d9ca78f3 has been submitted as an update to Fedora 34. https://bodhi.fedoraproject.org/updates/FEDORA-2022-75d9ca78f3 -- You are receiving this mail because: You are on the CC list

[Bug 2056250] perl-CPAN-Perl-Releases-5.20220220 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056250 Jitka Plesnikova changed: What|Removed |Added Status|ASSIGNED|MODIFIED Fixed In Version|

Planning to start unifying native and mingw packages

2022-02-20 Thread Sandro Mani
Hi Following recent discussions and to reduce the maintenance burden, I'm planning to start merging native and mingw packages. Initially, I'll be looking at these packages where I maintain both variants: eigen3 mingw-eigen3 enchant2 mingw-enchant2 freeimage mingw-freeimage gdal mingw-gdal

Fedora-36-20220220.n.0 compose check report

2022-02-20 Thread Fedora compose checker
No missing expected images. Failed openQA tests: 92/229 (x86_64), 60/161 (aarch64) New failures (same test not failed in Fedora-36-20220219.n.0): ID: 1138743 Test: x86_64 Workstation-upgrade gnome_text_editor URL: https://openqa.fedoraproject.org/tests/1138743 ID: 1138820 Test: x86_64

[Bug 2056250] perl-CPAN-Perl-Releases-5.20220220 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056250 Jitka Plesnikova changed: What|Removed |Added Doc Type|--- |If docs needed, set a value

[Bug 2056253] perl-Module-CoreList-5.20220220 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056253 Jitka Plesnikova changed: What|Removed |Added Doc Type|--- |If docs needed, set a value Fixed

Failed OpenQA tests for zchunk update - how to troubleshoot?

2022-02-20 Thread Jonathan Dieter
I've just pushed zchunk-1.2.0 to all active Fedora branches, and it's passed the (admittedly non-comprehensive) zchunk test suite, but I'm seeing 2 OpenQA failed tests in Bodhi: https://bodhi.fedoraproject.org/updates/FEDORA-2022-e4bcaeea7a

Fedora-IoT-36-20220220.0 compose check report

2022-02-20 Thread Fedora compose checker
No missing expected images. Failed openQA tests: 3/16 (x86_64), 2/15 (aarch64) Old failures (same test failed in Fedora-IoT-36-20220219.0): ID: 1138947 Test: x86_64 IoT-dvd_ostree-iso iot_clevis URL: https://openqa.fedoraproject.org/tests/1138947 ID: 1138948 Test: x86_64

[Bug 2056253] perl-Module-CoreList-5.20220220 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056253 Fedora Update System changed: What|Removed |Added Status|NEW |MODIFIED --- Comment #1 from

[Bug 2056253] perl-Module-CoreList-5.20220220 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056253 Fedora Update System changed: What|Removed |Added Status|NEW |MODIFIED --- Comment #1 from

Fedora 36 compose report: 20220220.n.0 changes

2022-02-20 Thread Fedora Rawhide Report
OLD: Fedora-36-20220219.n.0 NEW: Fedora-36-20220220.n.0 = SUMMARY = Added images:1 Dropped images: 0 Added packages: 1 Dropped packages:0 Upgraded packages: 107 Downgraded packages: 0 Size of added packages: 10.51 KiB Size of dropped packages:0 B Size

Re: Where are hardened build flags applied?

2022-02-20 Thread Mattia Verga via devel
Il 20/02/22 18:51, Vitaly Zaitsev via devel ha scritto: > On 20/02/2022 11:31, Mattia Verga via devel wrote: >> So, where -fPIE/-fPIC are supposed to be injected in build flags? > $ rpm -E %optflags > -O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches > -pipe -Wall

Re: Where are hardened build flags applied?

2022-02-20 Thread Mattia Verga via devel
Il 20/02/22 19:10, Peter Robinson ha scritto: >> I'm running a package review request for a package which uses suid and >> rpmlint complaints that it is not using hardened build flags. However, >> the specfile doesn't explicitly disable them with %undefine _hardened_build. >> >> Looking at the

Re: Where are hardened build flags applied?

2022-02-20 Thread Peter Robinson
> I'm running a package review request for a package which uses suid and > rpmlint complaints that it is not using hardened build flags. However, > the specfile doesn't explicitly disable them with %undefine _hardened_build. > > Looking at the build log of this one [1] I see that export CFLAGS and

Re: Where are hardened build flags applied?

2022-02-20 Thread Vitaly Zaitsev via devel
On 20/02/2022 11:31, Mattia Verga via devel wrote: So, where -fPIE/-fPIC are supposed to be injected in build flags? $ rpm -E %optflags -O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS

2FA (was: Preventing account takeovers through expired domains)

2022-02-20 Thread Björn Persson
Demi Marie Obenour wrote: > Security keys are the only form of 2fa that is immune to > phishing attacks. U2F and FIDO2 are said to be immune to phishing. HOTP, TOTP and various proprietary challenge-respone protocols are not immune. Björn Persson pgp_7IhtLa4JI.pgp Description: OpenPGP digital

Re: Preventing account takeovers through expired domains

2022-02-20 Thread Björn Persson
Mattia Verga via devel wrote: > Il 19/02/22 19:38, Björn Persson ha scritto: > > Zbigniew Jędrzejewski-Szmek wrote: > >> I think it'd be better to check the status weekly and only require > >> account reconfirmation if the quarantine status is detected ⌊N / 7 - 1⌋ > >> times in a row (where

Re: Preventing account takeovers through expired domains

2022-02-20 Thread Gary Buhrmaster
On Sun, Feb 20, 2022 at 4:01 PM Demi Marie Obenour wrote: > I think we should also require security key-based 2fa for all > packagers. In a previous discussion on this topic that was suggested (and at least partially rejected(*)). Many (larger) orgs have decided that issuing hardware security

Re: Preventing account takeovers through expired domains

2022-02-20 Thread Demi Marie Obenour
On 2/20/22 05:00, Mattia Verga via devel wrote: > Il 19/02/22 19:38, Björn Persson ha scritto: >> Zbigniew Jędrzejewski-Szmek wrote: >>> I think it'd be better to check the status weekly and only require >>> account reconfirmation if the quarantine status is detected ⌊N / 7 - 1⌋ >>> times in a row

[EPEL-devel] Re: Does EPEL 9 maintain upgrade path from EPEL 8?

2022-02-20 Thread Gary Buhrmaster
On Sat, Feb 19, 2022 at 8:21 PM Miro Hrončok wrote: > Once I remove the Obsoletes line from Fedora, should I worry about merging > that > commit to the epel9 branch or not? Logic dictates that the Obsolete should > remain in EPEL 9 forever, but I wonder if there is a policy/rule of thumb. >

[Bug 2056240] perl-MCE-1.878 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056240 Paul Howarth changed: What|Removed |Added Doc Type|--- |If docs needed, set a value

[EPEL-devel] Re: Does EPEL 9 maintain upgrade path from EPEL 8?

2022-02-20 Thread Stephen John Smoogen
On Sat, 19 Feb 2022 at 15:55, Neal Gompa wrote: > On Sat, Feb 19, 2022 at 3:21 PM Miro Hrončok wrote: > > > > Hello, > > > > I have a Fedora package that I've recently also branched for EPEL 9. > > > > The (so called) binary package used to be called "python3-tox", but has > been > > renamed to

[Bug 2056253] New: perl-Module-CoreList-5.20220220 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056253 Bug ID: 2056253 Summary: perl-Module-CoreList-5.20220220 is available Product: Fedora Version: rawhide Status: NEW Component: perl-Module-CoreList Keywords:

[Bug 2056250] New: perl-CPAN-Perl-Releases-5.20220220 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056250 Bug ID: 2056250 Summary: perl-CPAN-Perl-Releases-5.20220220 is available Product: Fedora Version: rawhide Status: NEW Component: perl-CPAN-Perl-Releases Keywords:

[Bug 2056240] perl-MCE-1.878 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056240 Upstream Release Monitoring changed: What|Removed |Added Summary|perl-MCE-1.877 is available |perl-MCE-1.878 is

Fedora-Rawhide-20220220.n.0 compose check report

2022-02-20 Thread Fedora compose checker
Missing expected images: Minimal raw-xz armhfp Compose FAILS proposed Rawhide gating check! 4 of 43 required tests failed, 4 results missing openQA tests matching unsatisfied gating requirements shown with **GATING** below Failed openQA tests: 24/231 (x86_64), 26/161 (aarch64) New failures

[Bug 2056224] perl-Sereal-4.023 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056224 Paul Howarth changed: What|Removed |Added Fixed In Version||perl-Sereal-4.023-1.fc36

Re: GNOME (and Cinnamon) issues in Rawhide: status report, including gnome-bluetooth soname issues

2022-02-20 Thread Miro Hrončok
On 20. 02. 22 8:09, Adam Williamson wrote: On Sun, 2022-02-20 at 00:39 +0100, Miro Hrončok wrote: On 16. 02. 22 9:03, Adam Williamson wrote: Full version: gnome-shell and mutter 42~beta builds were run yesterday. For Fedora 36 they were done in a sidetag, but for Rawhide, no sidetag yet

[Bug 2056222] perl-Sereal-Encoder-4.023 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056222 Paul Howarth changed: What|Removed |Added Status|NEW |CLOSED Fixed In Version|

[Bug 2056223] perl-Sereal-Decoder-4.023 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056223 Paul Howarth changed: What|Removed |Added Doc Type|--- |If docs needed, set a value

Fedora-Cloud-34-20220220.0 compose check report

2022-02-20 Thread Fedora compose checker
No missing expected images. Soft failed openQA tests: 1/8 (aarch64), 1/8 (x86_64) (Tests completed, but using a workaround for a known bug) New soft failures (same test not soft failed in Fedora-Cloud-34-20220219.0): ID: 1138074 Test: aarch64 Cloud_Base-qcow2-qcow2 cloud_autocloud@uefi URL:

Fedora-IoT-37-20220220.0 compose check report

2022-02-20 Thread Fedora compose checker
Missing expected images: Iot dvd x86_64 Iot dvd aarch64 Failed openQA tests: 3/16 (x86_64), 2/15 (aarch64) Old failures (same test failed in Fedora-IoT-37-20220219.0): ID: 1138115 Test: x86_64 IoT-dvd_ostree-iso iot_clevis URL: https://openqa.fedoraproject.org/tests/1138115 ID: 1138116

Where are hardened build flags applied?

2022-02-20 Thread Mattia Verga via devel
I'm running a package review request for a package which uses suid and rpmlint complaints that it is not using hardened build flags. However, the specfile doesn't explicitly disable them with %undefine _hardened_build. Looking at the build log of this one [1] I see that export CFLAGS and other

Fedora rawhide compose report: 20220220.n.0 changes

2022-02-20 Thread Fedora Rawhide Report
OLD: Fedora-Rawhide-20220219.n.0 NEW: Fedora-Rawhide-20220220.n.0 = SUMMARY = Added images:1 Dropped images: 0 Added packages: 1 Dropped packages:0 Upgraded packages: 118 Downgraded packages: 0 Size of added packages: 10.59 KiB Size of dropped packages:0

Re: Preventing account takeovers through expired domains

2022-02-20 Thread Mattia Verga via devel
Il 19/02/22 19:38, Björn Persson ha scritto: > Zbigniew Jędrzejewski-Szmek wrote: >> I think it'd be better to check the status weekly and only require >> account reconfirmation if the quarantine status is detected ⌊N / 7 - 1⌋ >> times in a row (where N=quarantine length in days). > It will be

[Bug 2056240] New: perl-MCE-1.877 is available

2022-02-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2056240 Bug ID: 2056240 Summary: perl-MCE-1.877 is available Product: Fedora Version: rawhide Status: NEW Component: perl-MCE Keywords: FutureFeature, Triaged

Fedora-Cloud-35-20220220.0 compose check report

2022-02-20 Thread Fedora compose checker
No missing expected images. Soft failed openQA tests: 1/8 (x86_64), 1/8 (aarch64) (Tests completed, but using a workaround for a known bug) Old soft failures (same test soft failed in Fedora-Cloud-35-20220219.0): ID: 1137653 Test: x86_64 Cloud_Base-qcow2-qcow2 cloud_autocloud URL: