[Pkg-mozext-maintainers] Bug#976697: webext-umatrix: no longer developed upstream, remove or switch to LibreMatrix or?

2021-09-04 Thread Paul Wise
On Sat, 2021-09-04 at 17:08 +0200, Axel Beckert wrote:

> Also it is unclear to me why the source is the Mozilla XPI while the
> package works with both and upstream offers different download files
> for Firefox and for Chromium/Chrome. (Then again, I haven't worked on
> browser extensions since Mozilla ditched XUL…)

I tried updating webext-umatrix to the latest release and immediately
encountered this issue too as the build fails with the upstream source
instead of the upstream prebuilt XPI file. I think that using prebuilt
XPI files when the upstream project has a git repository has a risk of
DFSG item 2 violations. Debian using XPI files is one of the reasons I
started this discussion about not using upstream packaging ecosystems:

   Debian choice of upstream tarballs for packaging
   
https://lists.debian.org/msgid-search/937697e40caf519e18119635db07d7b74b37b980.ca...@debian.org

That said, I expect building WebExtensions from source properly is
going to be a large undertaking that will require lots of node-*
packages and other dependencies to be added to Debian.

So a reasonable way to start is probably to update to the latest XPI
and then start working on the dependencies etc.

-- 
bye,
pabs

https://wiki.debian.org/PaulWise


signature.asc
Description: This is a digitally signed message part
___
Pkg-mozext-maintainers mailing list
Pkg-mozext-maintainers@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-mozext-maintainers


[Pkg-mozext-maintainers] Bug#971734: closed by Markus Koschany (Re: webext-ublock-origin: no longer functional in firefox-esr)

2021-09-04 Thread Christopher Cramer
On Fri, Sep 03, 2021 at 11:15:08PM +, Debian Bug Tracking System wrote:
> I believe those problems were resolved by a new version of Firefox in the 
> past.
> Personally I can't reproduce them anymore hence I am going to close these bug
> reports now.

You're right, I haven't seen the problem in a while now.

___
Pkg-mozext-maintainers mailing list
Pkg-mozext-maintainers@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-mozext-maintainers


[Pkg-mozext-maintainers] Bug#976697: webext-umatrix: no longer developed upstream, remove or switch to LibreMatrix or?

2021-09-04 Thread Axel Beckert
Hi,

Paul Wise wrote:
> uMatrix is no longer developed upstream:
> 
>    https://github.com/gorhill/uMatrix
>    
>    This repository has been archived by the owner. It is now read-only.
[…]
> The upstream author has stated they no longer have time for it:
> 
>
> https://github.com/uBlockOrigin/uMatrix-issues/issues/291#issuecomment-694988696
>
>I've archived uMatrix's repo, I can't and won't be spending any more
>time on this project, and neither on all such issues.

Despite this he did two stable release (1.4.2 and 1.4.4) in July 2021
a bunch of beta releases in 2020, February and July 2021:

https://github.com/gorhill/uMatrix/releases
https://chrome.google.com/webstore/detail/empty-title/ogfcmafjalglgifnmanfmnieipoejdcf?ucbcb=1
https://addons.mozilla.org/de/firefox/addon/umatrix/

(And then archived the Github repo again as it seems. *sigh*)

So for me it looks like the author still cares about security issues,
but has no time for other support. Which IMHO would be OK for a Debian
Stable release.

> These are the options for solving this issue:
> 
> uMatrix could be removed in favour of uBlock Origin's advanced mode.

IMHO this is no real solution. It works completely different and is at
least (from an UI/UX aspect) unusable for me. IMHO no alternative.

> uMatrix could be removed and LibreMatrix packaged, I think this is a
> community fork so it should be a drop-in replacement.
> 
>    https://www.librematrix.com/

Seems to have been rather short-lived and is dead and removed already:

  This site can’t be reached
  www.librematrix.com’s server IP address could not be found.

  […]

  ERR_NAME_NOT_RESOLVED

>    https://github.com/LibreMatrix/LibreMatrix

This as well:

  404 This is not the web page you are looking for.

The same counts for the according account:
https://github.com/LibreMatrix

So IMHO continuing with the original source seems (again) the best
solution to me.

I'd also help packaging 1.4.4 (at least), but the packaging is quite
non-standard while no debian/README.source is present. And
amo-changelog throws Python errors, probably needs an update wrt.
python3-urllib:

~/uMatrix/umatrix → make -f debian/rules get-orig-changelog
amo-changelog -p rst umatrix
failed to write debian/upstream/changelog.html: module 'urllib' has no 
attribute 'error'
make: *** [debian/rules:11: get-orig-changelog] Error 1

Also it is unclear to me why the source is the Mozilla XPI while the
package works with both and upstream offers different download files
for Firefox and for Chromium/Chrome. (Then again, I haven't worked on
browser extensions since Mozilla ditched XUL…)

Regards, Axel
-- 
 ,''`.  |  Axel Beckert , https://people.debian.org/~abe/
: :' :  |  Debian Developer, ftp.ch.debian.org Admin
`. `'   |  4096R: 2517 B724 C5F6 CA99 5329  6E61 2FF9 CD59 6126 16B5
  `-|  1024D: F067 EA27 26B9 C3FC 1486  202E C09E 1D89 9593 0EDE

___
Pkg-mozext-maintainers mailing list
Pkg-mozext-maintainers@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-mozext-maintainers


[Pkg-mozext-maintainers] Processed: tagging 991344

2021-09-04 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> # Fixed since 1.4.2, see https://github.com/gorhill/uMatrix/releases/tag/1.4.2
> tags 991344 + fixed-upstream
Bug #991344 [src:umatrix] umatrix: CVE-2021-36773: Denial of Service
Bug #991770 [src:umatrix] umatrix: new upstream release (1.4.4) fixes security 
issue
Added tag(s) fixed-upstream.
Added tag(s) fixed-upstream.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
991344: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=991344
991770: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=991770
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems

___
Pkg-mozext-maintainers mailing list
Pkg-mozext-maintainers@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-mozext-maintainers