Flaws detected by static analyzers in Fedora 41 Critical Path Packages

2024-07-05 Thread Siteshwar Vashisht
Hello, I am writing this message to get feedback from the community on possibly new defects identified by static analyzers in Critical Path Packages that have changed in Fedora 41. For context, please see my previous email[1]. TLDR: This report[2] contains 73976 identified defects. Please review

Re: libqalculate soname bump

2024-07-05 Thread Fabio Valentini
On Fri, Jul 5, 2024 at 7:45 PM Mukundan Ragavan wrote: > > I am updating libqalculate to v5.2.0 which bumps the soname version. I > will rebuild the following packages that depend on libqalculate. > > plasma-workspace > step > cantor > qalculate-kde Looks like you forgot to rebuild these packages

libqalculate soname bump

2024-07-05 Thread Mukundan Ragavan
I am updating libqalculate to v5.2.0 which bumps the soname version. I will rebuild the following packages that depend on libqalculate. plasma-workspace step cantor qalculate-kde Thanks, Mukundan. -- ___ devel mailing list -- devel@lists.fedoraproject

Intent to add bign-handheld-thumbnailer to official repos

2024-07-05 Thread Mateus Rodrigues Costa
Hello all, A few months back I have started a project called "bign-handheld-thumbnailer" which acts as a thumbnailer for Nintendo DS and Nintendo 3DS files. It was started as a successor/rewrite of gnome-nds-thumbnailer (https://gitlab.gnome.org/Archive/gnome-nds-thumbnailer) in Rust, but I decid

Re: F41 Change Proposal: Make OpenSSL distrust SHA-1 signatures by default (system-wide)

2024-07-05 Thread Clemens Lang
Hello Daniel, > On 5. Jul 2024, at 15:33, Daniel P. Berrangé wrote: > > It isn't listed there, but it certainly should be, as we've not > been considering it FIPS compliant, for precisely this reason. OK. I’ve asked our docs team to add it to the list. Thank you for bringing this to my attenti

Re: Error loading shared libraries: libMellowPlayer.Application.so: cannot open shared object file

2024-07-05 Thread Dominik 'Rathann' Mierzejewski
On Friday, 05 July 2024 at 16:16, Martin Gansser wrote: > Thank you for your answer. > > Finally, I have a question about compiling, here I get error messages > [2] with the requirement. How can solve this? > > [1] https://martinkg.fedorapeople.org/ErrorReports/mellowplayer.spec > [2] https://koj

Re: Error loading shared libraries: libMellowPlayer.Application.so: cannot open shared object file

2024-07-05 Thread Martin Gansser
Thank you for your answer. Finally, I have a question about compiling, here I get error messages [2] with the requirement. How can solve this? [1] https://martinkg.fedorapeople.org/ErrorReports/mellowplayer.spec [2] https://kojipkgs.fedoraproject.org//work/tasks/1808/120031808/build.log Regards

Re: F41 Change Proposal: Make OpenSSL distrust SHA-1 signatures by default (system-wide)

2024-07-05 Thread Daniel P . Berrangé
On Fri, Jul 05, 2024 at 02:59:36PM +0200, Clemens Lang wrote: > Hi, > > > On 5. Jul 2024, at 14:49, Daniel P. Berrangé wrote: > > > > On Fri, Jul 05, 2024 at 02:37:41PM +0200, Clemens Lang wrote: > >> > >> > >> Please start addressing this with whoever maintains the TPM specification. > > > >

Re: F41 Change Proposal: Make OpenSSL distrust SHA-1 signatures by default (system-wide)

2024-07-05 Thread Clemens Lang
Hi, > On 5. Jul 2024, at 14:49, Daniel P. Berrangé wrote: > > On Fri, Jul 05, 2024 at 02:37:41PM +0200, Clemens Lang wrote: >> >> >> Please start addressing this with whoever maintains the TPM specification. > > The TPM spec is maintained by the Trusted Computing Group, and I have > no influe

Re: HEADS UP: openssl engine-related FTBFS and Boost

2024-07-05 Thread Joe Orton
On Fri, Jul 05, 2024 at 02:06:33PM +0200, Clemens Lang wrote: > I’m sure Dmitry would be happy to do that if we as a community could > agree to no longer support OpenSSL ENGINEs, but it doesn’t seem that > this consensus exists in Fedora. This leaves us with deprecating > ENGINEs to give package

Re: F41 Change Proposal: Make OpenSSL distrust SHA-1 signatures by default (system-wide)

2024-07-05 Thread Daniel P . Berrangé
On Fri, Jul 05, 2024 at 02:37:41PM +0200, Clemens Lang wrote: > Hi, > > > On 5. Jul 2024, at 12:38, Daniel P. Berrangé wrote: > > > > I've (re-)discovered that this change is going to impact on swtpm that is > > used with QEMU to provide a virtual TPM to guests. > > > > The TPM2 specification h

Re: HEADS UP: openssl engine-related FTBFS and Boost

2024-07-05 Thread Clemens Lang
Hi, > On 5. Jul 2024, at 14:24, Peter Pentchev wrote: > > I wonder if it would be possible (of course it is technically possible, > more like how hard it would be) to make the OpenSSL devel package > conditionally define OPENSSL_NO_ENGINE if another package is > not installed. I can think of at

Re: F41 Change Proposal: Make OpenSSL distrust SHA-1 signatures by default (system-wide)

2024-07-05 Thread Clemens Lang
Hi, > On 5. Jul 2024, at 12:38, Daniel P. Berrangé wrote: > > I've (re-)discovered that this change is going to impact on swtpm that is > used with QEMU to provide a virtual TPM to guests. > > The TPM2 specification has fully crypto agility, however, the sha1 > algorithm is one of the few that

Re: HEADS UP: openssl engine-related FTBFS and Boost

2024-07-05 Thread Peter Pentchev
On Fri, Jul 05, 2024 at 11:10:08AM +0100, Joe Orton wrote: > On Tue, Jul 02, 2024 at 02:05:38PM +0200, Dmitry Belyavskiy wrote: > > In the long-term it would be better to provide a patch fixing build of the > > package. Probably adding -DOPENSSL_NO_ENGINE to build flags will work. > > Engines are d

Re: F42 Change Proposal: Opt-In Metrics for Fedora Workstation (system-wide)

2024-07-05 Thread Michael Catanzaro
Hi, please see: https://fedoraproject.org/wiki/Changes/Metrics#Who_will_have_access_to_metrics_data -- ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct:

Re: HEADS UP: openssl engine-related FTBFS and Boost

2024-07-05 Thread Clemens Lang
Hi, > On 5. Jul 2024, at 12:10, Joe Orton wrote: > > On Tue, Jul 02, 2024 at 02:05:38PM +0200, Dmitry Belyavskiy wrote: >> In the long-term it would be better to provide a patch fixing build of the >> package. Probably adding -DOPENSSL_NO_ENGINE to build flags will work. >> Engines are deprecate

Re: Oddness detecting new versions of ocamlbuild

2024-07-05 Thread Richard W.M. Jones
On Thu, Jul 04, 2024 at 04:56:03PM +0200, Fabio Valentini wrote: > On Thu, Jul 4, 2024 at 9:37 AM Richard W.M. Jones wrote: > > > > https://bugzilla.redhat.com/show_bug.cgi?id=1992935 > > > > A new version of ocamlbuild (Fedora: ocaml-ocamlbuild) was found. > > However the version isn't 4.02.3, bu

Fedora rawhide compose report: 20240705.n.0 changes

2024-07-05 Thread Fedora Rawhide Report
OLD: Fedora-Rawhide-20240704.n.0 NEW: Fedora-Rawhide-20240705.n.0 = SUMMARY = Added images:3 Dropped images: 0 Added packages: 3 Dropped packages:0 Upgraded packages: 51 Downgraded packages: 0 Size of added packages: 650.93 KiB Size of dropped packages:0

Re: F41 Change Proposal: Make OpenSSL distrust SHA-1 signatures by default (system-wide)

2024-07-05 Thread Daniel P . Berrangé
On Mon, Jun 10, 2024 at 08:40:22PM +0200, Clemens Lang wrote: > Hi, > > > On 10. Jun 2024, at 20:16, Richard W.M. Jones wrote: > > > > On Mon, Jun 10, 2024 at 01:43:57PM +0200, Vít Ondruch wrote: > >> I wish this proposal included some examples of what might get broken > >> and what will keep wo

Re: Error loading shared libraries: libMellowPlayer.Application.so: cannot open shared object file

2024-07-05 Thread Dominik 'Rathann' Mierzejewski
On Friday, 05 July 2024 at 09:01, Martin Gansser wrote: > Dominik 'Rathann' Mierzejewski wrote: > > On Thursday, 04 July 2024 at 17:00, Martin Gansser wrote: > > > when remove the RPATH i get this error message [1]: > > > [...] > > > ERROR 0002: file '/usr/bin/MellowPlayer' contains an invalid rp

Re: HEADS UP: openssl engine-related FTBFS and Boost

2024-07-05 Thread Joe Orton
On Tue, Jul 02, 2024 at 02:05:38PM +0200, Dmitry Belyavskiy wrote: > In the long-term it would be better to provide a patch fixing build of the > package. Probably adding -DOPENSSL_NO_ENGINE to build flags will work. > Engines are deprecated. You should not use engines and should migrate to > provi

Re: Automatic detection of unused BuildRequires

2024-07-05 Thread Michael Schwendt
On Wed, 3 Jul 2024 18:02:01 +0200, Marián Konček wrote: > To my knowledge there is no such project. Only highly experimental ones have been used many, many years ago. For example, in Fedora land I've caught some unused BuildRequires with a script that checks whether shared libs provided by build

Re: Error loading shared libraries: libMellowPlayer.Application.so: cannot open shared object file

2024-07-05 Thread Martin Gansser
Dominik 'Rathann' Mierzejewski wrote: > On Thursday, 04 July 2024 at 17:00, Martin Gansser wrote: > > when remove the RPATH i get this error message [1]: > > [...] > > ERROR 0002: file '/usr/bin/MellowPlayer' contains an invalid rpath > > '/usr/' in [/usr/lib64/mellowplayer:/usr/] > > The compla