* Re: [gentoo-dev] Lastrite: games-fps/openarena
2010-03-03 11:35 [gentoo-dev] Lastrite: games-fps/openarena Samuli Suominen
@ 2010-03-03 11:32 ` Joshua Saddler
2010-03-03 11:55 ` Tomáš Chvátal
2010-03-04 18:17 ` [gentoo-dev] Re: [gentoo-dev-announce] " Victor Ostorga
1 sibling, 1 reply; 15+ messages in thread
From: Joshua Saddler @ 2010-03-03 11:32 UTC (permalink / raw
To: gentoo-dev
[-- Attachment #1: Type: text/plain, Size: 569 bytes --]
On Wed, 03 Mar 2010 13:35:10 +0200
Samuli Suominen <ssuominen@gentoo.org> wrote:
> # Samuli Suominen <ssuominen@gentoo.org> (03 Mar 2010)
> # Masked for QA, security
> #
> # Internal copies of vuln. zlib, jpeg, speex and likely
> # others
> #
> # http://bugs.gentoo.org/show_bug.cgi?id=255453
> #
> # Masked for removal in 60 days.
> games-fps/openarena
>
Why? Why did you ignore the patches posted to the bug? Even Diego, the original reporter, commented that the patches fix the problems.[1]
[1] http://bugs.gentoo.org/show_bug.cgi?id=255453#c4
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 198 bytes --]
^ permalink raw reply [flat|nested] 15+ messages in thread
* [gentoo-dev] Lastrite: games-fps/openarena
@ 2010-03-03 11:35 Samuli Suominen
2010-03-03 11:32 ` Joshua Saddler
2010-03-04 18:17 ` [gentoo-dev] Re: [gentoo-dev-announce] " Victor Ostorga
0 siblings, 2 replies; 15+ messages in thread
From: Samuli Suominen @ 2010-03-03 11:35 UTC (permalink / raw
To: gentoo-dev-announce, gentoo-dev
# Samuli Suominen <ssuominen@gentoo.org> (03 Mar 2010)
# Masked for QA, security
#
# Internal copies of vuln. zlib, jpeg, speex and likely
# others
#
# http://bugs.gentoo.org/show_bug.cgi?id=255453
#
# Masked for removal in 60 days.
games-fps/openarena
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [gentoo-dev] Lastrite: games-fps/openarena
2010-03-03 11:32 ` Joshua Saddler
@ 2010-03-03 11:55 ` Tomáš Chvátal
2010-03-03 12:58 ` [gentoo-dev] " Ryan Hill
0 siblings, 1 reply; 15+ messages in thread
From: Tomáš Chvátal @ 2010-03-03 11:55 UTC (permalink / raw
To: gentoo-dev
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Dne 3.3.2010 12:32, Joshua Saddler napsal(a):
> On Wed, 03 Mar 2010 13:35:10 +0200
> Samuli Suominen <ssuominen@gentoo.org> wrote:
>
>> # Samuli Suominen <ssuominen@gentoo.org> (03 Mar 2010)
>> # Masked for QA, security
>> #
>> # Internal copies of vuln. zlib, jpeg, speex and likely
>> # others
>> #
>> # http://bugs.gentoo.org/show_bug.cgi?id=255453
>> #
>> # Masked for removal in 60 days.
>> games-fps/openarena
>>
>
> Why? Why did you ignore the patches posted to the bug? Even Diego, the original reporter, commented that the patches fix the problems.[1]
>
> [1] http://bugs.gentoo.org/show_bug.cgi?id=255453#c4
Bug opened for 1 year.
Diego commented on 30 July 2009.
No other response from maintainers...
If there is patch it is maintainers job to apply them. At least was when
I last looked.
We of course can patch the bundled versions and wait for next breakage,
but it is simpler to treeclean it and let people reintroduce it later
without bundled libs...
Tom
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.14 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
iEYEARECAAYFAkuOTjcACgkQHB6c3gNBRYc3FwCginYSFYiW0zOEKP9ehqUsweba
3BoAnRNtdY4YqNyX3C766xEXgPosBffY
=v05+
-----END PGP SIGNATURE-----
^ permalink raw reply [flat|nested] 15+ messages in thread
* [gentoo-dev] Re: Lastrite: games-fps/openarena
2010-03-03 11:55 ` Tomáš Chvátal
@ 2010-03-03 12:58 ` Ryan Hill
2010-03-03 13:09 ` Samuli Suominen
0 siblings, 1 reply; 15+ messages in thread
From: Ryan Hill @ 2010-03-03 12:58 UTC (permalink / raw
To: gentoo-dev
[-- Attachment #1: Type: text/plain, Size: 1314 bytes --]
> Dne 3.3.2010 12:32, Joshua Saddler napsal(a):
> > On Wed, 03 Mar 2010 13:35:10 +0200
> > Samuli Suominen <ssuominen@gentoo.org> wrote:
> >
> >> # Samuli Suominen <ssuominen@gentoo.org> (03 Mar 2010)
> >> # Masked for QA, security
> >> #
> >> # Internal copies of vuln. zlib, jpeg, speex and likely
> >> # others
> >> #
> >> # http://bugs.gentoo.org/show_bug.cgi?id=255453
> >> #
> >> # Masked for removal in 60 days.
> >> games-fps/openarena
> >>
> >
> > Why? Why did you ignore the patches posted to the bug? Even Diego, the original reporter, commented that the patches fix the problems.[1]
> >
> > [1] http://bugs.gentoo.org/show_bug.cgi?id=255453#c4
>
One of the reasons I left the treecleaner project was that it became apparent
that people were more interested in dumping packages with simple problems
than fixing them (which believe it or not, was what treecleaner was formed to
do). Now they call it QA. :)
I'm all for dropping broken crap, but things people use with working patches
attached? QA is also about getting that stuff applied.
--
fonts, by design, by neglect
gcc-porting, for a fact or just for effect
wxwidgets @ gentoo EFFD 380E 047A 4B51 D2BD C64F 8AA8 8346 F9A4 0662
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 198 bytes --]
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [gentoo-dev] Re: Lastrite: games-fps/openarena
2010-03-03 12:58 ` [gentoo-dev] " Ryan Hill
@ 2010-03-03 13:09 ` Samuli Suominen
2010-03-03 16:03 ` Michael Sterrett
0 siblings, 1 reply; 15+ messages in thread
From: Samuli Suominen @ 2010-03-03 13:09 UTC (permalink / raw
To: gentoo-dev
On 03/03/2010 02:58 PM, Ryan Hill wrote:
>> Dne 3.3.2010 12:32, Joshua Saddler napsal(a):
>>> On Wed, 03 Mar 2010 13:35:10 +0200
>>> Samuli Suominen <ssuominen@gentoo.org> wrote:
>>>
>>>> # Samuli Suominen <ssuominen@gentoo.org> (03 Mar 2010)
>>>> # Masked for QA, security
>>>> #
>>>> # Internal copies of vuln. zlib, jpeg, speex and likely
>>>> # others
>>>> #
>>>> # http://bugs.gentoo.org/show_bug.cgi?id=255453
>>>> #
>>>> # Masked for removal in 60 days.
>>>> games-fps/openarena
>>>>
>>>
>>> Why? Why did you ignore the patches posted to the bug? Even Diego, the original reporter, commented that the patches fix the problems.[1]
>>>
>>> [1] http://bugs.gentoo.org/show_bug.cgi?id=255453#c4
>>
>
> One of the reasons I left the treecleaner project was that it became apparent
> that people were more interested in dumping packages with simple problems
> than fixing them (which believe it or not, was what treecleaner was formed to
> do). Now they call it QA. :)
>
> I'm all for dropping broken crap, but things people use with working patches
> attached? QA is also about getting that stuff applied.
And now you have good 60 days to apply and test the package, and
co-ordinate it with upstream.
Don't forget to add yourself to metadata.xml, as it's a non-trivial task.
;-)
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [gentoo-dev] Re: Lastrite: games-fps/openarena
2010-03-03 13:09 ` Samuli Suominen
@ 2010-03-03 16:03 ` Michael Sterrett
2010-03-03 16:29 ` Mark Loeser
0 siblings, 1 reply; 15+ messages in thread
From: Michael Sterrett @ 2010-03-03 16:03 UTC (permalink / raw
To: gentoo-dev
I've remove the mask for games-fps/openarena.
The mask was done without consulting the games team.
On Wed, Mar 3, 2010 at 8:09 AM, Samuli Suominen <ssuominen@gentoo.org> wrote:
> On 03/03/2010 02:58 PM, Ryan Hill wrote:
>>> Dne 3.3.2010 12:32, Joshua Saddler napsal(a):
>>>> On Wed, 03 Mar 2010 13:35:10 +0200
>>>> Samuli Suominen <ssuominen@gentoo.org> wrote:
>>>>
>>>>> # Samuli Suominen <ssuominen@gentoo.org> (03 Mar 2010)
>>>>> # Masked for QA, security
>>>>> #
>>>>> # Internal copies of vuln. zlib, jpeg, speex and likely
>>>>> # others
>>>>> #
>>>>> # http://bugs.gentoo.org/show_bug.cgi?id=255453
>>>>> #
>>>>> # Masked for removal in 60 days.
>>>>> games-fps/openarena
>>>>>
>>>>
>>>> Why? Why did you ignore the patches posted to the bug? Even Diego, the original reporter, commented that the patches fix the problems.[1]
>>>>
>>>> [1] http://bugs.gentoo.org/show_bug.cgi?id=255453#c4
>>>
>>
>> One of the reasons I left the treecleaner project was that it became apparent
>> that people were more interested in dumping packages with simple problems
>> than fixing them (which believe it or not, was what treecleaner was formed to
>> do). Now they call it QA. :)
>>
>> I'm all for dropping broken crap, but things people use with working patches
>> attached? QA is also about getting that stuff applied.
>
> And now you have good 60 days to apply and test the package, and
> co-ordinate it with upstream.
>
> Don't forget to add yourself to metadata.xml, as it's a non-trivial task.
>
> ;-)
>
>
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [gentoo-dev] Re: Lastrite: games-fps/openarena
2010-03-03 16:03 ` Michael Sterrett
@ 2010-03-03 16:29 ` Mark Loeser
2010-03-03 16:59 ` Markos Chandras
0 siblings, 1 reply; 15+ messages in thread
From: Mark Loeser @ 2010-03-03 16:29 UTC (permalink / raw
To: gentoo-dev
[-- Attachment #1: Type: text/plain, Size: 633 bytes --]
Michael Sterrett <mr_bones_@gentoo.org> said:
> I've remove the mask for games-fps/openarena.
>
> The mask was done without consulting the games team.
This is no reason to remove the mask. The games team had more than
enough time to fix the package. I'll be adding the mask back as the
package is vulnerable via multiple bundled libs and therefore shouldn't
be in the tree. You can apply the patches if you want to keep it and
remove the mask at that time.
Thanks,
--
Mark Loeser
email - halcy0n AT gentoo DOT org
email - mark AT halcy0n DOT com
web - http://www.halcy0n.com
[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [gentoo-dev] Re: Lastrite: games-fps/openarena
2010-03-03 16:29 ` Mark Loeser
@ 2010-03-03 16:59 ` Markos Chandras
2010-03-03 19:56 ` Alec Warner
0 siblings, 1 reply; 15+ messages in thread
From: Markos Chandras @ 2010-03-03 16:59 UTC (permalink / raw
To: gentoo-dev
[-- Attachment #1: Type: Text/Plain, Size: 946 bytes --]
On Wednesday 03 March 2010 18:29:13 Mark Loeser wrote:
> Michael Sterrett <mr_bones_@gentoo.org> said:
> > I've remove the mask for games-fps/openarena.
> >
> > The mask was done without consulting the games team.
>
> This is no reason to remove the mask. The games team had more than
> enough time to fix the package. I'll be adding the mask back as the
> package is vulnerable via multiple bundled libs and therefore shouldn't
> be in the tree. You can apply the patches if you want to keep it and
> remove the mask at that time.
>
> Thanks,
This thread is yet another proof that we need to introduce a "Upcoming
masking" for unmaintained packages.
Instead of first masking a package and then announce it, we can simply announce
that we are gonna mask the package in 10days if there is no activity on the
respective bug
--
Markos Chandras (hwoarang)
Gentoo Linux Developer
Web: http://hwoarang.silverarrow.org
[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 198 bytes --]
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [gentoo-dev] Re: Lastrite: games-fps/openarena
2010-03-03 16:59 ` Markos Chandras
@ 2010-03-03 19:56 ` Alec Warner
0 siblings, 0 replies; 15+ messages in thread
From: Alec Warner @ 2010-03-03 19:56 UTC (permalink / raw
To: gentoo-dev
On Wed, Mar 3, 2010 at 8:59 AM, Markos Chandras <hwoarang@gentoo.org> wrote:
> On Wednesday 03 March 2010 18:29:13 Mark Loeser wrote:
>> Michael Sterrett <mr_bones_@gentoo.org> said:
>> > I've remove the mask for games-fps/openarena.
>> >
>> > The mask was done without consulting the games team.
>>
>> This is no reason to remove the mask. The games team had more than
>> enough time to fix the package. I'll be adding the mask back as the
>> package is vulnerable via multiple bundled libs and therefore shouldn't
>> be in the tree. You can apply the patches if you want to keep it and
>> remove the mask at that time.
>>
>> Thanks,
> This thread is yet another proof that we need to introduce a "Upcoming
> masking" for unmaintained packages.
<sarcasm>
Shall I file those forms in triplicate and fax them to the main office sir?
</sarcasm>
Since amazingly I actually started the Treecleaners project; the
intent was actually to fix problems with packages. Part of the
problem is that there are hundreds of packages in the tree and the
fixes vary in complexity so it is difficult to create hard-and-fast
rules on when to keep a package versus when to toss it. One of the
things I like about masking is that it quickly gets people who
actually care about the package up to bat to fix it instead of leaving
it broken for months. I realize maintainers do not exactly enjoy this
kind of poking, however when things have been left for long enough I
believe our options become a bit more limited (in this case, masking
for removal due to unfixed sec bugs.)
>
> Instead of first masking a package and then announce it, we can simply announce
> that we are gonna mask the package in 10days if there is no activity on the
> respective bug
> --
> Markos Chandras (hwoarang)
> Gentoo Linux Developer
> Web: http://hwoarang.silverarrow.org
>
^ permalink raw reply [flat|nested] 15+ messages in thread
* [gentoo-dev] Re: [gentoo-dev-announce] Lastrite: games-fps/openarena
2010-03-03 11:35 [gentoo-dev] Lastrite: games-fps/openarena Samuli Suominen
2010-03-03 11:32 ` Joshua Saddler
@ 2010-03-04 18:17 ` Victor Ostorga
2010-03-05 13:17 ` Ben de Groot
1 sibling, 1 reply; 15+ messages in thread
From: Victor Ostorga @ 2010-03-04 18:17 UTC (permalink / raw
To: gentoo-dev
[-- Attachment #1: Type: text/plain, Size: 628 bytes --]
On Wed, 03 Mar 2010 13:35:10 +0200
Samuli Suominen <ssuominen@gentoo.org> wrote:
> # Samuli Suominen <ssuominen@gentoo.org> (03 Mar 2010)
> # Masked for QA, security
> #
> # Internal copies of vuln. zlib, jpeg, speex and likely
> # others
> #
> # http://bugs.gentoo.org/show_bug.cgi?id=255453
> #
> # Masked for removal in 60 days.
> games-fps/openarena
>
0.8.5 was released on february 23, 2010 and the patch at bug
255453 seems to work fine.
Please don't remove one of the greatest open source games.
Regards,
--
Víctor Ostorga
Gentoo Linux developer (lxde, treecleaners)
http://www.gentoo.org
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 198 bytes --]
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [gentoo-dev] Re: [gentoo-dev-announce] Lastrite: games-fps/openarena
2010-03-04 18:17 ` [gentoo-dev] Re: [gentoo-dev-announce] " Victor Ostorga
@ 2010-03-05 13:17 ` Ben de Groot
2010-03-05 14:22 ` Markos Chandras
0 siblings, 1 reply; 15+ messages in thread
From: Ben de Groot @ 2010-03-05 13:17 UTC (permalink / raw
To: gentoo-dev
On 4 March 2010 19:17, Victor Ostorga <vostorga@gentoo.org> wrote:
> 0.8.5 was released on february 23, 2010 and the patch at bug
> 255453 seems to work fine.
> Please don't remove one of the greatest open source games.
So step up and maintain it!
Cheers,
--
Ben de Groot
Gentoo Linux developer (qt, media, lxde, desktop-misc)
______________________________________________________
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [gentoo-dev] Re: [gentoo-dev-announce] Lastrite: games-fps/openarena
2010-03-05 13:17 ` Ben de Groot
@ 2010-03-05 14:22 ` Markos Chandras
2010-03-05 15:06 ` Ben de Groot
0 siblings, 1 reply; 15+ messages in thread
From: Markos Chandras @ 2010-03-05 14:22 UTC (permalink / raw
To: gentoo-dev
[-- Attachment #1: Type: Text/Plain, Size: 523 bytes --]
On Friday 05 March 2010 15:17:06 Ben de Groot wrote:
> On 4 March 2010 19:17, Victor Ostorga <vostorga@gentoo.org> wrote:
> > 0.8.5 was released on february 23, 2010 and the patch at bug
> > 255453 seems to work fine.
> > Please don't remove one of the greatest open source games.
>
> So step up and maintain it!
>
> Cheers,
games herd already maintains that package . At least this is what I see on
metadata.xml
--
Markos Chandras (hwoarang)
Gentoo Linux Developer
Web: http://hwoarang.silverarrow.org
[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 198 bytes --]
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [gentoo-dev] Re: [gentoo-dev-announce] Lastrite: games-fps/openarena
2010-03-05 14:22 ` Markos Chandras
@ 2010-03-05 15:06 ` Ben de Groot
2010-03-05 15:23 ` Markos Chandras
0 siblings, 1 reply; 15+ messages in thread
From: Ben de Groot @ 2010-03-05 15:06 UTC (permalink / raw
To: gentoo-dev
On 5 March 2010 15:22, Markos Chandras <hwoarang@gentoo.org> wrote:
> On Friday 05 March 2010 15:17:06 Ben de Groot wrote:
>> So step up and maintain it!
>>
> games herd already maintains that package . At least this is what I see on
> metadata.xml
Nominally, yes. But if a package has open QA and security bugs and
patches that have not been reviewed or even commented upon by the
maintainer(s) for over 6 months, then you can't consider that package
actually maintained. So for this package to remain in the tree, someone
needs to step up and actually maintain it.
Cheers,
--
Ben de Groot
Gentoo Linux developer (qt, media, lxde, desktop-misc)
______________________________________________________
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [gentoo-dev] Re: [gentoo-dev-announce] Lastrite: games-fps/openarena
2010-03-05 15:06 ` Ben de Groot
@ 2010-03-05 15:23 ` Markos Chandras
2010-03-05 16:38 ` Ben de Groot
0 siblings, 1 reply; 15+ messages in thread
From: Markos Chandras @ 2010-03-05 15:23 UTC (permalink / raw
To: gentoo-dev
[-- Attachment #1: Type: Text/Plain, Size: 1097 bytes --]
On Friday 05 March 2010 17:06:21 Ben de Groot wrote:
> On 5 March 2010 15:22, Markos Chandras <hwoarang@gentoo.org> wrote:
> > On Friday 05 March 2010 15:17:06 Ben de Groot wrote:
> >> So step up and maintain it!
> >
> > games herd already maintains that package . At least this is what I see
> > on metadata.xml
>
> Nominally, yes. But if a package has open QA and security bugs and
> patches that have not been reviewed or even commented upon by the
> maintainer(s) for over 6 months, then you can't consider that package
> actually maintained. So for this package to remain in the tree, someone
> needs to step up and actually maintain it.
>
> Cheers,
I assume that only members of QA can actually step up and fix the problem.
Otherwise the games heard will complain that random devs are touching their
packages. I just assume that but I am not willing to step into their
"territory" and this is why I asked permission to touch the bug ( see my last
comment on the bug )
--
Markos Chandras (hwoarang)
Gentoo Linux Developer
Web: http://hwoarang.silverarrow.org
[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 198 bytes --]
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [gentoo-dev] Re: [gentoo-dev-announce] Lastrite: games-fps/openarena
2010-03-05 15:23 ` Markos Chandras
@ 2010-03-05 16:38 ` Ben de Groot
0 siblings, 0 replies; 15+ messages in thread
From: Ben de Groot @ 2010-03-05 16:38 UTC (permalink / raw
To: gentoo-dev
On 5 March 2010 16:23, Markos Chandras <hwoarang@gentoo.org> wrote:
> I assume that only members of QA can actually step up and fix the problem.
> Otherwise the games heard will complain that random devs are touching their
> packages. I just assume that but I am not willing to step into their
> "territory" and this is why I asked permission to touch the bug ( see my last
> comment on the bug )
Obviously, if there is a nominal maintainer, you should contact him/her/them.
But in cases like this, where open bugs show low or no activity, there is
often no problem stepping on any toes. What I usually do is mail the
maintainer or herd to which it is assigned, and ask if there are any
objections to fixing it. If no objections are raised within a reasonable
timeframe (depending on the seriousness of the bug), I would go ahead.
Cheers,
--
Ben de Groot
Gentoo Linux developer (qt, media, lxde, desktop-misc)
______________________________________________________
^ permalink raw reply [flat|nested] 15+ messages in thread
end of thread, other threads:[~2010-03-05 16:38 UTC | newest]
Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-03-03 11:35 [gentoo-dev] Lastrite: games-fps/openarena Samuli Suominen
2010-03-03 11:32 ` Joshua Saddler
2010-03-03 11:55 ` Tomáš Chvátal
2010-03-03 12:58 ` [gentoo-dev] " Ryan Hill
2010-03-03 13:09 ` Samuli Suominen
2010-03-03 16:03 ` Michael Sterrett
2010-03-03 16:29 ` Mark Loeser
2010-03-03 16:59 ` Markos Chandras
2010-03-03 19:56 ` Alec Warner
2010-03-04 18:17 ` [gentoo-dev] Re: [gentoo-dev-announce] " Victor Ostorga
2010-03-05 13:17 ` Ben de Groot
2010-03-05 14:22 ` Markos Chandras
2010-03-05 15:06 ` Ben de Groot
2010-03-05 15:23 ` Markos Chandras
2010-03-05 16:38 ` Ben de Groot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox