https://bugzilla.redhat.com/show_bug.cgi?id=2362330
Bug ID: 2362330 Summary: Review Request: kde-release-keyring - Includes all keys that have been used for releasing KDE software Product: Fedora Version: rawhide Hardware: All OS: Linux Status: NEW Component: Package Review Severity: medium Priority: medium Assignee: nobody@fedoraproject.org Reporter: marcdeop@fedoraproject.org QA Contact: extras-qa@fedoraproject.org CC: package-review@lists.fedoraproject.org Target Milestone: --- Classification: Fedora
Spec URL: https://marcdeop.fedorapeople.org/kde-release-keyring.spec SRPM URL: https://marcdeop.fedorapeople.org/kde-release-keyring-0.0.1%5Egit20250403.ae... Description: Includes all keys that have been used for releasing KDE software Fedora Account System Username: marcdeop
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
Fedora Review Service fedora-review-bot@fedoraproject.org changed:
What |Removed |Added ---------------------------------------------------------------------------- URL| |https://invent.kde.org/sysa | |dmin/%{base_name}/
--- Comment #1 from Fedora Review Service fedora-review-bot@fedoraproject.org --- Copr build: https://copr.fedorainfracloud.org/coprs/build/8967583 (succeeded)
Review template: https://download.copr.fedorainfracloud.org/results/@fedora-review/fedora-rev...
Found issues:
- Not a valid SPDX expression 'License: CC0-1.0'. Read more: https://fedoraproject.org/wiki/Changes/SPDX_Licenses_Phase_1
Please know that there can be false-positives.
--- This comment was created by the fedora-review-service https://github.com/FrostyX/fedora-review-service
If you want to trigger a new Copr build, add a comment containing new Spec and SRPM URLs or [fedora-review-service-build] string.
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
marcdeop@fedoraproject.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Comment|0 |updated
--- Comment #0 has been edited ---
Spec URL: https://marcdeop.fedorapeople.org/kde-release-keyring.spec SRPM URL: https://marcdeop.fedorapeople.org/kde-release-keyring-0.0.1%5Egit20250403.ae... Description: Includes all keys that have been used for releasing KDE software Fedora Account System Username: marcdeop
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
Neal Gompa ngompa13@gmail.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |ASSIGNED Assignee|nobody@fedoraproject.org |ngompa13@gmail.com Flags| |fedora-review? CC| |ngompa13@gmail.com
--- Comment #2 from Neal Gompa ngompa13@gmail.com --- Taking this review.
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
--- Comment #3 from Neal Gompa ngompa13@gmail.com --- Spec review:
# Without this build fails with Empty %files file {..}/debugsourcefiles.list %global debug_package %{nil}
Set "BuildArch: noarch" instead in your spec file. There's no arch-specific content in here anyway.
Summary: Includes all keys that have been used for releasing KDE software
Needs a tighter summary that explains what this is.
Suggestion: "Keyring of signing keys from KDE community members"
Source0: https://invent.kde.org/sysadmin/%%7Bbase_name%7D/-/archive/%%7Bcommit%7D/%%7...
DRY: "%{url}/-/archive/%{commit}/%{base_name}-%{shortcommit}.tar.gz"
install -m644 -p -D %{base_name}.asc %{buildroot}%{_datadir}/kde/%{base_name}.asc
No. This should be "%{_datadir}/%{name}/" instead of "%{_datadir}/kde/".
We also should install all the individual keys that make up the keyring in a subfolder.
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
--- Comment #4 from Neal Gompa ngompa13@gmail.com --- Legal review:
License: CC0-1.0
While permitted since this isn't code, you still need to install the license file.
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
marcdeop@fedoraproject.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Comment|0 |updated
--- Comment #0 has been edited ---
Spec URL: https://marcdeop.fedorapeople.org/kde-release-keyring.spec SRPM URL: https://marcdeop.fedorapeople.org/kde-release-keyring-0.0.1%5Egit20250403.ae... Description: Includes all keys that have been used for releasing KDE software Fedora Account System Username: marcdeop
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
--- Comment #5 from marcdeop@fedoraproject.org --- Requested changes have been implemented
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
--- Comment #6 from Neal Gompa ngompa13@gmail.com ---
- Fri Apr 25 2025 Marc Deop i Argemí marcdeop@fedoraproject.org - 0.1.0?gitae8f4d5-3
The version-release needs to match the actual verrel of the package.
Use something like "rpmdev-bumpspec" to generate the verrel if you don't want to construct it manually.
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
marcdeop@fedoraproject.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Comment|0 |updated
--- Comment #0 has been edited ---
Spec URL: https://marcdeop.fedorapeople.org/kde-release-keyring.spec SRPM URL: https://marcdeop.fedorapeople.org/kde-release-keyring-0.0.1%5Egit20250403.ae... Description: Includes all keys that have been used for releasing KDE software Fedora Account System Username: marcdeop
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
--- Comment #7 from marcdeop@fedoraproject.org --- Updated!
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
Björn Persson bjorn@xn--rombobjrn-67a.se changed:
What |Removed |Added ---------------------------------------------------------------------------- CC| |bjorn@xn--rombobjrn-67a.se
--- Comment #8 from Björn Persson bjorn@xn--rombobjrn-67a.se --- release-keyring.asc shouldn't have the suffix ".asc" because it's not ASCII-armored. It's a keybox file, so the suffix should be ".kbx" (unless you drop that file and package only the separate key files). There may not be any software that cares about the suffix, but humans who see ".asc" will expect an ASCII-armored file.
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
marcdeop@fedoraproject.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Comment|0 |updated
--- Comment #0 has been edited ---
Spec URL: https://marcdeop.fedorapeople.org/kde-release-keyring.spec SRPM URL: https://marcdeop.fedorapeople.org/kde-release-keyring-0.0.1%5Egit20250403.ae... Description: Includes all keys that have been used for releasing KDE software Fedora Account System Username: marcdeop
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
--- Comment #9 from marcdeop@fedoraproject.org --- You are right @Björn Persson
Updated the spec file accordingly
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
marcdeop@fedoraproject.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Comment|0 |updated
--- Comment #0 has been edited ---
Spec URL: https://marcdeop.fedorapeople.org/kde-release-keyring.spec SRPM URL: https://marcdeop.fedorapeople.org/kde-release-keyring-0~git20250403.ae8f4d5-... Description: Includes all keys that have been used for releasing KDE software Fedora Account System Username: marcdeop
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
--- Comment #10 from marcdeop@fedoraproject.org --- Added additional fixes. Mostly versioning and changelogs adjustments
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
Neal Gompa ngompa13@gmail.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Flags|fedora-review? |fedora-review+ Status|ASSIGNED |POST
--- Comment #11 from Neal Gompa ngompa13@gmail.com --- Review notes:
* Package follows Fedora packaging guidelines * Package licensing is correct and license file is installed * Package builds and installs * No serious issues from rpmlint
PACKAGE APPROVED.
https://bugzilla.redhat.com/show_bug.cgi?id=2362330
Fedora Admin user for bugzilla script actions fedora-admin-xmlrpc@fedoraproject.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|POST |RELEASE_PENDING
--- Comment #12 from Fedora Admin user for bugzilla script actions fedora-admin-xmlrpc@fedoraproject.org --- The Pagure repository was created at https://src.fedoraproject.org/rpms/kde-release-keyring
package-review@lists.fedoraproject.org