On 2012-04-10 12:09, Mo Morsi wrote:
On 04/09/2012 06:07 PM, Zuhao wrote:
Hi Everyone,
IsItFedoraRuby.com is an idea proposed in this year's Google Summer of Code. The website will be mainly used for tracking the progress of the conversion of each gem (similar to isitruby19.com http://isitruby19.com), promoting the Fedora/Ruby integration, as well as highlighting some success stories. Hopefully, this website will let more people to be aware of the project, and thus more would contribute to make it better.
I have drafted a proposal with some preliminary design of the website. I would love to hear any thoughts or suggestions from you. As a developer, what do you want to see on this website so that it can be most helpful to the Fedora/Ruby community?
The proposal is at:
https://fedoraproject.org/wiki/GSOC_2012/Student_Application_Zuhao/IsItFedor...
Any feedback is much appreciated!
Thanks,
Zuhao
Hey Zuhao, thanks for the submission. the proposal looks very strong, and the mockups look great.
I encourage anyone else who may have any additional ideas as how to promote Ruby on Fedora and/or develop additional tooling to streamline the Ruby to Fedora process to respond here and/or on the proposal itself.
I've often had questions (after the usual question of what gem version is in what version of what platform (between Fedora/EPEL/RHEL)) about whether a specific version of a gem distributed with a given version of the platform had;
1) been updated with CVE patches, 2) been patched to negate bugs.
Depending on the feasibility, of course, perhaps there's opportunity to contain that information in isitfedoraruby.com as well?
Kind regards,
Jeroen van Meeuwen
Hi Jeroen,
What you've suggested is definitely a good idea. I do agree it's important to reflect which *version*, in addtion to the name, link, etc. of a particular gem that was converted into rpm, as sometimes the latest patches and bug fixes are not included in the rpm.
Thanks,
Zuhao On Sunday, April 15, 2012, Jeroen van Meeuwen (Kolab Systems) wrote:
On 2012-04-10 12:09, Mo Morsi wrote:
On 04/09/2012 06:07 PM, Zuhao wrote:
Hi Everyone,
IsItFedoraRuby.com is an idea proposed in this year's Google Summer of Code. The website will be mainly used for tracking the progress of the conversion of each gem (similar to isitruby19.com http://isitruby19.com), promoting the Fedora/Ruby integration, as well as highlighting some success stories. Hopefully, this website will let more people to be aware of the project, and thus more would contribute to make it better.
I have drafted a proposal with some preliminary design of the website. I would love to hear any thoughts or suggestions from you. As a developer, what do you want to see on this website so that it can be most helpful to the Fedora/Ruby community?
The proposal is at:
https://fedoraproject.org/**wiki/GSOC_2012/Student_**Application_Zuhao/* *IsItFedoraRubyhttps://fedoraproject.org/wiki/GSOC_2012/Student_Application_Zuhao/IsItFedoraRuby
Any feedback is much appreciated!
Thanks,
Zuhao
Hey Zuhao, thanks for the submission. the proposal looks very strong, and the mockups look great.
I encourage anyone else who may have any additional ideas as how to promote Ruby on Fedora and/or develop additional tooling to streamline the Ruby to Fedora process to respond here and/or on the proposal itself.
I've often had questions (after the usual question of what gem version is in what version of what platform (between Fedora/EPEL/RHEL)) about whether a specific version of a gem distributed with a given version of the platform had;
- been updated with CVE patches,
- been patched to negate bugs.
Depending on the feasibility, of course, perhaps there's opportunity to contain that information in isitfedoraruby.com as well?
Kind regards,
Jeroen van Meeuwen
-- Systems Architect, Kolab Systems AG
e: vanmeeuwen at kolabsys.com m: +44 74 2516 3817 w: http://www.kolabsys.com
pgp: 9342 BF08 ______________________________**_________________ ruby-sig mailing list ruby-sig@lists.fedoraproject.org https://admin.fedoraproject.**org/mailman/listinfo/ruby-sighttps://admin.fedoraproject.org/mailman/listinfo/ruby-sig
On 2012-04-14 21:08, Wan Zuhao wrote:
Hi Jeroen,
What you've suggested is definitely a good idea. I do agree it's important to reflect which *version*, in addtion to the name, link, etc. of a particular gem that was converted into rpm, as sometimes the latest patches and bug fixes are not included in the rpm.
The point is also, sometimes bug fixes (especially security issues) *are* in fact included in the RPM, but the gem/rpm package version number would not reflect that.
Kind regards,
Jeroen van Meeuwen
I see your point.
On Sunday, April 15, 2012 at 9:37 AM, Jeroen van Meeuwen (Kolab Systems) wrote:
On 2012-04-14 21:08, Wan Zuhao wrote:
Hi Jeroen,
What you've suggested is definitely a good idea. I do agree it's important to reflect which *version*, in addtion to the name, link, etc. of a particular gem that was converted into rpm, as sometimes the latest patches and bug fixes are not included in the rpm.
The point is also, sometimes bug fixes (especially security issues) *are* in fact included in the RPM, but the gem/rpm package version number would not reflect that.
Kind regards,
Jeroen van Meeuwen
-- Systems Architect, Kolab Systems AG
e: vanmeeuwen at kolabsys.com (http://kolabsys.com) m: +44 74 2516 3817 w: http://www.kolabsys.com
pgp: 9342 BF08 _______________________________________________ ruby-sig mailing list ruby-sig@lists.fedoraproject.org (mailto:ruby-sig@lists.fedoraproject.org) https://admin.fedoraproject.org/mailman/listinfo/ruby-sig
I do agree that it's very likely to miss out information such as patches and bug fixes applied if we rely on gem versions solely.
Maybe we can compare the timestamp of the built rpm to that of the gem commits? Then we can roughly tell by the time the rpm was built, which patches have already been applied. Apparently this method can't be 100% accurate. I'm trying to figure out some other more reliable way, but I'm still kinda new to the Fedora dev community, so it will probably take some time for me to get a better grip on these. I'll have to dig deeper to see exactly what information is available.
By the way, could you please give some examples of such gem/rpm?
Thanks,
Zuhao
On Sunday, April 15, 2012 at 11:31 PM, Wan Zuhao wrote:
I see your point.
On Sunday, April 15, 2012 at 9:37 AM, Jeroen van Meeuwen (Kolab Systems) wrote:
On 2012-04-14 21:08, Wan Zuhao wrote:
Hi Jeroen,
What you've suggested is definitely a good idea. I do agree it's important to reflect which *version*, in addtion to the name, link, etc. of a particular gem that was converted into rpm, as sometimes the latest patches and bug fixes are not included in the rpm.
The point is also, sometimes bug fixes (especially security issues) *are* in fact included in the RPM, but the gem/rpm package version number would not reflect that.
Kind regards,
Jeroen van Meeuwen
-- Systems Architect, Kolab Systems AG
e: vanmeeuwen at kolabsys.com (http://kolabsys.com) m: +44 74 2516 3817 w: http://www.kolabsys.com
pgp: 9342 BF08 _______________________________________________ ruby-sig mailing list ruby-sig@lists.fedoraproject.org (mailto:ruby-sig@lists.fedoraproject.org) https://admin.fedoraproject.org/mailman/listinfo/ruby-sig
This sounds like a good feature to add to the site. It could simply be accomplished by listing the gems available for every Fedora version + rawhide along w/ their versions and other metadata.
This metadata can include a list of patches applied to the gem (as well as direct access to their contents if we wanted). We can extract this information directly from the (s)rpm itself.
Going forward, if we start standardizing on patch names, it might make it easier to automate parsing patch information from the srpm. I always try naming patches %{gemname}-%{version}-%{some general subject/description}
We will look at producing some mockups for this feature and implementing them as part of the GSoC (keep those suggestions coming!)
BTW as a related side note, I'm looking for a co-mentor for this project. The person will not have to do anything except for have their name appear on the list as a formality to the GSoC process. If you're interested please ping me on or off list (asap please as the final project evaluation deadline is in a few days)
Appreciate it, -Mo
On 04/15/2012 05:46 PM, Wan Zuhao wrote:
I do agree that it's very likely to miss out information such as patches and bug fixes applied if we rely on gem versions solely.
Maybe we can compare the timestamp of the built rpm to that of the gem commits? Then we can roughly tell by the time the rpm was built, which patches have already been applied. Apparently this method can't be 100% accurate. I'm trying to figure out some other more reliable way, but I'm still kinda new to the Fedora dev community, so it will probably take some time for me to get a better grip on these. I'll have to dig deeper to see exactly what information is available.
By the way, could you please give some examples of such gem/rpm?
Thanks,
Zuhao
On Sunday, April 15, 2012 at 11:31 PM, Wan Zuhao wrote:
I see your point.
On Sunday, April 15, 2012 at 9:37 AM, Jeroen van Meeuwen (Kolab Systems) wrote:
On 2012-04-14 21:08, Wan Zuhao wrote:
Hi Jeroen,
What you've suggested is definitely a good idea. I do agree it's important to reflect which *version*, in addtion to the name, link, etc. of a particular gem that was converted into rpm, as sometimes the latest patches and bug fixes are not included in the rpm.
The point is also, sometimes bug fixes (especially security issues) *are* in fact included in the RPM, but the gem/rpm package version number would not reflect that.
Kind regards,
Jeroen van Meeuwen
-- Systems Architect, Kolab Systems AG
e: vanmeeuwen at kolabsys.com http://kolabsys.com m: +44 74 2516 3817 w: http://www.kolabsys.com
pgp: 9342 BF08 _______________________________________________ ruby-sig mailing list ruby-sig@lists.fedoraproject.org mailto:ruby-sig@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/ruby-sig
ruby-sig mailing list ruby-sig@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/ruby-sig
ruby-sig@lists.fedoraproject.org