[Bug 499394] Review Request: ampache - web based audio/video streaming application

bugzilla at redhat.com bugzilla at redhat.com
Thu May 14 10:15:44 UTC 2009


Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug.


https://bugzilla.redhat.com/show_bug.cgi?id=499394





--- Comment #8 from Paulo Roma Cavalcanti <promac at gmail.com>  2009-05-14 06:15:42 EDT ---
(In reply to comment #7)
> rpmlint on the binary still has some issues: 
> [ke4qqq at nalleyt61 SPECS]$ rpmlint ../RPMS/noarch/ampache-3.5-7.fc10.noarch.rpm 
> ampache.noarch: E: non-executable-script
> /var/www/ampache/locale/base/gather-messages.sh 0644
> ampache.noarch: W: non-standard-uid /var/log/ampache apache
> ampache.noarch: W: non-standard-gid /etc/ampache.cfg apache
> ampache.noarch: E: non-readable /etc/ampache.cfg 0640
> 1 packages and 0 specfiles checked; 2 errors, 2 warnings.
> 
> The non-standard gid/uid warnings can be ignored, but the two errors should be
> looked at. 

The file /etc/ampache.cfg contains the mysql ampache database password
in clear text. Therefore, I think it is better a more restrictive reading
permission.

The script /var/www/ampache/locale/base/gather-messages.sh can have a 755
permission if you prefer this way.

> 
> Also I noticed that you are putting content in /var/www/apache
> 
> https://fedoraproject.org/wiki/Packaging/Guidelines#Web_Applications
> requires that web apps use /usr/share/%{name}

I changed the server root to /usr/share/ampache

> 
> Also the Requires(hint) line - lame and mp3splt, as you identify above aren't
> in fedora, so you can't require those (not to mention the legal issues that
> abound)  

Removed non free packages.

SRPM URL: http://orion.lcg.ufrj.br/RPMS/src/ampache-3.5-8.fc10.src.rpm

-- 
Configure bugmail: https://bugzilla.redhat.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.




More information about the package-review mailing list