First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 132343
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Crypto team <crypto@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Carsten Lohrke <carlo@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 132343 depends on: 130994 Show dependency tree
Show dependency graph
Bug 132343 blocks: 132213
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-05-05 06:50 0000
We need the following ebuilds stable for KDE 3.5.2 (see bug 120587):

>=app-crypt/dirmngr-0.9.3 ~x86
>=dev-libs/libksba-0.9.13 ~x86 
>=dev-libs/libassuan-0.6.9 ~x86 
>=app-crypt/gpgme-1.1.2 ~x86 
>=app-crypt/gnupg-1.9.0 ~x86


Please check if the ebuild are ready and invite arch herds as soon as possible.

------- Comment #1 From Caleb Tennis 2006-05-10 05:46:10 0000 -------
Crypto, does anyone object to asking arch teams to mark stable (other than the
blocker bug issue) ?

------- Comment #2 From Daniel Black 2006-05-10 06:50:51 0000 -------
no objections here. Feel free to CC the arches you want.

Arch testers:

If there is a self test in gnupg-1.9.20-r1 that fails due to USE=-smime. This
is harmless as the self test is for a smime program.
Ref: https://bugs.gentoo.org/show_bug.cgi?id=131026#c5

app-crypt/gpgme-1.1.2-r1 is the same as app-crypt/gpgme-1.1.2 except
--with-gnusm (smime stuff) forced instead of a USE flag. There is no logical
change that would preclude a stabilization.

------- Comment #3 From Carsten Lohrke 2006-05-12 16:51:50 0000 -------
Please add app-crypt/pinentry to the list.

------- Comment #4 From Chris Gianelloni (RETIRED) 2006-05-16 13:34:13 0000 -------
So should we start working on this or what?

------- Comment #5 From Markus Ullmann 2006-05-21 10:06:28 0000 -------
Well as we have nothing left to stop this, let's dance ;)

Please test and mark stable

------- Comment #6 From Markus Ullmann 2006-05-21 10:20:46 0000 -------
Okay, stop for a minute, taviso raised objections, discussion on -dev is about
to be started

------- Comment #7 From Tavis Ormandy (RETIRED) 2006-05-21 11:21:34 0000 -------
I think splitting gnupg into gnupg2 gpgsm is a better idea, marking gnupg-1.9.x
would be pretty dangerous. 

removing arches for now until these new packages are ready.

------- Comment #8 From Stefan Schweizer 2006-05-21 12:30:09 0000 -------
After some discussion on #gentoo-dev I added a new revision of gnupg-1.9.20
that has a gpg2-experimental useflag to not install the unstable gpg2.
It is currently masked. Please test if it works ok.

------- Comment #9 From Carsten Lohrke 2006-05-25 06:57:41 0000 -------
Would the crypto herd take bug 13337 into account, please?

------- Comment #10 From Chris Gianelloni (RETIRED) 2006-05-25 11:18:24 0000 -------
Bug #13337?  I'm sure you meant another one.

Anyway, I'm testing this new masked version on x86 and it works fine for
signing/encrypting/decrypting.  I say it is ready to go (at least on x86).

------- Comment #11 From Markus Ullmann 2006-05-25 12:57:02 0000 -------
Full ack ;)

------- Comment #12 From Chris Gianelloni (RETIRED) 2006-05-25 14:19:13 0000 -------
I've gone ahead and done the KEYWORDS for this stuff for x86.  You'll probably
want to unmask the newer gnupg revision, as I didn't touch that.  I feel that
is best left up to the maintainers.

------- Comment #13 From cilly 2006-05-26 03:14:18 0000 -------
On the gnupg homepage it is said clearly, that gnupg 1.9.x is the developer
branch:

"GnuPG 1.9 is the development branch of GnuPG with support for S/MIME."

Since: 

the gnupg project is alive
the devs aren't run over by a bus
the devs are working on it and will release never versions

It is not wise to mark software out of the developer branch as stable and to
confuse others!

This software IS developer software and 1.9 will never be released it will
always be a developer branch, this has not to be added to a stable system!

I see this as a security flaw, since gnupg checks signatures and provides
integrity.

------- Comment #14 From Henrik Brix Andersen 2006-05-26 03:20:00 0000 -------
(In reply to comment #13)
> It is not wise to mark software out of the developer branch as stable and to
> confuse others!

I fully agree. We should not mark developer snapshots/developer releases stable
in Gentoo Portage when upstream doesn't consider the code ready for production
use.

------- Comment #15 From Chris Gianelloni (RETIRED) 2006-05-26 06:12:01 0000 -------
Well, the version that I marked stable is still masked, so if you guys feel
like reverting the KEYWORDS, it shouldn't affect anyone (other than those that
have unmasked it intentionally).

------- Comment #16 From Daniel Black 2006-05-26 06:17:00 0000 -------
It is considered stable by upstream which is why this request went ahead. Refer
URL.

------- Comment #17 From Daniel Black 2006-05-26 06:35:10 0000 -------
Tavis, Henrik - upstream are happy. Are you?

------- Comment #18 From Chris Gianelloni (RETIRED) 2006-05-26 07:31:35 0000 -------
So can I do amd64 yet?

*grin*

------- Comment #19 From Henrik Brix Andersen 2006-05-26 07:54:25 0000 -------
(In reply to comment #17)
> Tavis, Henrik - upstream are happy. Are you?

That announcement is not reflected on their web site, which is where I checked.
Thank you for clearing that up. Thumbs up from me :)

------- Comment #20 From Chris Gianelloni (RETIRED) 2006-05-26 08:07:08 0000 -------
In that case... amd64 is done... =]

------- Comment #21 From Doug Goldstein 2006-05-26 17:54:38 0000 -------
Shouldn't you guys add some arches?

------- Comment #22 From Daniel Black 2006-05-26 18:42:10 0000 -------
Take 2:

As per URL most of the gnupg-1.9 branch is stable. The gpg from gnupg-1.4 is
still recommended for day to day use. This explains the odd dependency on it
self and the gpg2-experimental USE flag.

The stable targets are:
=app-crypt/dirmngr-0.9.3
=dev-libs/libksba-0.9.13
=dev-libs/libassuan-0.6.10
=app-crypt/gpgme-1.1.2-r1
=app-crypt/gnupg-1.9.20-r3

From memory all these programs include good selftests.

------- Comment #23 From Carsten Lohrke 2006-05-28 06:17:38 0000 -------
(In reply to comment #10)
> Bug #13337?  I'm sure you meant another one.

Sorry. Bug 133377.

------- Comment #24 From Jason Wever (RETIRED) 2006-05-29 12:34:52 0000 -------
Everything is now SPARC stable

------- Comment #25 From Joe Jezak 2006-05-29 18:58:18 0000 -------
Marked ppc stable.

------- Comment #26 From Thomas Cort (RETIRED) 2006-05-31 21:48:28 0000 -------
alpha stable.

------- Comment #27 From Robin Johnson 2006-10-04 21:20:25 0000 -------
arm/hppa/mips/s390: *bump* on stabilization.
See commment 22 for the list.

------- Comment #28 From CPUShare 2006-11-06 10:55:31 0000 -------
may I ask why gnupg-1.9 has gnupg-1.4 as a dependency? That looks a bit
confusing. I monitor duplicate packages through emerge -p -P, and I couldn't
figure out which was the package requiring gnupg-1.4, until I figured out it
was gnupg-1.9 itself ;). "equery depends gnupg" doesn't show gnupg as a
dependency on itself, that's why I couldn't figure it out (I had to read the
.ebuild to figure it out for sure).

Perhaps the rdependency is what requires it? Does it mean gpg-1.9 requires 1.4
to be installed in order to build? Shouldn't then 1.4 be deleted completely
from the system instead of hanging around in emerge -p -P listing?

------- Comment #29 From Daniel Black 2006-11-06 11:27:45 0000 -------
(In reply to comment #28)
> may I ask why gnupg-1.9 has gnupg-1.4 as a dependency?
Earlier versions of gnupg-1.9 (<1.9.92) needed gnupg-1.4 to provide the full
compliment of service.
http://lists.gnupg.org/pipermail/gnupg-announce/2005q4/000209.html

> That looks a bit confusing.
Yes - thankfully the upstream have merged 1.4 codebase into 1.9.92
http://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000236.html

> Does it mean gpg-1.9 requires 1.4
> to be installed in order to build?
no - its a RDEPEND

> Shouldn't then 1.4 be deleted completely
no - not fully stable - see 1.9.92 annoucement

------- Comment #30 From Jeroen Roovers 2006-11-15 16:01:53 0000 -------
HPPA done.

------- Comment #31 From Jakub Moc 2007-01-01 13:20:32 0000 -------
Nothing left to do here...

First Last Prev Next    No search results available      Search page      Enter new bug