Path: csiph.com!eternal-september.org!feeder.eternal-september.org!aioe.org!bofh.it!news.nic.it!robomod From: Nikolaus Rath Newsgroups: linux.debian.maint.python Subject: Re: Searching for a roundup sponsor Date: Fri, 02 Oct 2015 18:10:02 +0200 Message-ID: References: X-Original-To: debian-python@lists.debian.org X-Mailbox-Line: From debian-python-request@lists.debian.org Fri Oct 2 16:06:02 2015 Old-Return-Path: X-Amavis-Spam-Status: No, score=-2.6 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FOURLA=0.1, MURPHY_DRUGS_REL8=0.02, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01] autolearn=no autolearn_force=no X-Policyd-Weight: DYN_NJABL=ERR(0) NOT_IN_SBL_XBL_SPAMHAUS=-1.5 BL_NJABL=ERR(-1.5) CL_IP_EQ_HELO_IP=-2 (check from: .rath. - helo: .out4-smtp.messagingengine. - helo-domain: .messagingengine.) FROM/MX_MATCHES_HELO(DOMAIN)=-2; rate: -7 Dkim-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d= messagingengine.com; h=content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-sasl-enc:x-sasl-enc; s=smtpout; bh=I7TV39j1HrOSz3a N058gIwsNf4c=; b=h4GFnrs8XHBPnebz3eQ7labPYzGM8n+nboYcBTL//6wezKd ceMt/q9s/dN+9ihLI3VN3xxGwS9nDrfOMKRxL0k1D7b+TTLWssR07M14zmlo4Ohl k0wn2F9RjFHPyg4ih7eAAu6J3qjPfG529F5mdrvzz5vDB/mSpLE9tGgosgpk= X-Sasl-Enc: qN3unHF9CYtG/I1Gce8F50ecUh9RR5VuD/kRsZHNb3Wq 1443801924 Mail-Copies-To: never Mail-Followup-To: debian-python@lists.debian.org User-Agent: Gnus/5.130014 (Ma Gnus v0.14) Emacs/24.4 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Mailing-List: archive/latest/12736 List-ID: List-URL: List-Archive: https://lists.debian.org/msgid-search/87bnchuugs.fsf@thinkpad.rath.org Approved: robomod@news.nic.it Lines: 41 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Date: Fri, 02 Oct 2015 09:05:23 -0700 X-Original-Message-ID: <87bnchuugs.fsf@thinkpad.rath.org> X-Original-References: <2DC14910-C100-48CC-B042-BC0D967522B9@xs4all.nl> Xref: csiph.com linux.debian.maint.python:7425 On Oct 01 2015, "Kai Storbeck" wrote: > Hi, > > Roundup 1.4.20-1.1 is still the version in stable. Roundup 1.5 was > released a few years back, and I need someone to help me with the > final stages in getting 1.5 in stretch, or getting it removed. > > > Roundup is a python web application with quite some vendored code > (javascript libs and fonts), 5 different licenses, and in 1.5.0 there > is an offending file that has an incompatible licensing, so I had to > "dfsg" it. (is there a verb for that?) > > During this work a security issue came along and this made me realise > that the architecture of roundup isn't exactly compatible with what I > would expect from a proper Debain package. > > We can create security updates for roundup, but that won't help any > existing user as all actual issue trackers are using a copy of the lib > at the time of their birth. > > I'm quite unsure on how to proceed here, but perhaps someone with more > experience can help me with the steps needed. I'd suggest to patch the roundip initialization command to use symlinks to /usr instead of copying the libs. Disclaimer: it's been a while since I last used roundup, and much longer since I last set up a fresh instance. Best, -Nikolaus --=20 GPG encrypted emails preferred. Key id: 0xD113FCAC3C4E599F Fingerprint: ED31 791B 2C5C 1613 AF38 8B8A D113 FCAC 3C4E 599F =C2=BBTime flies like an arrow, fruit flies like a Banana.=C2= =AB