[Bug 509619] Review Request: srtp - Secure Real-Time Transport Protocol (SRTP) Library

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug.


https://bugzilla.redhat.com/show_bug.cgi?id=509619





--- Comment #1 from Jason Tibbitts <tibbs@xxxxxxxxxxx>  2009-07-11 01:54:34 EDT ---
It really helps if you could run rpmlint on your packages and address the
output before you submit them for review.

  srtp-debuginfo.x86_64: E: empty-debuginfo-package
You should disable the debuginfo package if you don't create a main package.

  srtp-devel.x86_64: W: wrong-file-end-of-line-encoding
   /usr/share/doc/srtp-devel-1.4.2/draft-irtf-cfrg-icm-00.txt
This needs to be run through tr -d \\r or dos2unix to fix up the line endings.

In addition, I feel significant unease at a security sensitive network protocol
being available only as a static library.  If a security issue is found,
everything that linked against it will need to be rebuilt.  At least one distro
seems to build this as a shared library:
http://www.mail-archive.com/pld-cvs-commit@xxxxxxxxxxxxxxxxxxx/msg58219.html

Also, version 1.4.4 seems to be current, while you've packaged 1.4.2.

-- 
Configure bugmail: https://bugzilla.redhat.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.

_______________________________________________
Fedora-package-review mailing list
Fedora-package-review@xxxxxxxxxx
http://www.redhat.com/mailman/listinfo/fedora-package-review

[Index of Archives]     [Fedora Legacy]     [Fedora Desktop]     [Fedora SELinux]     [Yosemite News]     [KDE Users]     [Fedora Tools]