Re: [Security-Discuss] Invalid signature on perl-URPM-1.03-2mdk.i586.rpm
Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On 18-Dec-04, at 5:19 PM, Rick Kunath wrote:
> {snip}
>
>> if this
>> hadn't been brought up on the list, I'm afraid I wouldn't have even
>> found out about this.
>
> What about this on the Mandrake Club web page (Posted on December 1):
>
> ------------------------------
> Distro: Bugzilla is now the only way to report bugs
>
> Posted by warly on Wednesday, December 01 2004 @ 14:02:53 CET
>
> Bugzilla is now the only location where to report your problems
>
> ------------------------------
>
> So are we to follow Warly's instructions, or follow some other
> recommended
> method? What is the preferred method?
This is Warly talking about Bugzilla vs. Anthill. We've consolidated
everything to Bugzilla now and Anthill will be shut down in the very
near future (as soon as I have time).
So, yes, when referring to reporting bugs, Bugzilla is the place to
report bugs *as opposed to Anthill*. Warly kinda left that part out.
> If you let us all know the best way to bring these things to the
> attention
> of the appropriate individuals, and I'll make sure to proceed that way
> in
> the future.
>
> And I did get a response from Warly very quickly via Bugzilla,
> something
> commendable.
I'm not saying don't use Bugzilla. The reason why I responded as I did
was because giving someone a hard time for reporting a problem here
isn't really good form. Yes, reporting to Bugzilla is a good thing
but... letting me know of the problem is a good thing to (when it comes
to updates). Assigning the problem to Warly doesn't do me any good...
I won't ever see the report. So instead of it being fixed the next
day, it could have been Monday before anyone bothered to let me know
about it.
Dropping a note here as well is appreciated because then I'll actually
be aware of the problem.
>>> In this case, the bug filing has already been done.
>
> Let's see... there were a lot of folks having issues with the file,
> rpms on
> several community as well as official update mirrors all possessed the
> same
> erroneous signature, Mandrake Update as well as urpmi rejected the
> rpm, the
> error was verified at the GUI level and at the command line. I didn't
> want
> to install an update rpm rejected for an incorrect signature, so I
> filed a
> report.
>
> I still think a bug report was the best way to flag the issue. But you
> let
> us know how you'd rather we proceed.
Yes, a bug report is a good thing. Chiding someone for making mention
of it here isn't. That's not really good form.
>> Yes, and it's a bogus report. There's nothing wrong with the file.
>> Look at my comments on the report and you'll see that, unlike the
>> poster and some other people, I went through and actually *checked* to
>> see what the problem was.
>
>> And there was none.
>
> Thanks for re-signing and re-uploading the problem rpm.
No worries. It appears that things move too quickly... =( rpm for
CS2.1 doesn't adequately deal with rpms built in 10.1 which was the
source of the problem. This is a fairly significant problem for me
because I can't keep upgrading my build machines... =) Once CS3 comes
out, this sort of thing shouldn't happen anymore (although I suspect
there will be other issues... Murphy's Law).
> We all appreciate your hard work Vincent, and we may not always
> proceed just
> exactly as you would hope, but our heart is still in the right place.
I know that... =)
> The important thing is that the community worked. We all helped each
> other
> and you were actually there and responsive to users.
That's what I aim to do. Doesn't always happen, but I try my damndest
(which is why, contrary to my normal guidelines, I pushed the php
update testing and release late last night rather than waiting until
Monday).
--
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig
(application/pgp-signature, 186 B) - not displayed