Re: ipp-usb 0.9.27 announce

Johannes Meixner <[email protected]> Wed, 24 Jul 2024 16:14:35 +0200
Newsgroups dev.linux.lists.printing-architecture
Message-ID <[email protected]>
Hello Zdenek

On 2024-07-24 15:37, Zdenek Dohnal wrote:
> can I somehow ignore vendor dir of goipp at the moment?

I don't know how ipp-usb is made on Fedora / Red Hat
so I may misunderstand things here.

I guess you talk about some additional vendor.tar.zst
source file?

At openSUSE we have ipp-usb and goipp as separated
source packages in the openSUSE Build Service (OBS)
see
https://build.opensuse.org/package/show/Printing/ipp-usb
and
https://build.opensuse.org/package/show/Printing/goipp

Why separated source packages?

See my
https://build.opensuse.org/request/show/1157901#comment-1919874
where I wrote (excerpt):
-----------------------------------------------------------
please describe via an explanatory comment in the spec file
what the additional vendor.tar.zst source is,
what its purpose is, and wherefrom it can be downloaded
(exact upstream download URL) so that others at openSUSE
can understand what that additional source is,
why it is needed for the openSUSE package, and
that we can verify that vendor.tar.zst in the openSUSE
package is the unmodified source from its upstream URL.
-----------------------------------------------------------
and my subsequent
https://build.opensuse.org/request/show/1157901#comment-1919883
where I wrote (excerpt):
-----------------------------------------------------------
In this particular case (additional vendor.tar.zst source)
the files in vendor/github.com/OpenPrinting/goipp
neither match GitHub master code in
https://github.com/OpenPrinting/goipp
nor what on
https://github.com/OpenPrinting/goipp/tags
the tar.gz for v1.0.0 nor v1.1.0 result
(in contrast to what vendor/modules.txt seems to tell)
so currently the additional vendor.tar.zst source
looks rather "suspicious" - at least to me.
-----------------------------------------------------------

I wrote that in Aplil 2024 with the XZ attack in my mind
so additional sources that do not match what one gets
from its "well known" upstream URLs are rather scary.

I would recommend to
Keep Separated Sources Strictly Separated ( KSSSS ;-)
so that others can understand what "the sources" are
and can retrace where "the sources" come from and
can validate that "the sources" are unmodified
upstream sources.


Kind Regards
Johannes Meixner
-- 
SUSE Software Solutions Germany GmbH
Frankenstr. 146 - 90461 Nuernberg - Germany
(HRB 36809, AG Nuernberg) GF: Ivo Totev