Re: ipp-usb 0.9.27 announce

Zdenek Dohnal <[email protected]> Wed, 24 Jul 2024 17:53:17 +0200
Newsgroups dev.linux.lists.printing-architecture
Message-ID <[email protected]>
Hi Johannes,

On 7/24/24 16:14, Johannes Meixner wrote:
>
> Hello Zdenek
>
> On 2024-07-24 15:37, Zdenek Dohnal wrote:
>> can I somehow ignore vendor dir of goipp at the moment?
>
> I don't know how ipp-usb is made on Fedora / Red Hat
> so I may misunderstand things here.
>
> I guess you talk about some additional vendor.tar.zst
> source file?
Nope, Alex added some version of goipp (around goipp upstream commit  
94c92a6d5d2 ) into ipp-usb 0.9.27 archive itself - there are some 
differences, but it does not look critical, and they are in the current 
goipp master...
>
> At openSUSE we have ipp-usb and goipp as separated
> source packages in the openSUSE Build Service (OBS)
> see
> https://build.opensuse.org/package/show/Printing/ipp-usb
> and
> https://build.opensuse.org/package/show/Printing/goipp
I packaged goipp and ipp-usb this way as well, back in 2020 or something 
- https://koji.fedoraproject.org/koji/packageinfo?packageID=32067 , 
https://koji.fedoraproject.org/koji/packageinfo?packageID=32248
>
> Why separated source packages?

I usually am against bundling, but sometimes it makes sense - if we 
could say ipp-usb is the only project using goipp, then it could be okay 
to include it. But this could happen only in OS, where it is defined 
that ipp-usb will be the only goipp user. This we can't say for sure for 
github project, where we don't know how many  users forked and uses the 
code...

So I would go for goipp being separated as well...

>
> See my
> https://build.opensuse.org/request/show/1157901#comment-1919874
> where I wrote (excerpt):
> -----------------------------------------------------------
> please describe via an explanatory comment in the spec file
> what the additional vendor.tar.zst source is,
> what its purpose is, and wherefrom it can be downloaded
> (exact upstream download URL) so that others at openSUSE
> can understand what that additional source is,
> why it is needed for the openSUSE package, and
> that we can verify that vendor.tar.zst in the openSUSE
> package is the unmodified source from its upstream URL.
> -----------------------------------------------------------
> and my subsequent
> https://build.opensuse.org/request/show/1157901#comment-1919883
> where I wrote (excerpt):
> -----------------------------------------------------------
> In this particular case (additional vendor.tar.zst source)
> the files in vendor/github.com/OpenPrinting/goipp
> neither match GitHub master code in
> https://github.com/OpenPrinting/goipp
> nor what on
> https://github.com/OpenPrinting/goipp/tags
> the tar.gz for v1.0.0 nor v1.1.0 result
> (in contrast to what vendor/modules.txt seems to tell)
> so currently the additional vendor.tar.zst source
> looks rather "suspicious" - at least to me.
> -----------------------------------------------------------
>
> I wrote that in Aplil 2024 with the XZ attack in my mind
> so additional sources that do not match what one gets
> from its "well known" upstream URLs are rather scary.
>
> I would recommend to
> Keep Separated Sources Strictly Separated ( KSSSS ;-)
> so that others can understand what "the sources" are
> and can retrace where "the sources" come from and
> can validate that "the sources" are unmodified
> upstream sources.

The archive you speak about looks to be added by someone from community, 
where here it was added by goipp author.


Best regards,

Zdenek


P.S. 0.9.27 can be compiled even without vendor dir (I was afraid it 
will fail since it is missing and Makefile sets -mod=vendor)

>
>
> Kind Regards
> Johannes Meixner

-- 
Zdenek Dohnal
Senior Software Engineer
Red Hat, BRQ-TPBC