3) the VERIFY QA is obligated to:
- check the GPG signature and checksum of the packages
- install it, run it, test if it works.
- running rpm-build-compare.sh on the binaries to see if there have
been any significant changes (e.g., to the libraries used)
rpm-build-compare.sh is usually run after building in mach and before
posting to updates-testing. I don't think this should be mandatory for
people to give a VERIFY as it will require more work than they will
probably be willing to do. That said, if anyone actually does it, it's
definitely a plus...