Process Change: Package Reviews with Flags

Dominik 'Rathann' Mierzejewski dominik at greysector.net
Wed Feb 7 19:47:32 UTC 2007


On Wednesday, 07 February 2007 at 19:18, Jesse Keating wrote:
> On Wednesday 07 February 2007 11:12, Dominik 'Rathann' Mierzejewski wrote:
[...]
> > > or even worse, insert some small thing in a package that gets pulled into
> > > most buildroots that will further taint any more builds.  Could be hard
> > > to detect until it is far far too late.
> >
> > It would be stopped at the sign-and-push stage at worst. I'm sure there are
> > many eyes following the cvs commits list. It would be spotted quite fast
> > IMHO.
> 
> You can prevent messages from being posted to cvs commits.

So why isn't that fixed already?

> > >  With proper barriers in place,
> > > the most damage a rouge user can do is to their own
> > > package, or to any packages foolishly left wide open.
> >
> > I don't really mind the ACLs as much as I do mind having to go through
> > another approval (for CVS import) after my package has ALREADY been
> > APPROVED.
> 
> You don't.  Once your package is approved, appropriate people are notified and 
> setup the location so that you can do your import and build.  What is so 
> difficult about this?

Oh really? Since when? The Contributors page still says (after my package
is APPROVED):

---cut---
Identify Yourself as the Owner of the Package

Place your requests in the 'New Package' section at:
    * Extras/CVSSyncNeeded
with:
   1. The name of the package
   2. Your bugzilla account e-mail address
   3. A list of who, if anyone, should also be CC'd on bug reports
   4. A pointer to the review ticket

This will be used to set up the proper records in the owners database,
which is used for access to build the package, bugzilla population, and
other features. Once this is done, you may then import the package. 
---cut---

This wasn't necessary before (I could just add myself to owners.list) and
THAT's what I have issues with. Now I have to wait until someone manually
add something I used to be able to add myself. And I'm NOT notified when
this is done (or am I?). And no, subscribing to CVSSyncNeeded changes is
NOT an option.

Regards,
R.

-- 
Fedora Extras contributor  http://fedoraproject.org/wiki/DominikMierzejewski
Livna contributor http://rpm.livna.org MPlayer developer http://mplayerhq.hu
"Faith manages."
        -- Delenn to Lennier in Babylon 5:"Confessions and Lamentations"




More information about the Fedora-maintainers mailing list