[Bug 1173881] New: tuxguitar package differs from .DSA file
http://bugzilla.opensuse.org/show_bug.cgi?id=1173881 Bug ID: 1173881 Summary: tuxguitar package differs from .DSA file Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: Other OS: openSUSE Factory Status: NEW Severity: Normal Priority: P5 - None Component: Other Assignee: fstrba@suse.com Reporter: bwiedemann@suse.com QA Contact: qa-bugs@suse.de CC: opensuse.lietuviu.kalba@gmail.com Blocks: 1062303 Found By: Development Blocker: --- While working on reproducible builds for openSUSE, I found that our tuxguitar package differs for every build. build-compare pkg-diff shows that /usr/share/tuxguitar/plugins/tuxguitar-viewer.jar/META-INF/TUXGUITA.DSA differs Is that .DSA file required for something? It cannot really help security in this way, can it? btw: tigervnc has a similar problem with its /usr/share/vnc/classes/VncViewer.jar/META-INF/TIGERVNC.RSA -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1173881 http://bugzilla.opensuse.org/show_bug.cgi?id=1173881#c1 --- Comment #1 from Fridrich Strba <fstrba@suse.com> --- With https://build.opensuse.org/request/show/819447 the DSA file does not exist any more. But there might be other issues for reproducibility, since xmvn metadata specification mandates an uuid for each element. And this is the version of Tuxguitar that is built using maven. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1173881 Fridrich Strba <fstrba@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |IN_PROGRESS -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1173881 http://bugzilla.opensuse.org/show_bug.cgi?id=1173881#c2 --- Comment #2 from Bernhard Wiedemann <bwiedemann@suse.com> --- The xmvn issue is tracked in bug 1162112 xmvn seems to not be a problem with tuxguitar-1.4 -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1173881 http://bugzilla.opensuse.org/show_bug.cgi?id=1173881#c3 --- Comment #3 from Fridrich Strba <fstrba@suse.com> --- (In reply to Bernhard Wiedemann from comment #2)
The xmvn issue is tracked in bug 1162112 xmvn seems to not be a problem with tuxguitar-1.4
tuxguitar-1.4 does not use maven/xmvn for building -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com