FAQ Search Today's Posts Mark Forums Read
» Video Reviews

» Linux Archive

Linux-archive is a website aiming to archive linux email lists and to make them easily accessible for linux users/developers.


» Sponsor

» Partners

» Sponsor

Go Back   Linux Archive > Debian > Debian Development

 
 
LinkBack Thread Tools
 
Old 09-14-2012, 11:51 AM
"Didier 'OdyX' Raboud"
 
Default Bug#687624: ITP: libdvdcss-pkg -- automated installer for libdvdcss

Hi Dmitry,

Le vendredi, 14 septembre 2012 13.19:43, Dmitry Smirnov a écrit :
> Package name: libdvdcss-pkg

Surprising package.

> * Installer is implemented as shell script installed as DPKG post-invoke
> handler.
>
> * Host package version meant to me an exact match of guest package
> with debian/watch file inherited from guest package for notifications
> about new upstream versions.

uscan does absolutely no checking of the resulting tarball so this is
sensitive to DNS MITM (at least). IMHO having a tighter connection between
this libdvdcss-pkg and the upstream tarballs hashsums would be a good idea:
you would need to upload a new version of libdvdcss-pkg for each new version
of libdvdcss to tighten the trust chain.

Cheers,

OdyX
 
Old 09-14-2012, 12:09 PM
Thomas Koch
 
Default Bug#687624: ITP: libdvdcss-pkg -- automated installer for libdvdcss

> Le vendredi, 14 septembre 2012 13.19:43, Dmitry Smirnov a écrit :
> > * Installer is implemented as shell script installed as DPKG post-invoke
> > handler.

I remember a discussion from somewhere, sometime that it would be a good
thing(tm) to have a common infrastructure (helper script) for this kind of
packages. The common infrastructure should make sure that the downloaded files
are crytographically checked against a hashsum.

From my head I know these similar packages: flash-installer-nonfree, some
microsoft fonts downloader, java-package (for sun's java), ...?

Regards,

Thomas Koch, http://www.koch.ro


--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 201209141409.49855.thomas@koch.ro">http://lists.debian.org/201209141409.49855.thomas@koch.ro
 
Old 09-14-2012, 12:14 PM
Reinhard Tartler
 
Default Bug#687624: ITP: libdvdcss-pkg -- automated installer for libdvdcss

On Fri, Sep 14, 2012 at 1:19 PM, Dmitry Smirnov <onlyjob@member.fsf.org> wrote:
> Package: wnpp
> Severity: wishlist
> X-Debbugs-CC: debian-devel@lists.debian.org
>
> Package name: libdvdcss-pkg
> Version: 1.2.12-1
> Upstream Author: Dmitry Smirnov <onlyjob@member.fsf.org>
> License: GPL-3+
> Description: download, build and install libdvdcss package
> This package will automatically download, build and install
> libdvdcss on your system.
> .
> libdvdcss is a library for accessing and unscrambling DVDs encrypted
> with the Content Scramble System (CSS).
> It is a free software but it may be illegal in some jurisdictions.
>
> This is a proof-of-concept implementation of automated installer for libdvdcss.

This has been discussed before within the pkg-multimedia team. There
is even preliminary work available at
http://anonscm.debian.org/gitweb/?p=pkg-multimedia/libdvdcss-installer.git;a=summary.

Team pkg-multimedia, does anyone remember or know why that branch has
not been uploaded to debian yet?

--
regards,
Reinhard


--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: CAJ0cceaOdLMphs3jNcLwS6tSM6ka7BOymxuH8Qac132AXhFu5 w@mail.gmail.com">http://lists.debian.org/CAJ0cceaOdLMphs3jNcLwS6tSM6ka7BOymxuH8Qac132AXhFu5 w@mail.gmail.com
 
Old 09-14-2012, 12:18 PM
Dmitry Smirnov
 
Default Bug#687624: ITP: libdvdcss-pkg -- automated installer for libdvdcss

On Fri, 14 Sep 2012 21:51:44 Didier 'OdyX' Raboud wrote:

> uscan does absolutely no checking of the resulting tarball so this is
> sensitive to DNS MITM (at least). IMHO having a tighter connection between
> this libdvdcss-pkg and the upstream tarballs hashsums would be a good idea:
> you would need to upload a new version of libdvdcss-pkg for each new
> version of libdvdcss to tighten the trust chain.

Thanks for your feedback -- I like the idea of having tarballs hashsums.
I will implement it.

Regards,
Dmitry.


--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 201209142218.18206.onlyjob@member.fsf.org">http://lists.debian.org/201209142218.18206.onlyjob@member.fsf.org
 
Old 09-14-2012, 12:26 PM
Simon McVittie
 
Default Bug#687624: ITP: libdvdcss-pkg -- automated installer for libdvdcss

On 14/09/12 13:09, Thomas Koch wrote:
> From my head I know these similar packages: flash-installer-nonfree, some
> microsoft fonts downloader, java-package (for sun's java), ...?

game-data-packager, although that one is a bit different: it supports a
relatively large number of game-data packages, and most of the data it
works on is not freely downloadable, so it often has to support building
"the same" package from various different releases (American vs.
European publisher, original version vs. budget re-release, etc.) in
order to support the particular disk/CD/DVD that a user owns.

S


--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 5053226B.40609@debian.org">http://lists.debian.org/5053226B.40609@debian.org
 
Old 09-14-2012, 12:26 PM
Dmitry Smirnov
 
Default Bug#687624: ITP: libdvdcss-pkg -- automated installer for libdvdcss

On Fri, 14 Sep 2012 22:09:48 Thomas Koch wrote:
> I remember a discussion from somewhere, sometime that it would be a good
> thing(tm) to have a common infrastructure (helper script) for this kind of
> packages. The common infrastructure should make sure that the downloaded
> files are crytographically checked against a hashsum.

We could start from one nice implementation and then think what it can become.
To me start from reasonably good template would be a good one.


> From my head I know these similar packages: flash-installer-nonfree, some
> microsoft fonts downloader, java-package (for sun's java), ...?

There is not too much similarity here:

java-package expect user to download upstream archive and run make-jpkg to
generate .deb and install generated debs manually (no upgrades).

Others do not build packages...

I'd like to handle upgrades and install only using package management system.

Cheers,
Dmitry.


--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 201209142226.54537.onlyjob@member.fsf.org">http://lists.debian.org/201209142226.54537.onlyjob@member.fsf.org
 
Old 09-14-2012, 12:49 PM
Dmitry Smirnov
 
Default Bug#687624: ITP: libdvdcss-pkg -- automated installer for libdvdcss

On Fri, 14 Sep 2012 22:14:57 Reinhard Tartler wrote:
> This has been discussed before within the pkg-multimedia team. There
> is even preliminary work available at
> http://anonscm.debian.org/gitweb/?p=pkg-multimedia/libdvdcss-installer.git;
> a=summary.

Thank you, I'm aware of that. Some time ago I wrote to Andres Mejia (who made
libdvdcss-installer) to discuss but got no reply yet.

Our implementations are very different.

I'm member of pkg-multimedia but I hesitated to alter libdvdcss-installer
without Andres' consent.


> Team pkg-multimedia, does anyone remember or know why that branch has
> not been uploaded to debian yet?

If I recall correctly, it can't install the package from postinst due to DPKG
lock. Probably that's the main reason.
Also it is manual, got no debconf prompt to warn user about consequences,
can't handle upgrades (and removes) gracefully etc.

Cheers,
Dmitry.


--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: 201209142249.21579.onlyjob@member.fsf.org">http://lists.debian.org/201209142249.21579.onlyjob@member.fsf.org
 
Old 09-14-2012, 03:45 PM
Jon Dowland
 
Default Bug#687624: ITP: libdvdcss-pkg -- automated installer for libdvdcss

On Fri, Sep 14, 2012 at 01:26:19PM +0100, Simon McVittie wrote:
> game-data-packager, although that one is a bit different: it supports a
> relatively large number of game-data packages, and most of the data it
> works on is not freely downloadable, so it often has to support building
> "the same" package from various different releases (American vs.
> European publisher, original version vs. budget re-release, etc.) in
> order to support the particular disk/CD/DVD that a user owns.

Indeed - I had envisaged game-data-packager growing into 'data-packager' at
some point.

The design was initially inspired by java-package, which IMHO was a better
solution than run-as-root postinst (the flash installer method, and the one
OP is proposing in this ITP). java-package since disappeared, as the sun
java's could be packaged; that situation has sadly regressed so perhaps
there's call for java support in (game-)data-packager once again.

In this case, however, it seems as easy to install libdvdcss from
debian-multimedia than to have hacks to build it from source. The hacky
package would have to live in contrib anyway, so it's still not in Debian.


--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: http://lists.debian.org/20120914154511.GB3124@debian
 

Thread Tools




All times are GMT. The time now is 10:35 AM.

VBulletin, Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.
Copyright ©2007 - 2008, www.linux-archive.org