MainInclusionReportSnort

Differences between revisions 1 and 2
Revision 1 as of 2008-01-14 10:40:28
Size: 2494
Editor: gordian
Comment:
Revision 2 as of 2008-08-06 16:33:11
Size: 2514
Editor: localhost
Comment: converted to 1.6 markup
Deletions are marked like this. Additions are marked like this.
Line 5: Line 5:
 0. ''Availability:'' [http://archive.ubuntu.com/ubuntu/pool/universe/s/snort]; available for all supported architectures.  0. ''Availability:'' [[http://archive.ubuntu.com/ubuntu/pool/universe/s/snort]]; available for all supported architectures.
Line 9: Line 9:
  * [http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=snort CVE entries]: this is a nightmare...
  * [http://secunia.com/search/?search=snort Secunia history]: another nightmare on elm street.
  * [[http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=snort|CVE entries]]: this is a nightmare...
  * [[http://secunia.com/search/?search=snort|Secunia history]]: another nightmare on elm street.
Line 22: Line 22:
  * [http://bugs.debian.org/src:snort Debian bugs]: several bugs are there at different severities. Most worring is the SIG11 and endian issues.
  * [http://packages.qa.debian.org/s/snort.html Maintenance in Debian] is vigorous
  * [http://www.snort.org/ Upstream] is vigorous
  * [[http://bugs.debian.org/src:snort|Debian bugs]]: several bugs are there at different severities. Most worring is the SIG11 and endian issues.
  * [[http://packages.qa.debian.org/s/snort.html|Maintenance in Debian]] is vigorous
  * [[http://www.snort.org/|Upstream]] is vigorous
Line 28: Line 28:
  * [http://www.pathname.com/fhs/ FHS], [http://www.de.debian.org/doc/debian-policy/ Debian Policy].   * [[http://www.pathname.com/fhs/|FHS]], [[http://www.de.debian.org/doc/debian-policy/|Debian Policy]].
Line 30: Line 30:
  * [http://www.netfort.gr.jp/~dancer/column/libpkg-guide/libpkg-guide.html Debian library packaging guide] standards compliance ?   * [[http://www.netfort.gr.jp/~dancer/column/libpkg-guide/libpkg-guide.html|Debian library packaging guide]] standards compliance ?
Line 40: Line 40:
MIR bug: [https://bugs.launchpad.net/182806] MIR bug: [[https://bugs.launchpad.net/182806]]

Main Inclusion Report for sourcepackage

Requirements

  1. Availability: http://archive.ubuntu.com/ubuntu/pool/universe/s/snort; available for all supported architectures.

  2. Rationale:

  3. Security:

    • CVE entries: this is a nightmare...

    • Secunia history: another nightmare on elm street.

    • Any binaries running as root or suid/sgid ? Any daemons ?
      • yes. there is a daemon running.
    • Network activity: does it open any port ? Does it handle incoming network data ?
      • Given the nature of the package...
    • Any source code review performed ? (The approver will do a quick and shallow check.)
      • no.
  4. Quality assurance:

    • In what situations does the package not work out of the box without configuration ?
      • afaict it works out of the box. it seems to have sane defaults. Can't test all the options in my environment.
    • Does the package ask any debconf questions higher than priority 'medium' ?
      • yes depending on how the config autodetection goes.
    • Debian bugs: several bugs are there at different severities. Most worring is the SIG11 and endian issues.

    • Maintenance in Debian is vigorous

    • Upstream is vigorous

    • Hardware: Does this package deal with hardware and if so how exotic is it ?
      • none.
  5. Standards compliance:

    • FHS, Debian Policy.

      • Package looks FHS compliant. Tons of lintian errors some of which are a bit annoying and bad debconf usage.
    • Debian library packaging guide standards compliance ?

      • Interesting way of shipping libraries.... at best.
    • Packaging system (debhelper/cdbs/dbs) ? Patch system ? Any packaging oddities ?
      • debhelper. patches are inline (diff.gz). Package is complex and requires deep understanding.
  6. Dependencies:

    • Build-deps on gs-common and libprelude-dev that are in universe.
    • Depends on libprelude2 that is in universe.

Reviewers

MIR bug: https://bugs.launchpad.net/182806

The author of this report should put their name here; reviewers will add comments etc. too

FabioMassimoDiNitto

MainInclusionReportSnort (last edited 2008-08-06 16:33:11 by localhost)