Review for Source Package: fonts-font-awesome-legacy
Launchpad bug: https://bugs.launchpad.net/bugs/2159639
Target series: devel
Analysed source version: 6-3 (release pocket)
Binary packages: fonts-font-awesome-legacy
Review type: reorg (renamed/reorganised source) — Detected a
renamed/reorganised source that appears to have been in main before: a prior
MIR bug exists under a source name that is no longer published in the archive -
a renamed/absorbed predecessor (https://bugs.launchpad.net/bugs/1509662).
Treated like a re-review — all findings are non-blocking recommendations; the
reviewer can promote any line back to Required.
[Summary]
- This is not really a renamed/reorganised source, but also to some extend it
is. The old fonts are provided as they were but built from a new source.
OK:
- Review for Source Package: fonts-font-awesome-legacy
- Reporter MIR content found and used as context.
- The binary package fonts-font-awesome-legacy needs to be promoted from
universe to main. No other binaries are built from this source, so all built
binaries require promotion.
(The promotion status shows the source is currently in universe with one
binary (fonts-font-awesome-legacy) that is not yet in main and needs promotion.
This is informational per policy and not a blocker.)
=> MIR team ACK
=> This does not need a security review
Required TODOs:
- none
Recommended TODOs:
- #1 The package should get a team bug subscriber on this bug before being
promoted
- #2 Testing, it is not theoretical - see for ideas below
[Rationale, Duplication and Ownership]
OK:
- There is no other package in main providing the same functionality.
(The only candidate in main is fonts-font-awesome, which the MIR report
identifies as the runtime dependent that requires this legacy package — they
are complementary, not duplicative. Other candidates (fonts-fork-awesome,
node-fortawesome-fontawesome-free) are in universe and provide distinct forks
or platform-specific packaging rather than the same legacy Font Awesome font
files.)
- The rationale given in the report seems valid and useful for Ubuntu
(The rationale correctly identifies that this package is needed in main to
satisfy a runtime dependency from fonts-font-awesome (already in main), and the
dependency analysis confirms the package has no further dependencies requiring
promotion. A reviewer comment notes this is not merely a rename/split but a
rebuild from SVG sources, which does not undermine the dependency-driven
justification.)
Problems:
- No owning team is subscribed to the bug
[Dependencies]
OK:
- no runtime dependencies outside main needing MIR
- no other build-time Dependencies with active code in the final binaries to
MIR due to this
(The single binary package fonts-font-awesome-legacy is an architecture-all
fonts package containing only font files (ttf, woff, woff2, eot, otf, svg),
LESS/SCSS stylesheets, and YAML metadata. There are no static binaries, no
static link hints, no vendored directories, and no runtime dependencies, so
build-time tools such as fontforge and python3-fontforge do not contribute
active code to the shipped artifacts.)
- no -dev/-debug/-doc packages that need exclusion
- No dependencies in main that are only superficially tested requiring more
tests now.
(The package has no runtime dependencies at all, and therefore no runtime
dependencies in main that could be only superficially tested.)
Problems: none
[Embedded sources and static linking]
OK:
- no static linking
- does not have unexpected Built-Using entries
- not a go package, no extra constraints to consider in that regard
- not a rust package, no extra constraints to consider in that regard
- Does not include vendored code
Problems: none
[Security]
OK:
- history of CVEs does not look concerning
(Both the Ubuntu CVE tracker and the cross-vendor NVD/cvelistV5 corpus
returned zero CVEs for the current package name and appropriate predecessor
terms (fonts-font-awesome, fontawesome).)
- does not run a daemon as root
- does not use webkit1,2
- does not use lib*v8 directly
- does not parse data formats (files [images, video, audio, xml, json, asn.1],
network packets, structures, ...) from an untrusted source.
(The package has no runtime dependencies and ships only font files and icon
SVGs under a fonts section. There are no executables, services, or
network-facing components, so no untrusted data format parsing occurs at
runtime.)
- does not expose any external endpoint (port/socket/... or similar)
(No systemd service files or apparmor profiles are present, and the package
contains only font assets and build scripts with no network binding patterns. A
fonts package has no mechanism to expose external endpoints.)
- does not process arbitrary web content
(The package has no runtime dependencies, no executables, no services, and no
network-facing components — it is in the fonts section and ships only font
files and related assets. There is no mechanism by which it could process
arbitrary web content.)
- does not use centralized online accounts
- does not integrate arbitrary javascript into the desktop
(The package ships only static font assets (SVG/OTF/TTF) and build helpers,
has zero runtime dependencies, and no desktop file or JS integration patterns
were found. The binary section is solely 'fonts', confirming no desktop
integration surface exists.)
- does not deal with system authentication (eg, pam), etc)
- does not deal with security attestation (secure boot, tpm, signatures)
(The source package contains only font files, stylesheets, and metadata with
no executables, services, or network-facing components. No cryptographic, TPM,
secure boot, or PKCS#11 patterns were found in the source or its dependencies,
and the package has no runtime dependencies at all.)
- does not deal with cryptography (en-/decryption, certificates, signing, ...)
(The package has no runtime dependencies and its build dependencies
(debhelper, eot-utils, fontforge, python3-fontforge) are font tooling, not
crypto libraries. No crypto-related source patterns were detected, and the
package only ships static font files, stylesheets, and metadata.)
- this makes appropriate (for its exposure) use of established risk mitigation
features (dropping permissions, using temporary environments, restricted
users/groups, seccomp, systemd isolation features, apparmor, ...)
(The package contains only font files, LESS/SCSS stylesheets, and YAML
metadata under /usr/share/fonts and /usr/share/fonts-font-awesome. No service
files, AppArmor profiles, setuid/setgid binaries, systemd units, or executables
were found, confirming the exposure level is minimal and isolation mechanisms
are unnecessary.)
Problems: none
[Common blockers]
OK:
- does not FTBFS currently; Launchpad build records pass for arches: amd64,
amd64v3, arm64, armhf, i386, ppc64el, riscv64, s390x
- This does not need special HW for build or test
(The reporter explicitly states the package does not depend on exotic
hardware. The package is in the fonts section, builds with standard font
tooling (fontforge, eot-utils), and installs only static font files with no
executables or services, so no dedicated or exotic hardware is required for
building or testing.)
- no special hardware needed, so there is no compromise to accept
- no new python2 dependency
- not a python package, no extra constraints to consider in that regard
- not a go package, no extra constraints to consider in that regard
Problems:
- No built or autopkgtest is declared or has been observed running for this
package.
In theory a non-trivial autopkgtest should be added.
But given what this is that is very non-gating
But you could think of validating font files with fonttools or fc-query
before passing blindly?
[Packaging red flags]
OK:
- Ubuntu does not carry a delta
(The delta analysis reports the package as a sync (no Ubuntu revision) with
no delta present and no diffstat, confirming there is no Ubuntu-specific
packaging divergence to maintain.)
- symbols tracking not applicable for this kind of code
(the package ships no shared library (.so), so ABI symbol tracking does not
apply)
- Upstream update history is (good/slow/sporadic)
(The package is explicitly a legacy font package shipping older Font Awesome
versions required by fonts-font-awesome; such packages naturally have minimal
upstream activity because the tracked versions are no longer under active
development upstream. No upstream tracker data was available, but the package
nature and description confirm intentional stability rather than abandonment.)
- Debian/Ubuntu update history is (good/slow/sporadic)
(The computed release cadence descriptor is 'good' with 4 releases in 32 days
(avg interval 10.3 days), well exceeding the one-upload-per-six-months
threshold. No upstream tracker data is available for comparison, but the distro
cadence alone is clearly active.)
- promoting this does not seem to cause issues for MOTUs that so far maintained
the package
(The package has no individual or team uploaders listed in
ubuntu-upload-permission, and the upload history shows no specific uploader,
indicating it is likely synced from Debian without regular Ubuntu-specific
maintenance.)
- no excessive lintian warnings
- It is not on the lto-disabled list
- debian/control defines a correct Maintainer field
- Current release is packaged - well this is tricky, the conceptual argument it
have the old versions here, so this is okay
Problems:
- Non-native package but debian/watch not found - yet this was explained in the
report
- The rules file uses a standard debhelper base but contains substantial
hand-rolled install logic in the dh_install override with nested shell loops,
string manipulation, and symlink creation using relative paths across multiple
font versions and file formats.
(The build override merely calls helper scripts and is acceptable, but the
install override performs extensive manual file copying, renaming, and symlink
creation across three upstream versions and multiple font formats, which is
fragile and warrants a reviewer's judgment on maintainability.)
I understand how you got to this combining mulitple sources and font versions
into one, not hard recommending or requiring an improvement of this.
[Upstream red flags]
OK:
- no incautious use of malloc/sprintf (the language has no direct MM)
(The source tree contains only font assets, LESS/SCSS stylesheets, YAML
metadata, and Python build helper scripts — no compiled languages or direct
memory management APIs are present. Python is a memory-safe language with no
direct malloc/sprintf usage.)
- no use of sudo, gksu, pkexec, or LD_LIBRARY_PATH (usage is OK inside tests)
- no use of user 'nobody' outside of tests
- no use of setuid / setgid
- no important open bugs (crashers, etc) in Debian or Ubuntu
(Launchpad shows one open bug which is the MIR request (not a functional
issue), Debian BTS reports zero open and zero RC bugs, and the upstream tracker
reports zero open issues.)
- no dependency on webkit, qtwebkit or libseed
- not part of the UI for extra checks
(The package is in the fonts section and ships only static font files,
stylesheets, and metadata with no GUI toolkit runtime dependencies or
executable binaries. It is not the kind of application an end user would launch
from a desktop menu.)
- not user-visible, translations not needed
- no important Errors/warnings during the build
Problems: none
** Changed in: fonts-font-awesome-legacy (Ubuntu)
Status: Confirmed => Fix Committed
** Changed in: fonts-font-awesome-legacy (Ubuntu)
Status: Fix Committed => In Progress
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2159639
Title:
[MIR] fonts-font-awesome-legacy
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/fonts-font-awesome-legacy/+bug/2159639/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs