Review for Source Package: fonts-font-awesome-legacy
Launchpad bug: https://bugs.launchpad.net/bugs/2159639
Target series: devel
Analysed source version: 6-3 (release pocket)
Binary packages: fonts-font-awesome-legacy
Review type: reorg (renamed/reorganised source) — Detected a 
renamed/reorganised source that appears to have been in main before: a prior 
MIR bug exists under a source name that is no longer published in the archive - 
a renamed/absorbed predecessor (https://bugs.launchpad.net/bugs/1509662). 
Treated like a re-review — all findings are non-blocking recommendations; the 
reviewer can promote any line back to Required.

[Summary]
- This is not really a renamed/reorganised source, but also to some extend it 
is. The old fonts are provided as they were but built from a new source.

OK:
- Review for Source Package: fonts-font-awesome-legacy
- Reporter MIR content found and used as context.
- The binary package fonts-font-awesome-legacy needs to be promoted from 
universe to main. No other binaries are built from this source, so all built 
binaries require promotion.
  (The promotion status shows the source is currently in universe with one 
binary (fonts-font-awesome-legacy) that is not yet in main and needs promotion. 
This is informational per policy and not a blocker.)

=> MIR team ACK
=> This does not need a security review

Required TODOs:
- none

Recommended TODOs:
- #1 The package should get a team bug subscriber on this bug before being 
promoted
- #2 Testing, it is not theoretical - see for ideas below

[Rationale, Duplication and Ownership]
OK:
- There is no other package in main providing the same functionality.
  (The only candidate in main is fonts-font-awesome, which the MIR report 
identifies as the runtime dependent that requires this legacy package — they 
are complementary, not duplicative. Other candidates (fonts-fork-awesome, 
node-fortawesome-fontawesome-free) are in universe and provide distinct forks 
or platform-specific packaging rather than the same legacy Font Awesome font 
files.)
- The rationale given in the report seems valid and useful for Ubuntu
  (The rationale correctly identifies that this package is needed in main to 
satisfy a runtime dependency from fonts-font-awesome (already in main), and the 
dependency analysis confirms the package has no further dependencies requiring 
promotion. A reviewer comment notes this is not merely a rename/split but a 
rebuild from SVG sources, which does not undermine the dependency-driven 
justification.)

Problems:
- No owning team is subscribed to the bug

[Dependencies]
OK:
- no runtime dependencies outside main needing MIR
- no other build-time Dependencies with active code in the final binaries to 
MIR due to this
  (The single binary package fonts-font-awesome-legacy is an architecture-all 
fonts package containing only font files (ttf, woff, woff2, eot, otf, svg), 
LESS/SCSS stylesheets, and YAML metadata. There are no static binaries, no 
static link hints, no vendored directories, and no runtime dependencies, so 
build-time tools such as fontforge and python3-fontforge do not contribute 
active code to the shipped artifacts.)
- no -dev/-debug/-doc packages that need exclusion
- No dependencies in main that are only superficially tested requiring more 
tests now.
  (The package has no runtime dependencies at all, and therefore no runtime 
dependencies in main that could be only superficially tested.)

Problems: none

[Embedded sources and static linking]
OK:
- no static linking
- does not have unexpected Built-Using entries
- not a go package, no extra constraints to consider in that regard
- not a rust package, no extra constraints to consider in that regard
- Does not include vendored code

Problems: none

[Security]
OK:
- history of CVEs does not look concerning
  (Both the Ubuntu CVE tracker and the cross-vendor NVD/cvelistV5 corpus 
returned zero CVEs for the current package name and appropriate predecessor 
terms (fonts-font-awesome, fontawesome).)
- does not run a daemon as root
- does not use webkit1,2
- does not use lib*v8 directly
- does not parse data formats (files [images, video, audio, xml, json, asn.1], 
network packets, structures, ...) from an untrusted source.
  (The package has no runtime dependencies and ships only font files and icon 
SVGs under a fonts section. There are no executables, services, or 
network-facing components, so no untrusted data format parsing occurs at 
runtime.)
- does not expose any external endpoint (port/socket/... or similar)
  (No systemd service files or apparmor profiles are present, and the package 
contains only font assets and build scripts with no network binding patterns. A 
fonts package has no mechanism to expose external endpoints.)
- does not process arbitrary web content
  (The package has no runtime dependencies, no executables, no services, and no 
network-facing components — it is in the fonts section and ships only font 
files and related assets. There is no mechanism by which it could process 
arbitrary web content.)
- does not use centralized online accounts
- does not integrate arbitrary javascript into the desktop
  (The package ships only static font assets (SVG/OTF/TTF) and build helpers, 
has zero runtime dependencies, and no desktop file or JS integration patterns 
were found. The binary section is solely 'fonts', confirming no desktop 
integration surface exists.)
- does not deal with system authentication (eg, pam), etc)
- does not deal with security attestation (secure boot, tpm, signatures)
  (The source package contains only font files, stylesheets, and metadata with 
no executables, services, or network-facing components. No cryptographic, TPM, 
secure boot, or PKCS#11 patterns were found in the source or its dependencies, 
and the package has no runtime dependencies at all.)
- does not deal with cryptography (en-/decryption, certificates, signing, ...)
  (The package has no runtime dependencies and its build dependencies 
(debhelper, eot-utils, fontforge, python3-fontforge) are font tooling, not 
crypto libraries. No crypto-related source patterns were detected, and the 
package only ships static font files, stylesheets, and metadata.)
- this makes appropriate (for its exposure) use of established risk mitigation 
features (dropping permissions, using temporary environments, restricted 
users/groups, seccomp, systemd isolation features, apparmor, ...)
  (The package contains only font files, LESS/SCSS stylesheets, and YAML 
metadata under /usr/share/fonts and /usr/share/fonts-font-awesome. No service 
files, AppArmor profiles, setuid/setgid binaries, systemd units, or executables 
were found, confirming the exposure level is minimal and isolation mechanisms 
are unnecessary.)

Problems: none

[Common blockers]
OK:
- does not FTBFS currently; Launchpad build records pass for arches: amd64, 
amd64v3, arm64, armhf, i386, ppc64el, riscv64, s390x
- This does not need special HW for build or test
  (The reporter explicitly states the package does not depend on exotic 
hardware. The package is in the fonts section, builds with standard font 
tooling (fontforge, eot-utils), and installs only static font files with no 
executables or services, so no dedicated or exotic hardware is required for 
building or testing.)
- no special hardware needed, so there is no compromise to accept
- no new python2 dependency
- not a python package, no extra constraints to consider in that regard
- not a go package, no extra constraints to consider in that regard

Problems:
- No built or autopkgtest is declared or has been observed running for this 
package.
  In theory a non-trivial autopkgtest should be added.
  But given what this is that is very non-gating
  But you could think of validating font files with fonttools or fc-query 
before passing blindly?

[Packaging red flags]
OK:
- Ubuntu does not carry a delta
  (The delta analysis reports the package as a sync (no Ubuntu revision) with 
no delta present and no diffstat, confirming there is no Ubuntu-specific 
packaging divergence to maintain.)
- symbols tracking not applicable for this kind of code
  (the package ships no shared library (.so), so ABI symbol tracking does not 
apply)
- Upstream update history is (good/slow/sporadic)
  (The package is explicitly a legacy font package shipping older Font Awesome 
versions required by fonts-font-awesome; such packages naturally have minimal 
upstream activity because the tracked versions are no longer under active 
development upstream. No upstream tracker data was available, but the package 
nature and description confirm intentional stability rather than abandonment.)
- Debian/Ubuntu update history is (good/slow/sporadic)
  (The computed release cadence descriptor is 'good' with 4 releases in 32 days 
(avg interval 10.3 days), well exceeding the one-upload-per-six-months 
threshold. No upstream tracker data is available for comparison, but the distro 
cadence alone is clearly active.)
- promoting this does not seem to cause issues for MOTUs that so far maintained 
the package
  (The package has no individual or team uploaders listed in 
ubuntu-upload-permission, and the upload history shows no specific uploader, 
indicating it is likely synced from Debian without regular Ubuntu-specific 
maintenance.)
- no excessive lintian warnings
- It is not on the lto-disabled list
- debian/control defines a correct Maintainer field
- Current release is packaged - well this is tricky, the conceptual argument it 
have the old versions here, so this is okay

Problems:
- Non-native package but debian/watch not found - yet this was explained in the 
report
- The rules file uses a standard debhelper base but contains substantial 
hand-rolled install logic in the dh_install override with nested shell loops, 
string manipulation, and symlink creation using relative paths across multiple 
font versions and file formats.
  (The build override merely calls helper scripts and is acceptable, but the 
install override performs extensive manual file copying, renaming, and symlink 
creation across three upstream versions and multiple font formats, which is 
fragile and warrants a reviewer's judgment on maintainability.)
  I understand how you got to this combining mulitple sources and font versions 
into one, not hard recommending or requiring an improvement of this.

[Upstream red flags]
OK:
- no incautious use of malloc/sprintf (the language has no direct MM)
  (The source tree contains only font assets, LESS/SCSS stylesheets, YAML 
metadata, and Python build helper scripts — no compiled languages or direct 
memory management APIs are present. Python is a memory-safe language with no 
direct malloc/sprintf usage.)
- no use of sudo, gksu, pkexec, or LD_LIBRARY_PATH (usage is OK inside tests)
- no use of user 'nobody' outside of tests
- no use of setuid / setgid
- no important open bugs (crashers, etc) in Debian or Ubuntu
  (Launchpad shows one open bug which is the MIR request (not a functional 
issue), Debian BTS reports zero open and zero RC bugs, and the upstream tracker 
reports zero open issues.)
- no dependency on webkit, qtwebkit or libseed
- not part of the UI for extra checks
  (The package is in the fonts section and ships only static font files, 
stylesheets, and metadata with no GUI toolkit runtime dependencies or 
executable binaries. It is not the kind of application an end user would launch 
from a desktop menu.)
- not user-visible, translations not needed
- no important Errors/warnings during the build

Problems: none

** Changed in: fonts-font-awesome-legacy (Ubuntu)
       Status: Confirmed => Fix Committed

** Changed in: fonts-font-awesome-legacy (Ubuntu)
       Status: Fix Committed => In Progress

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2159639

Title:
  [MIR] fonts-font-awesome-legacy

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/fonts-font-awesome-legacy/+bug/2159639/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to