#736360 lintian: do not emit source-is-missing for doxygen embedding jquery

#736360#5
Date:
2014-01-22 18:32:19 UTC
From:
To:
Dear Maintainers,

Please stop warning about jquery.js as embedded by Doxygen. I evaluated
all options at fixing this issue in Doxygen and conclude that a fix is
infeasible and its usefulness is limited. The issue and the problems
about fixing it are documented in /usr/share/doc/doxygen/README.jquery
(in the doxygen package >= jessie). Even if there were a security issue
in jquery, it will likely not affect any user via Doxygen.

For detection I suggest to look for doxygen.png and doxygen.css. If both
are present, the jquery warning should be suppressed.

Note that some maintainers have started replacing jquery.js in response
to the lintian tag. Unfortunately what is named jquery.js does not only
contain jquery. Thus some generated documentation is now broken. I would
like lintian to error out if jquery.js of Doxygen-generated
documentation is a symbolic link to the jquery package. Do you need a
separate bug number for this?

Thanks

Helmut

#736360#8
Date:
2014-02-03 11:39:10 UTC
From:
To:
* Helmut Grohne <helmut@subdivi.de>, 2014-01-22, 19:32:

Security is not the only issue here. jquery.js created by Doxygen is
minified, so there's a risk that we ship it without source.

#736360#13
Date:
2014-02-03 12:33:15 UTC
From:
To:
Thanks for highlighting the issue. Fortunately we already have a tool to
work around this issue. It is called Built-Using. Last time I checked
whether (dh_)doxygen should be simplifying the process of adding the
Built-Using headers, I achieved no consensus on the value of such a
change and discussion on what Built-Using is supposed to mean was still
ongoing. If there is consensus now, we can use that tool to address this
particular issue.

Do you think that this would adequately address the availability of
source? Do you happen to have an alternative proposal in mind?

Helmut

#736360#16
Date:
2014-02-08 22:03:13 UTC
From:
To:
* Helmut Grohne <helmut@subdivi.de>, 2014-02-03, 13:33:

Yes.

Well, the simpler alternative is to make doxygen use unminified JS.

#736360#21
Date:
2014-02-09 06:47:31 UTC
From:
To:
I am not yet entirely convinced about the "simpler" yet. Thanks for the
suggestion anyway.

Upstream goes to great lengths to make using unminified JS hard. There
is this jquery/split_jquery.pl script, that hacks jquery pieces of 1<<15
bytes. Of course the number of pieces is hard coded as 3 in various
places. Even in the best case the file ending up in generated
documentation as "jquery.js" is a compilation (concatenation) of various
libraries. So it might not count as source either. To actually ship
unminified JS, an alternative might be to replace the code that creates
jquery.js with a file copy operation and shipping the JS outside the
doxygen binary. There is a drafted patch for this variant at
http://bugs.debian.org/736432#5. In any case simple is not an attribute
of the process.

Helmut

#736360#26
Date:
2017-10-28 17:56:44 UTC
From:
To:
#736360#33
Date:
2017-10-29 12:35:50 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
lintian, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 736360@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Chris Lamb <lamby@debian.org> (supplier of updated lintian package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 29 Oct 2017 12:14:30 +0000
Source: lintian
Binary: lintian
Built-For-Profiles: nocheck
Architecture: source all
Version: 2.5.57
Distribution: unstable
Urgency: medium
Maintainer: Debian Lintian Maintainers <lintian-maint@debian.org>
Changed-By: Chris Lamb <lamby@debian.org>
Description:
 lintian    - Debian package checker
Closes: 718640 736360 878575 879977
Changes:
 lintian (2.5.57) unstable; urgency=medium
 .
   * Summary of tag changes:
     + Added:
       - debian-rules-should-not-set-CFLAGS-from-noopt
 .
   * checks/control-file.pm:
     + [CL] Avoid false positives in debian-control-has-empty-field when the
       field is wrapped onto a new line. Thanks to Mattia Rizzolo for the
       report.  (Closes: #879977)
   * checks/cruft.desc:
     + [CL] Add example on how to remove trailing whitespace with sed.
     + [CL] Drop README.source from files to check against the
       file-contains-trailing-whitespace tag as it can include quotes
       from upstream that would be ideally left intact.
   * checks/debhelper.pm:
     + [NT] Remove code handling named compat levels.
   * checks/files.desc:
     + [CL] Ignore embedded jQuery libraries for Doxygen.  (Closes: #736360)
   * checks/rules.desc:
     + [CL] Warn if packages set CFLAGS if the value of DEB_BUILD_OPTIONS
       contains noopt.  (Closes: #718640)
 .
   * commands/lintian.pm:
     + [NT] Have lintian resignal between various stages of the
       processing.  Previously, ill-timed signals would be caught and
       "semi-ignored" with lintian happily continuing to process the
       next package.  (Closes: #878575)
 .
   * data/debhelper/named-compat-levels:
     + [NT] Removed; no longer used.
Checksums-Sha1:
 dec4d05fc0c0b7359140b2edd8d72768fcc117ea 2898 lintian_2.5.57.dsc
 6b55830b4ecd83b03912985f75132617e7b1061c 1245140 lintian_2.5.57.tar.xz
 8854f386d22b6e0ea79883215ae262ab74df404c 1069580 lintian_2.5.57_all.deb
 4bd0eb98393f93eac4c7dc0e99463052082ad3dc 16245 lintian_2.5.57_amd64.buildinfo
Checksums-Sha256:
 d17230b1a6f435cd4eba334670935002402fb1ed08fbc5ba70264283ca412389 2898 lintian_2.5.57.dsc
 ce8438ef27ed367aba6ca5640d6a6f089ff18458516eddfd896bdd687618218f 1245140 lintian_2.5.57.tar.xz
 1bcfe780a2fefb0afee119979ca7abeff994a508ec2059823421c29b6d93c29f 1069580 lintian_2.5.57_all.deb
 5575e3da81ffa901c7ef903c53d2f8a948ee981b008c442a4b4ed2ecb7400780 16245 lintian_2.5.57_amd64.buildinfo
Files:
 dd499cf365a9413fd0a0dece659ba43a 2898 devel optional lintian_2.5.57.dsc
 14430f8591d3bf830ce8341f79c779e3 1245140 devel optional lintian_2.5.57.tar.xz
 868e639a242538df703f1a6abbe7d83b 1069580 devel optional lintian_2.5.57_all.deb
 4239d7daf54403481000c85000e6699d 16245 devel optional lintian_2.5.57_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAln1xpIACgkQHpU+J9Qx
Hlg9Vw//a+Q3iArQT6Wu1NFlAhsBXUF+tKZvea4aOCaMEhmsVnmfgDRQLN1+mX8R
WcLXo9C+IvKPNr481/R2kWf3CYXwNTJxxiL6m2eHWlQQcpMBTjp7XVf6DCDwdR8c
Ka2KiTOH8FGA8K+gqEDGzPLDtuaWQvNufdj/EN2HxVWo6N1Kobe10s/tO2sdDowf
sWNAuFEYU6nxFJEN6biaGix2BPoWsMv/il0+EtUrkKUeVxNFGI6Qe5AxqpXYeZjM
XNwPpBxLPvmflA9DkjCeUr1KkXh9trV5fvSftT5ylv7l2/3Iay6DNq8QloWNXXoz
ZeMebyNO9RzFTnaTA/7MrqxLTpq/gUZZpia8r5ircobZc+dXrVJJj7ohMWbBUrE9
jCoC666GKSUd8a0zRMfTZuy/dVu12hYUTKXSBKY/Xj+i1z4NELURHiTyMjTC0LPb
o4XQnRiSVMtv6SD+w8tnIeFLlduz9Fc58S43iFwB2qRG2FO90SnYRWRyNYppa9C9
KWNOuvkr3c5rTFpZHnzX0lLqeeF5c+LJjF10CrO4lkwglaxs4snFNyK7RsZB1LyN
QwDVEcf9uciLCqBMC4NKa5JpK0gddQXsL9528xNEPkWgAHR7LUTw1YQZCcYmzelK
JasNrc2PlK7VKme6ld8mG5mdYA6MhF4zPK+pSKQV4rSCEcW7HxI=
=QFoL
-----END PGP SIGNATURE-----

#736360#38
Date:
2017-11-29 13:50:06 UTC
From:
To:
Hi,

it seems that this correctly fixed for library embedding, but not for source-
missing:

E: libimobiledevice source: source-is-missing docs/html/jquery.js line length
is 32402 characters (>512)

I think the same exception should be done for this tag.

Regards,

#736360#43
Date:
2017-11-29 13:57:39 UTC
From:
To:
found 736360 2.5.60
thanks

Hi,

Re-opening to track this properly.


Regards,