From Fedora Project Wiki
(Only for libraries; rewording about comments)
 
(7 intermediate revisions by 3 users not shown)
Line 1: Line 1:
== Addition to ReviewGuidelines ==
== Addition to ReviewGuidelines ==


MUST: Reviewer must examine an RPM package's list of dependencies and any unnecessary explicit Requires found must be removed. <BR>
MUST: A package's list of dependencies must not contain any unnecessary explicit Requires on libraries.
SHOULD: Anything in the spec file which is not obvious should have a comment explaining it.


== Addition to Packaging Guidelines ==
== Addition to Packaging Guidelines ==


=== Explicit Requires ===
=== Explicit Requires ===
Packages should not contain superfluous explicit ''Requires'' within the spec file,
Packages must not contain explicit ''Requires'' on libraries except when absolutely  
except when absolutely necessary. Any explicit ''Requires'' should be explained with comments in the spec file.
necessary. When explicit library ''Requires'' are necessary, there should be a spec file comment justifying it.


In particular, we rely on rpmbuild's automatically added dependencies on library SONAMEs.  
We generally rely on rpmbuild to automatically add dependencies on library SONAMEs.  
Modern package management tools are capable of resolving such dependencies to determine  
Modern package management tools are capable of resolving such dependencies to determine  
the required packages. Explicit dependencies on specific package names may aid the  
the required packages. Explicit dependencies on specific package names may aid the  
inexperienced user, who attempts at installing RPM packages manually. However, history  
inexperienced user, who attempts at installing RPM packages manually, however, history  
has shown that such dependencies add confusion when library/files are moved from one  
has shown that such dependencies add confusion when library/files are moved from one  
package to another, when packages get renamed, when one out of multiple alternative  
package to another, when packages get renamed, when one out of multiple alternative  
Line 28: Line 27:
</pre>
</pre>


Packagers should revisit an explicit dependency as appropriate to avoid that
Packagers should revisit an explicit dependency as appropriate to avoid  
it becomes inaccurate and superfluous.
it becoming inaccurate and superfluous.  For instance in the example above, when no current Fedora release shipped with libfubar < 1.2.3-7, it is no longer necessary to list the explicit, versioned requirement.


=== Non-Obvious Items in Spec Files ===
[[Category:Packaging guidelines drafts]]
Anything in the spec file which is not obvious should have a comment explaining it.
 
Some examples of non-obvious items include (but are not limited to):
* Some explicit requires
* FHS violations
* Changes to optflags
* Not using <code>%configure</code> or make install
* Provides/Obsoletes
* Modified tarballs
* Licensing or legal related changes

Latest revision as of 16:49, 22 February 2009

Addition to ReviewGuidelines

MUST: A package's list of dependencies must not contain any unnecessary explicit Requires on libraries.

Addition to Packaging Guidelines

Explicit Requires

Packages must not contain explicit Requires on libraries except when absolutely necessary. When explicit library Requires are necessary, there should be a spec file comment justifying it.

We generally rely on rpmbuild to automatically add dependencies on library SONAMEs. Modern package management tools are capable of resolving such dependencies to determine the required packages. Explicit dependencies on specific package names may aid the inexperienced user, who attempts at installing RPM packages manually, however, history has shown that such dependencies add confusion when library/files are moved from one package to another, when packages get renamed, when one out of multiple alternative packages would suffice, and when versioned explicit dependencies become out-of-date and inaccurate. Additionally, in some cases, old explicit dependencies on package names require unnecessary updates/rebuilds. For example, Fedora packages are only required to retain historical provides for two full release cycles.

Exemplary rationale for a versioned explicit dependency:

  # The automatic dependency on libfubar.so.1 is insufficient,
  # as we strictly need at least the release that fixes two segfaults.
  Requires: libfubar >= 0:1.2.3-7

Packagers should revisit an explicit dependency as appropriate to avoid it becoming inaccurate and superfluous. For instance in the example above, when no current Fedora release shipped with libfubar < 1.2.3-7, it is no longer necessary to list the explicit, versioned requirement.