You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@felix.apache.org by Carsten Ziegeler <cz...@apache.org> on 2010/02/18 09:08:24 UTC

[VOTE] Release Apache Felix EventAdmin 1.2.2

Hi,

We solved 6 issues in this release:
https://issues.apache.org/jira/browse/FELIX/fixforversion/12314393

Staging repository:
https://repository.apache.org/content/repositories/orgapachefelix-008/

You can use this UNIX script to download the release and verify the
signatures:
http://svn.apache.org/repos/asf/felix/trunk/check_staged_release.sh

Usage:
sh check_staged_release.sh 008 /tmp/felix-staging

Please vote to approve this release:

[ ] +1 Approve the release
[ ] -1 Veto the release (please provide specific comments)

This vote will be open for 72 hours.

Carsten
-- 
Carsten Ziegeler
cziegeler@apache.org


Re: [VOTE] Release Apache Felix EventAdmin 1.2.2

Posted by Rob Walker <ro...@ascert.com>.
+1

- Rob

Carsten Ziegeler wrote:
> Hi,
>
> We solved 6 issues in this release:
> https://issues.apache.org/jira/browse/FELIX/fixforversion/12314393
>
> Staging repository:
> https://repository.apache.org/content/repositories/orgapachefelix-008/
>
> You can use this UNIX script to download the release and verify the
> signatures:
> http://svn.apache.org/repos/asf/felix/trunk/check_staged_release.sh
>
> Usage:
> sh check_staged_release.sh 008 /tmp/felix-staging
>
> Please vote to approve this release:
>
> [ ] +1 Approve the release
> [ ] -1 Veto the release (please provide specific comments)
>
> This vote will be open for 72 hours.
>
> Carsten
>   

-- 


Ascert - Taking systems to the Edge
robw@ascert.com
+44 (0)20 7488 3470
www.ascert.com


Re: [VOTE] Release Apache Felix EventAdmin 1.2.2

Posted by Chris Custine <ch...@gmail.com>.
+1 (non-binding)

Disregard my last email, I didn't have your new strong signing key imported
and I haven't had any coffee this morning  :-D  Everything looks good now.

Chris

--
Chris Custine
FUSESource :: http://fusesource.com
My Blog :: http://blog.organicelement.com
Apache ServiceMix :: http://servicemix.apache.org
Apache Felix :: http://felix.apache.org
Apache Directory Server :: http://directory.apache.org


On Thu, Feb 18, 2010 at 8:21 AM, Chris Custine <ch...@gmail.com>wrote:

> The release looks good but there are only checksums and no pgp sigs on the
> artifacts.  As of last week Nexus is automatically verifying pgp sigs while
> promoting from stage to Maven central and will fail if none are present or
> validation fails.  There is an email from Brian Fox dated Feb 12 about this
> on repository@apache.org (anyone who does releases should subscribe to it)
> but I have inserted the content below.  This also means our sigs MUST be on
> a public key server as mentioned below.
>
> ===============
> We converted http://repository.apache.org to authenticate against LDAP
> today. For most users this should be a transparent migration. It was
> previously authenticating against svn. This means if you have changed
> your password recently, there is a possibility that the password you
> used to login to Nexus and deploy artifacts has changed. You should
> use the same password that you would use to access people.
>
> Additionally, we are now validating that proper pgp signatures are
> present on and available for all artifacts being deployed. The system
> will pull your key from a public key server to validate it. This means
> that if you haven't already, you should upload your public key to a
> server like http://pgp.mit.edu (you can also use the gpg --send-keys
> command) or you will get an error that your key can't be verified when
> you attempt to close or promote a staged repository.
>
> Thanks,
> Brian
> ================
> --
> Chris Custine
> FUSESource :: http://fusesource.com
> My Blog :: http://blog.organicelement.com
> Apache ServiceMix :: http://servicemix.apache.org
> Apache Felix :: http://felix.apache.org
> Apache Directory Server :: http://directory.apache.org
>
>
>
> On Thu, Feb 18, 2010 at 1:08 AM, Carsten Ziegeler <cz...@apache.org>wrote:
>
>> Hi,
>>
>> We solved 6 issues in this release:
>> https://issues.apache.org/jira/browse/FELIX/fixforversion/12314393
>>
>> Staging repository:
>> https://repository.apache.org/content/repositories/orgapachefelix-008/
>>
>> You can use this UNIX script to download the release and verify the
>> signatures:
>> http://svn.apache.org/repos/asf/felix/trunk/check_staged_release.sh
>>
>> Usage:
>> sh check_staged_release.sh 008 /tmp/felix-staging
>>
>> Please vote to approve this release:
>>
>> [ ] +1 Approve the release
>> [ ] -1 Veto the release (please provide specific comments)
>>
>> This vote will be open for 72 hours.
>>
>> Carsten
>> --
>> Carsten Ziegeler
>> cziegeler@apache.org
>>
>>
>

Re: [VOTE] Release Apache Felix EventAdmin 1.2.2

Posted by Chris Custine <ch...@gmail.com>.
The release looks good but there are only checksums and no pgp sigs on the
artifacts.  As of last week Nexus is automatically verifying pgp sigs while
promoting from stage to Maven central and will fail if none are present or
validation fails.  There is an email from Brian Fox dated Feb 12 about this
on repository@apache.org (anyone who does releases should subscribe to it)
but I have inserted the content below.  This also means our sigs MUST be on
a public key server as mentioned below.

===============
We converted http://repository.apache.org to authenticate against LDAP
today. For most users this should be a transparent migration. It was
previously authenticating against svn. This means if you have changed
your password recently, there is a possibility that the password you
used to login to Nexus and deploy artifacts has changed. You should
use the same password that you would use to access people.

Additionally, we are now validating that proper pgp signatures are
present on and available for all artifacts being deployed. The system
will pull your key from a public key server to validate it. This means
that if you haven't already, you should upload your public key to a
server like http://pgp.mit.edu (you can also use the gpg --send-keys
command) or you will get an error that your key can't be verified when
you attempt to close or promote a staged repository.

Thanks,
Brian
================
--
Chris Custine
FUSESource :: http://fusesource.com
My Blog :: http://blog.organicelement.com
Apache ServiceMix :: http://servicemix.apache.org
Apache Felix :: http://felix.apache.org
Apache Directory Server :: http://directory.apache.org


On Thu, Feb 18, 2010 at 1:08 AM, Carsten Ziegeler <cz...@apache.org>wrote:

> Hi,
>
> We solved 6 issues in this release:
> https://issues.apache.org/jira/browse/FELIX/fixforversion/12314393
>
> Staging repository:
> https://repository.apache.org/content/repositories/orgapachefelix-008/
>
> You can use this UNIX script to download the release and verify the
> signatures:
> http://svn.apache.org/repos/asf/felix/trunk/check_staged_release.sh
>
> Usage:
> sh check_staged_release.sh 008 /tmp/felix-staging
>
> Please vote to approve this release:
>
> [ ] +1 Approve the release
> [ ] -1 Veto the release (please provide specific comments)
>
> This vote will be open for 72 hours.
>
> Carsten
> --
> Carsten Ziegeler
> cziegeler@apache.org
>
>

Re: [VOTE] Release Apache Felix EventAdmin 1.2.2

Posted by Guillaume Nodet <gn...@gmail.com>.
+1

On Thu, Feb 18, 2010 at 09:08, Carsten Ziegeler <cz...@apache.org> wrote:
> Hi,
>
> We solved 6 issues in this release:
> https://issues.apache.org/jira/browse/FELIX/fixforversion/12314393
>
> Staging repository:
> https://repository.apache.org/content/repositories/orgapachefelix-008/
>
> You can use this UNIX script to download the release and verify the
> signatures:
> http://svn.apache.org/repos/asf/felix/trunk/check_staged_release.sh
>
> Usage:
> sh check_staged_release.sh 008 /tmp/felix-staging
>
> Please vote to approve this release:
>
> [ ] +1 Approve the release
> [ ] -1 Veto the release (please provide specific comments)
>
> This vote will be open for 72 hours.
>
> Carsten
> --
> Carsten Ziegeler
> cziegeler@apache.org
>
>



-- 
Cheers,
Guillaume Nodet
------------------------
Blog: http://gnodet.blogspot.com/
------------------------
Open Source SOA
http://fusesource.com

Re: [VOTE] Release Apache Felix EventAdmin 1.2.2

Posted by Carsten Ziegeler <cz...@apache.org>.
[X] +1 Approve the release

Carsten

Carsten Ziegeler wrote:
> Hi,
> 
> We solved 6 issues in this release:
> https://issues.apache.org/jira/browse/FELIX/fixforversion/12314393
> 
> Staging repository:
> https://repository.apache.org/content/repositories/orgapachefelix-008/
> 
> You can use this UNIX script to download the release and verify the
> signatures:
> http://svn.apache.org/repos/asf/felix/trunk/check_staged_release.sh
> 
> Usage:
> sh check_staged_release.sh 008 /tmp/felix-staging
> 
> Please vote to approve this release:
> 
> [ ] +1 Approve the release
> [ ] -1 Veto the release (please provide specific comments)
> 
> This vote will be open for 72 hours.
> 
> Carsten


-- 
Carsten Ziegeler
cziegeler@apache.org

[VOTE RESULT] Release Apache Felix EventAdmin 1.2.2

Posted by Carsten Ziegeler <cz...@apache.org>.
Hi,

The vote has passed with the following result :

  +1 (binding): Rob Walker, Carsten Ziegeler, Guillaume Nodet, Felix
Meschberger, and Richard Hall
  +1 (non-binding): Chris Custine

I will copy this release to the Felix dist directory and
promote the artifacts to the central Maven repository.

Thanks for voting!

Carsten

-- 
Carsten Ziegeler
cziegeler@apache.org

Re: [VOTE] Release Apache Felix EventAdmin 1.2.2

Posted by "Richard S. Hall" <he...@ungoverned.org>.
+1

-> richard

On 2/18/10 4:08 PM, Carsten Ziegeler wrote:
> Hi,
>
> We solved 6 issues in this release:
> https://issues.apache.org/jira/browse/FELIX/fixforversion/12314393
>
> Staging repository:
> https://repository.apache.org/content/repositories/orgapachefelix-008/
>
> You can use this UNIX script to download the release and verify the
> signatures:
> http://svn.apache.org/repos/asf/felix/trunk/check_staged_release.sh
>
> Usage:
> sh check_staged_release.sh 008 /tmp/felix-staging
>
> Please vote to approve this release:
>
> [ ] +1 Approve the release
> [ ] -1 Veto the release (please provide specific comments)
>
> This vote will be open for 72 hours.
>
> Carsten
>    

Re: [VOTE] Release Apache Felix EventAdmin 1.2.2

Posted by Carsten Ziegeler <cz...@apache.org>.
Clement Escoffier wrote:
> Hi,
> 
> I've looked into this release, and I've a couple of comments:
> - first the NOTICE file does not follow the format generally used for Felix projects which means that automatic or semi-automatic checking tools failed.
> - then, the embedded EDU.oswego.cs.dl.util.concurrent package should also be cited in the license. The work 'partially' comes from Sun which means that some parts was made directly at oswego. It would be nice to cite them under the same license term. 
> - despite it's obvious the 'Licensed under the Apache License 2.0.' is missing for the software developed at the ASF. 
> 
> I'm not sure these issues are blocking the release, but it would be useful to fix them in the next versions.
> 
I don't consider these blockers - we discussed the oswego stuff and the
notice file with the attempt to do the 1.2.0 release; we withdrew it and
 thought that the new notice file would be good :)

But you're right that we should update the notice file for the future.

Carsten

> Regards,
> 
> Clement
> 
> 
>> On 18.02.2010 09:08, Carsten Ziegeler wrote:
>>> Hi,
>>>
>>> We solved 6 issues in this release:
>>> https://issues.apache.org/jira/browse/FELIX/fixforversion/12314393
>>>
>>> Staging repository:
>>> https://repository.apache.org/content/repositories/orgapachefelix-008/
>>>
>>> You can use this UNIX script to download the release and verify the
>>> signatures:
>>> http://svn.apache.org/repos/asf/felix/trunk/check_staged_release.sh
>>>
>>> Usage:
>>> sh check_staged_release.sh 008 /tmp/felix-staging
>>>
>>> Please vote to approve this release:
>>>
>>> [ ] +1 Approve the release
>>> [ ] -1 Veto the release (please provide specific comments)
>>>
>>> This vote will be open for 72 hours.
>>>
>>> Carsten
> 
> 


-- 
Carsten Ziegeler
cziegeler@apache.org

NOTICE file (Was Re: [VOTE] Release Apache Felix EventAdmin 1.2.2)

Posted by "Richard S. Hall" <he...@ungoverned.org>.
On 2/21/10 6:37 PM, Clement Escoffier wrote:
> Hi,
>
> I've looked into this release, and I've a couple of comments:
> - first the NOTICE file does not follow the format generally used for Felix projects which means that automatic or semi-automatic checking tools failed.
> - then, the embedded EDU.oswego.cs.dl.util.concurrent package should also be cited in the license. The work 'partially' comes from Sun which means that some parts was made directly at oswego. It would be nice to cite them under the same license term.
>    

We are still straightening this out, but we are told that the NOTICE 
file should only include references to licenses that require NOTICE. So, 
if we are going to follow that rule from now on, then I guess Oswego 
doesn't require it, but the Sun portion does.

We had looked into automating this at one time (Felix!), but I think it 
wasn't completely successful. At any rate, we should likely start 
following this approach for future releases, but we never did decide if 
were were going to have a separate acknowledgments file for other 
dependencies or just don't mention them at all.

-> richard

> - despite it's obvious the 'Licensed under the Apache License 2.0.' is missing for the software developed at the ASF.
>
> I'm not sure these issues are blocking the release, but it would be useful to fix them in the next versions.
>
> Regards,
>
> Clement
>
>
>    
>> On 18.02.2010 09:08, Carsten Ziegeler wrote:
>>      
>>> Hi,
>>>
>>> We solved 6 issues in this release:
>>> https://issues.apache.org/jira/browse/FELIX/fixforversion/12314393
>>>
>>> Staging repository:
>>> https://repository.apache.org/content/repositories/orgapachefelix-008/
>>>
>>> You can use this UNIX script to download the release and verify the
>>> signatures:
>>> http://svn.apache.org/repos/asf/felix/trunk/check_staged_release.sh
>>>
>>> Usage:
>>> sh check_staged_release.sh 008 /tmp/felix-staging
>>>
>>> Please vote to approve this release:
>>>
>>> [ ] +1 Approve the release
>>> [ ] -1 Veto the release (please provide specific comments)
>>>
>>> This vote will be open for 72 hours.
>>>
>>> Carsten
>>>        
>    

Re: [VOTE] Release Apache Felix EventAdmin 1.2.2

Posted by Clement Escoffier <cl...@gmail.com>.
Hi,

I've looked into this release, and I've a couple of comments:
- first the NOTICE file does not follow the format generally used for Felix projects which means that automatic or semi-automatic checking tools failed.
- then, the embedded EDU.oswego.cs.dl.util.concurrent package should also be cited in the license. The work 'partially' comes from Sun which means that some parts was made directly at oswego. It would be nice to cite them under the same license term. 
- despite it's obvious the 'Licensed under the Apache License 2.0.' is missing for the software developed at the ASF. 

I'm not sure these issues are blocking the release, but it would be useful to fix them in the next versions.

Regards,

Clement


> On 18.02.2010 09:08, Carsten Ziegeler wrote:
>> Hi,
>> 
>> We solved 6 issues in this release:
>> https://issues.apache.org/jira/browse/FELIX/fixforversion/12314393
>> 
>> Staging repository:
>> https://repository.apache.org/content/repositories/orgapachefelix-008/
>> 
>> You can use this UNIX script to download the release and verify the
>> signatures:
>> http://svn.apache.org/repos/asf/felix/trunk/check_staged_release.sh
>> 
>> Usage:
>> sh check_staged_release.sh 008 /tmp/felix-staging
>> 
>> Please vote to approve this release:
>> 
>> [ ] +1 Approve the release
>> [ ] -1 Veto the release (please provide specific comments)
>> 
>> This vote will be open for 72 hours.
>> 
>> Carsten


Re: [VOTE] Release Apache Felix EventAdmin 1.2.2

Posted by Felix Meschberger <fm...@gmail.com>.
+1

Regards
Felix

On 18.02.2010 09:08, Carsten Ziegeler wrote:
> Hi,
> 
> We solved 6 issues in this release:
> https://issues.apache.org/jira/browse/FELIX/fixforversion/12314393
> 
> Staging repository:
> https://repository.apache.org/content/repositories/orgapachefelix-008/
> 
> You can use this UNIX script to download the release and verify the
> signatures:
> http://svn.apache.org/repos/asf/felix/trunk/check_staged_release.sh
> 
> Usage:
> sh check_staged_release.sh 008 /tmp/felix-staging
> 
> Please vote to approve this release:
> 
> [ ] +1 Approve the release
> [ ] -1 Veto the release (please provide specific comments)
> 
> This vote will be open for 72 hours.
> 
> Carsten