Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1171269 > unrolled thread

Bug#1053725: apt-listchanges: Shows NEWS for package tor from 2008

Started byAxel Beckert <abe@debian.org>
First post2023-10-09 18:10 +0200
Last post2023-10-09 20:10 +0200
Articles 7 — 3 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1053725: apt-listchanges: Shows NEWS for package tor from 2008 Axel Beckert <abe@debian.org> - 2023-10-09 18:10 +0200
    Bug#1053725: apt-listchanges: Shows NEWS for package tor from 2008 Russ Allbery <rra@debian.org> - 2023-10-09 18:20 +0200
      Bug#1053725: apt-listchanges: Shows NEWS for package tor from 2008 Jonathan Kamens <jik@kamens.us> - 2023-10-09 19:10 +0200
        Bug#1053725: apt-listchanges: Shows NEWS for package tor from 2008 Axel Beckert <abe@debian.org> - 2023-10-09 20:10 +0200
          Bug#1053725: apt-listchanges: Shows NEWS for package tor from 2008 Jonathan Kamens <jik@kamens.us> - 2023-10-09 21:40 +0200
            Bug#1053725: apt-listchanges: Shows NEWS for package tor from 2008 Axel Beckert <abe@debian.org> - 2023-10-09 21:50 +0200
        Bug#1053725: apt-listchanges: Shows NEWS for package tor from 2008 Russ Allbery <rra@debian.org> - 2023-10-09 20:10 +0200

#1171269 — Bug#1053725: apt-listchanges: Shows NEWS for package tor from 2008

FromAxel Beckert <abe@debian.org>
Date2023-10-09 18:10 +0200
SubjectBug#1053725: apt-listchanges: Shows NEWS for package tor from 2008
Message-ID<Hn0Zr-eG7O-3@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Package: apt-listchanges
Version: 4.0
Severity: normal

Hi,

after the upgrade to 4.0, apt-listchanges showed me this ancient NEWS
when upgrading tor from 0.4.8.6-1 to 0.4.8.7-1.

Reading changelogs... Done
apt-listchanges: News
---------------------

--- News for tor ---

tor (0.2.0.26-rc-1) experimental; urgency=critical

  * weak cryptographic keys

    It has been discovered that the random number generator in Debian's
    openssl package is predictable.  This is caused by an incorrect
    Debian-specific change to the openssl package (CVE-2008-0166).  As a
    result, cryptographic key material may be guessable.

    See Debian Security Advisory number 1571 (DSA-1571) for more information:
    http://lists.debian.org/debian-security-announce/2008/msg00152.html

    If you run a Tor server using this package please see
    /var/lib/tor/keys/moved-away-by-tor-package/README.REALLY

 -- Peter Palfrader <weasel@debian.org>  Tue, 13 May 2008 12:49:05 +0200

(press q to quit)

(In this case it even was an especially embarassing topic for Debian...)

Might be related or the same as #1053696 by Russ (X-Debbugs-Cc'ed).


-- Package-specific info:

[toc] | [next] | [standalone]


#1171271

FromRuss Allbery <rra@debian.org>
Date2023-10-09 18:20 +0200
Message-ID<Hn197-eGaP-3@gated-at.bofh.it>
In reply to#1171269
Control: merge 1053696 1053725

Axel Beckert <abe@debian.org> writes:

> after the upgrade to 4.0, apt-listchanges showed me this ancient NEWS
> when upgrading tor from 0.4.8.6-1 to 0.4.8.7-1.

[...]

> Might be related or the same as #1053696 by Russ (X-Debbugs-Cc'ed).

Yeah, fairly sure this is the same problem.

-- 
Russ Allbery (rra@debian.org)              <https://www.eyrie.org/~eagle/>

[toc] | [prev] | [next] | [standalone]


#1171274

FromJonathan Kamens <jik@kamens.us>
Date2023-10-09 19:10 +0200
Message-ID<Hn1Vv-eGFY-7@gated-at.bofh.it>
In reply to#1171271

[Multipart message — attachments visible in raw view] — view raw

Control: unmerge -1

Not the same bug. #1053696 only applies to changelog entries, not NEWS 
entries, since the latter can't be downloaded via apt.

I am thus far unable to reproduce this. Still investigating.

On 10/9/23 12:12, Russ Allbery wrote:
> Control: merge 1053696 1053725
>
> Axel Beckert<abe@debian.org>  writes:
>
>> after the upgrade to 4.0, apt-listchanges showed me this ancient NEWS
>> when upgrading tor from 0.4.8.6-1 to 0.4.8.7-1.
> [...]
>
>> Might be related or the same as #1053696 by Russ (X-Debbugs-Cc'ed).
> Yeah, fairly sure this is the same problem.
>

[toc] | [prev] | [next] | [standalone]


#1171277

FromAxel Beckert <abe@debian.org>
Date2023-10-09 20:10 +0200
Message-ID<Hn2Rz-eHeS-3@gated-at.bofh.it>
In reply to#1171274

[Multipart message — attachments visible in raw view] — view raw

Hi Jonathan.

Jonathan Kamens wrote:
> Not the same bug. #1053696 only applies to changelog entries, not NEWS
> entries, since the latter can't be downloaded via apt.

Good point. I'm glad that I filed my bug report despite Russ' bug report.

> I am thus far unable to reproduce this. Still investigating.

Anything I can help? This is a Sid installation running more or less
permanently (besides reboots :-) since May 2016. So the
apt-listchanges database might have seen a few packages. Then again,
it seems rather short for > 14'000 installed packages.

I've attached my /var/lib/apt/listchanges file. (State after having
shown that NEWS entry from 2008, though.)

BTW, while trying to figure out where that db could be I noticed that
despite 4.0 is installed according to "dpkg -l apt-listchanges", the
tool itself contains a different version number:

  ~ → head -2 /usr/bin/apt-listchanges
  #!/usr/bin/python3
  # EASY-INSTALL-ENTRY-SCRIPT: 'apt-listchanges==3.27','console_scripts','apt-listchanges'

HTH!

		Regards, Axel
-- 
 ,''`.  |  Axel Beckert <abe@debian.org>, https://people.debian.org/~abe/
: :' :  |  Debian Developer, ftp.ch.debian.org Admin
`. `'   |  4096R: 2517 B724 C5F6 CA99 5329  6E61 2FF9 CD59 6126 16B5
  `-    |  1024D: F067 EA27 26B9 C3FC 1486  202E C09E 1D89 9593 0EDE

[toc] | [prev] | [next] | [standalone]


#1171284

FromJonathan Kamens <jik@kamens.us>
Date2023-10-09 21:40 +0200
Message-ID<Hn4gF-eHW4-3@gated-at.bofh.it>
In reply to#1171277

[Multipart message — attachments visible in raw view] — view raw

OK, this will be fixed in 4.1. Description of the bug and fix, copied 
from the commit message:

     Bug:
     
     * Main package a has both changelog and NEWS.
     * Subpackage a-sub has identical changelog but no NEWS.
     * Both a and a-sub version 1 are installed but not in database.
     * apt goes to upgrade a and a-sub to version 2.
     * apt-listchanges parses a-sub first, records installed entries under
       package a instead of a-sub, since we were using the package name in
       the changelog entry to determine where in the seen DB to record
       entries.
     * apt-listchanges parses a, sees that there are entries for it in
       database, therefore does not parse installed entries so does not
       notice NEWS entry in installed package.
     * As a result, apt-listchanges displays NEWS entry for a when it
       shouldn't have.
     
     Fix:
     
     * Associate entries with binary package names, not the package name in
       the changelog entry itself.
     * When checking if an entry has already been seen, check across all
       packages, not just the binary package being parsed. To facilitate
       this, the seen database maintains a merged dict of all checksums.

I added a unit test for this case which now passes, and all other unit 
tests continue to pass with the change described above.

Additional FYI comments below.

On 10/9/23 14:05, Axel Beckert wrote:
> Anything I can help? This is a Sid installation running more or less
> permanently (besides reboots :-) since May 2016. So the
> apt-listchanges database might have seen a few packages. Then again,
> it seems rather short for > 14'000 installed packages.
Note that the database is entirely replaced when upgraded from pre-4.0 
to 4.x because its format and what we're storing in it are completely 
different.
> BTW, while trying to figure out where that db could be I noticed that
> despite 4.0 is installed according to "dpkg -l apt-listchanges", the
> tool itself contains a different version number:
>
>    ~ → head -2 /usr/bin/apt-listchanges
>    #!/usr/bin/python3
>    # EASY-INSTALL-ENTRY-SCRIPT: 'apt-listchanges==3.27','console_scripts','apt-listchanges'

Thanks, fixed this as well.

   jik


[toc] | [prev] | [next] | [standalone]


#1171286

FromAxel Beckert <abe@debian.org>
Date2023-10-09 21:50 +0200
Message-ID<Hn4ql-eHZi-7@gated-at.bofh.it>
In reply to#1171284
Hi Jonathan,

Jonathan Kamens wrote:
> OK, this will be fixed in 4.1.

Yay, thanks!

> Description of the bug and fix, copied from the commit message:
> 
>     Bug:
>     * Main package a has both changelog and NEWS.
>     * Subpackage a-sub has identical changelog but no NEWS.
>     * Both a and a-sub version 1 are installed but not in database.
>     * apt goes to upgrade a and a-sub to version 2.
>     * apt-listchanges parses a-sub first, records installed entries under
>       package a instead of a-sub, since we were using the package name in
>       the changelog entry to determine where in the seen DB to record
>       entries.

Ouch, that seemed rather non-trivial to figure out and reproduce.

> I added a unit test for this case which now passes, and all other unit tests
> continue to pass with the change described above.

Perfect!

> Note that the database is entirely replaced when upgraded from pre-4.0 to
> 4.x because its format and what we're storing in it are completely
> different.

Ok, wasn't sure how relevant its content is. Just tried to help. :-)

> >    # EASY-INSTALL-ENTRY-SCRIPT: 'apt-listchanges==3.27','console_scripts','apt-listchanges'
> 
> Thanks, fixed this as well.

Great!

		Regards, Axel
-- 
 ,''`.  |  Axel Beckert <abe@debian.org>, https://people.debian.org/~abe/
: :' :  |  Debian Developer, ftp.ch.debian.org Admin
`. `'   |  4096R: 2517 B724 C5F6 CA99 5329  6E61 2FF9 CD59 6126 16B5
  `-    |  1024D: F067 EA27 26B9 C3FC 1486  202E C09E 1D89 9593 0EDE

[toc] | [prev] | [next] | [standalone]


#1171278

FromRuss Allbery <rra@debian.org>
Date2023-10-09 20:10 +0200
Message-ID<Hn2RA-eHeS-19@gated-at.bofh.it>
In reply to#1171274
Jonathan Kamens <jik@kamens.us> writes:

> Not the same bug. #1053696 only applies to changelog entries, not NEWS
> entries, since the latter can't be downloaded via apt.

> I am thus far unable to reproduce this. Still investigating.

Ah, whoops, sorry, I wasn't reading carefully enough.

-- 
Russ Allbery (rra@debian.org)              <https://www.eyrie.org/~eagle/>

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web