Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1250624 > unrolled thread

Bug#1108127: bookworm-pu: package debian-security-support/12+2025.06.20

Started bySantiago Ruano Rincón <santiagorr@riseup.net>
First post2025-06-20 23:40 +0200
Last post2025-06-21 18:00 +0200
Articles 3 — 3 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1108127: bookworm-pu: package debian-security-support/12+2025.06.20 Santiago Ruano Rincón <santiagorr@riseup.net> - 2025-06-20 23:40 +0200
    Bug#1108127: bookworm-pu: package debian-security-support/12+2025.06.20 "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2025-06-21 12:30 +0200
    Bug#1108127: debian-security-support 12+2025.06.20 flagged for acceptance Adam D Barratt <adam@adam-barratt.org.uk> - 2025-06-21 18:00 +0200

#1250624 — Bug#1108127: bookworm-pu: package debian-security-support/12+2025.06.20

FromSantiago Ruano Rincón <santiagorr@riseup.net>
Date2025-06-20 23:40 +0200
SubjectBug#1108127: bookworm-pu: package debian-security-support/12+2025.06.20
Message-ID<KZRCN-bYTy-3@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Package: release.debian.org
Severity: normal
Tags: bookworm
User: release.debian.org@packages.debian.org
Usertags: pu
X-Debbugs-Cc: debian-security-support@packages.debian.org
Control: affects -1 + src:debian-security-support

Dear release team,

I'd like to propose a bookworm update for debian-security-support.

[ Reason ]
The are two changes: fixing #1106203, and a typo in a package name.
#1106203 makes that the purpose of check-security-support (the main
debian-security-support script) is null for packages that have been
NMU'ed or that have a different version between the source and binary
packages.  See some examples at
https://salsa.debian.org/debian/debian-security-support/-/merge_requests/44#note_615156

[ Impact ]
The user will continue to no be warned that the concerned installed
packages don't benefit from a full security support from debian.

[ Tests ]
A test has been added to the package, that is run during build time.
I've tested the test on my own bookworm machine, and now I get results
like:

    * Source:golang-github-containers-buildah
      Details: See https://www.debian.org/releases/bookworm/amd64/release-notes/ch-information.en.html#golang-static-linking
      Affected binary package:
      - buildah (installed version: 1.28.2+ds1-3+deb12u1+b1)

[ Risks ]
The code is trivial, and the tests have good coverage.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
The main change is:

diff -Nru debian-security-support-12+2025.05.10/check-support-status.in debian-security-support-12+2025.06.20/check-support-status.in
--- debian-security-support-12+2025.05.10/check-support-status.in       2025-05-10 09:43:50.000000000 -0300
+++ debian-security-support-12+2025.06.20/check-support-status.in       2025-06-20 17:54:47.000000000 -0300
@@ -169,7 +169,7 @@
 # Get list of installed packages
 INSTALLED_LIST="$TEMPDIR/installed"

-LC_ALL=C [% DPKG_QUERY %] --show --showformat '${Status}\t${binary:Package}\t${Version}\t${Source}\n' |
+LC_ALL=C [% DPKG_QUERY %] --show --showformat '${Status}\t${binary:Package}\t${Version}\t${source:Package}\n' |
 [% AWK %] '($1=="install"){print}' |
 [% AWK %] -F'\t' '{if($4==""){print $2"\t"$3"\t"$2}else{print $2"\t"$3"\t"$4}}' >"$INSTALLED_LIST"

When the version of a binary package differs from the source package,
the old dpkg-query returns something like:

install ok installed    buildah 1.28.2+ds1-3+deb12u1+b1 golang-github-containers-buildah (1.28.2+ds1-3+deb12u1)
                                                        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
and the new one:

install ok installed    buildah 1.28.2+ds1-3+deb12u1+b1 golang-github-containers-buildah
                                                        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

The remaining code compares the name of the source package with the
underlined (^) string, with grep -x, so the name didn't match.

Changes in t/check-support-status.t include a test for the above.

And there is a typo fix in security-support-limited s/gobgpd/gobgp/
since check-security-support checks for the name of the source package,
not the binary. I've verified that this works.

[ Other info ]
N/A

Thanks!

 -- Santiago

[toc] | [next] | [standalone]


#1250661

From"Adam D. Barratt" <adam@adam-barratt.org.uk>
Date2025-06-21 12:30 +0200
Message-ID<L03DX-c6LS-9@gated-at.bofh.it>
In reply to#1250624
Control: tags -1 + confirmed

On Fri, 2025-06-20 at 18:33 -0300, Santiago Ruano Rincón wrote:
> I'd like to propose a bookworm update for debian-security-support.
> 
> [ Reason ]
> The are two changes: fixing #1106203, and a typo in a package name.
> #1106203 makes that the purpose of check-security-support (the main
> debian-security-support script) is null for packages that have been
> NMU'ed or that have a different version between the source and binary
> packages.  See some examples at
> https://salsa.debian.org/debian/debian-security-support/-/merge_requests/44#note_615156

Please go ahead; thanks.

Regards,

Adam

[toc] | [prev] | [next] | [standalone]


#1250690 — Bug#1108127: debian-security-support 12+2025.06.20 flagged for acceptance

FromAdam D Barratt <adam@adam-barratt.org.uk>
Date2025-06-21 18:00 +0200
SubjectBug#1108127: debian-security-support 12+2025.06.20 flagged for acceptance
Message-ID<L08Nj-c9VE-9@gated-at.bofh.it>
In reply to#1250624
package release.debian.org
tags 1108127 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==============

Package: debian-security-support
Version: 12+2025.06.20

Explanation: query source:Package instead of Source to get the correct list of packages; fix typo related to gobgp

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web