Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1200519

Bug#1072983: bookworm-pu: package golang-github-google-nftables/0.1.0-4~deb12u1

From Cyril Brulebois <cyril@debamax.com>
Newsgroups linux.debian.bugs.dist, linux.debian.devel.release
Subject Bug#1072983: bookworm-pu: package golang-github-google-nftables/0.1.0-4~deb12u1
Date 2024-06-11 11:40 +0200
Message-ID <IO68V-27FP-9@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Package: release.debian.org
Severity: normal
Tags: bookworm
User: release.debian.org@packages.debian.org
Usertags: pu
X-Debbugs-Cc: golang-github-google-nftables@packages.debian.org
Control: affects -1 + src:golang-github-google-nftables

Hi,

[ Reason ]

I'd like to fix the #1071247/#1071248 pair in bookworm, which results in
crowdsec-firewall-bouncer's being broken on little-endian architectures
(addresses are getting logged just fine, but they're not passed over
correctly to the firewall layer). 

I've checked with the security team, this doesn't warrant a DSA.

This is the library part (golang-github-google-nftables).

[ Impact ]

If the fix doesn't make it into stable, crowdsec-firewall-bouncer
remains broken on little-endian architectures.

[ Tests ]

Same checks as for unstable when I uploaded the fixes there:
 - amd64 (LE, baremetal) before: KO
 - amd64 (LE, baremetal) after: OK
 - s390x (BE, debvm) before: OK
 - s390x (BE, debvm) after: OK

[ Risks ]

Except for a possible regression on s390x (which isn't the case, see
previous section), it cannot be worse than it currently is.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in stable
  [x] the issue is verified as fixed in unstable

Additionally, that reached testing.

[ Changes ]

The fix is a direct backport from upstream, which adds byte order
information to the function used by crowdsec-firewall-bouncer
(AddSet).

[ Other info ]

Next bug report is the crowdsec-firewall-bouncer part.


Cheers,
-- 
Cyril Brulebois -- Debian Consultant @ DEBAMAX -- https://debamax.com/

Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Bug#1072983: bookworm-pu: package golang-github-google-nftables/0.1.0-4~deb12u1 Cyril Brulebois <cyril@debamax.com> - 2024-06-11 11:40 +0200
  Bug#1072983: bookworm-pu: package golang-github-google-nftables/0.1.0-4~deb12u1 "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2024-06-15 17:10 +0200
    Bug#1072983: bookworm-pu: package golang-github-google-nftables/0.1.0-4~deb12u1 Cyril Brulebois <cyril@debamax.com> - 2024-06-16 01:50 +0200
  Bug#1072983: golang-github-google-nftables 0.1.0-4~deb12u1 flagged for acceptance Adam D Barratt <adam@adam-barratt.org.uk> - 2024-06-16 22:00 +0200

csiph-web