Bug#1063053: [Pkg-utopia-maintainers] Bug#1063053: volume-key: NMU diff for 64-bit time_t transition

2024-02-05 Thread Steve Langasek
Hi Michael,

On Mon, Feb 05, 2024 at 11:29:44AM +0100, Michael Biebl wrote:
> This also looks like a false positive.
> volume-key uses time_t internally at

> https://salsa.debian.org/utopia-team/volume-key/-/blob/debian/sid/lib/kmip.c?ref_type=heads#L2132-2154

> This is not exposed in the ABI though or am I misunderstanding the changes
> introduced by the time-t transition ?

volume-key could not be analyzed because its headers have undeclared
dependencies (cert.h):

https://adrien.dcln.fr/misc/armhf-time_t/2024-02-03T09%3A18%3A00/logs/libvolume-key-dev/base/log.txt

Therefore we conservatively assume a transition is needed, rather than
allowing runtime breakage to impact our users.

On Mon, Feb 05, 2024 at 02:41:30PM +0100, Michael Biebl wrote:
> Please put a hold on the upload until this has been investigated properly.

If you as maintainer want to close this bug report (indicating that no
transition is required) or un-tag it 'pending' (indicating that a transition
may be required but the patch is not ready to upload), and accept any
fallout if it turns out this is incorrect, that will mark it so that we will
not include it in NMUs to unstable.

*I* will not be making either of those state changes to the bug, because I
currently don't have proof that the library's ABI is not affected by time_t.

Thanks,
-- 
Steve Langasek   Give me a lever long enough and a Free OS
Debian Developer   to set it on, and I can move the world.
Ubuntu Developer   https://www.debian.org/
slanga...@ubuntu.com vor...@debian.org


signature.asc
Description: PGP signature


Bug#1063053: [Pkg-utopia-maintainers] Bug#1063053: volume-key: NMU diff for 64-bit time_t transition

2024-02-05 Thread Michael Biebl

Am 04.02.24 um 19:31 schrieb Steve Langasek:

Source: volume-key
Version: 0.3.12-5
Severity: serious
Tags: patch pending sid trixie
Justification: library ABI skew on upgrade
User: debian-...@lists.debian.org
Usertags: time-t

NOTICE: these changes must not be uploaded to unstable yet!

Dear maintainer,

As part of the 64-bit time_t transition required to support 32-bit
architectures in 2038 and beyond
(https://wiki.debian.org/ReleaseGoals/64bit-time), we have identified
volume-key as a source package shipping runtime libraries whose ABI
either is affected by the change in size of time_t, or could not be
analyzed via abi-compliance-checker (and therefore to be on the safe
side we assume is affected).

To ensure that inconsistent combinations of libraries with their
reverse-dependencies are never installed together, it is necessary to
have a library transition, which is most easily done by renaming the
runtime library package.

Since turning on 64-bit time_t is being handled centrally through a change
to the default dpkg-buildflags (https://bugs.debian.org/1037136), it is
important that libraries affected by this ABI change all be uploaded close
together in time.  Therefore I have prepared a 0-day NMU for volume-key
which will initially be uploaded to experimental if possible, then to
unstable after packages have cleared binary NEW.

Please find the patch for this NMU attached.

If you have any concerns about this patch, please reach out ASAP.  Although
this package will be uploaded to experimental immediately, there will be a
period of several days before we begin uploads to unstable; so if information
becomes available that your package should not be included in the transition,
there is time for us to amend the planned uploads.



This also looks like a false positive.
volume-key uses time_t internally at

https://salsa.debian.org/utopia-team/volume-key/-/blob/debian/sid/lib/kmip.c?ref_type=heads#L2132-2154

This is not exposed in the ABI though or am I misunderstanding the 
changes introduced by the time-t transition ?




OpenPGP_signature.asc
Description: OpenPGP digital signature