Your message dated Tue, 17 Feb 2009 03:47:03 +0000
with message-id <[email protected]>
and subject line Bug#498401: fixed in irssi-plugin-otr 0.3-1
has caused the Debian Bug report #498401,
regarding irssi-plugin-otr truncates ~/.irssi/otr/otr.key during new key
generation
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
498401: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=498401
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: irssi-plugin-otr
Version: 0.2-1
Severity: normal
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
I just tried out irssi-plugin-otr for the first time. Very nice. I'm
a little concerned about the behavior when using the plugin on
multiple networks, though, given that i've seen irssi itself crash in
the past. In particular, i'm worried about the possibility of irssi
completely destroying the OTR private keystore.
Here's what i observed:
* on first network where i tried to use OTR, there was a long lag
during key generation (this is expected).
* when the key was finally created, it populated ~/.irssi/otr/otr.key
with the raw key material. (the ~/.irssi/otr directory should
probably be created with mode 0700, btw).
* When i tried to connect to a new network and to use OTR there, a
new genkey operation started.
* while this new genkey operation is underway, ~/.irssi/otr/otr.key
is truncated to 0 length.
* when the genkey completes, both keys get written back to
~/.irssi/otr/otr.key
If irssi crashes during this (lengthy) window, or if there's a power
failure, or whatever, it looks like all the previous private key
material will be destroyed permanently. Since these are potentially
important credentials, it seems like it would be better for the OTR
plugin to modify the keyfile only *after* it completes the keygen.
And ideally, the operation would be an atomic one (create a new file,
and mv it into place?), to eliminate the window of possible failure.
Thanks for packaging this useful tool for debian!
Regards,
--dkg
- -- System Information:
Debian Release: lenny/sid
APT prefers testing
APT policy: (500, 'testing'), (200, 'unstable'), (101, 'experimental')
Architecture: i386 (i686)
Kernel: Linux 2.6.26-1-686 (SMP w/1 CPU core)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash
Versions of packages irssi-plugin-otr depends on:
ii irssi 0.8.12-4 terminal based IRC client
ii libc6 2.7-13 GNU C Library: Shared libraries
ii libglib2.0-0 2.16.4-2 The GLib library of C routines
ii libotr2 3.2.0-1 Off-the-Record Messaging library
irssi-plugin-otr recommends no packages.
irssi-plugin-otr suggests no packages.
- -- no debconf information
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iQIVAwUBSMbIHszS7ZTSFznpAQJnkA//dt2tfO9ZlZAfp/udNEfHiYb15mK/DuJ2
Y18QDdDsuUuF0T/fxGdXq8iglOJTyYqdNj4Xcxa+lRwRe+TccZpJ9bv3fvooWxXs
vJxn3uOUhGPAOGRncYq/pxbO/e9BUvRM6XBHyeAXK0Op/G4qnvWb3QgMG7YfhqZX
ryChhoSeUPBMRKsNSCx7X7vkSRxg+Ha4YwtkM8YiAsK8sIb38pJb/+NxpnP+tZLG
R6ckhkPNVUoFNdVR+i4DWpl8v9y8Xr2y66UdKyshUuh6JrekZdBBNx5DwrJqF4Gq
KLcLfHubRLq4FyrHzh33+0CYxM/OXPkkgFuCwAysM0pgkglbGCFexSMR4/korju3
HV6PC9JaTPTIfmLYWUZEEjcn9s7aFQeR3/ib/z3WUPRGwtiMdJER4XcLV1+gMlZk
56aLgAuspWFDDJ0OfxUEosJqmTYZ2ClavB2Hw8VUIflR9q0wPbInrg8Vi73DJ4iS
CqH+sHTvkRB6WYDV/qNgw37VmHyOp6LR9RKSrZXX1jXKdvQJc9skOG/4J+ubK+5b
GXz7OO3SJ2pWE+tlyR4wMXaiYmFuYFImdGHtcFtCVarv2JPqcoCn3EvTb2NTeQkD
1eqmX3FKeInBc3mOUkMkcKVQrnKPUYiqjz8+UkCWe+xnVzwalbojaIJf7DpiqWFG
JSL1bhutg7Y=
=Um7m
-----END PGP SIGNATURE-----
--- End Message ---
--- Begin Message ---
Source: irssi-plugin-otr
Source-Version: 0.3-1
We believe that the bug you reported is fixed in the latest version of
irssi-plugin-otr, which is due to be installed in the Debian FTP archive:
irssi-plugin-otr_0.3-1.diff.gz
to pool/main/i/irssi-plugin-otr/irssi-plugin-otr_0.3-1.diff.gz
irssi-plugin-otr_0.3-1.dsc
to pool/main/i/irssi-plugin-otr/irssi-plugin-otr_0.3-1.dsc
irssi-plugin-otr_0.3-1_i386.deb
to pool/main/i/irssi-plugin-otr/irssi-plugin-otr_0.3-1_i386.deb
irssi-plugin-otr_0.3.orig.tar.gz
to pool/main/i/irssi-plugin-otr/irssi-plugin-otr_0.3.orig.tar.gz
xchat-otr_0.3-1_i386.deb
to pool/main/i/irssi-plugin-otr/xchat-otr_0.3-1_i386.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
David Spreen <[email protected]> (supplier of updated irssi-plugin-otr
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Mon, 16 Feb 2009 16:33:28 -0800
Source: irssi-plugin-otr
Binary: irssi-plugin-otr xchat-otr
Architecture: source i386
Version: 0.3-1
Distribution: unstable
Urgency: low
Maintainer: David Spreen <[email protected]>
Changed-By: David Spreen <[email protected]>
Description:
irssi-plugin-otr - Off-the-Record Messaging Plugin for Irssi
xchat-otr - Off-the-Record Messaging Plugin for X-Chat
Closes: 498401 498502
Changes:
irssi-plugin-otr (0.3-1) unstable; urgency=low
.
* New upstream release.
* First upload to unstable after 0.2. Introduces xchat-otr
to unstable.
.
irssi-plugin-otr (0.2+20090206-1) experimental; urgency=low
.
* New git snapshot.
* debian/patches/01_fix_irssisbar_h.patch: Removed (fixed upstream).
* debian/patches/02_remove_irssi_reference_from_keygen.patch:
Removed (patch adopted by upstream).
* debian/patches/01_remove_buildfor_variable.patch: Added patch
to keep building xchat and irssi targets from the same source.
.
irssi-plugin-otr (0.2+20090128-1) experimental; urgency=low
.
* New git snapshot now with X-Chat support!
* debian/control: Added X-Chat binary package including
build-dependency on xchat-common.
* debian/rules: Manually installing README.xchat
* debian/*.install: Added install files for irssi and
xchat plugin packages.
* debian/patch/01_fix_irssisbar_h.patch: Fixed check
for local copy of irssi statusbar headers.
* debian/patch/02_remove_irssi_reference_from_keygen.patch:
Removed irssi reference from keygen message.
.
irssi-plugin-otr (0.2+20090119-1) experimental; urgency=low
.
* New git snapshot. (Closes: #498502, 498401)
* debian/rules: Changed build-system to cdbs.
* debian/control: Added cdbs build-dependency.
Checksums-Sha1:
09df2458279343452b0cee2718f7c7e857a78298 1173 irssi-plugin-otr_0.3-1.dsc
5b831dd64e7d84fcda45219b71f017233a6c327b 33514 irssi-plugin-otr_0.3.orig.tar.gz
12dc01a2e81b3af2aae9f76e07b5cdf6f2ce0945 3029 irssi-plugin-otr_0.3-1.diff.gz
56a6800243ab7416a933fbe09021db7f98e11998 25130 irssi-plugin-otr_0.3-1_i386.deb
61caf134d8f96095696520040bbb4d4e6f4de0e6 22150 xchat-otr_0.3-1_i386.deb
Checksums-Sha256:
0fffccc0d59521b7890ac676f081f74a847635f3115a4337c948a8e0c9d90c19 1173
irssi-plugin-otr_0.3-1.dsc
816cb13794c0efa33ee1618a4e926b3f1c3587c675ad3cc44b4f8de3b1b2c60e 33514
irssi-plugin-otr_0.3.orig.tar.gz
67723d6546f4d0ebc64295cf8c1e78c9f4e23826bcc7e4e527c28dd956022704 3029
irssi-plugin-otr_0.3-1.diff.gz
dba6df63a6a3585ebc9e9c355b7d4866f7195226d35f12d4d1e9d38440825d6d 25130
irssi-plugin-otr_0.3-1_i386.deb
ce48bb1db5005ae43095d6e6ef8824102385fa5ef5bb07e93e8f29765d376bad 22150
xchat-otr_0.3-1_i386.deb
Files:
602fc2a9f3e847a7f880f35cb8764ecb 1173 net optional irssi-plugin-otr_0.3-1.dsc
e3d46a31955470dd3fa0f6392c1dcfb4 33514 net optional
irssi-plugin-otr_0.3.orig.tar.gz
0fadfbd46a40340b30984cc1c4c2329b 3029 net optional
irssi-plugin-otr_0.3-1.diff.gz
d03f7169fb5292b56c9b03b6d9598f44 25130 net optional
irssi-plugin-otr_0.3-1_i386.deb
cb4c487e61b93ba0ef4faa6f04917500 22150 net optional xchat-otr_0.3-1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAkmaMFcACgkQdhEvvPyx3SN23wCdH895yeZJBXlyQnGfo4dbmyJK
Fd4AoJy3wkIzcOu/Q+7NYxLJ5N9YPQzx
=+QIK
-----END PGP SIGNATURE-----
--- End Message ---