Your message dated Fri, 08 Jul 2011 05:02:09 +0000
with message-id <[email protected]>
and subject line Bug#626761: fixed in fastx-toolkit 0.0.13.1-1
has caused the Debian Bug report #626761,
regarding fastx-toolkit: fgets called with bigger size than length of 
destination buffer
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
626761: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=626761
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: fastx-toolkit
Version: 0.0.13-1
Severity: normal

(Report recorded on the Debian bug tracking system).

Dear Gordon,

while trying to build fastx-toolkit on Ubuntu, I encountered the following
warning, treated as error:

Making all in libfastx
make[4]: Entering directory `/build/buildd/fastx-toolkit-0.0.13/src/libfastx'
gcc -DHAVE_CONFIG_H -I. -I../..     -g -O2 -g -O2 -Wall -Wextra 
-Wformat-nonliteral -Wformat-security -Wswitch-default -Wswitch-enum 
-Wunused-parameter -Wfloat-equal -Werror -DDEBUG -g -O1 -c chomp.c
gcc -DHAVE_CONFIG_H -I. -I../..     -g -O2 -g -O2 -Wall -Wextra 
-Wformat-nonliteral -Wformat-security -Wswitch-default -Wswitch-enum 
-Wunused-parameter -Wfloat-equal -Werror -DDEBUG -g -O1 -c fastx.c
cc1: warnings being treated as errors
In file included from /usr/include/stdio.h:930:0,
                 from fastx.c:18:
In function 'fgets',
    inlined from 'fastx_read_next_record' at fastx.c:323:11:
/usr/include/bits/stdio2.h:253:2: error: call to '__fgets_chk_warn' declared 
with attribute warning: fgets called with bigger size than length of 
destination buffer
In function 'fgets',
    inlined from 'fastx_read_next_record' at fastx.c:365:12:
/usr/include/bits/stdio2.h:253:2: error: call to '__fgets_chk_warn' declared 
with attribute warning: fgets called with bigger size than length of 
destination buffer
make[4]: *** [fastx.o] Error 1

The full log is available here:
https://launchpadlibrarian.net/71709349/buildlog_ubuntu-natty-amd64.fastx-toolkit_0.0.13-1~natty1_FAILEDTOBUILD.txt.gz

I am not sure I understand, but it seems related to “hardening” and the
prevention of buffer overflows.  I looked at the two following URLs,
but did not find more information.

https://wiki.ubuntu.com/Security/Features
http://wiki.debian.org/Hardening

Cheers,

-- 
Charles



--- End Message ---
--- Begin Message ---
Source: fastx-toolkit
Source-Version: 0.0.13.1-1

We believe that the bug you reported is fixed in the latest version of
fastx-toolkit, which is due to be installed in the Debian FTP archive:

fastx-toolkit_0.0.13.1-1.debian.tar.gz
  to main/f/fastx-toolkit/fastx-toolkit_0.0.13.1-1.debian.tar.gz
fastx-toolkit_0.0.13.1-1.dsc
  to main/f/fastx-toolkit/fastx-toolkit_0.0.13.1-1.dsc
fastx-toolkit_0.0.13.1-1_amd64.deb
  to main/f/fastx-toolkit/fastx-toolkit_0.0.13.1-1_amd64.deb
fastx-toolkit_0.0.13.1.orig.tar.bz2
  to main/f/fastx-toolkit/fastx-toolkit_0.0.13.1.orig.tar.bz2



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Charles Plessy <[email protected]> (supplier of updated fastx-toolkit package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Fri, 08 Jul 2011 13:11:37 +0900
Source: fastx-toolkit
Binary: fastx-toolkit
Architecture: source amd64
Version: 0.0.13.1-1
Distribution: unstable
Urgency: low
Maintainer: Debian Med Packaging Team 
<[email protected]>
Changed-By: Charles Plessy <[email protected]>
Description: 
 fastx-toolkit - FASTQ/A short nucleotide reads pre-processing tools
Closes: 626761
Changes: 
 fastx-toolkit (0.0.13.1-1) unstable; urgency=low
 .
   * New upstream release (Closes: #626761).
   * Incremented Standards-Version to reflect conformance with Policy 3.9.2
     (debian/control, no changes needed).
   * Corrected Vcs-Git URL (debian/control).
Checksums-Sha1: 
 9a6c04cc41145ff0055b182351f825f993b734ba 2023 fastx-toolkit_0.0.13.1-1.dsc
 5e6a4c0c019424e1513487736a3cd0a59f9e3fad 1153417 
fastx-toolkit_0.0.13.1.orig.tar.bz2
 ebdc3a20fb5c5f23726c610616e50790a96c5574 14317 
fastx-toolkit_0.0.13.1-1.debian.tar.gz
 8a90adb68f78bd8533f81cf791c053feb464a7e1 107906 
fastx-toolkit_0.0.13.1-1_amd64.deb
Checksums-Sha256: 
 49ca3e6cf90f1bb01431dcc3bba5de8ace1d6414c46cbaec576f06b380ce38b4 2023 
fastx-toolkit_0.0.13.1-1.dsc
 7e1dddd6d56bf148e82d0ef7d5efae7ce62d3419ecb5077f9199a527a5366c90 1153417 
fastx-toolkit_0.0.13.1.orig.tar.bz2
 2ea1acbfce059c312060b89443d200790489c3b332eaf6f21bf80d94023ac407 14317 
fastx-toolkit_0.0.13.1-1.debian.tar.gz
 b4df6c8c2713a295925317a92545c7df4e16f89a9d60de6a3497ff3548343641 107906 
fastx-toolkit_0.0.13.1-1_amd64.deb
Files: 
 95ab1cf0d424bf1928814a863207510f 2023 science optional 
fastx-toolkit_0.0.13.1-1.dsc
 3b0acec3aef0241d46f4c709d5714f09 1153417 science optional 
fastx-toolkit_0.0.13.1.orig.tar.bz2
 80c91bf5df6a27f66e7dd32d892daae3 14317 science optional 
fastx-toolkit_0.0.13.1-1.debian.tar.gz
 9369f98ae50fad5c455593636a08dcf3 107906 science optional 
fastx-toolkit_0.0.13.1-1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQIcBAEBCAAGBQJOFotUAAoJEMW9bI8ildUC670P/jb7X9AIx8u2VBQyeiYM72cR
Uksgc86eVkE/4r80BgYkjZI2M/j1sz54q7lqtBB/jHHxEFcqUsIutIRqQyCcbK1C
+IvJZeqhJE9ns6MkDaKiQsbnDFRkNQDYfFW0imyx2N8cbQEbqLGDaeLjb6PdF9D5
NRnaSM3M4D/x+TaY9YHrTlbHjbixb7JNVMSUmvAWPsydbk8c/1n5ycsZI1iCIr1w
i+u3swrCCVTDRwoPsduoU3X4E0d2Pepr2t1icyESfkY3jxIhyNu6YpFx142vOw2P
gynu9dZN4sohJHp9451rGZ25PebWwKt7YYV8QjOQXevgyAv/9nQGvI15NtcRYSQD
XgOj0FjkKQKmDPa9dbRXKNhoUNNpoTD58nBOYDUvb4BfCvnCOdhuQr81RVQo2Cb8
eETHD3QZrx2WD96iBLi6FVxvJkG87I91QmLOfpdwRZgpoWUL9aH9BhfTO2r09+Px
zy0aZFnEk/hCJINvceCTevpTGFcZ23tTW1zK/78M2LKOpMSxgzrvvpswKAxEH6zY
BB0vuoDWxp+BCrZW3SqRitEQpV/3aBbrsKwyxL0HsRHvE/vY0YptUf2T5nRgPWtH
sYsAn6bHP9RRfzL5CbgJ6l3XmzxkFW2IX+FJhb1GBVX3IGfKALRSVFhd2d2XT4bI
JKmUa6F0sEh8AepfcDr9
=rPg3
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to