Your message dated Sun, 23 Oct 2011 21:47:39 +0000
with message-id <[email protected]>
and subject line Bug#646268: fixed in grads 2.0.a9-3
has caused the Debian Bug report #646268,
regarding grads: FTBFS with -Werror=format-security
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
646268: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=646268
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: grads
Version: 2.0.a9-2
Severity: normal
User: [email protected]
Usertags: hardening-format-security hardening

the package grads fails to compile with the new hardened compiler
flags dpkg-buildflag outputs [0].
The problematic flag is: -Werror=format-security
See the ubuntu buildlog:
https://launchpadlibrarian.net/83137933/buildlog_ubuntu-precise-i386.grads_2.0.a9-2_FAILEDTOBUILD.txt.gz
Snippet:
gcc -DHAVE_CONFIG_H -I. -I/usr/include/ -I/usr/include/gd
-I/usr/include/grib2c  -I/usr/include/udunits -I/usr/include/netcdf
-I/usr/include/hdf5 -I/usr/include/tiff -I/usr/include/geotiff
-I/usr/include/shapelib -I/usr/include/shp     -I/usr/include/hdf
-D_FORTIFY_SOURCE=2  -g -O2 -fstack-protector --param=ssp-buffer-size=4
-Wformat -Wformat-security -Werror=format-security -rdynamic -c gagx.c
gagx.c: In function 'gashpwrt':
gagx.c:3524:5: error: format not a string literal and no format
arguments [-Werror=format-security]
gagx.c:3524:5: error: format not a string literal and no format
arguments [-Werror=format-security]
cc1: some warnings being treated as errors



The buildflags are not exported in debian, but can be enabled e.g. by
adding this to debian/rules:

 DPKG_EXPORT_BUILDFLAGS = 1
 include /usr/share/dpkg/buildflags.mk

Please fix the issues and maybe also enable the hardened build in debian.

[0] http://lists.debian.org/debian-devel-announce/2011/09/msg00001.html




Attachment: signature.asc
Description: OpenPGP digital signature


--- End Message ---
--- Begin Message ---
Source: grads
Source-Version: 2.0.a9-3

We believe that the bug you reported is fixed in the latest version of
grads, which is due to be installed in the Debian FTP archive:

grads_2.0.a9-3.debian.tar.gz
  to main/g/grads/grads_2.0.a9-3.debian.tar.gz
grads_2.0.a9-3.dsc
  to main/g/grads/grads_2.0.a9-3.dsc
grads_2.0.a9-3_i386.deb
  to main/g/grads/grads_2.0.a9-3_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Alastair McKinstry <[email protected]> (supplier of updated grads package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sun, 23 Oct 2011 17:54:31 +0100
Source: grads
Binary: grads
Architecture: source i386
Version: 2.0.a9-3
Distribution: unstable
Urgency: low
Maintainer: Alastair McKinstry <[email protected]>
Changed-By: Alastair McKinstry <[email protected]>
Description: 
 grads      - Grid Analysis and Display System for earth science data
Closes: 643144 646268
Changes: 
 grads (2.0.a9-3) unstable; urgency=low
 .
   * B-D on netcdf-bin for nc-config, or ./configure may behave differently.
   * Enable  --enable-dyn-supplibs for dynamic linking.
   * Enable --with-hdf4-include to find HDF4 ; patch needed to compile.
   * Patch for format-security error. Closes: #646268.
   * Autogenerated gunk breaks building from source. Fix. Closes: #643144.
   * Remove debian-changes-* patches;
Checksums-Sha1: 
 0645ae669891ad889e6867ecf470864fca23727f 2530 grads_2.0.a9-3.dsc
 8b6462baefdf3c969cb9875ba3d16c0d6ef428c0 471489 grads_2.0.a9-3.debian.tar.gz
 57d4e8751cda16ead5c3fe48877e6df219f51e48 4541086 grads_2.0.a9-3_i386.deb
Checksums-Sha256: 
 b73b56ccde7201f5bbb87e58cbf91076decacc87f12e8090ea47548a176a7dfa 2530 
grads_2.0.a9-3.dsc
 c64b2e4745a3d93b2529106d1457d981105c624adb970730efddcfc3f4dc34e4 471489 
grads_2.0.a9-3.debian.tar.gz
 f2056d50afac9df010f81ddbda4d9db411b55340fc07e55c3a2b59c6c90bc4da 4541086 
grads_2.0.a9-3_i386.deb
Files: 
 296934c9420f41997a0d7f4ed2290f82 2530 science optional grads_2.0.a9-3.dsc
 1548b9cff785e61a35d606f8f4af5622 471489 science optional 
grads_2.0.a9-3.debian.tar.gz
 d739ec9874016d07d9c7f901335c3181 4541086 science optional 
grads_2.0.a9-3_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAEBCAAGBQJOpHlUAAoJEN9LdrZRJ3Qs4IwP/2Em4KyDDvbiKxrEn2UBnfAj
N3Asc7HqYx/g17X5UoDC9mcoBjXtXqS2XobeL1/K2ZT/RcyDgMjNWCNojcpYtd7a
oy+3SXToIDpQU73OqwWhBGY6kIeUSg0/BVVu9EVR8eWXbHoUMT65m44y3s50/Q2Q
E0lCBKQXKIlWnM7zQTVj+Ep7P+rO44NZYsQQ0xeAj2rZk0XvsVfE6LQPkhRqqBba
i+Z4ZXN/Riz3I8vF9zKD5CrnSA07LzgwQB+MMX2G/O4CKCjsIvC8L/QwMbnjgtV/
k1bXTikUgHxyMWL92QMZhqkk6jRxJOmgj9p4rC8ZuDXtpP4PKoqPV5hgrX+JW4XG
ZTshl4AmDsyADzApi2vxDyRMrnltZ52huVy5qSAZA1qvTG4m6byYTuQywtCuQGdd
gosXi1UOmT/xUf5H18UPedN9XAFw5OU1tmZyYZ2q0UddbVDlyobQhqppnO8Z9sQh
EYAj0NKfi7jMKsQsc/zUad9NBpkVUECWoyOf6Gu5eElN5uKIASBtQjudpiifS9Oc
FWnNNwSOn/H/XVZeTc5+hJlLhADLVZTwk6smOjQj7Wj5npaX7QUR99V/tnJ1gxG+
4pmLtU1J+AfpqoeG4j4BAOoNvNichuBTvkUVQWYrUBGZhJpeawmhSA7B6Vxx6WNf
8HcEVmsA9pCt7Fwa2ZQ/
=atlW
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to