Your message dated Thu, 08 Mar 2012 04:02:54 +0000
with message-id <[email protected]>
and subject line Bug#651964: fixed in cdbs 0.4.106
has caused the Debian Bug report #651964,
regarding cdbs: class/langcore.mk doesn't set CPPFLAGS and LDFLAGS from 
dpkg-buildflags
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
651964: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=651964
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: cdbs
Severity: important
Tags: patch

Hello,

While trying to build poppler with hardening flags I noticed that
CPPFLAGS and LDFLAGS were not set correctly. This is an important
problem as it causes several hardening flags (fortify source,
relro) to not get included in the build.

Adding the following lines to class/langcore.mk.in in line 57
where CFLAGS and CXXFLAGS are already set fixes the problem:

    CPPFLAGS += $(deb_cppflags)
    LDFLAGS += $(deb_ldflags)

Regards,
Simon

-- System Information:
Debian Release: wheezy/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.1.0-1-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash



--- End Message ---
--- Begin Message ---
Source: cdbs
Source-Version: 0.4.106

We believe that the bug you reported is fixed in the latest version of
cdbs, which is due to be installed in the Debian FTP archive:

cdbs_0.4.106.dsc
  to main/c/cdbs/cdbs_0.4.106.dsc
cdbs_0.4.106.tar.gz
  to main/c/cdbs/cdbs_0.4.106.tar.gz
cdbs_0.4.106_all.deb
  to main/c/cdbs/cdbs_0.4.106_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jonas Smedegaard <[email protected]> (supplier of updated cdbs package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 08 Mar 2012 04:06:35 +0100
Source: cdbs
Binary: cdbs
Architecture: source all
Version: 0.4.106
Distribution: unstable
Urgency: low
Maintainer: CDBS Hackers <[email protected]>
Changed-By: Jonas Smedegaard <[email protected]>
Description: 
 cdbs       - common build system for Debian packages
Closes: 642950 651964 651966 661983
Changes: 
 cdbs (0.4.106) unstable; urgency=low
 .
   * Fix set libexecdir to /usr/lib (not /usr/lib/$pkg) in
     autotools-vars.mk.
     Closes: bug#661983. Thanks to Rémi Denis-Courmont.
   * Fix strip PD libraries below per-package install dirs (only for
     single-binary-package below debian/tmp).
     Closes: Bug#661983. Thanks to Felipe Sateler.
   * Fix set CPPFLAGS (not bogus CPPLAGS) in langcore.mk.
     Closes: bug#651964. Thanks (again) to Simon Ruderich and Moritz
     Muehlenhoff.
   * Fix create cruft subdirs before using them in utils.mk. Bump
     resolved build-dependency on cdbs as cruft handling was completely
     broken previously.
   * Handle FFLAGS in langcore.mk.
   * Re-issue news about changes to compiler flags:
     + LDFLAGS was broken when previously announced (in 0.4.103).
     + FFLAGS in also handled now.
     + Advertise use of /usr/share/dpkg/buildflags.mk, now supported
       but explicitly required as it clashes with flags explicitly set or
       unset locally in rules files.
       Closes: bug#651966, #642950. Thanks to Simon Ruderich and Raphael
       Hertzog.
   * Fix Makefile.am to use pkglibexec_SCRIPTS and avoid libexecdir.
   * Update autotools (with autoreconf -f -i).
   * Update copyright file:
     + Fix double-indent copyright lines.
     + Extend copyright years for automade files.
     + Add copyright holders for Makefile.in files.
Checksums-Sha1: 
 4a0b61f771136a7e675f1206e5476be133c02c9d 1833 cdbs_0.4.106.dsc
 6b6cb266bec1de6082ad09a45312caa47e892cee 266417 cdbs_0.4.106.tar.gz
 6be6bd33e42b7bdf7b9d9af14b731d7d2a35cbe9 79404 cdbs_0.4.106_all.deb
Checksums-Sha256: 
 28752f2d1a117d9c4e98d25e925bac0fd5d6bcc7cc76b06fa6249fd7f6d0d49a 1833 
cdbs_0.4.106.dsc
 10e3d8959be7161913abe8b8124884f0eada4c801e2d0bb20509b052d2915718 266417 
cdbs_0.4.106.tar.gz
 1e2562c4cfd6739ff426377397df5e4a91b4d6941c5b32e47f83359926d3fbdd 79404 
cdbs_0.4.106_all.deb
Files: 
 950c76889b71245e0e81d3f8ddde1c3c 1833 devel optional cdbs_0.4.106.dsc
 f820afeafd518e95ad3d5c8864e36274 266417 devel optional cdbs_0.4.106.tar.gz
 ea24c71a7612aadac793faa30b412c99 79404 devel optional cdbs_0.4.106_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBCgAGBQJPWC4ZAAoJECx8MUbBoAEhFd0P/2mH6clEqU5CcDNGAm4oKh9D
Y7Fd2vEEyvW0PZEJoj6p5RSEGBVrBfP2INpB45voDRrR4t9AljaZTkVvwPz4B3Hu
XqJfRgstiEY7PGfZgeW6W3vHnnqnl+4MVldtzFjSns3SA1Ckl7cU4BvO4a8cVb4s
21/z9tXeMrzKQdwqFQyJe4K70ZiyvEBDAtg5Rzev0Er/saM8jKvEEt0Msc+9/qht
BNdZ0040BlrFXBSO2K+ZAcdChXh5zz1vbdfBqGRleqZCiQ5jjEFBiKjUyP5db1aU
TTFx6bV1YVneqiE9iLFVdKZq132TgeulhUtSpoMUrAdrv8eeADQ/2Wfu68FXX1B7
dSoP5FM9KKbNvDGEK5SgRLzqg9oSQIw2pum8jyQ8amIUk2SJ95D4flkErlcYsglo
YYNz4zgzIBG34rNukOWnWlW3Qk79ExPs5VmO1k7Nf7bq0myBzB+N8n2YVzFStEyt
RuqpZSgpeheTfKf90Rk3oqqw6oQchDpQW2MazVQfYhv2xcwdEYGqbvW3NyuWER8c
KROcc6vSnwp8qzfyI7ge9HTYF5mIJETuIquhUWIltpYCLit7dE6HZQnquV9w1sPz
fHQkH9eekZkO5ARwXAXJ7chjclzXWXsHXCOWlx7EKi10tK14kWXAZZmWD5A+ibqC
94L80VGl2ocGpwZwnIOf
=6knZ
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to