Your message dated Sun, 21 Oct 2018 10:35:58 +0000
with message-id <[email protected]>
and subject line Bug#910672: fixed in openjdk-8 8u181-b13-2
has caused the Debian Bug report #910672,
regarding openjdk-8: Debian patch jdk-freetypeScaler-crash.diff causes a memory
leak
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
910672: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=910672
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: openjdk-8
Version: 8u181-b13-1~deb9u1
Severity: important
Dear Maintainer,
The Debian patch makes a FreetypeScaler native code create a global reference
to the FileFont object whose scaler it is. The global reference would be
removed when FreetypeScaler.dispose() is run, but that only happens after the
FileFont becomes garbage. Which it can't become because the global reference
keeps it alive even after all other references to the font have expired.
I asked about this patch earlier on the debian-java mailing list
(https://lists.debian.org/debian-java/2018/10/msg00002.html, demo program
included) and Florian Weimer spotted that the same patch had been submitted
upstream:
https://bugs.openjdk.java.net/browse/JDK-6761791
According to the notes in that bug report, the global references change was
unnecessary in the first place. And the problem has had a fix upstream since
Java 7.
Seeing as the patch is both unnecessary with Java 8 and actively harmful, please
remove it.
-- System Information:
Debian Release: 9.5
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 4.13.16-100.fc25.x86_64 (SMP w/8 CPU cores)
Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE=C.UTF-8
(charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: unable to detect
--- End Message ---
--- Begin Message ---
Source: openjdk-8
Source-Version: 8u181-b13-2
We believe that the bug you reported is fixed in the latest version of
openjdk-8, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Matthias Klose <[email protected]> (supplier of updated openjdk-8 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Sun, 21 Oct 2018 12:23:32 +0200
Source: openjdk-8
Binary: openjdk-8-jdk-headless openjdk-8-jre-headless openjdk-8-jdk
openjdk-8-jre openjdk-8-demo openjdk-8-source openjdk-8-doc openjdk-8-dbg
openjdk-8-jre-zero
Architecture: source
Version: 8u181-b13-2
Distribution: unstable
Urgency: high
Maintainer: OpenJDK Team <[email protected]>
Changed-By: Matthias Klose <[email protected]>
Description:
openjdk-8-dbg - Java runtime based on OpenJDK (debugging symbols)
openjdk-8-demo - Java runtime based on OpenJDK (demos and examples)
openjdk-8-doc - OpenJDK Development Kit (JDK) documentation
openjdk-8-jdk - OpenJDK Development Kit (JDK)
openjdk-8-jdk-headless - OpenJDK Development Kit (JDK) (headless)
openjdk-8-jre - OpenJDK Java runtime, using
openjdk-8-jre-headless - OpenJDK Java runtime, using (headless)
openjdk-8-jre-zero - Alternative JVM for OpenJDK, using Zero/Shark
openjdk-8-source - OpenJDK Development Kit (JDK) source files
Closes: 910672
Changes:
openjdk-8 (8u181-b13-2) unstable; urgency=high
.
[ Tiago Stürmer Daitx ]
* Apply patches from 8u191-b12 security update.
- CVE-2018-3136, S8194534: Manifest better support.
- CVE-2018-3139, S8196902: Better HTTP Redirection.
- CVE-2018-3149, S8199177: Enhance JNDI lookups.
- CVE-2018-3169, S8199226: Improve field accesses.
- CVE-2018-3180, S8202613: Improve TLS connections stability.
- CVE-2018-3183, S8202936: Improve script engine support.
- CVE-2018-3214, S8205361: Better RIFF reading support.
- CVE-2018-3211: Unspecified vulnerability in the Serviceability component.
- S8195868: Address Internet Addresses.
- S8195874: Improve jar specification adherence.
- S8201756: Improve cipher inputs.
- S8203654: Improve cypher state updates.
- S8204497: Better formatting of decimals.
* debian/patches/jdk-freetypeScaler-crash.diff: removed as this patch causes
a memory leak; upstream fixed it in openjdk-7, albeit in a different way.
Closes: #910672.
.
[ Matthias Klose ]
* Bump standards version.
Checksums-Sha1:
655a0c359c43a2ad64249c7086fa6af2dfa9a81a 4496 openjdk-8_8u181-b13-2.dsc
64fd4a378d0a067f3a4da4d5e5051f849bc4d04e 255640
openjdk-8_8u181-b13-2.debian.tar.xz
b851266a96836ce1f9c7b3abd20548cd7cc20346 17455
openjdk-8_8u181-b13-2_source.buildinfo
Checksums-Sha256:
73824b4b81020527c3ce278762f548f593eee5fb5817b24bf2d1b8f7a1ce2d19 4496
openjdk-8_8u181-b13-2.dsc
dc5b1f9cccd31a3f368dfbe87f505afd9eeb70221f9295dfe7094d6c9f3f7705 255640
openjdk-8_8u181-b13-2.debian.tar.xz
4a8aa6ff4c5327fc6f5e7a20c78050c7151fe8cda0922d58f1b202b5cbd394f9 17455
openjdk-8_8u181-b13-2_source.buildinfo
Files:
6929e18d05de560d845e19d2dbd237c3 4496 java optional openjdk-8_8u181-b13-2.dsc
5567145c1e0a441a1e0b68b7f5c49940 255640 java optional
openjdk-8_8u181-b13-2.debian.tar.xz
41c6bc769e702239db53659c38236473 17455 java optional
openjdk-8_8u181-b13-2_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJEBAEBCAAuFiEE1WVxuIqLuvFAv2PWvX6qYHePpvUFAlvMU7EQHGRva29AdWJ1
bnR1LmNvbQAKCRC9fqpgd4+m9SrLEADDhAtrmNBO2uToVAFOtNH8SOEbcchWi5uR
ZP5nfPxnR+cD0AV4Twa/2shqqt6wBndo4avJGcoSIWsxTx30sN1Ou+WiJ99PPf3W
QEg1qh+c0ibCC2AObIlS5n7px+K64F0srRr6ZgFYL8sXBg9aDJBXqWrIBBbbmUXK
H1JN+kITq2Psi+bt/mO6WSCkaUTjZVY9OMtOWX/H/QyODdVvBoZ2ow9eMdcq630S
dS4/YT8xS0Q+8O5TseR4a2tVGb0rWg1KFfPJtduY3sR/ppr11du8bL/qdOXV7rok
9OG1XdRT++sB3eyqqaLuIOqWdq7njg+PgqV/j9SjaKAcA68uqWCbJkGUxS6WNvEw
XkvD+gg4xX7HqkYTgwH2ye4ylx/WZg8E8hpDW5thasiV+3CKPhVmn8CGKj5NYoO6
g1a7wtHvDRkIHSzwrwcQ5HyB5ZyHPCV22eZS/b9j8Lsglr3yXaY/HtzgKwIHGb2r
HGmKict284kMqsSU+uSfmjXG9Zud6OECbTzPpwQwHz2R8DLOSqqdsbzWfpYBTa5g
3PpxMnrwji9xV2S71O6gIka2CLvQWD7CelVJi/K5NmMpaE7nTKTuu4NAvztaVZ09
fIjCCd1Wu34kvgraSvsV+/Dlm0I1osQONX/lGDQXQO/doDf8iqUTXjFPS0QGCkRN
VWhRd/uIwQ==
=98D3
-----END PGP SIGNATURE-----
--- End Message ---