Your message dated Sat, 01 Oct 2022 17:20:30 +0000
with message-id <[email protected]>
and subject line Bug#1012734: fixed in firejail 0.9.70-2
has caused the Debian Bug report #1012734,
regarding firejail-profiles: Debian-patched transmission programs cannot run 
inside firejail with shipped profiles
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1012734: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1012734
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: firejail-profiles
Version: 0.9.70-1
Severity: normal

Dear Maintainer,

Debian have patched the current transmission to fit OpenSSL 3.0, but in order to use the legacy RC4 algorithm, ossl-modules/legacy.so should be able to load at runtime, otherwise Debian-patched transmission programs will be terminated
with SIGSEGV when trying to set up an EVP_CIPHER_CTX for RC4, as in the
attached backtrace. (against a /usr/local/bin/transmission-daemon built from
Debian-patched source with the same config, but with debug symbols retained)

This dependency has rendered the current Debian-patched transmission programs
cannot run inside firejail with shipped profiles. To walk this issue around,
"private-lib <multiarch triplet>/ossl-modules,legacy.so" should be added into
the (included) profile snippet of the transmission program.


-- System Information:
Debian Release: bookworm/sid
APT prefers testing
APT policy: (900, 'testing'), (500, 'unstable'), (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 5.17.0-1-amd64 (SMP w/4 CPU threads; PREEMPT)
Kernel taint flags: TAINT_FIRMWARE_WORKAROUND
Locale: LANG=zh_CN.utf8, LC_CTYPE=zh_CN.utf8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages firejail-profiles depends on:
ii firejail 0.9.70-1

firejail-profiles recommends no packages.

firejail-profiles suggests no packages.

-- no debconf information
#0  0x0000563113cb4c0f in tr_rc4_set_key (h=0x0, key=key@entry=0x7f5ee6068170 "D\333O\357m\020F\260\213\r\216\320u\310\330Vs\273>\272", key_length=key_length@entry=20) at crypto-utils-openssl.c:255
255	    if (!check_result(EVP_CIPHER_CTX_set_key_length(handle->cipher_ctx, key_length)))
[Current thread is 1 (Thread 0x7f5ee606a640 (LWP 55))]
#1  0x0000563113cdad31 in initRC4 (crypto=crypto@entry=0x7f5ee38f69b0, setme=setme@entry=0x7f5ee38f69b8, key=<optimized out>) at crypto.c:106
#2  0x0000563113cdb040 in tr_cryptoEncryptInit (crypto=0x7f5ee38f69b0) at crypto.c:140
#3  0x0000563113cdbaba in readYb (inbuf=0x7f5ee376dba0, handshake=0x7f5ee3699190) at handshake.c:460
#4  canRead (io=<optimized out>, arg=0x7f5ee3699190, piece=<optimized out>) at handshake.c:1060
#5  0x0000563113cc5c5b in canReadWrapper (io=0x7f5ee38f65f0) at peer-io.c:211
#6  0x0000563113ced542 in UTP_ProcessIncoming (conn=conn@entry=0x7f5ee376d050, packet=packet@entry=0x7f5ee6068a50 "\001", len=len@entry=363, syn=syn@entry=false) at utp.cpp:2158
#7  0x0000563113cee380 in UTP_IsIncomingUTP (incoming_proc=incoming_proc@entry=0x563113ca78e0 <incoming>, send_to_proc=send_to_proc@entry=0x563113ca7a30 <tr_utpSendTo>, send_to_userdata=send_to_userdata@entry=0x563114b0ac00, buffer=buffer@entry=0x7f5ee6068a50 "\001", 
    len=len@entry=363, to=<optimized out>, tolen=16) at utp.cpp:2587
#8  0x0000563113ca7aba in tr_utpPacket (buf=buf@entry=0x7f5ee6068a50 "\001", buflen=buflen@entry=363, from=from@entry=0x7f5ee60689d0, fromlen=16, ss=ss@entry=0x563114b0ac00) at tr-utp.c:181
#9  0x0000563113ca71f5 in event_callback (s=<optimized out>, type=<optimized out>, sv=0x563114b0ac00) at tr-udp.c:285
#10 0x00007f5ee7d25428 in ?? () from /usr/lib/x86_64-linux-gnu/libevent-2.1.so.7
#11 0x00007f5ee7d25b77 in event_base_loop () from /usr/lib/x86_64-linux-gnu/libevent-2.1.so.7
#12 0x0000563113ca84d8 in libeventThreadFunc (veh=0x563114b0b170) at trevent.c:263
#13 0x0000563113c96d38 in ThreadFunc (_t=0x563114af5570) at platform.c:104
#14 0x00007f5ee762ad80 in start_thread (arg=0x7f5ee606a640) at pthread_create.c:481
#15 0x00007f5ee754476f in clone () at ../sysdeps/unix/sysv/linux/x86_64/clone.S:95

--- End Message ---
--- Begin Message ---
Source: firejail
Source-Version: 0.9.70-2
Done: Reiner Herrmann <[email protected]>

We believe that the bug you reported is fixed in the latest version of
firejail, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Reiner Herrmann <[email protected]> (supplier of updated firejail package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 01 Oct 2022 18:30:05 +0200
Source: firejail
Architecture: source
Version: 0.9.70-2
Distribution: unstable
Urgency: medium
Maintainer: Reiner Herrmann <[email protected]>
Changed-By: Reiner Herrmann <[email protected]>
Closes: 1012734 1013326 1019386
Changes:
 firejail (0.9.70-2) unstable; urgency=medium
 .
   [ Reiner Herrmann ]
   * Update firefox profiles to allow new dbus names used in ESR version.
     (Closes: #1019386)
   * Drop private-lib from transmission profiles to allow loading additional
     modules. (Closes: #1012734)
   * Adapt lintian overrides to new version.
   * Bump Standards-Version to 4.6.1.
   * Use api.github.com for searching upstream releases.
 .
   [ Olivier Tilloy ]
   * Restrict architectures of firefox in autopkgtest to the ones supported
     in Ubuntu. (Closes: #1013326)
Checksums-Sha1:
 681c0b99858731b8f987e65250183adf4415ee21 2479 firejail_0.9.70-2.dsc
 28b54d73f15ab9263dfa1e940da976e2ee430c44 16808 firejail_0.9.70-2.debian.tar.xz
 e3c3c1f2de49fa4f201ec7a5b6a059597bca16b7 6748 
firejail_0.9.70-2_source.buildinfo
Checksums-Sha256:
 af4b8206e438b20cacb54d9de0eadd5d3072a1f1a73d3110580c43bc89e188f4 2479 
firejail_0.9.70-2.dsc
 ef563201937039ae08401eda40ea93ae2a2440a0a2ba8a1dba96061fe0c98d5a 16808 
firejail_0.9.70-2.debian.tar.xz
 971f93093a49811d39641f5aae2334be13c1d7634ef9310abc575a2cde1ec1ef 6748 
firejail_0.9.70-2_source.buildinfo
Files:
 f0b728ec2297d4e48209940d36331120 2479 utils optional firejail_0.9.70-2.dsc
 0c52104880e8929ecc6575e2d2efae81 16808 utils optional 
firejail_0.9.70-2.debian.tar.xz
 5313f9bbb189b3ef7d2cc409d302de69 6748 utils optional 
firejail_0.9.70-2_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE2Pb6feok2Q1urHM7zPBJKNsO6qcFAmM4a/oACgkQzPBJKNsO
6qepgQ/7BQIRevykWcLg0X8k5W1eBQgvyOyfWtp4bBSN4CSJBX5G192jF3Gy3jTm
BKYrMUA9ommi8+WRE6bV/SjoAyzFo29zfHdx1/9nfK+SH7cBb3bLW9UEXNYhDvLQ
+BrLbgXazC8BYbQhpsWkSsFT1DkW0RitLlBYG9TGc3nxEezol1GzKn+5SV9F/Dm+
1jKsbef2WN9pge7J46MBCf3EakGR64msTEpQgIK2sUhSodAaChSvTEHj0os6fb0I
b2m9lHC6aXzUglkggKHRlWmgIkJh/jY+4wRTvz+IInb+63Pa82gOEVNA2mPpz2FA
TRDZzSGHZkE7Eb6LIEQo5HHNcqJuezsj13LYISMVrQ+wmMS+Apz5vOd8NoYuTVBR
qzLRvC3UUQ2uZTNXLW7OqcDGDoIuGRLl4xHJE40baIGR+hs2FuEQSJ/q+5q84SDp
gEgUWU7pkHnLWjwDP7OI2hu5u0uPYseeLG4PDFmLdg7bpoP7/WiA9UmAa22yhqfT
/cqXTK4aeIHdp9OgHbao3GIkih2dhsHUud2Wc3sY6+mPvXcz+VVik7lVT8pgCtOa
8ggG1bsLfgi2U84iCgo/HqWr89WnJDBgddmknjkitTXBKW8rNludXiU0+w/SuGdU
3ZgUU3QdKsYnwEhrI7sKdK25iGjOR+XTptVSPHibB+0Q6dKCpTo=
=Vl12
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to