Your message dated Mon, 31 Aug 2026 20:37:43 +0000
with message-id <[email protected]>
and subject line Bug#971005: fixed in mariadb 1:11.8.9+ds-1
has caused the Debian Bug report #971005,
regarding make it harder to accidentally use the bundled readline
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
971005: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=971005
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: mariadb-10.5
Version: 1:10.3.24-2
Severity: important

Hi Otto,

I'm a bit disappointed. You told me that mariadb would stop using
libreadline-gplv2-dev in >= 10.4. While that's technically correct, it's
not the whole truth. In 10.5, mariadb has a vendor copy of it. Instead
of actually moving to a recent version, mariadb just added an embedded
code copy. The Debian policy discourages such copies. I don't think it
makes sense to reiterate the reasons.

Please figure out whether you can unembed readline. This may be
difficult to do and you may come to the conclusion that doing so is
infeasible. In that case, please register your copy with the security
tracker to enable the security team supporting mariadb.  Refer to
https://wiki.debian.org/EmbeddedCopies for details.

Helmut

--- End Message ---
--- Begin Message ---
Source: mariadb
Source-Version: 1:11.8.9+ds-1
Done: Otto Kekäläinen <[email protected]>

We believe that the bug you reported is fixed in the latest version of
mariadb, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Otto Kekäläinen <[email protected]> (supplier of updated mariadb package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 29 Aug 2026 19:19:19 +0000
Source: mariadb
Architecture: source
Version: 1:11.8.9+ds-1
Distribution: unstable
Urgency: medium
Maintainer: Debian MySQL Maintainers <[email protected]>
Changed-By: Otto Kekäläinen <[email protected]>
Closes: 971005 971367 1140151 1140296
Changes:
 mariadb (1:11.8.9+ds-1) unstable; urgency=medium
 .
   [ Otto Kekäläinen ]
   * New upstream maintenance release version 11.8.9. Includes several fixes as
     noted at 
https://mariadb.com/docs/release-notes/community-server/11.8/11.8.9
     and also the following security issues:
     - CVE-2026-61081
     - CVE-2026-60585
     - CVE-2026-60331
     - CVE-2026-60747
     - CVE-2026-47023
     - CVE-2026-60184
   * Drop patches applied upstream
   * Update server trace to include new parameters and values
     - New option innodb-index-shrink (default TRUE)
   * Clean up d/copyright of files that no longer ship in this release
   * Update Lintian overrides for new upstream version
   * Update maintainer documentation to ensure it is current
   * Skip tests main.mysql_client_test* as they require Internet access
   * Salsa CI: Clean away defunct test jobs and start testing with MySQL 9.7
 .
   [ Luke Yasuda ]
   * d/*.lintian-overrides: fix all the mismatched-override
   * d/mariadb-server.links: drop the use of dh-exec
   * d/control: upgrade debhelper compatibility level to 14
   * d/watch: add +ds suffix
   * Add Files-Excluded section to d/copyright based on d/rules deletions.
     Until now unwanted upstream storage engines, precompiled binaries and 3rd
     party libraries and components have been removed in debian/rules clean
     section, but the proper way to exclude is to filter them out from the
     upstream release tarball before including them in Debian to begin with.
     (Closes: #971005, #971367)
   * d/copyright: drop entries for excluded files
   * d/gbp.conf: do not force check upstream sigs.
     We repack orig tarballs now, leaving this on will cause
     "gbp import-orig --uscan" to fail. uscan already checks the upstream
     signature and gbp does it again and fails, which is not we want.
   * drop unused source lintian overrides
   * drop unused local-options
 .
   [ Dick Hollenbeck ]
   * libmariadb-dev: make Multi-Arch: same co-installable (Closes: #1140296)
   * libmariadb-dev-compat: make Multi-Arch: same co-installable
     (Closes: #1140151)
 .
   [ Daniel Black ]
   * MDEV-39584: links mariadb.org/kb -> mariadb.com/docs
Checksums-Sha1:
 f114f162477ff9b2282988dadc531ce985d2ee88 5396 mariadb_11.8.9+ds-1.dsc
 0ce74570334ff745fbb094b090db199eaebe5f96 42060036 mariadb_11.8.9+ds.orig.tar.xz
 8b2be388aac7078dee76b049d307731508107c3a 302748 
mariadb_11.8.9+ds-1.debian.tar.xz
 89033ead6c297bc3300190eec288a6da0608fa09 13742 
mariadb_11.8.9+ds-1_source.buildinfo
Checksums-Sha256:
 315f5670a29b9db536c1704fa5ef9ec9e0761258181a1ac7632e4cea10217b0a 5396 
mariadb_11.8.9+ds-1.dsc
 af102b8ca599d764b74788a95ce14b737b17441811fea6e49392cf2890d2dc28 42060036 
mariadb_11.8.9+ds.orig.tar.xz
 58114dba766cb7922dc0c6d5a8d29a584676487d67ec888ba0c9012e0a7600b9 302748 
mariadb_11.8.9+ds-1.debian.tar.xz
 d3e4c2bd92b666eb838c2e34b7caeafb660d3a94fe53b709f633a9c7807a6ce6 13742 
mariadb_11.8.9+ds-1_source.buildinfo
Files:
 4a9026f906893210ed8a644242cf1c05 5396 database optional mariadb_11.8.9+ds-1.dsc
 0932c1707fbafb14b180036ccb8624c9 42060036 database optional 
mariadb_11.8.9+ds.orig.tar.xz
 c7d230209a7fa9a2ddd982b9fb37c5a8 302748 database optional 
mariadb_11.8.9+ds-1.debian.tar.xz
 35fe965d6dca045cb603ab3c0bf0407a 13742 database optional 
mariadb_11.8.9+ds-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEmbRSsR88dMO0U+RvvthEn87o2ogFAmqVskEACgkQvthEn87o
2oirHxAAroj3xtAHXsKbrg4nPpAReNeeXZdkBKunklVvdgiMqqZdVgMnw9uouiU4
egjKJhwIxpCppIwmApO2rr9FditmqDJ9twhUcRgs4vENCTGyhjToWjw+GbaCMYj6
OtCQxC9g8tc/suElvunlSngu2ax0doM0DbgcqPwYZOlrPU9B9Dixxwb+RMon3yjO
gVtpmKyQjBIT/FL4zXE8zh9xAmb4eZMNjxzDpDG3hM/FPmSOaiUfoSzH7SVj6iR5
KESF2OHc1YHSIMPnzricafcTVsJCpBM3SgDX5qJ8+5l8bXFbR8PmDoj3M1WEzGKr
rMjuNuKbb0xlX0yPNrbTgwYkagQuvq65P8G6ABGn2TdYeb/9o0NRTPZF2ZEgtpZZ
JnPYpgUmjLHa+hrOLQpfNSXw9U47q5OHyuUMoRJMBHXN5qw2YkL6YS6J08rnAYqi
UUVUfX78yGshtP003XTccUodF9K5LEz8dRKgKT80GwKO0O65x0FG6tlAInajBxb0
enblTKAXA3iKbiXCq7bLCAq5PTawzjfMrvMr8IXpIGsMlmnGVOoJ6dyPDHfDJK5f
v+6nDzhsYo4HpwFgk/tmdLG6zOXQrqYQADpEE/RFOWdEvMgag/8EoLpfH6KBi0Kh
JS4Q82bY8OYjVTbECxmQe1YvcoHj23Wmyn3Nl2lWEZgnQq8vHHM=
=iZV1
-----END PGP SIGNATURE-----

Attachment: pgpj3ejOQcn0W.pgp
Description: PGP signature


--- End Message ---

Reply via email to