Package: libengine-pkcs11-openssl
Version: 0.4.9-2
Severity: serious
User: debian...@lists.debian.org
Usertags: piuparts replaces-without-breaks

Hi,

during a test with piuparts and DOSE tools I noticed your package causes
removal of files that also belong to another package.
This is caused by using Replaces without corresponding Breaks.

The installation sequence to reproduce this problem is

  apt-get install libengine-pkcs11-openssl1.1/stretch
  # (1)
  apt-get install libengine-pkcs11-openssl/sid
  apt-get remove libengine-pkcs11-openssl
  # (2)

The list of installed files at points (1) and (2) should be identical,
but the following files have disappeared:

  /usr/lib/x86_64-linux-gnu/engines-1.1/libpkcs11.so
  /usr/lib/x86_64-linux-gnu/engines-1.1/pkcs11.la
  /usr/lib/x86_64-linux-gnu/engines-1.1/pkcs11.so


This is a serious bug violating policy 7.6, see
https://www.debian.org/doc/debian-policy/ch-relationships.html#overwriting-files-and-replacing-packages-replaces
and also see the footnote that describes this incorrect behavior:
https://www.debian.org/doc/debian-policy/ch-relationships.html#id13

The $OFFENDER package has the following relationships with $VICTIM:

  Conflicts: n/a
  Breaks:    n/a
  Replaces:  libengine-pkcs11-openssl1.1
  Provides:  libengine-pkcs11-openssl1.1


>From the attached log (scroll to the bottom...):

18m52.8s ERROR: FAIL: After purging files have disappeared:
  /usr/lib/x86_64-linux-gnu/engines-1.1/libpkcs11.so -> pkcs11.so        owned 
by: libengine-pkcs11-openssl:amd64
  /usr/lib/x86_64-linux-gnu/engines-1.1/pkcs11.la        owned by: 
libengine-pkcs11-openssl:amd64
  /usr/lib/x86_64-linux-gnu/engines-1.1/pkcs11.so        owned by: 
libengine-pkcs11-openssl:amd64

18m52.8s ERROR: FAIL: After purging files have been modified:
  /var/lib/dpkg/info/libengine-pkcs11-openssl1.1:amd64.list      not owned


cheers,

Andreas

Attachment: libengine-pkcs11-openssl1.1=0.4.4-4_libengine-pkcs11-openssl=0.4.9-2.log.gz
Description: application/gzip

Reply via email to