[Git][glibc-team/glibc][bullseye] 2 commits: debian/patches/local-CVE-2021-33574-mq_notify-use-after-free.diff: fix a...

2022-01-18 Thread Aurelien Jarno (@aurel32)


Aurelien Jarno pushed to branch bullseye at GNU Libc Maintainers / glibc


Commits:
fabb878c by Aurelien Jarno at 2022-01-18T21:57:15+01:00
debian/patches/local-CVE-2021-33574-mq_notify-use-after-free.diff: fix a 
possible use-after-free in mq_notify (CVE-2021-33574).  Closes: #989147.

- - - - -
807163b5 by Aurelien Jarno at 2022-01-18T21:57:15+01:00
debian/patches/git-updates.diff: update from upstream stable branch:

  - Fix a buffer overflow in sunrpc svcunix_create (CVE-2022-23218).
  - Fix a buffer overflow in sunrpc clnt_create (CVE-2022-23219).

- - - - -


4 changed files:

- debian/changelog
- + debian/patches/any/local-CVE-2021-33574-mq_notify-use-after-free.diff
- debian/patches/git-updates.diff
- debian/patches/series


View it on GitLab: 
https://salsa.debian.org/glibc-team/glibc/-/compare/0c881a8e622e50008086de53a72cb1ce3156e68b...807163b57e19e22b1f597ac0099bdaa3d64b7f1d

-- 
View it on GitLab: 
https://salsa.debian.org/glibc-team/glibc/-/compare/0c881a8e622e50008086de53a72cb1ce3156e68b...807163b57e19e22b1f597ac0099bdaa3d64b7f1d
You're receiving this email because of your account on salsa.debian.org.




[Git][glibc-team/glibc][sid] debian/patches/git-updates.diff: update from upstream stable branch:

2022-01-18 Thread Aurelien Jarno (@aurel32)


Aurelien Jarno pushed to branch sid at GNU Libc Maintainers / glibc


Commits:
20e02061 by Aurelien Jarno at 2022-01-18T23:19:09+01:00
debian/patches/git-updates.diff: update from upstream stable branch:

* debian/patches/git-updates.diff: update from upstream stable branch:
  - Fix FTBFS on powerpc and ppc64 with recent binutils snapshots.
  - Fix autopkgtest on armhf.

- - - - -


2 changed files:

- debian/changelog
- debian/patches/git-updates.diff


View it on GitLab: 
https://salsa.debian.org/glibc-team/glibc/-/commit/20e02061f900515ebac6ee3872c5cd22ea5801d2

-- 
View it on GitLab: 
https://salsa.debian.org/glibc-team/glibc/-/commit/20e02061f900515ebac6ee3872c5cd22ea5801d2
You're receiving this email because of your account on salsa.debian.org.




[Git][glibc-team/glibc][glibc-2.34] debian/testsuite-xfail-debian.mk: Update hurd tests

2022-01-18 Thread Samuel Thibault (@sthibault)


Samuel Thibault pushed to branch glibc-2.34 at GNU Libc Maintainers / glibc


Commits:
c2293925 by Samuel Thibault at 2022-01-18T21:37:34+01:00
debian/testsuite-xfail-debian.mk: Update hurd tests

- - - - -


1 changed file:

- debian/testsuite-xfail-debian.mk


View it on GitLab: 
https://salsa.debian.org/glibc-team/glibc/-/commit/c229392506ac6a27da061fa3c0efc071712c10b8

-- 
View it on GitLab: 
https://salsa.debian.org/glibc-team/glibc/-/commit/c229392506ac6a27da061fa3c0efc071712c10b8
You're receiving this email because of your account on salsa.debian.org.




glibc_2.33-3_source.changes ACCEPTED into unstable

2022-01-18 Thread Debian FTP Masters



Accepted:

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Format: 1.8
Date: Tue, 18 Jan 2022 19:06:44 +0100
Source: glibc
Architecture: source
Version: 2.33-3
Distribution: unstable
Urgency: medium
Maintainer: GNU Libc Maintainers 
Changed-By: Aurelien Jarno 
Closes: 1003574 1003610 1003847
Changes:
 glibc (2.33-3) unstable; urgency=medium
 .
   [ Samuel Thibault ]
   * debian/patches/hurd-i386/git-ttydefaults.diff: New patch to fix default
 character for termio cc[VSTATE].
   * debian/patches/hurd-i386/git-const.diff: Constify RPCs server-side.
 - debian/control: Bump mig build-dep accordingly.
 .
   [ Aurelien Jarno ]
   * debian/patches/git-updates.diff: update from upstream stable branch:
 - Fix FTBFS on ppc64el with recent binutils snapshots.  Closes: #1003847.
 - Fix crashes in bzero/memset on i386 with SSE2 when the cache size cannot
   be determined.  Closes: #1003574, #1003610.
 - Fix a buffer overflow in sunrpc svcunix_create (CVE-2022-23218).
 - Fix a buffer overflow in sunrpc clnt_create (CVE-2022-23219).
 .
   [ Gunnar Hjalmarsson ]
   * debian/local/usr_sbin/update-locale: tweak validation of args to
 update-locale().
Checksums-Sha1:
 6e9f094f445a8f6a883080d566a4bb39cd080e66 9631 glibc_2.33-3.dsc
 c6cb74fc11a6b7b84b15134b1073d5db25fc9133 815404 glibc_2.33-3.debian.tar.xz
 6ed674db63e1bb32ceade0950b1dcd25f28256cd 8897 glibc_2.33-3_source.buildinfo
Checksums-Sha256:
 5f2f07b974f79975369ea77a7dd5dddb5d85b6fec5e390da5c295529932c16c5 9631 
glibc_2.33-3.dsc
 4b184b55337cec4786c15c162314d05421a5b734089ad5dd54a34d49e37a81ff 815404 
glibc_2.33-3.debian.tar.xz
 a32cc1bdfe0529c3d4a20a0ac54c96a7ff2bd5f2a344c8f3da8d17403883d389 8897 
glibc_2.33-3_source.buildinfo
Files:
 71926b8274d2646ee90b80e388be7100 9631 libs required glibc_2.33-3.dsc
 8d4c5c4050441e874ef7f41387151755 815404 libs required 
glibc_2.33-3.debian.tar.xz
 f608aefd47f4024c7e386c85ac32c7e0 8897 libs required 
glibc_2.33-3_source.buildinfo

-BEGIN PGP SIGNATURE-

iQIzBAEBCgAdFiEEUryGlb40+QrX1Ay4E4jA+JnoM2sFAmHnIusACgkQE4jA+Jno
M2vkug/+KbopxKz/29IpY3H5aJ79IHH9wmhwSHalgSpqv+JC90Rhaea2zEFOMa4E
uFh4SQC6qhZ8cxTSSb8AFX0ZPiPTIOrCT+J2+1gWbZ+mkClzaqfIaHeCusp/HvdI
zWBT7aPLKaSxXRT5/HdUw56H2xbfFWngmnq3yTvCueZH6x0gjaP/ug94dG7ElFLC
DtvZowQLvmnBHC7Dsx/5UfV10XWUrgYeVjqnmmvxqfyKzKIF96X2GoFeEu+PwVXi
Rnbnwha0zbES0VpGrIaJuBR8DoJoPE7UrSS9z9SPf67rNbfurDQITAuR4CvojXx8
DbUHTLO6kWaAO2oQ3p0v/VJVrmpk3S4x2nNsB+fkF73KMSWvx6op4kB/ObvbqaQA
pPnqO6YXXAQnB0gG1AE+PJfFPaj+2AYIzM6SAGqXbO2ikxS7n7ufyW35Teo4CN5h
0oLWq2jshNbqytk/4fraL6whMvZORtkG8qFgfxvyWMK4SsEBMi+v9omiJESufTNS
RkIB0v3xa3AEmxFx0b9OsKL/s3mF3ioZ4hQAf18C4nnZvW9gYhJbNglfK07HGC3p
uqjqgHv87pkCCqiPu0U9lwfB/ViAk6svgf0XHjAemAsy3Z4RyaGL0BEh9/s6hRG4
G63dBt0CwW3gxt8QSCUTxlWNZX4qUmOZqQNXCWhDGLa0+QpCwdA=
=C9SG
-END PGP SIGNATURE-


Thank you for your contribution to Debian.



Processing of glibc_2.33-3_source.changes

2022-01-18 Thread Debian FTP Masters
glibc_2.33-3_source.changes uploaded successfully to localhost
along with the files:
  glibc_2.33-3.dsc
  glibc_2.33-3.debian.tar.xz
  glibc_2.33-3_source.buildinfo

Greetings,

Your Debian queue daemon (running on host usper.debian.org)



Bug#1003847: marked as done (binutils breaks glibc autopkgtest on ppc64el: unrecognized opcode: `vspltisb' (and others))

2022-01-18 Thread Debian Bug Tracking System
Your message dated Tue, 18 Jan 2022 20:35:00 +
with message-id 
and subject line Bug#1003847: fixed in glibc 2.33-3
has caused the Debian Bug report #1003847,
regarding binutils breaks glibc autopkgtest on ppc64el: unrecognized opcode: 
`vspltisb' (and others)
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
1003847: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003847
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---

Source: binutils, glibc
Control: found -1 binutils/2.37.50.20220106-2
Control: found -1 glibc/2.33-2
Severity: serious
Tags: sid bookworm
X-Debbugs-CC: debian...@lists.debian.org
User: debian...@lists.debian.org
Usertags: breaks needs-update
Control: affects -1 gcc-10 gcc-11

Dear maintainer(s),

With a recent upload of binutils the autopkgtest of glibc fails in 
testing when that autopkgtest is run with the binary packages of 
binutils from unstable. It passes when run with only packages from 
testing. In tabular form:


   passfail
binutils   from testing2.37.50.20220106-2
glibc  from testing2.33-2
all others from testingfrom testing

I copied some of the output at the bottom of this report.

Currently this regression is blocking the migration of binutils, gcc-10 
and gcc-11 to testing [1]. Due to the nature of this issue, I filed this 
bug report against the binutils and glibc source packages. Can you 
please investigate the situation and reassign the bug to the right package?


More information about this bug and the reason for filing it can be found on
https://wiki.debian.org/ContinuousIntegration/RegressionEmailInformation

Paul

[1] https://qa.debian.org/excuses.php?package=binutils

https://ci.debian.net/data/autopkgtest/testing/ppc64el/g/glibc/18280958/log.gz

powerpc64le-linux-gnu-gcc-10 
../sysdeps/ieee754/ldbl-128ibm/tst-strtold-ldbl-128ibm.c -c -std=gnu11 
-fgnu89-inline  -pipe -O2 -g 
-fdebug-prefix-map=/tmp/autopkgtest-lxc.448kjxt6/downtmp/build.UW5/src=. 
-mcpu=power8 -Wall -Wwrite-strings -Wundef -Werror -fmerge-all-constants 
-frounding-math -fstack-protector-strong -Wstrict-prototypes 
-Wold-style-definition -fmath-errno -mabi=ieeelongdouble -Wno-psabi 
-mno-gnu-attribute  -mlong-double-128   -mabi=ibmlongdouble 
-isystem 
/tmp/autopkgtest-lxc.448kjxt6/downtmp/build.UW5/src/debian/include 
-I../include 
-I/tmp/autopkgtest-lxc.448kjxt6/downtmp/build.UW5/src/build-tree/ppc64el-libc/stdlib 

-I/tmp/autopkgtest-lxc.448kjxt6/downtmp/build.UW5/src/build-tree/ppc64el-libc 
 -I../sysdeps/unix/sysv/linux/powerpc/powerpc64/le/fpu 
-I../sysdeps/unix/sysv/linux/powerpc/powerpc64/fpu 
-I../sysdeps/unix/sysv/linux/powerpc/powerpc64/le 
-I../sysdeps/unix/sysv/linux/powerpc/powerpc64 
-I../sysdeps/unix/sysv/linux/wordsize-64 
-I../sysdeps/unix/sysv/linux/powerpc  -I../sysdeps/powerpc/nptl 
-I../sysdeps/unix/sysv/linux/include -I../sysdeps/unix/sysv/linux 
-I../sysdeps/nptl  -I../sysdeps/pthread  -I../sysdeps/gnu 
-I../sysdeps/unix/inet  -I../sysdeps/unix/sysv 
-I../sysdeps/unix/powerpc  -I../sysdeps/unix  -I../sysdeps/posix 
-I../sysdeps/powerpc/powerpc64/le/power8/fpu/multiarch 
-I../sysdeps/powerpc/powerpc64/le/power7/fpu/multiarch 
-I../sysdeps/powerpc/powerpc64/le/fpu/multiarch 
-I../sysdeps/powerpc/powerpc64/le/power8/fpu 
-I../sysdeps/powerpc/powerpc64/le/power7/fpu 
-I../sysdeps/powerpc/powerpc64/le/fpu 
-I../sysdeps/powerpc/powerpc64/fpu 
-I../sysdeps/powerpc/powerpc64/le/power8/multiarch 
-I../sysdeps/powerpc/powerpc64/le/power7/multiarch 
-I../sysdeps/powerpc/powerpc64/le/multiarch 
-I../sysdeps/powerpc/powerpc64/multiarch 
-I../sysdeps/powerpc/powerpc64/le/power8 
-I../sysdeps/powerpc/powerpc64/power8 
-I../sysdeps/powerpc/powerpc64/le/power7 
-I../sysdeps/powerpc/powerpc64/power7 
-I../sysdeps/powerpc/powerpc64/power6 
-I../sysdeps/powerpc/powerpc64/power4  -I../sysdeps/powerpc/power4 
-I../sysdeps/powerpc/powerpc64/le  -I../sysdeps/powerpc/powerpc64 
-I../sysdeps/wordsize-64  -I../sysdeps/powerpc/fpu  -I../sysdeps/powerpc 
 -I../sysdeps/ieee754/ldbl-128ibm-compat 
-I../sysdeps/ieee754/ldbl-128ibm/include 
-I../sysdeps/ieee754/ldbl-128ibm  -I../sysdeps/ieee754/ldbl-opt 
-I../sysdeps/ieee754/dbl-64  -I../sysdeps/ieee754/flt-32 
-I../sysdeps/ieee754/float128  -I../sysdeps/ieee754 
-I../sysdeps/generic  -I.. -I../libio -I. -nostdinc -isystem 
/usr/lib/gcc/powerpc64le-linux-gnu/10/include -isystem 
/tmp/autopkgtest-lxc.448kjxt6/downtmp/build.UW5/src/debian/include 
-D_LIBC_REENTRANT -include 
/tmp/autopkgtest-lxc.448kjxt6/downtmp/build.UW5/src/build-tree/ppc64el-libc/

Bug#1003574: marked as done (segfault in libc-2.33.so during i386 boot ofde QEMU VM)

2022-01-18 Thread Debian Bug Tracking System
Your message dated Tue, 18 Jan 2022 20:35:00 +
with message-id 
and subject line Bug#1003610: fixed in glibc 2.33-3
has caused the Debian Bug report #1003610,
regarding segfault in libc-2.33.so during i386 boot ofde QEMU VM
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
1003610: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003610
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: libc6
Version: 2.33-2
Severity: normal

When booting an i386 VM built for autopkgtests, I see the following
segfault during boot:

> [1.374128] Freeing unused kernel image (initmem) memory: 940K
> [1.384002] Write protecting kernel text and read-only data: 11292k
> [1.384526] Run /init as init process
> Loading, please wait...
> Starting version 250.2-1
> [1.406157] udevadm[106]: segfault at bc ip b7d9f638 sp bf989cb8 error 
> 6 in libc-2.33.so[b7c6e000
> [1.407017] Code: 1c 8b 01 ca ff e3 29 d9 8d b4 26 00 00 00 00 8d 76 00 0f 
> 18 8a c0 03 00 00 0f 18 8a
> Segmentation fault

Boot continues briefly after that, but then drops to an emergency shell.

I've tried the other popular architectures, but I only saw this on i386.


To reproduce, this requires qemu-system-x86 and autopkgtest >= 5.17.

# Build image
$ sudo autopkgtest-build-qemu \
--mirror http://deb.debian.org/debian
--arch i386 \
unstable i386.img

# Boot image. -enable-kvm assumes that this is being tested on amd64
# Optionally use -nographic for terminal output instead of GUI
$ qemu-system-i386 \
-machine q35 \
-enable-kvm \
-device virtio-serial \
-nic user,model=virtio \
-m 1024 -smp 1 \
i386.img

Filing as severity "normal" as it can't be ruled out that this is a QEMU
issue, though I would be surprised. Unfortunately, I no longer have i386
hardware on which I could test this.
--- End Message ---
--- Begin Message ---
Source: glibc
Source-Version: 2.33-3
Done: Aurelien Jarno 

We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1003...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aurelien Jarno  (supplier of updated glibc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Format: 1.8
Date: Tue, 18 Jan 2022 19:06:44 +0100
Source: glibc
Architecture: source
Version: 2.33-3
Distribution: unstable
Urgency: medium
Maintainer: GNU Libc Maintainers 
Changed-By: Aurelien Jarno 
Closes: 1003574 1003610 1003847
Changes:
 glibc (2.33-3) unstable; urgency=medium
 .
   [ Samuel Thibault ]
   * debian/patches/hurd-i386/git-ttydefaults.diff: New patch to fix default
 character for termio cc[VSTATE].
   * debian/patches/hurd-i386/git-const.diff: Constify RPCs server-side.
 - debian/control: Bump mig build-dep accordingly.
 .
   [ Aurelien Jarno ]
   * debian/patches/git-updates.diff: update from upstream stable branch:
 - Fix FTBFS on ppc64el with recent binutils snapshots.  Closes: #1003847.
 - Fix crashes in bzero/memset on i386 with SSE2 when the cache size cannot
   be determined.  Closes: #1003574, #1003610.
 - Fix a buffer overflow in sunrpc svcunix_create (CVE-2022-23218).
 - Fix a buffer overflow in sunrpc clnt_create (CVE-2022-23219).
 .
   [ Gunnar Hjalmarsson ]
   * debian/local/usr_sbin/update-locale: tweak validation of args to
 update-locale().
Checksums-Sha1:
 6e9f094f445a8f6a883080d566a4bb39cd080e66 9631 glibc_2.33-3.dsc
 c6cb74fc11a6b7b84b15134b1073d5db25fc9133 815404 glibc_2.33-3.debian.tar.xz
 6ed674db63e1bb32ceade0950b1dcd25f28256cd 8897 glibc_2.33-3_source.buildinfo
Checksums-Sha256:
 5f2f07b974f79975369ea77a7dd5dddb5d85b6fec5e390da5c295529932c16c5 9631 
glibc_2.33-3.dsc
 4b184b55337cec4786c15c162314d05421a5b734089ad5dd54a34d49e37a81ff 815404 
glibc_2.33-3.debian.tar.xz
 a32cc1bdfe0529c3d4a20a0ac54c96a7ff2bd5f2a344c8f3da8d17403883d389 8897 
glibc_2.33-3_source.buildinfo
Files:
 71926b8274d2646ee90b80e388be7100 9631 libs required glibc_2.33-3.dsc
 8d4c5c4050441e874ef7f41387151755 815404 libs required 
glibc_2.33-3.debian.tar.xz
 f608aefd47f4024c7e386c8

Bug#1003610: marked as done (libc6 crashes with VIA C7 and VIA Eden processors starting with 2.33)

2022-01-18 Thread Debian Bug Tracking System
Your message dated Tue, 18 Jan 2022 20:35:00 +
with message-id 
and subject line Bug#1003610: fixed in glibc 2.33-3
has caused the Debian Bug report #1003610,
regarding libc6 crashes with VIA C7 and VIA Eden processors starting with 2.33
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
1003610: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003610
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---

Package: libc6
Version: 2.33-2
Severity: important

After upgrading from libc6 2.32 to 2.33 all machines with a VIA C7 or 
VIA Eden show segfaults in libc (i.e. hostname fails to work, or 
rebooting fails). Machines with VIA Nehemiah work fine.


I tested again starting with an older version of sid, upgrading all 
packages but libc6 (pinned to 2.32) (some other packaages could not been 
updated because they already depend on 2.33). This works fine.



Regards,
--
Wolfgang Walter
Studentenwerk München
Anstalt des öffentlichen Rechts
--- End Message ---
--- Begin Message ---
Source: glibc
Source-Version: 2.33-3
Done: Aurelien Jarno 

We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1003...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aurelien Jarno  (supplier of updated glibc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Format: 1.8
Date: Tue, 18 Jan 2022 19:06:44 +0100
Source: glibc
Architecture: source
Version: 2.33-3
Distribution: unstable
Urgency: medium
Maintainer: GNU Libc Maintainers 
Changed-By: Aurelien Jarno 
Closes: 1003574 1003610 1003847
Changes:
 glibc (2.33-3) unstable; urgency=medium
 .
   [ Samuel Thibault ]
   * debian/patches/hurd-i386/git-ttydefaults.diff: New patch to fix default
 character for termio cc[VSTATE].
   * debian/patches/hurd-i386/git-const.diff: Constify RPCs server-side.
 - debian/control: Bump mig build-dep accordingly.
 .
   [ Aurelien Jarno ]
   * debian/patches/git-updates.diff: update from upstream stable branch:
 - Fix FTBFS on ppc64el with recent binutils snapshots.  Closes: #1003847.
 - Fix crashes in bzero/memset on i386 with SSE2 when the cache size cannot
   be determined.  Closes: #1003574, #1003610.
 - Fix a buffer overflow in sunrpc svcunix_create (CVE-2022-23218).
 - Fix a buffer overflow in sunrpc clnt_create (CVE-2022-23219).
 .
   [ Gunnar Hjalmarsson ]
   * debian/local/usr_sbin/update-locale: tweak validation of args to
 update-locale().
Checksums-Sha1:
 6e9f094f445a8f6a883080d566a4bb39cd080e66 9631 glibc_2.33-3.dsc
 c6cb74fc11a6b7b84b15134b1073d5db25fc9133 815404 glibc_2.33-3.debian.tar.xz
 6ed674db63e1bb32ceade0950b1dcd25f28256cd 8897 glibc_2.33-3_source.buildinfo
Checksums-Sha256:
 5f2f07b974f79975369ea77a7dd5dddb5d85b6fec5e390da5c295529932c16c5 9631 
glibc_2.33-3.dsc
 4b184b55337cec4786c15c162314d05421a5b734089ad5dd54a34d49e37a81ff 815404 
glibc_2.33-3.debian.tar.xz
 a32cc1bdfe0529c3d4a20a0ac54c96a7ff2bd5f2a344c8f3da8d17403883d389 8897 
glibc_2.33-3_source.buildinfo
Files:
 71926b8274d2646ee90b80e388be7100 9631 libs required glibc_2.33-3.dsc
 8d4c5c4050441e874ef7f41387151755 815404 libs required 
glibc_2.33-3.debian.tar.xz
 f608aefd47f4024c7e386c85ac32c7e0 8897 libs required 
glibc_2.33-3_source.buildinfo

-BEGIN PGP SIGNATURE-

iQIzBAEBCgAdFiEEUryGlb40+QrX1Ay4E4jA+JnoM2sFAmHnIusACgkQE4jA+Jno
M2vkug/+KbopxKz/29IpY3H5aJ79IHH9wmhwSHalgSpqv+JC90Rhaea2zEFOMa4E
uFh4SQC6qhZ8cxTSSb8AFX0ZPiPTIOrCT+J2+1gWbZ+mkClzaqfIaHeCusp/HvdI
zWBT7aPLKaSxXRT5/HdUw56H2xbfFWngmnq3yTvCueZH6x0gjaP/ug94dG7ElFLC
DtvZowQLvmnBHC7Dsx/5UfV10XWUrgYeVjqnmmvxqfyKzKIF96X2GoFeEu+PwVXi
Rnbnwha0zbES0VpGrIaJuBR8DoJoPE7UrSS9z9SPf67rNbfurDQITAuR4CvojXx8
DbUHTLO6kWaAO2oQ3p0v/VJVrmpk3S4x2nNsB+fkF73KMSWvx6op4kB/ObvbqaQA
pPnqO6YXXAQnB0gG1AE+PJfFPaj+2AYIzM6SAGqXbO2ikxS7n7ufyW35Teo4CN5h
0oLWq2jshNbqytk/4fraL6whMvZORtkG8qFgfxvyWMK4SsEBMi+v9omiJESufTNS
RkIB0v3xa3AEmxFx0b9OsKL/s3mF3ioZ4hQAf18C4nnZvW9gYhJbNglfK07HGC3p
uqjqgHv87pkCCqiPu0U9lwfB/ViAk6svgf0XHjAemAsy3Z4RyaGL0BEh9/s6hRG4
G63dBt0CwW3gxt8QSCUTxlWNZX4qUmOZqQNXCWhDGLa0+QpCwdA=
=C9SG
-END PGP SIGNATURE End Message ---


Bug#1003610: marked as done (libc6 crashes with VIA C7 and VIA Eden processors starting with 2.33)

2022-01-18 Thread Debian Bug Tracking System
Your message dated Tue, 18 Jan 2022 20:35:00 +
with message-id 
and subject line Bug#1003574: fixed in glibc 2.33-3
has caused the Debian Bug report #1003574,
regarding libc6 crashes with VIA C7 and VIA Eden processors starting with 2.33
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
1003574: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003574
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---

Package: libc6
Version: 2.33-2
Severity: important

After upgrading from libc6 2.32 to 2.33 all machines with a VIA C7 or 
VIA Eden show segfaults in libc (i.e. hostname fails to work, or 
rebooting fails). Machines with VIA Nehemiah work fine.


I tested again starting with an older version of sid, upgrading all 
packages but libc6 (pinned to 2.32) (some other packaages could not been 
updated because they already depend on 2.33). This works fine.



Regards,
--
Wolfgang Walter
Studentenwerk München
Anstalt des öffentlichen Rechts
--- End Message ---
--- Begin Message ---
Source: glibc
Source-Version: 2.33-3
Done: Aurelien Jarno 

We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1003...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aurelien Jarno  (supplier of updated glibc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Format: 1.8
Date: Tue, 18 Jan 2022 19:06:44 +0100
Source: glibc
Architecture: source
Version: 2.33-3
Distribution: unstable
Urgency: medium
Maintainer: GNU Libc Maintainers 
Changed-By: Aurelien Jarno 
Closes: 1003574 1003610 1003847
Changes:
 glibc (2.33-3) unstable; urgency=medium
 .
   [ Samuel Thibault ]
   * debian/patches/hurd-i386/git-ttydefaults.diff: New patch to fix default
 character for termio cc[VSTATE].
   * debian/patches/hurd-i386/git-const.diff: Constify RPCs server-side.
 - debian/control: Bump mig build-dep accordingly.
 .
   [ Aurelien Jarno ]
   * debian/patches/git-updates.diff: update from upstream stable branch:
 - Fix FTBFS on ppc64el with recent binutils snapshots.  Closes: #1003847.
 - Fix crashes in bzero/memset on i386 with SSE2 when the cache size cannot
   be determined.  Closes: #1003574, #1003610.
 - Fix a buffer overflow in sunrpc svcunix_create (CVE-2022-23218).
 - Fix a buffer overflow in sunrpc clnt_create (CVE-2022-23219).
 .
   [ Gunnar Hjalmarsson ]
   * debian/local/usr_sbin/update-locale: tweak validation of args to
 update-locale().
Checksums-Sha1:
 6e9f094f445a8f6a883080d566a4bb39cd080e66 9631 glibc_2.33-3.dsc
 c6cb74fc11a6b7b84b15134b1073d5db25fc9133 815404 glibc_2.33-3.debian.tar.xz
 6ed674db63e1bb32ceade0950b1dcd25f28256cd 8897 glibc_2.33-3_source.buildinfo
Checksums-Sha256:
 5f2f07b974f79975369ea77a7dd5dddb5d85b6fec5e390da5c295529932c16c5 9631 
glibc_2.33-3.dsc
 4b184b55337cec4786c15c162314d05421a5b734089ad5dd54a34d49e37a81ff 815404 
glibc_2.33-3.debian.tar.xz
 a32cc1bdfe0529c3d4a20a0ac54c96a7ff2bd5f2a344c8f3da8d17403883d389 8897 
glibc_2.33-3_source.buildinfo
Files:
 71926b8274d2646ee90b80e388be7100 9631 libs required glibc_2.33-3.dsc
 8d4c5c4050441e874ef7f41387151755 815404 libs required 
glibc_2.33-3.debian.tar.xz
 f608aefd47f4024c7e386c85ac32c7e0 8897 libs required 
glibc_2.33-3_source.buildinfo

-BEGIN PGP SIGNATURE-

iQIzBAEBCgAdFiEEUryGlb40+QrX1Ay4E4jA+JnoM2sFAmHnIusACgkQE4jA+Jno
M2vkug/+KbopxKz/29IpY3H5aJ79IHH9wmhwSHalgSpqv+JC90Rhaea2zEFOMa4E
uFh4SQC6qhZ8cxTSSb8AFX0ZPiPTIOrCT+J2+1gWbZ+mkClzaqfIaHeCusp/HvdI
zWBT7aPLKaSxXRT5/HdUw56H2xbfFWngmnq3yTvCueZH6x0gjaP/ug94dG7ElFLC
DtvZowQLvmnBHC7Dsx/5UfV10XWUrgYeVjqnmmvxqfyKzKIF96X2GoFeEu+PwVXi
Rnbnwha0zbES0VpGrIaJuBR8DoJoPE7UrSS9z9SPf67rNbfurDQITAuR4CvojXx8
DbUHTLO6kWaAO2oQ3p0v/VJVrmpk3S4x2nNsB+fkF73KMSWvx6op4kB/ObvbqaQA
pPnqO6YXXAQnB0gG1AE+PJfFPaj+2AYIzM6SAGqXbO2ikxS7n7ufyW35Teo4CN5h
0oLWq2jshNbqytk/4fraL6whMvZORtkG8qFgfxvyWMK4SsEBMi+v9omiJESufTNS
RkIB0v3xa3AEmxFx0b9OsKL/s3mF3ioZ4hQAf18C4nnZvW9gYhJbNglfK07HGC3p
uqjqgHv87pkCCqiPu0U9lwfB/ViAk6svgf0XHjAemAsy3Z4RyaGL0BEh9/s6hRG4
G63dBt0CwW3gxt8QSCUTxlWNZX4qUmOZqQNXCWhDGLa0+QpCwdA=
=C9SG
-END PGP SIGNATURE End Message ---


Bug#1003574: marked as done (segfault in libc-2.33.so during i386 boot ofde QEMU VM)

2022-01-18 Thread Debian Bug Tracking System
Your message dated Tue, 18 Jan 2022 20:35:00 +
with message-id 
and subject line Bug#1003574: fixed in glibc 2.33-3
has caused the Debian Bug report #1003574,
regarding segfault in libc-2.33.so during i386 boot ofde QEMU VM
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
1003574: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003574
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: libc6
Version: 2.33-2
Severity: normal

When booting an i386 VM built for autopkgtests, I see the following
segfault during boot:

> [1.374128] Freeing unused kernel image (initmem) memory: 940K
> [1.384002] Write protecting kernel text and read-only data: 11292k
> [1.384526] Run /init as init process
> Loading, please wait...
> Starting version 250.2-1
> [1.406157] udevadm[106]: segfault at bc ip b7d9f638 sp bf989cb8 error 
> 6 in libc-2.33.so[b7c6e000
> [1.407017] Code: 1c 8b 01 ca ff e3 29 d9 8d b4 26 00 00 00 00 8d 76 00 0f 
> 18 8a c0 03 00 00 0f 18 8a
> Segmentation fault

Boot continues briefly after that, but then drops to an emergency shell.

I've tried the other popular architectures, but I only saw this on i386.


To reproduce, this requires qemu-system-x86 and autopkgtest >= 5.17.

# Build image
$ sudo autopkgtest-build-qemu \
--mirror http://deb.debian.org/debian
--arch i386 \
unstable i386.img

# Boot image. -enable-kvm assumes that this is being tested on amd64
# Optionally use -nographic for terminal output instead of GUI
$ qemu-system-i386 \
-machine q35 \
-enable-kvm \
-device virtio-serial \
-nic user,model=virtio \
-m 1024 -smp 1 \
i386.img

Filing as severity "normal" as it can't be ruled out that this is a QEMU
issue, though I would be surprised. Unfortunately, I no longer have i386
hardware on which I could test this.
--- End Message ---
--- Begin Message ---
Source: glibc
Source-Version: 2.33-3
Done: Aurelien Jarno 

We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1003...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aurelien Jarno  (supplier of updated glibc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Format: 1.8
Date: Tue, 18 Jan 2022 19:06:44 +0100
Source: glibc
Architecture: source
Version: 2.33-3
Distribution: unstable
Urgency: medium
Maintainer: GNU Libc Maintainers 
Changed-By: Aurelien Jarno 
Closes: 1003574 1003610 1003847
Changes:
 glibc (2.33-3) unstable; urgency=medium
 .
   [ Samuel Thibault ]
   * debian/patches/hurd-i386/git-ttydefaults.diff: New patch to fix default
 character for termio cc[VSTATE].
   * debian/patches/hurd-i386/git-const.diff: Constify RPCs server-side.
 - debian/control: Bump mig build-dep accordingly.
 .
   [ Aurelien Jarno ]
   * debian/patches/git-updates.diff: update from upstream stable branch:
 - Fix FTBFS on ppc64el with recent binutils snapshots.  Closes: #1003847.
 - Fix crashes in bzero/memset on i386 with SSE2 when the cache size cannot
   be determined.  Closes: #1003574, #1003610.
 - Fix a buffer overflow in sunrpc svcunix_create (CVE-2022-23218).
 - Fix a buffer overflow in sunrpc clnt_create (CVE-2022-23219).
 .
   [ Gunnar Hjalmarsson ]
   * debian/local/usr_sbin/update-locale: tweak validation of args to
 update-locale().
Checksums-Sha1:
 6e9f094f445a8f6a883080d566a4bb39cd080e66 9631 glibc_2.33-3.dsc
 c6cb74fc11a6b7b84b15134b1073d5db25fc9133 815404 glibc_2.33-3.debian.tar.xz
 6ed674db63e1bb32ceade0950b1dcd25f28256cd 8897 glibc_2.33-3_source.buildinfo
Checksums-Sha256:
 5f2f07b974f79975369ea77a7dd5dddb5d85b6fec5e390da5c295529932c16c5 9631 
glibc_2.33-3.dsc
 4b184b55337cec4786c15c162314d05421a5b734089ad5dd54a34d49e37a81ff 815404 
glibc_2.33-3.debian.tar.xz
 a32cc1bdfe0529c3d4a20a0ac54c96a7ff2bd5f2a344c8f3da8d17403883d389 8897 
glibc_2.33-3_source.buildinfo
Files:
 71926b8274d2646ee90b80e388be7100 9631 libs required glibc_2.33-3.dsc
 8d4c5c4050441e874ef7f41387151755 815404 libs required 
glibc_2.33-3.debian.tar.xz
 f608aefd47f4024c7e386c8

Processed: Bug#1003610 marked as pending in glibc

2022-01-18 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 pending
Bug #1003610 [libc6] libc6 crashes with VIA C7 and VIA Eden processors starting 
with 2.33
Bug #1003574 [libc6] segfault in libc-2.33.so during i386 boot ofde QEMU VM
Ignoring request to alter tags of bug #1003610 to the same tags previously set
Ignoring request to alter tags of bug #1003574 to the same tags previously set

-- 
1003574: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003574
1003610: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003610
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: Bug#1003574 marked as pending in glibc

2022-01-18 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 pending
Bug #1003574 [libc6] segfault in libc-2.33.so during i386 boot ofde QEMU VM
Bug #1003610 [libc6] libc6 crashes with VIA C7 and VIA Eden processors starting 
with 2.33
Ignoring request to alter tags of bug #1003574 to the same tags previously set
Ignoring request to alter tags of bug #1003610 to the same tags previously set

-- 
1003574: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003574
1003610: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003610
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



[Git][glibc-team/glibc][glibc-2.34] 11 commits: hurd: fix default character for termio cc[VSTATE]

2022-01-18 Thread Aurelien Jarno (@aurel32)


Aurelien Jarno pushed to branch glibc-2.34 at GNU Libc Maintainers / glibc


Commits:
9bb7cc7e by Samuel Thibault at 2022-01-07T00:25:56+01:00
hurd: fix default character for termio cc[VSTATE]

  * debian/patches/hurd-i386/git-ttydefaults.diff

- - - - -
a4769a89 by Aurelien Jarno at 2022-01-10T23:47:11+01:00
debian/patches/git-updates.diff: update from upstream stable branch:

* debian/patches/git-updates.diff: update from upstream stable branch:
  - Fix FTBFS on ppc64el with recent binutils snapshots.

- - - - -
fbf0e469 by Gunnar Hjalmarsson at 2022-01-12T17:30:25+00:00
Tweak validation of args to update-locale()

Fixes https://launchpad.net/bugs/1892825

- - - - -
91219d60 by Aurelien Jarno at 2022-01-12T19:38:26+00:00
Merge branch 'arg-validate' into 'sid'

Tweak validation of args to update-locale()

See merge request glibc-team/glibc!1
- - - - -
016afaf0 by Aurelien Jarno at 2022-01-12T20:39:42+01:00
Add changelog entry

- - - - -
abe7d7b7 by Samuel Thibault at 2022-01-16T18:36:49+00:00
debian/patches/hurd-i386/git-const.diff: Constify RPCs server-side

- debian/control: Bump mig build-dep accordingly.

- - - - -
23f1570b by Aurelien Jarno at 2022-01-16T22:20:06+01:00
Add bug number

- - - - -
41086a4c by Aurelien Jarno at 2022-01-18T19:06:13+01:00
debian/patches/git-updates.diff: update from upstream stable branch:

  - Fix crashes in bzero/memset on i386 with SSE2 when the cache size cannot
be determined.  Closes: #1003574, #1003610.
  - Fix a buffer overflow in sunrpc svcunix_create (CVE-2022-23218).
  - Fix a buffer overflow in sunrpc clnt_create (CVE-2022-23219).

- - - - -
8742b831 by Aurelien Jarno at 2022-01-18T21:14:16+01:00
releasing package glibc version 2.33-3

- - - - -
6d7a9e5a by Aurelien Jarno at 2022-01-18T21:20:30+01:00
Merge branch 'sid' into glibc-2.34

- - - - -
a4d2aacc by Aurelien Jarno at 2022-01-18T21:26:08+01:00
debian/patches/git-updates.diff: update from upstream stable branch

- - - - -


8 changed files:

- debian/changelog
- debian/control
- debian/control.in/main
- debian/local/usr_sbin/update-locale
- debian/patches/git-updates.diff
- + debian/patches/hurd-i386/git-const.diff
- + debian/patches/hurd-i386/git-ttydefaults.diff
- debian/patches/series


View it on GitLab: 
https://salsa.debian.org/glibc-team/glibc/-/compare/5c18ede4346e11b185e52595c05c66d9989d849e...a4d2aacc938a9b7b942fec1b3a3f10828f598145

-- 
View it on GitLab: 
https://salsa.debian.org/glibc-team/glibc/-/compare/5c18ede4346e11b185e52595c05c66d9989d849e...a4d2aacc938a9b7b942fec1b3a3f10828f598145
You're receiving this email because of your account on salsa.debian.org.




[Git][glibc-team/glibc][sid] releasing package glibc version 2.33-3

2022-01-18 Thread Aurelien Jarno (@aurel32)


Aurelien Jarno pushed to branch sid at GNU Libc Maintainers / glibc


Commits:
8742b831 by Aurelien Jarno at 2022-01-18T21:14:16+01:00
releasing package glibc version 2.33-3

- - - - -


1 changed file:

- debian/changelog


View it on GitLab: 
https://salsa.debian.org/glibc-team/glibc/-/commit/8742b831b66995c8ba01aaf73e8c79617adcd9e7

-- 
View it on GitLab: 
https://salsa.debian.org/glibc-team/glibc/-/commit/8742b831b66995c8ba01aaf73e8c79617adcd9e7
You're receiving this email because of your account on salsa.debian.org.




[Git][glibc-team/glibc] Pushed new tag debian/2.33-3

2022-01-18 Thread Aurelien Jarno (@aurel32)


Aurelien Jarno pushed new tag debian/2.33-3 at GNU Libc Maintainers / glibc

-- 
View it on GitLab: 
https://salsa.debian.org/glibc-team/glibc/-/tree/debian/2.33-3
You're receiving this email because of your account on salsa.debian.org.




Processed: Bug#1003610 marked as pending in glibc

2022-01-18 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 pending
Bug #1003610 [libc6] libc6 crashes with VIA C7 and VIA Eden processors starting 
with 2.33
Bug #1003574 [libc6] segfault in libc-2.33.so during i386 boot ofde QEMU VM
Ignoring request to alter tags of bug #1003610 to the same tags previously set
Ignoring request to alter tags of bug #1003574 to the same tags previously set

-- 
1003574: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003574
1003610: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003610
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: Bug#1003574 marked as pending in glibc

2022-01-18 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 pending
Bug #1003574 [libc6] segfault in libc-2.33.so during i386 boot ofde QEMU VM
Bug #1003610 [libc6] libc6 crashes with VIA C7 and VIA Eden processors starting 
with 2.33
Added tag(s) pending.
Added tag(s) pending.

-- 
1003574: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003574
1003610: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003610
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



[Git][glibc-team/glibc][sid] debian/patches/git-updates.diff: update from upstream stable branch:

2022-01-18 Thread Aurelien Jarno (@aurel32)


Aurelien Jarno pushed to branch sid at GNU Libc Maintainers / glibc


Commits:
41086a4c by Aurelien Jarno at 2022-01-18T19:06:13+01:00
debian/patches/git-updates.diff: update from upstream stable branch:

  - Fix crashes in bzero/memset on i386 with SSE2 when the cache size cannot
be determined.  Closes: #1003574, #1003610.
  - Fix a buffer overflow in sunrpc svcunix_create (CVE-2022-23218).
  - Fix a buffer overflow in sunrpc clnt_create (CVE-2022-23219).

- - - - -


2 changed files:

- debian/changelog
- debian/patches/git-updates.diff


View it on GitLab: 
https://salsa.debian.org/glibc-team/glibc/-/commit/41086a4c85e828a019b1ab3adbf20f0d6d791df6

-- 
View it on GitLab: 
https://salsa.debian.org/glibc-team/glibc/-/commit/41086a4c85e828a019b1ab3adbf20f0d6d791df6
You're receiving this email because of your account on salsa.debian.org.