Processed: Re: Bug#964338: buster-pu: package mariadb-10.3 10.3.23-0+deb10u1

2020-07-09 Thread Debian Bug Tracking System
Processing control commands:

> tags -1 + confirmed
Bug #964338 [release.debian.org] buster-pu: package mariadb-10.3 
10.3.23-0+deb10u1
Added tag(s) confirmed.

-- 
964338: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=964338
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#964338: buster-pu: package mariadb-10.3 10.3.23-0+deb10u1

2020-07-09 Thread Adam D. Barratt
Control: tags -1 + confirmed

On Tue, 2020-07-07 at 21:34 +0300, Otto Kekäläinen wrote:
> Sorry, the changelog is wrong, it was actually not removed, just
> changed location:
> 
> --- a/debian/libmariadb-dev.install
> +++ b/debian/libmariadb-dev.install
> @@ -8,4 +8,4 @@ usr/lib/*/libmysqlservices.a
>  usr/share/aclocal/mysql.m4
>  usr/share/man/man1/mysql_config.1
>  usr/lib/pkgconfig/libmariadb.pc
> usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/
> -usr/share/pkgconfig/mariadb.pc
> usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/
> +usr/lib/*/pkgconfig/mariadb.pc
> 
> So upstream adopted our view of what the location should be, so the
> move was removed. End result is that location is exactly the same.
> 
> 
> This is the correct changelog:
> 
> mariadb-10.3 (1:10.3.23-0+deb10u1) buster; urgency=high
> 
>   * SECURITY UPDATE: New upstream version 10.3.23. Includes fixes for
> the
> following security vulnerabilities (Closes: #961849):
> - CVE-2020-2752
> - CVE-2020-2760
> - CVE-2020-2812
> - CVE-2020-2814
> - CVE-2020-13249
>   * Backport upstream patch to fix regression in RocksDB ZSTD
> detection
> which prevents a serious bug and also autopkgtest detectable
> regression.
>   * Update libmariadb symbols for upstream release 3.1.8. Upstream
> added one new symbol and it needs to be tracked in the symbols
> file.
> 

OK, please go ahead.

Regards,

Adam



Bug#964338: buster-pu: package mariadb-10.3 10.3.23-0+deb10u1

2020-07-07 Thread Otto Kekäläinen
Sorry, the changelog is wrong, it was actually not removed, just
changed location:

--- a/debian/libmariadb-dev.install
+++ b/debian/libmariadb-dev.install
@@ -8,4 +8,4 @@ usr/lib/*/libmysqlservices.a
 usr/share/aclocal/mysql.m4
 usr/share/man/man1/mysql_config.1
 usr/lib/pkgconfig/libmariadb.pc usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/
-usr/share/pkgconfig/mariadb.pc usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/
+usr/lib/*/pkgconfig/mariadb.pc

So upstream adopted our view of what the location should be, so the
move was removed. End result is that location is exactly the same.


This is the correct changelog:

mariadb-10.3 (1:10.3.23-0+deb10u1) buster; urgency=high

  * SECURITY UPDATE: New upstream version 10.3.23. Includes fixes for the
following security vulnerabilities (Closes: #961849):
- CVE-2020-2752
- CVE-2020-2760
- CVE-2020-2812
- CVE-2020-2814
- CVE-2020-13249
  * Backport upstream patch to fix regression in RocksDB ZSTD detection
which prevents a serious bug and also autopkgtest detectable
regression.
  * Update libmariadb symbols for upstream release 3.1.8. Upstream
added one new symbol and it needs to be tracked in the symbols file.

 -- Otto Kekäläinen   Sat, 04 Jul 2020 15:31:51 +0300


Since the amendment is so small I will not attach a new debdiff.
Latest source always visible at
https://salsa.debian.org/mariadb-team/mariadb-10.3/-/tree/buster



Bug#964338: buster-pu: package mariadb-10.3 10.3.23-0+deb10u1

2020-07-07 Thread Adam D. Barratt
On Sun, 2020-07-05 at 22:41 +0300, Otto Kekäläinen wrote:
> mariadb-10.3 (1:10.3.23-0+deb10u1) buster; urgency=high
> 
>   * SECURITY UPDATE: New upstream version 10.3.23. Includes fixes for
> the
> following security vulnerabilities (Closes: #961849):
> - CVE-2020-2752
> - CVE-2020-2760
> - CVE-2020-2812
> - CVE-2020-2814
> - CVE-2020-13249
>   * Remove mariadb.pc from package as upstream no longer provides it.
> Update the mysqlclient.pc link to point to the libmariadb.pc file
> instead to keep backwards compatibility.

I assume nothing actually links against / using mariadb.pc?

Regards,

Adam