Bug#834854: jessie-pu: package charybdis/3.4.2-5~deb8u1

2018-06-13 Thread Antoine Beaupré
On 2018-06-13 16:00:41, Adam D. Barratt wrote: > On Tue, 2016-09-13 at 12:04 +0200, Julien Cristau wrote: >> On Sun, Sep 11, 2016 at 16:58:34 -0400, Antoine Beaupré wrote: >> >> > 1. ignore the above two extra issues and simply add the patch for >> > #215 >> > to the pile of patches in jessie >> >

Bug#834854: jessie-pu: package charybdis/3.4.2-5~deb8u1

2018-06-13 Thread Adam D. Barratt
On Tue, 2016-09-13 at 12:04 +0200, Julien Cristau wrote: > On Sun, Sep 11, 2016 at 16:58:34 -0400, Antoine Beaupré wrote: > > > 1. ignore the above two extra issues and simply add the patch for > > #215 > > to the pile of patches in jessie > > 2. import the new gnutls.c module from an eventual new

Bug#834854: jessie-pu: package charybdis/3.4.2-5~deb8u1

2016-09-13 Thread Julien Cristau
On Sun, Sep 11, 2016 at 16:58:34 -0400, Antoine Beaupré wrote: > 1. ignore the above two extra issues and simply add the patch for #215 > to the pile of patches in jessie > 2. import the new gnutls.c module from an eventual new 3.5 release > upstream directly in jessie - this may be difficult beca

Bug#834854: jessie-pu: package charybdis/3.4.2-5~deb8u1

2016-09-11 Thread Antoine Beaupré
Control: tags -1 -moreinfo Hi, New developments on the Charybdis front: a patch has been developed upstream to fix the issue, but it is pretty invasive. They have basically rewritten the whole GNUTLS backend to make it on par with the other implementations. It's a good thing: there were memory le

Bug#834854: jessie-pu: package charybdis/3.4.2-5~deb8u1

2016-09-06 Thread Antoine Beaupré
Control: tags -1 +moreinfo On 2016-09-06 09:10:43, Antoine Beaupré wrote: > On 2016-09-06 03:58:44, Adam D. Barratt wrote: >> On 2016-09-06 1:31, Antoine Beaupré wrote: >>> Turns out this took about three weeks instead of 24h. But 3.5.3 is >>> released, and I will push the update to unstable now.

Bug#834854: jessie-pu: package charybdis/3.4.2-5~deb8u1

2016-09-06 Thread Antoine Beaupré
On 2016-09-06 03:58:44, Adam D. Barratt wrote: > On 2016-09-06 1:31, Antoine Beaupré wrote: >> Turns out this took about three weeks instead of 24h. But 3.5.3 is >> released, and I will push the update to unstable now. >> >> The situation is a tad more complicated now because there was a >> secur

Bug#834854: jessie-pu: package charybdis/3.4.2-5~deb8u1

2016-09-06 Thread Adam D. Barratt
On 2016-09-06 1:31, Antoine Beaupré wrote: Turns out this took about three weeks instead of 24h. But 3.5.3 is released, and I will push the update to unstable now. The situation is a tad more complicated now because there was a security issue disclosed in the meantime: https://security-tracke

Bug#834854: jessie-pu: package charybdis/3.4.2-5~deb8u1

2016-09-05 Thread Antoine Beaupré
Control: tags -1 -moreinfo On 2016-08-19 18:05:34, Antoine Beaupré wrote: > On 2016-08-19 17:56:29, Adam D. Barratt wrote: >> On Fri, 2016-08-19 at 17:35 -0400, Antoine Beaupré wrote: >>> TL;DR: Charybdis 3.4 (Jessie) introduces a regression (CertFP broken) >>> from Charybdis 3.3 (Wheezy). 7-line

Bug#834854: jessie-pu: package charybdis/3.4.2-5~deb8u1

2016-08-19 Thread Antoine Beaupré
On 2016-08-19 17:56:29, Adam D. Barratt wrote: > Control: tags -1 + moreinfo > > On Fri, 2016-08-19 at 17:35 -0400, Antoine Beaupré wrote: >> TL;DR: Charybdis 3.4 (Jessie) introduces a regression (CertFP broken) >> from Charybdis 3.3 (Wheezy). 7-line patch (attached) fixes the issue. >> >> Charybd

Bug#834854: jessie-pu: package charybdis/3.4.2-5~deb8u1

2016-08-19 Thread Adam D. Barratt
Control: tags -1 + moreinfo On Fri, 2016-08-19 at 17:35 -0400, Antoine Beaupré wrote: > TL;DR: Charybdis 3.4 (Jessie) introduces a regression (CertFP broken) > from Charybdis 3.3 (Wheezy). 7-line patch (attached) fixes the issue. > > Charybdis 3.4 suffers from a regression which breaks authentica

Bug#834854: jessie-pu: package charybdis/3.4.2-5~deb8u1

2016-08-19 Thread Antoine Beaupré
Package: release.debian.org Severity: normal Tags: jessie User: release.debian@packages.debian.org Usertags: pu TL;DR: Charybdis 3.4 (Jessie) introduces a regression (CertFP broken) from Charybdis 3.3 (Wheezy). 7-line patch (attached) fixes the issue. Charybdis 3.4 suffers from a regression w