Re: Missing samba DSA-4513 changelog in https://metadata.ftp-master.debian.org/changelogs/

2021-05-02 Thread Andrew Bartlett
On Sun, 2021-05-02 at 11:53 +0900, Hideki Yamane wrote:
> Hi,
> 
> On Sat, 1 May 2021 15:19:43 +0200
> Mattia Rizzolo  wrote:
> > > > The samba package is held in stable-new by bug#939419, see
> > > > https://release.debian.org/proposed-updates/stable.html
> > > 
> > >  Thanks, Julien.
> > > 
> > >  Can we fix it with cherry-picking 
> > > https://salsa.debian.org/samba-team/samba/commit/bedd051122980c31dd1c1431ce9e40ba01dc5990
> > >  as 2:4.9.5+dfsg-5+deb10u2 then?
> > 
> > Rather, I think
> > https://debdiffs.raspbian.org/main/s/samba/samba_4.9.5+dfsg-5+deb10u1+rpi1.debdiff
> > would be more appropriate, as it is, for me, more appropriate than
> > dropping a binary.
> 
>  samba package maintainers, how about pushing above change and
>  before security fixes to proposed-updates?

PIDL should never have remained packaged after openchange was removed 
https://tracker.debian.org/pkg/openchange

This was the only consumer (globally, not just in Debian).

Andrew Bartlett

-- 
Andrew Bartlett (he/him)https://samba.org/~abartlet/
Samba Team Member (since 2001)  https://samba.org
Samba Developer, Catalyst IThttps://catalyst.net.nz/services/samba




Re: Missing samba DSA-4513 changelog in https://metadata.ftp-master.debian.org/changelogs/

2021-05-01 Thread Hideki Yamane
Hi,

On Sat, 1 May 2021 15:19:43 +0200
Mattia Rizzolo  wrote:
> > > The samba package is held in stable-new by bug#939419, see
> > > https://release.debian.org/proposed-updates/stable.html
> > 
> >  Thanks, Julien.
> > 
> >  Can we fix it with cherry-picking 
> > https://salsa.debian.org/samba-team/samba/commit/bedd051122980c31dd1c1431ce9e40ba01dc5990
> >  as 2:4.9.5+dfsg-5+deb10u2 then?
> 
> Rather, I think
> https://debdiffs.raspbian.org/main/s/samba/samba_4.9.5+dfsg-5+deb10u1+rpi1.debdiff
> would be more appropriate, as it is, for me, more appropriate than
> dropping a binary.

 samba package maintainers, how about pushing above change and
 before security fixes to proposed-updates?


-- 
Regards,

 Hideki Yamane henrich @ debian.org/iijmio-mail.jp



Re: Missing samba DSA-4513 changelog in https://metadata.ftp-master.debian.org/changelogs/

2021-05-01 Thread Mattia Rizzolo
On Sat, May 01, 2021 at 02:26:31PM +0900, Hideki Yamane wrote:
> On Wed, 7 Apr 2021 18:20:09 +0200
> Julien Cristau  wrote:
> > The samba package is held in stable-new by bug#939419, see
> > https://release.debian.org/proposed-updates/stable.html
> 
>  Thanks, Julien.
> 
>  Can we fix it with cherry-picking 
> https://salsa.debian.org/samba-team/samba/commit/bedd051122980c31dd1c1431ce9e40ba01dc5990
>  as 2:4.9.5+dfsg-5+deb10u2 then?

Rather, I think
https://debdiffs.raspbian.org/main/s/samba/samba_4.9.5+dfsg-5+deb10u1+rpi1.debdiff
would be more appropriate, as it is, for me, more appropriate than
dropping a binary.

-- 
regards,
Mattia Rizzolo

GPG Key: 66AE 2B4A FCCF 3F52 DA18  4D18 4B04 3FCD B944 4540  .''`.
More about me:  https://mapreri.org : :'  :
Launchpad user: https://launchpad.net/~mapreri  `. `'`
Debian QA page: https://qa.debian.org/developer.php?login=mattia  `-


signature.asc
Description: PGP signature


Re: Missing samba DSA-4513 changelog in https://metadata.ftp-master.debian.org/changelogs/

2021-05-01 Thread Hideki Yamane
On Wed, 7 Apr 2021 18:20:09 +0200
Julien Cristau  wrote:
> The samba package is held in stable-new by bug#939419, see
> https://release.debian.org/proposed-updates/stable.html

 Thanks, Julien.

 Can we fix it with cherry-picking 
https://salsa.debian.org/samba-team/samba/commit/bedd051122980c31dd1c1431ce9e40ba01dc5990
 as 2:4.9.5+dfsg-5+deb10u2 then?


-- 
Regards,

 Hideki Yamane henrich @ debian.org/iijmio-mail.jp



Re: Missing samba DSA-4513 changelog in https://metadata.ftp-master.debian.org/changelogs/

2021-04-07 Thread Julien Cristau
On Wed, Apr 07, 2021 at 02:49:49PM +0200, Ben Hutchings wrote:
> On Wed, 2021-04-07 at 20:07 +0900, Hideki Yamane wrote:
> > Hi,
> > 
> >  I cannot find appropriate pseudo package in reportbug, so ask this
> >  in -devel.
> > 
> >  Fumiyasu (CCed) found a issue with samba package changelog in
> > packages.d.o.
> >  https://packages.debian.org/buster/samba has "Debian Changelog" link
> >  but its 
> > https://metadata.ftp-master.debian.org/changelogs//main/s/samba/samba_4.9.5+dfsg-5+deb10u1_changelog
> >  link is 404.
> 
> The latter site is part of the main archive and does not have
> information about package versions that are only in the security
> archive.
> 
> Packages uploaded to the security archive are normally copied to the
> (old)stable-proposed-update suite of the main archive, so long as that
> is open, i.e. until the last point release.  So it looks as if the copy
> to the main archive failed for some reason.
> 
The samba package is held in stable-new by bug#939419, see
https://release.debian.org/proposed-updates/stable.html

Cheers,
Julien

> >  Something wrong with 
> > https://metadata.ftp-master.debian.org/changelogs/ ,
> >  that doesn't have the changelog were introduced with DSA 4513-1 as
> >  
> > https://tracker.debian.org/news/1061236/accepted-samba-2495dfsg-5deb10u1-source-into-stable-embargoed-stable/
> > 
> >  Also, why DSA 4513-1 is not included in Debian10.2 ?
> >  See https://www.debian.org/News/2019/20191116
> 
> Because the package didn't get copied to the main archive.
> 
> The common reason why this may fail is that a maintainer uploads a
> different orig tarball to the security archive.  However, the two
> versions agree on the checksums of the orig tarball.  I would take this
> up with the FTP team.
> 



Re: Missing samba DSA-4513 changelog in https://metadata.ftp-master.debian.org/changelogs/

2021-04-07 Thread Ben Hutchings
On Wed, 2021-04-07 at 20:07 +0900, Hideki Yamane wrote:
> Hi,
> 
>  I cannot find appropriate pseudo package in reportbug, so ask this
>  in -devel.
> 
>  Fumiyasu (CCed) found a issue with samba package changelog in
> packages.d.o.
>  https://packages.debian.org/buster/samba has "Debian Changelog" link
>  but its 
> https://metadata.ftp-master.debian.org/changelogs//main/s/samba/samba_4.9.5+dfsg-5+deb10u1_changelog
>  link is 404.

The latter site is part of the main archive and does not have
information about package versions that are only in the security
archive.

Packages uploaded to the security archive are normally copied to the
(old)stable-proposed-update suite of the main archive, so long as that
is open, i.e. until the last point release.  So it looks as if the copy
to the main archive failed for some reason.

>  Something wrong with 
> https://metadata.ftp-master.debian.org/changelogs/ ,
>  that doesn't have the changelog were introduced with DSA 4513-1 as
>  
> https://tracker.debian.org/news/1061236/accepted-samba-2495dfsg-5deb10u1-source-into-stable-embargoed-stable/
> 
>  Also, why DSA 4513-1 is not included in Debian10.2 ?
>  See https://www.debian.org/News/2019/20191116

Because the package didn't get copied to the main archive.

The common reason why this may fail is that a maintainer uploads a
different orig tarball to the security archive.  However, the two
versions agree on the checksums of the orig tarball.  I would take this
up with the FTP team.

Ben.

-- 
Ben Hutchings
It is a miracle that curiosity survives formal education.
  - Albert Einstein


signature.asc
Description: This is a digitally signed message part


Missing samba DSA-4513 changelog in https://metadata.ftp-master.debian.org/changelogs/

2021-04-07 Thread Hideki Yamane
Hi,

 I cannot find appropriate pseudo package in reportbug, so ask this
 in -devel.

 Fumiyasu (CCed) found a issue with samba package changelog in packages.d.o.
 https://packages.debian.org/buster/samba has "Debian Changelog" link
 but its 
https://metadata.ftp-master.debian.org/changelogs//main/s/samba/samba_4.9.5+dfsg-5+deb10u1_changelog
 link is 404.

 Something wrong with https://metadata.ftp-master.debian.org/changelogs/ ,
 that doesn't have the changelog were introduced with DSA 4513-1 as
 
https://tracker.debian.org/news/1061236/accepted-samba-2495dfsg-5deb10u1-source-into-stable-embargoed-stable/

 Also, why DSA 4513-1 is not included in Debian10.2 ?
 See https://www.debian.org/News/2019/20191116

 
-- 
Regards,

 Hideki Yamane henrich @ debian.org/iijmio-mail.jp