Public bug reported:
Binary package hint: openoffice.org
The "openoffice.org" source package has three different versions in hardy:
release, 1:2.4.0-3ubuntu6
security, 1:2.4.1-1ubuntu2.1
updates, 1:2.4.1-1ubuntu2.1
The "openoffice.org-l10n" source package has two versions in hardy:
release, 1:2.4.0-3ubuntu1
updates, 1:2.4.1-1ubuntu2
The "openoffice.org-l10n" packages doesn't seem to be compatible to
openoffice.org 2.4.1, as an example the package "openoffice.org-l10n-sv" has
the following property.
Conflicts: openoffice.org-core (>= 1:2.4.0.1), openoffice.org-core (<<
1:2.4.0), openoffice.org2-l10n-sv
This means that a hardy system that doesn't have hardy-updates enabled
but only hardy-security can't upgrade openoffice.org without removing
all language support for openoffice (the packages generated by
"openoffice.org-l10n"). Version 2.4.1 of openoffice requires 2.4.1
version of the language support. An upgrade of openoffice from the
security archive will then try to remove all of those packages.
The simple solution for this is to simply build "openoffice.org-l10n"
with the same upstream version of openoffice.org as already included in
hardy-security and also include this package in hardy-security. However,
this doesn't feel like however the ideal solution as we want to keep
security as small as possible and only change the packages that actually
needs the security fix. In my opinion no upgrade in security should be
incompatible with old packages in the system, i.e. should not change the
ABI, but that is probably not possible in all situations. Actually, is
seems rather strange to include a new upstream version of an application
in a system that doesn't have updates enabled. Is the solution to have
two separate security repositories, one for systems without updates
enabled and one for system with updates enabled?
Anyway, a simple rebuild of "openoffice.org-l10n" should be ok for now
so users can upgrade their systems. But for upcoming releases I think
the architecture for security updates should be reviewed.
** Affects: openoffice.org (Ubuntu)
Importance: Undecided
Status: New
** Affects: openoffice.org-l10n (Ubuntu)
Importance: Undecided
Status: New
** Visibility changed to: Public
** This bug is no longer flagged as a security issue
** Also affects: openoffice.org-l10n (Ubuntu)
Importance: Undecided
Status: New
--
New upstream version of openoffice.org in hardy-security
https://bugs.launchpad.net/bugs/310359
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs