Debian Bug report logs - #613535
/usr/lib/libSDL-1.2.so.0: executable stack is falsely requested for /usr/lib/libSDL-1.2.so.0

version graph

Package: libsdl1.2debian-alsa; Maintainer for libsdl1.2debian-alsa is Debian SDL packages maintainers <pkg-sdl-maintainers@lists.alioth.debian.org>;

Reported by: russell@coker.com.au

Date: Tue, 15 Feb 2011 14:15:05 UTC

Severity: important

Tags: moreinfo

Found in version libsdl1.2/1.2.14-6.1

Done: "Manuel A. Fernandez Montecelo" <manuel.montezelo@gmail.com>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian SDL packages maintainers <pkg-sdl-maintainers@lists.alioth.debian.org>:
Bug#613535; Package libsdl1.2debian-alsa. (Tue, 15 Feb 2011 14:15:08 GMT) Full text and rfc822 format available.

Acknowledgement sent to russell@coker.com.au:
New Bug report received and forwarded. Copy sent to Debian SDL packages maintainers <pkg-sdl-maintainers@lists.alioth.debian.org>. (Tue, 15 Feb 2011 14:15:08 GMT) Full text and rfc822 format available.

Message #5 received at submit@bugs.debian.org (full text, mbox):

From: Russell Coker <russell@coker.com.au>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: /usr/lib/libSDL-1.2.so.0: executable stack is falsely requested for /usr/lib/libSDL-1.2.so.0
Date: Wed, 16 Feb 2011 01:14:16 +1100
Package: libsdl1.2debian-alsa
Version: 1.2.14-6.1
Severity: important
File: /usr/lib/libSDL-1.2.so.0

# execstack -q /usr/lib/libSDL-1.2.so.0
X /usr/lib/libSDL-1.2.so.0

The shared object /usr/lib/libSDL-1.2.so.0 claims to need an executable stack.

When I rebuilt this package from source without making any changes it didn't
claim to need an executable stack.  So presumably this problem is due to some
assembler issue.

Could the next squeeze update please include a rebuilt copy of this for i386
to solve this bug?  The current situation weakens the security of every
application that links against this library for no good reason.

-- System Information:
Debian Release: 6.0
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: i386 (i686)

Kernel: Linux 2.6.32-5-xen-686 (SMP w/1 CPU core)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/dash

Versions of packages libsdl1.2debian-alsa depends on:
ii  libasound2                    1.0.23-2.1 shared library for ALSA 
applicatio
ii  libc6                         2.11.2-10  Embedded GNU C Library: Shared 
lib
ii  libdirectfb-1.2-9             1.2.10.0-4 direct frame buffer graphics - 
sha
ii  libsvga1                      1:1.4.3-29 console SVGA display libraries

libsdl1.2debian-alsa recommends no packages.

libsdl1.2debian-alsa suggests no packages.

-- no debconf information




Information forwarded to debian-bugs-dist@lists.debian.org, Debian SDL packages maintainers <pkg-sdl-maintainers@lists.alioth.debian.org>:
Bug#613535; Package libsdl1.2debian-alsa. (Thu, 16 Feb 2012 23:48:03 GMT) Full text and rfc822 format available.

Acknowledgement sent to "Manuel A. Fernandez Montecelo" <manuel.montezelo@gmail.com>:
Extra info received and forwarded to list. Copy sent to Debian SDL packages maintainers <pkg-sdl-maintainers@lists.alioth.debian.org>. (Thu, 16 Feb 2012 23:48:03 GMT) Full text and rfc822 format available.

Message #10 received at 613535@bugs.debian.org (full text, mbox):

From: "Manuel A. Fernandez Montecelo" <manuel.montezelo@gmail.com>
To: 613535@bugs.debian.org, Russell Coker <russell@coker.com.au>
Subject: Re: /usr/lib/libSDL-1.2.so.0: executable stack is falsely requested for /usr/lib/libSDL-1.2.so.0
Date: Thu, 16 Feb 2012 23:45:47 +0000
notfound 613535 1.2.15-1
tags 613535 + moreinfo
stop

Hello,

Thank you for your interest in improving Debian, and sorry to keep the
bug unattended for so long.  There's now an effort to review the open
bugs related with SDL packages.

The version in unstable doesn't seem to have these problems (in my
system, anyway):
---------------------------------------------
$ dpkg -l libsdl1.2-dev | grep ii
ii  libsdl1.2-dev                      1.2.15-1

$ execstack /usr/lib/x86_64-linux-gnu/libSDL-1.2.so.0
- /usr/lib/x86_64-linux-gnu/libSDL-1.2.so.0
---------------------------------------------

However, I understand that your request is more related to the
specific version released with the original squeeze than with fixing a
general problem with the packaging.

Do you think that it's still useful to upload a new build of the
package now? .4 was released ~1 year later than .0 and only a few days
ago, so it'll probably take a few months for .5 to get out.

Regards.




Added tag(s) moreinfo. Request was from "Manuel A. Fernandez Montecelo" <manuel.montezelo@gmail.com> to control@bugs.debian.org. (Thu, 16 Feb 2012 23:48:05 GMT) Full text and rfc822 format available.

Information forwarded to debian-bugs-dist@lists.debian.org, Debian SDL packages maintainers <pkg-sdl-maintainers@lists.alioth.debian.org>:
Bug#613535; Package libsdl1.2debian-alsa. (Fri, 24 Feb 2012 13:06:03 GMT) Full text and rfc822 format available.

Acknowledgement sent to russell@coker.com.au:
Extra info received and forwarded to list. Copy sent to Debian SDL packages maintainers <pkg-sdl-maintainers@lists.alioth.debian.org>. (Fri, 24 Feb 2012 13:06:06 GMT) Full text and rfc822 format available.

Message #17 received at 613535@bugs.debian.org (full text, mbox):

From: Russell Coker <russell@coker.com.au>
To: "Manuel A. Fernandez Montecelo" <manuel.montezelo@gmail.com>
Cc: 613535@bugs.debian.org
Subject: Re: /usr/lib/libSDL-1.2.so.0: executable stack is falsely requested for /usr/lib/libSDL-1.2.so.0
Date: Fri, 24 Feb 2012 23:44:20 +1100
On Fri, 17 Feb 2012, "Manuel A. Fernandez Montecelo" 
<manuel.montezelo@gmail.com> wrote:
> However, I understand that your request is more related to the
> specific version released with the original squeeze than with fixing a
> general problem with the packaging.
> 
> Do you think that it's still useful to upload a new build of the
> package now? .4 was released ~1 year later than .0 and only a few days
> ago, so it'll probably take a few months for .5 to get out.

Given the current status of Squeeze it seems most likely that everyone who 
wants that will have done it themself by now, "execstack -c" isn't that 
difficult and we heading towards the end of Squeeze being current.

If Unstable and Testing are OK in this regard then it's probably best to just 
close the bug report and save time for the release team.

-- 
My Main Blog         http://etbe.coker.com.au/
My Documents Blog    http://doc.coker.com.au/




Reply sent to "Manuel A. Fernandez Montecelo" <manuel.montezelo@gmail.com>:
You have taken responsibility. (Fri, 24 Feb 2012 15:27:10 GMT) Full text and rfc822 format available.

Notification sent to russell@coker.com.au:
Bug acknowledged by developer. (Fri, 24 Feb 2012 15:27:12 GMT) Full text and rfc822 format available.

Message #22 received at 613535-done@bugs.debian.org (full text, mbox):

From: "Manuel A. Fernandez Montecelo" <manuel.montezelo@gmail.com>
To: russell@coker.com.au
Cc: 613535-done@bugs.debian.org
Subject: Re: /usr/lib/libSDL-1.2.so.0: executable stack is falsely requested for /usr/lib/libSDL-1.2.so.0
Date: Fri, 24 Feb 2012 15:26:11 +0000
2012/2/24 Russell Coker <russell@coker.com.au>:
> Given the current status of Squeeze it seems most likely that everyone who
> wants that will have done it themself by now, "execstack -c" isn't that
> difficult and we heading towards the end of Squeeze being current.
>
> If Unstable and Testing are OK in this regard then it's probably best to just
> close the bug report and save time for the release team.

OK, closing the bug report then.

Regards and thanks for your report.




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sat, 24 Mar 2012 07:37:42 GMT) Full text and rfc822 format available.

Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Apr 23 15:07:01 2014; Machine Name: buxtehude.debian.org

Debian Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.