Debian Bug report logs - #686319
unblock: iceweasel/10.0.7esr-1

Package: release.debian.org; Maintainer for release.debian.org is Debian Release Team <debian-release@lists.debian.org>;

Reported by: Mike Hommey <mh+reportbug@glandium.org>

Date: Fri, 31 Aug 2012 05:30:01 UTC

Severity: normal

Done: Julien Cristau <jcristau@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian Release Team <debian-release@lists.debian.org>:
Bug#686319; Package release.debian.org. (Fri, 31 Aug 2012 05:30:04 GMT) Full text and rfc822 format available.

Acknowledgement sent to Mike Hommey <mh+reportbug@glandium.org>:
New Bug report received and forwarded. Copy sent to Debian Release Team <debian-release@lists.debian.org>. (Fri, 31 Aug 2012 05:30:04 GMT) Full text and rfc822 format available.

Message #5 received at submit@bugs.debian.org (full text, mbox):

From: Mike Hommey <mh+reportbug@glandium.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: unblock: iceweasel/10.0.7esr-1
Date: Fri, 31 Aug 2012 07:28:24 +0200
Package: release.debian.org
Severity: normal
User: release.debian.org@packages.debian.org
Usertags: unblock

Please unblock package iceweasel

10.0.7esr-1 is a security/stability upstream update.
It also fixes iceweasel-l10n-all version to have an epoch so that it has
a greater version number than the package in current stable.

I won't attach the 150KB of debdiff.

The changelog reads:
  * New upstream release.
  * Fixes for mfsa2012-{57-58,60-63,65,69-70,72}, also known as
    CVE-2012-1970, CVE-2012-1972, CVE-2012-1973, CVE-2012-1974,
    CVE-2012-1975, CVE-2012-1976, CVE-2012-3957, CVE-2012-3959,
    CVE-2012-3960, CVE-2012-3962, CVE-2012-3966, CVE-2012-3967,
    CVE-2012-3969, CVE-2012-3972, CVE-2012-3976, CVE-2012-3978,
    CVE-2012-3980.
  * debian/rules: Also use an epoch for iceweasel-l10n-all.

The debian/rules change is the following:

diff -Nru iceweasel-10.0.6esr/debian/rules iceweasel-10.0.7esr/debian/rules
--- iceweasel-10.0.6esr/debian/rules    2012-08-03 07:34:31.000000000 +0000
+++ iceweasel-10.0.7esr/debian/rules    2012-08-29 06:16:51.000000000 +0000
@@ -333,8 +333,8 @@
        LD_LIBRARY_PATH=$(CURDIR)/debian/tmp/usr/lib/xulrunner-$(GRE_VERSION) dpkg-shlibdeps -Tdebian/xulrunner-$(GRE_VERSION).substvars -dDepends -pgnome $(foreach lib,dbusservice,debian/xulrunner-$(GRE_VERSION)/usr/lib/xulrunner-$(GRE_VERSION)/components/lib$(lib).so)

 override_dh_gencontrol:
-       dh_gencontrol$(foreach pkg,$(L10N_PACKAGES), -p$(pkg)) -- -v1:$(DEBIAN_VERSION)
-       dh_gencontrol$(foreach pkg,$(L10N_PACKAGES), -N$(pkg))
+       dh_gencontrol$(foreach pkg,$(L10N_PACKAGES) iceweasel-l10n-all, -p$(pkg)) -- -v1:$(DEBIAN_VERSION)
+       dh_gencontrol$(foreach pkg,$(L10N_PACKAGES) iceweasel-l10n-all, -N$(pkg))

 install binary binary-arch binary-indep: $(GENERATED_FILES)

Note one of the CVEs essentially disables webGL with mesa because of a
mesa bug that leads to security problems.

unblock iceweasel/10.0.7esr-1

-- System Information:
Debian Release: wheezy/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.5-trunk-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash



Information forwarded to debian-bugs-dist@lists.debian.org, Debian Release Team <debian-release@lists.debian.org>:
Bug#686319; Package release.debian.org. (Fri, 31 Aug 2012 07:03:05 GMT) Full text and rfc822 format available.

Acknowledgement sent to Mike Hommey <mh@glandium.org>:
Extra info received and forwarded to list. Copy sent to Debian Release Team <debian-release@lists.debian.org>. (Fri, 31 Aug 2012 07:03:05 GMT) Full text and rfc822 format available.

Message #10 received at 686319@bugs.debian.org (full text, mbox):

From: Mike Hommey <mh@glandium.org>
To: 686319@bugs.debian.org
Subject: Re: Bug#686319: unblock: iceweasel/10.0.7esr-1
Date: Fri, 31 Aug 2012 09:00:14 +0200
On Fri, Aug 31, 2012 at 07:28:24AM +0200, Mike Hommey wrote:
> Note one of the CVEs essentially disables webGL with mesa because of a
> mesa bug that leads to security problems.

Considering the mesa bug has been fixed in 8.0.4-2 and doesn't affect
stable/stable-backports, I'm planning a 10.0.7esr-2 upload reenabling
webgl for mesa. Should I wait for the transition to happen, or should
i go ahead straight away?

Mike



Reply sent to Julien Cristau <jcristau@debian.org>:
You have taken responsibility. (Fri, 31 Aug 2012 08:21:14 GMT) Full text and rfc822 format available.

Notification sent to Mike Hommey <mh+reportbug@glandium.org>:
Bug acknowledged by developer. (Fri, 31 Aug 2012 08:21:14 GMT) Full text and rfc822 format available.

Message #15 received at 686319-done@bugs.debian.org (full text, mbox):

From: Julien Cristau <jcristau@debian.org>
To: Mike Hommey <mh+reportbug@glandium.org>, 686319-done@bugs.debian.org
Subject: Re: Bug#686319: unblock: iceweasel/10.0.7esr-1
Date: Fri, 31 Aug 2012 10:16:52 +0200
[Message part 1 (text/plain, inline)]
On Fri, Aug 31, 2012 at 07:28:24 +0200, Mike Hommey wrote:

> Package: release.debian.org
> Severity: normal
> User: release.debian.org@packages.debian.org
> Usertags: unblock
> 
> Please unblock package iceweasel
> 
Unblocked.

Cheers,
Julien
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian Release Team <debian-release@lists.debian.org>:
Bug#686319; Package release.debian.org. (Sat, 01 Sep 2012 19:33:03 GMT) Full text and rfc822 format available.

Acknowledgement sent to Mike Hommey <mh@glandium.org>:
Extra info received and forwarded to list. Copy sent to Debian Release Team <debian-release@lists.debian.org>. (Sat, 01 Sep 2012 19:33:03 GMT) Full text and rfc822 format available.

Message #20 received at 686319@bugs.debian.org (full text, mbox):

From: Mike Hommey <mh@glandium.org>
To: 686319@bugs.debian.org
Subject: Re: Bug#686319 closed by Julien Cristau <jcristau@debian.org> (Re: Bug#686319: unblock: iceweasel/10.0.7esr-1)
Date: Sat, 1 Sep 2012 21:29:25 +0200
On Fri, Aug 31, 2012 at 08:21:14AM +0000, Debian Bug Tracking System wrote:
> This is an automatic notification regarding your Bug report
> which was filed against the release.debian.org package:
> 
> #686319: unblock: iceweasel/10.0.7esr-1
> 
> It has been closed by Julien Cristau <jcristau@debian.org>.
> 
> Their explanation is attached below along with your original report.
> If this explanation is unsatisfactory and you have not received a
> better one in a separate message then please contact Julien Cristau <jcristau@debian.org> by
> replying to this email.
> 
> 
> -- 
> 686319: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686319
> Debian Bug Tracking System
> Contact owner@bugs.debian.org with problems

> Date: Fri, 31 Aug 2012 10:16:52 +0200
> From: Julien Cristau <jcristau@debian.org>
> To: Mike Hommey <mh+reportbug@glandium.org>, 686319-done@bugs.debian.org
> Subject: Re: Bug#686319: unblock: iceweasel/10.0.7esr-1
> User-Agent: Mutt/1.5.21 (2010-09-15)
> Message-ID: <20120831081652.GF6588@radis.cristau.org>
> 
> On Fri, Aug 31, 2012 at 07:28:24 +0200, Mike Hommey wrote:
> 
> > Package: release.debian.org
> > Severity: normal
> > User: release.debian.org@packages.debian.org
> > Usertags: unblock
> > 
> > Please unblock package iceweasel
> > 
> Unblocked.

Can you also make it age faster?

Cheers,

Mike



Information forwarded to debian-bugs-dist@lists.debian.org, Debian Release Team <debian-release@lists.debian.org>:
Bug#686319; Package release.debian.org. (Mon, 03 Sep 2012 08:51:03 GMT) Full text and rfc822 format available.

Acknowledgement sent to Julien Cristau <jcristau@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Release Team <debian-release@lists.debian.org>. (Mon, 03 Sep 2012 08:51:03 GMT) Full text and rfc822 format available.

Message #25 received at 686319@bugs.debian.org (full text, mbox):

From: Julien Cristau <jcristau@debian.org>
To: Mike Hommey <mh@glandium.org>, 686319@bugs.debian.org
Subject: Re: Bug#686319: closed by Julien Cristau <jcristau@debian.org> (Re: Bug#686319: unblock: iceweasel/10.0.7esr-1)
Date: Mon, 3 Sep 2012 10:47:11 +0200
[Message part 1 (text/plain, inline)]
On Sat, Sep  1, 2012 at 21:29:25 +0200, Mike Hommey wrote:

> Can you also make it age faster?
> 
Done.

Cheers,
Julien
[signature.asc (application/pgp-signature, inline)]

Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Tue, 02 Oct 2012 07:26:46 GMT) Full text and rfc822 format available.

Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Sun Apr 20 16:08:08 2014; Machine Name: buxtehude.debian.org

Debian Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.