Debian Bug report logs - #705369
charybdis: SSL issues when linking GnuTLS servers

version graph

Package: charybdis; Maintainer for charybdis is Antoine Beaupré <anarcat@debian.org>; Source for charybdis is src:charybdis (PTS, buildd, popcon).

Reported by: Tero Marttila <tero.marttila@paivola.fi>

Date: Sat, 13 Apr 2013 19:54:01 UTC

Severity: important

Tags: fixed-upstream, patch, upstream

Found in versions charybdis/3.5.3-1, charybdis/3.3.0-7.1

Fixed in versions charybdis/3.4.2-5, charybdis/3.4.2-5~deb8u1, charybdis/3.5.5-2

Done: Antoine Beaupré <anarcat@debian.org>

Bug is archived. No further changes may be made.

Forwarded to https://github.com/atheme/charybdis/issues/12

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Antoine Beaupré <anarcat@debian.org>:
Bug#705369; Package charybdis. (Sat, 13 Apr 2013 19:54:06 GMT) (full text, mbox, link).


Acknowledgement sent to Tero Marttila <tero.marttila@paivola.fi>:
New Bug report received and forwarded. Copy sent to Antoine Beaupré <anarcat@debian.org>. (Sat, 13 Apr 2013 19:54:06 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Tero Marttila <tero.marttila@paivola.fi>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: charybdis: SSL issues when linking GnuTLS servers
Date: Sat, 13 Apr 2013 22:42:25 +0300
Package: charybdis
Version: 3.3.0-7.1
Severity: important

SSL-linking between charybdis servers compiled with GnuTLS appears to be broken:

	2013/4/13 21.57 Connecting to irc.*[...] port 8097 (IPv4)
	2013/4/13 21.58 ssld error for irc.*[unknown@...]: Read error: Input/output error

Issue reported upstream:
	
	https://github.com/atheme/charybdis/issues/12

which indicates it is related to the certfp feature support. There seem to be some efforts to fix the issue upstream:

	https://github.com/atheme/charybdis/commit/3d7890b99c1de151a557c07c1f86b64398f7cdb2
	https://github.com/atheme/charybdis/commit/77444dcc1f754f0916c7314baf9e6836556616dd

However, it seems that upstream has simply removed GnuTLS support since:

	https://github.com/atheme/charybdis/commit/f2d58c6d72a1735b28ef95566fbd26bb0736246d
	https://github.com/atheme/charybdis/commit/6a25507e90c2b2f934724e8eb278e9782acac923

 -- Tero Marttila

-- System Information:
Debian Release: 7.0
  APT prefers testing-updates
  APT policy: (500, 'testing-updates'), (500, 'testing')
Architecture: i386 (i686)

Kernel: Linux 3.2.0-4-686-pae (SMP w/2 CPU cores)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages charybdis depends on:
ii  adduser         3.113+nmu3
ii  libc6           2.13-38
ii  libgnutls26     2.12.20-4
ii  libsqlite3-0    3.7.13-1
ii  zlib1g [libz1]  1:1.2.7.dfsg-13

charybdis recommends no packages.

charybdis suggests no packages.

-- Configuration Files:
/etc/charybdis/ircd.conf changed [not included]
/etc/charybdis/ircd.motd changed [not included]
/etc/default/charybdis changed [not included]

-- no debconf information



Information forwarded to debian-bugs-dist@lists.debian.org, Antoine Beaupré <anarcat@debian.org>:
Bug#705369; Package charybdis. (Wed, 05 Jun 2013 03:39:04 GMT) (full text, mbox, link).


Acknowledgement sent to anarcat <anarcat@debian.org>:
Extra info received and forwarded to list. Copy sent to Antoine Beaupré <anarcat@debian.org>. (Wed, 05 Jun 2013 03:39:04 GMT) (full text, mbox, link).


Message #10 received at 705369@bugs.debian.org (full text, mbox, reply):

From: anarcat <anarcat@debian.org>
To: 705369@bugs.debian.org
Cc: Tero Marttila <tero.marttila@paivola.fi>
Subject: gnutls is gone
Date: Tue, 4 Jun 2013 23:37:32 -0400
[Message part 1 (text/plain, inline)]
I don't see this being fixed in wheezy. There are flags to build against
OpenSSL there if you want (see debian/README.source) but I am working on
updating the package to 3.4 which simply removes gnutls support in favor
of OpenSSL which is upstream's fix to the issue.

I have requested a license exception for everything to be legit before
the upload:

https://github.com/atheme/charybdis/issues/22

So this should be fixed shortly in sid/jessie. I may also backport 3.4
to wheezy.

A.

-- 
It is a miracle that curiosity survives formal education
                        - Albert Einstein
[signature.asc (application/pgp-signature, inline)]

Added tag(s) pending. Request was from Antoine Beaupré <anarcat@debian.org> to control@bugs.debian.org. (Wed, 05 Jun 2013 03:39:09 GMT) (full text, mbox, link).


Added tag(s) upstream. Request was from Antoine Beaupré <anarcat@debian.org> to control@bugs.debian.org. (Wed, 05 Jun 2013 03:39:10 GMT) (full text, mbox, link).


Added tag(s) wontfix. Request was from Antoine Beaupré <anarcat@debian.org> to control@bugs.debian.org. (Wed, 05 Jun 2013 03:39:14 GMT) (full text, mbox, link).


Added blocking bug(s) of 705369: 711152 Request was from Antoine Beaupré <anarcat@debian.org> to control@bugs.debian.org. (Wed, 05 Jun 2013 06:12:38 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Antoine Beaupré <anarcat@debian.org>:
Bug#705369; Package charybdis. (Mon, 01 Jul 2013 01:06:09 GMT) (full text, mbox, link).


Acknowledgement sent to anarcat <anarcat@debian.org>:
Extra info received and forwarded to list. Copy sent to Antoine Beaupré <anarcat@debian.org>. (Mon, 01 Jul 2013 01:06:09 GMT) (full text, mbox, link).


Message #23 received at 705369@bugs.debian.org (full text, mbox, reply):

From: anarcat <anarcat@debian.org>
To: 705369@bugs.debian.org
Subject: no license exception
Date: Sun, 30 Jun 2013 21:04:16 -0400
[Message part 1 (text/plain, inline)]
Control: tags -1 -wontfix
Control: tags -1 -pending

So it seems upstream can't actually provide a license exception. They
are considering switching to libnss, but in the meantime, I have made a
patch (upstream at https://github.com/atheme/charybdis/issues/30) to
re-introduce gnutls support in 3.4, and it was merged in upstream, so we
can ship 3.4 with gnutls support again.

A.

-- 
O gentilshommes, la vie est courte.
Si nous vivons, nous vivons 
pour marcher sur la tête des rois.
                        - William Shakespeare
[signature.asc (application/pgp-signature, inline)]

Removed tag(s) wontfix. Request was from anarcat <anarcat@debian.org> to 705369-submit@bugs.debian.org. (Mon, 01 Jul 2013 01:06:09 GMT) (full text, mbox, link).


Removed tag(s) pending. Request was from anarcat <anarcat@debian.org> to 705369-submit@bugs.debian.org. (Mon, 01 Jul 2013 01:06:10 GMT) (full text, mbox, link).


Removed blocking bug(s) of 705369: 711152 Request was from Antoine Beaupré <anarcat@debian.org> to control@bugs.debian.org. (Mon, 01 Jul 2013 04:54:04 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Antoine Beaupré <anarcat@debian.org>:
Bug#705369; Package charybdis. (Mon, 01 Jul 2013 05:21:04 GMT) (full text, mbox, link).


Acknowledgement sent to anarcat <anarcat@debian.org>:
Extra info received and forwarded to list. Copy sent to Antoine Beaupré <anarcat@debian.org>. (Mon, 01 Jul 2013 05:21:04 GMT) (full text, mbox, link).


Message #34 received at 705369@bugs.debian.org (full text, mbox, reply):

From: anarcat <anarcat@debian.org>
To: 705369@bugs.debian.org
Subject: use the gnutls openssl compatibility layer?
Date: Mon, 1 Jul 2013 01:17:50 -0400
[Message part 1 (text/plain, inline)]
So it seems that using gnutls 3.0 doesn't fix the linking problem and
that the latest upstream gnutls code is still buggy.

My last guess at this (short of debugging the gnutls code further) is to
try to use the OpenSSL compability mode of gnutls. This will probably
require changes to the toolchain, but may work better...

A.

-- 
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Antoine Beaupré <anarcat@debian.org>:
Bug#705369; Package charybdis. (Sun, 12 Jan 2014 01:36:04 GMT) (full text, mbox, link).


Acknowledgement sent to Clint Adams <clint@debian.org>:
Extra info received and forwarded to list. Copy sent to Antoine Beaupré <anarcat@debian.org>. (Sun, 12 Jan 2014 01:36:04 GMT) (full text, mbox, link).


Message #39 received at 705369@bugs.debian.org (full text, mbox, reply):

From: Clint Adams <clint@debian.org>
To: 705369@bugs.debian.org
Subject: gnutls
Date: Sun, 12 Jan 2014 01:32:10 +0000
This works for me on wheezy, with the hard-coded library
dependencies removed:

--- a/ssld/ssld.c
+++ b/ssld/ssld.c
@@ -683,7 +683,7 @@
 
 	if(status == RB_OK)
 	{
-		if(rb_get_ssl_certfp(F, &buf[5]))
+		if(rb_get_ssl_certfp(F, (uint8_t *)&buf[5]))
 		{
 			buf[0] = 'F';
 			int32_to_buf(&buf[1], conn->id);
@@ -706,7 +706,7 @@
 
 	if(status == RB_OK)
 	{
-		if(rb_get_ssl_certfp(F, &buf[5]))
+		if(rb_get_ssl_certfp(F, (uint8_t *)&buf[5]))
 		{
 			buf[0] = 'F';
 			int32_to_buf(&buf[1], conn->id);
--- a/libratbox/src/gnutls.c
+++ b/libratbox/src/gnutls.c
@@ -571,21 +571,25 @@
 	if (cert_list == NULL)
 	{
 		gnutls_x509_crt_deinit(cert);
+		rb_lib_log("rb_get_ssl_cert: Unable get peers");
 		return 0;
 	}
 
 	if (gnutls_x509_crt_import(cert, &cert_list[0], GNUTLS_X509_FMT_DER) < 0)
 	{
 		gnutls_x509_crt_deinit(cert);
+		rb_lib_log("rb_get_ssl_cert: Unable to import");
 		return 0;
 	}
 
 	if (gnutls_x509_crt_get_fingerprint(cert, GNUTLS_DIG_SHA1, digest, &digest_size) < 0)
 	{
 		gnutls_x509_crt_deinit(cert);
+		rb_lib_log("rb_get_ssl_cert: Unable get fingerprint");
 		return 0;
 	}
 
+	rb_lib_log("rb_get_ssl_cert: done did %d", digest_size);
 	memcpy(certfp, digest, RB_SSL_CERTFP_LEN);
 
 	gnutls_x509_crt_deinit(cert);
--- a/libratbox/configure.ac
+++ b/libratbox/configure.ac
@@ -349,7 +349,7 @@
 [cf_enable_gnutls="auto"])
  
 if test "$cf_enable_gnutls" != no; then
-       PKG_CHECK_MODULES(GNUTLS, [gnutls >= 3.0], [
+       PKG_CHECK_MODULES(GNUTLS, [gnutls >= 2.0], [
                cf_enable_gnutls="yes"   
        ], [cf_enable_gnutls="no"])      
 fi



Added tag(s) patch. Request was from Antoine Beaupré <anarcat@debian.org> to control@bugs.debian.org. (Sun, 02 Feb 2014 16:57:09 GMT) (full text, mbox, link).


Set Bug forwarded-to-address to 'https://github.com/atheme/charybdis/issues/12'. Request was from Antoine Beaupré <anarcat@debian.org> to control@bugs.debian.org. (Sun, 02 Feb 2014 16:57:12 GMT) (full text, mbox, link).


Added tag(s) fixed-upstream. Request was from bts-link-upstream@lists.alioth.debian.org to control@bugs.debian.org. (Thu, 19 Feb 2015 16:51:28 GMT) (full text, mbox, link).


Reply sent to Antoine Beaupré <anarcat@debian.org>:
You have taken responsibility. (Fri, 13 Nov 2015 22:21:04 GMT) (full text, mbox, link).


Notification sent to Tero Marttila <tero.marttila@paivola.fi>:
Bug acknowledged by developer. (Fri, 13 Nov 2015 22:21:04 GMT) (full text, mbox, link).


Message #50 received at 705369-close@bugs.debian.org (full text, mbox, reply):

From: Antoine Beaupré <anarcat@debian.org>
To: 705369-close@bugs.debian.org
Subject: Bug#705369: fixed in charybdis 3.4.2-5
Date: Fri, 13 Nov 2015 22:19:00 +0000
Source: charybdis
Source-Version: 3.4.2-5

We believe that the bug you reported is fixed in the latest version of
charybdis, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 705369@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Antoine Beaupré <anarcat@debian.org> (supplier of updated charybdis package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Fri, 13 Nov 2015 16:35:35 -0500
Source: charybdis
Binary: charybdis charybdis-dbg
Architecture: source amd64
Version: 3.4.2-5
Distribution: unstable
Urgency: high
Maintainer: Antoine Beaupré <anarcat@debian.org>
Changed-By: Antoine Beaupré <anarcat@debian.org>
Description:
 charybdis  - fast, scalable irc server
 charybdis-dbg - fast, scalable irc server
Closes: 705369 768339
Changes:
 charybdis (3.4.2-5) unstable; urgency=high
 .
   * switch to new anonscm hostnames
   * initialise gnutls properly (Closes: #768339, #705369)
   * add fix for CVE-2015-5290, cherry-picked from upstream d5f856c^..172b58f
Checksums-Sha1:
 4a37315cda961e49ec2c3ae179fecc0dc3123ba5 2074 charybdis_3.4.2-5.dsc
 e8c04001709da0f2c46da29643cae11961c7e0b9 22904 charybdis_3.4.2-5.debian.tar.xz
 7fbdb8d81012e249b89da609fc619c136ff1c0ef 1584760 charybdis-dbg_3.4.2-5_amd64.deb
 fa17211cc762ab86469845d042609bd779cc7487 577922 charybdis_3.4.2-5_amd64.deb
Checksums-Sha256:
 d2a48fb509f35a8dd19e530be140dd916612b7239812c37ced6345465a97befb 2074 charybdis_3.4.2-5.dsc
 891e8efcbcdf83f618706d58497a32f1b4bf89943560ea1d5acdd15f3db74068 22904 charybdis_3.4.2-5.debian.tar.xz
 513ac1f8b76a1453966d03c58e170b039cd27d28467b8cf35e82854e79dccc6a 1584760 charybdis-dbg_3.4.2-5_amd64.deb
 da278b4cad0163c01f5c6aaaaa66b16311a5baffd6033dc651212a5c2c2e1cfb 577922 charybdis_3.4.2-5_amd64.deb
Files:
 5a0a70c81086186b2ebefab0534e828b 2074 net optional charybdis_3.4.2-5.dsc
 08142cb17752a05fca7765d1f0e02388 22904 net optional charybdis_3.4.2-5.debian.tar.xz
 5511dcf3049ca5e4e61f6237d249632c 1584760 debug extra charybdis-dbg_3.4.2-5_amd64.deb
 ee5e6161a9a4b8cbc69a301573c6be1b 577922 net optional charybdis_3.4.2-5_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJWRl8fAAoJEHkhUlJ7dZIerx4P/RioeLWEWihM3MRKmPOk7vki
P7glmUhFGYe25u3nsfMx4oaDezQntYG/lEd4lgFBvLHM3I7tctIAoIXHnajeSmV0
yu2C7+XQTGfTWHotASDhc4P8mDR1+Ba7kAk3fzungCrh022VjhC65OfXpiKFHN3N
58UIkeen5U/gqrDPQEzfxT10rmLKzjxmPkTJR4crg/iGdGmHeAPlRcFO6FflA2Cq
Vgyz2enCTdcoW2aB7XJ7I+3D12mXwDU9V83q33BLpSt1/8kkX0J/mRK3Zph32ZeI
1cjhWx/R9ok4vzyhXSxRzajpc78sxusbwdtC17BX95jOPCdyfEtPZaKqg9yhR6tO
18x6vBbR+wXhDQhn9fLnJi5gfYkBYM1/JvI7pJNcchADIpgJc3I66W5u7R62Fmob
D0/GdhQ0kxNf/QUCeIfc2KceQskCRmI+7wcoL1szD2B0VCo+Uuxmgc08ftVZT3n8
1szjN+oqAte23QSiONzCeUCpt+jaGr8d9sYqV8eIDUbNUHZUZJxZhUaCe91oH9UX
FJVwUvRdme/c3NSJbjzQrLdzXf6gpFqO8sC1C8peIEKlT7ZC+2bxCXdEMAvxpbCp
vdSIrH3k/FPQqTuXnCgrpKZeWH4Kay/P2WxA00gCPv/VdGlTdI9rf1146n7253Gi
bEmiLSxK8UHKkOlzXSeh
=VTO7
-----END PGP SIGNATURE-----




Reply sent to Antoine Beaupré <anarcat@debian.org>:
You have taken responsibility. (Thu, 26 Nov 2015 21:21:18 GMT) (full text, mbox, link).


Notification sent to Tero Marttila <tero.marttila@paivola.fi>:
Bug acknowledged by developer. (Thu, 26 Nov 2015 21:21:18 GMT) (full text, mbox, link).


Message #55 received at 705369-close@bugs.debian.org (full text, mbox, reply):

From: Antoine Beaupré <anarcat@debian.org>
To: 705369-close@bugs.debian.org
Subject: Bug#705369: fixed in charybdis 3.4.2-5~deb8u1
Date: Thu, 26 Nov 2015 21:17:05 +0000
Source: charybdis
Source-Version: 3.4.2-5~deb8u1

We believe that the bug you reported is fixed in the latest version of
charybdis, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 705369@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Antoine Beaupré <anarcat@debian.org> (supplier of updated charybdis package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Fri, 13 Nov 2015 16:35:35 -0500
Source: charybdis
Binary: charybdis charybdis-dbg
Architecture: source amd64
Version: 3.4.2-5~deb8u1
Distribution: stable
Urgency: high
Maintainer: Antoine Beaupré <anarcat@debian.org>
Changed-By: Antoine Beaupré <anarcat@debian.org>
Description:
 charybdis  - fast, scalable irc server
 charybdis-dbg - fast, scalable irc server
Closes: 705369 768339
Changes:
 charybdis (3.4.2-5~deb8u1) stable; urgency=high
 .
   * switch to new anonscm hostnames
   * initialise gnutls properly (Closes: #768339, #705369)
   * add fix for CVE-2015-5290, cherry-picked from upstream d5f856c^..172b58f
Checksums-Sha1:
 8b0810d1ece86e1a0e67e6c2bd3c7d105024e43a 2087 charybdis_3.4.2-5~deb8u1.dsc
 9c937bbc63107662b70ccacefd2748f7d3982fce 22920 charybdis_3.4.2-5~deb8u1.debian.tar.xz
 6e3ab0f49d82c28a4e33c2173c295febd91f861b 579118 charybdis_3.4.2-5~deb8u1_amd64.deb
 3dd475d26087d99c1fcea6cb6cede1865bc0ee5f 1518134 charybdis-dbg_3.4.2-5~deb8u1_amd64.deb
Checksums-Sha256:
 8d26013507fe3c7253a8ff44d9bcba933b43f0f278f0d201cfd4a55ad02d08ab 2087 charybdis_3.4.2-5~deb8u1.dsc
 46689ba11322d952cba1d9d8ac8ef610513296ed6a0fd5b56ae74b828c95e584 22920 charybdis_3.4.2-5~deb8u1.debian.tar.xz
 b476ff79b3329c808784c196ae1c22f8e9ab1a37983ecd0d6966e42a8e0b5ee1 579118 charybdis_3.4.2-5~deb8u1_amd64.deb
 25abaf7b694225274d1b6bb8b4907981626c870f5e0cbbb9190ce53d21caa1d1 1518134 charybdis-dbg_3.4.2-5~deb8u1_amd64.deb
Files:
 9ca11a4f880c4ec6e06988dd9cdc9cb8 2087 net optional charybdis_3.4.2-5~deb8u1.dsc
 74b420916ff96b7e8bb6580615c9cf0c 22920 net optional charybdis_3.4.2-5~deb8u1.debian.tar.xz
 f68106a31cebf0249927fbca8a5cb861 579118 net optional charybdis_3.4.2-5~deb8u1_amd64.deb
 1da446be9a77304a281f0cc755d6c36d 1518134 debug extra charybdis-dbg_3.4.2-5~deb8u1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJWVdSfAAoJEHkhUlJ7dZIeSJwP/2iBJgk7cHyPCSd4GGezuieR
0VFAn002kzByLDVUtzt82XLfpIwmfmp2CkJEZYE6mz4aWSztrnCAEBwEzPgY3ELR
WwHtRFWpB2gGc9j15Eq4+2dLry2TtZtUbzmhX09Gsyld0Bmf9XV84I8bi6YoCjxk
21pr7D2nAJWINvtRgpY08S0OP9gb2zXmFsXUwZBYQqSu45nIPlZkyxE9sxKYd1ew
ck38KGzfyCB7Op0lcxcNGHKfZU9Bn82An7c5C2UFImpFvAhsEFBw2NmipYdg1dw9
utkIiZDRm4kyegrTvPYVwKrj4AesyEoLJTkp/FA/fywAJYyOJTX7RCP5UhYGwqkW
VcMsJKNtP25xfikjC6qWwwKnvtABkZFibTDiMIWRNXWGo6k1sy6H+MSjUNttrhje
ipJpdbYOwMX0gYpLJYoOMA8Yg7FJ5951G0ASYaNfIgC2qKVzmcQziG24W1s5jIrK
5j94CFbBHFcB+WgavQTgZ9sdddLIk3h9t1FnEKg8ZXrCqgjzxUI2529NjUPHVxoq
n3OO5U8iX6HH7ZbXiMg7N27v1UWc7Cr4E0RpmIkrFMwSwWPNp2ZqtTOHQuir2mzM
cZUq+Ax8jRW3fNpQApcEMsc1ylp7SrAvpXPi903pSOgYuDPqIyEdGCMuSH/085zm
wbiFRcfKkjz7ZmqlmmyN
=snkn
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Fri, 25 Dec 2015 07:31:10 GMT) (full text, mbox, link).


Bug unarchived. Request was from Antoine Beaupré <anarcat@debian.org> to control@bugs.debian.org. (Thu, 03 Aug 2017 16:51:05 GMT) (full text, mbox, link).


Marked as found in versions charybdis/3.5.3-1 and reopened. Request was from Antoine Beaupré <anarcat@debian.org> to control@bugs.debian.org. (Thu, 03 Aug 2017 16:51:05 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Antoine Beaupré <anarcat@debian.org>:
Bug#705369; Package charybdis. (Thu, 03 Aug 2017 17:00:03 GMT) (full text, mbox, link).


Acknowledgement sent to anarcat <anarcat@debian.org>:
Extra info received and forwarded to list. Copy sent to Antoine Beaupré <anarcat@debian.org>. (Thu, 03 Aug 2017 17:00:03 GMT) (full text, mbox, link).


Message #66 received at 705369@bugs.debian.org (full text, mbox, reply):

From: anarcat <anarcat@debian.org>
To: Clint Adams <clint@debian.org>, 705369@bugs.debian.org
Subject: Re: Bug#705369: gnutls support broken in charybdis
Date: Thu, 3 Aug 2017 12:56:33 -0400
GnuTLS support is still broken in charybdis. On irc.indymedia.org, we
couldn't link servers with gnutls - we'd get all sorts of errors like
"Read error: Error in the pull function". Our experience was documented
here:

https://we.riseup.net/ircd/outage-20170202

So I reopened this issue and marked unstable as affected.

An upcoming upload should fix the issue by switching to the mbedtls
backend, which behaved better (so far) in our tests. There's code in the
debian/rules file to switch backends, as documented in
debian/README.source.

A.



Reply sent to Antoine Beaupré <anarcat@debian.org>:
You have taken responsibility. (Thu, 03 Aug 2017 17:36:05 GMT) (full text, mbox, link).


Notification sent to Tero Marttila <tero.marttila@paivola.fi>:
Bug acknowledged by developer. (Thu, 03 Aug 2017 17:36:05 GMT) (full text, mbox, link).


Message #71 received at 705369-close@bugs.debian.org (full text, mbox, reply):

From: Antoine Beaupré <anarcat@debian.org>
To: 705369-close@bugs.debian.org
Subject: Bug#705369: fixed in charybdis 3.5.5-2
Date: Thu, 03 Aug 2017 17:34:08 +0000
Source: charybdis
Source-Version: 3.5.5-2

We believe that the bug you reported is fixed in the latest version of
charybdis, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 705369@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Antoine Beaupré <anarcat@debian.org> (supplier of updated charybdis package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Thu, 03 Aug 2017 12:47:26 -0400
Source: charybdis
Binary: charybdis
Architecture: source amd64
Version: 3.5.5-2
Distribution: unstable
Urgency: medium
Maintainer: Antoine Beaupré <anarcat@debian.org>
Changed-By: Antoine Beaupré <anarcat@debian.org>
Description:
 charybdis  - fast, scalable irc server
Closes: 705369
Changes:
 charybdis (3.5.5-2) unstable; urgency=medium
 .
   [ Unit 193 ]
   * d/rules: Fix tabs-vs-spaces for a few comments.
   * d/rules: Re-enable hardening, append LDFLAGS to link only as needed.
   * d/rules: Simplify logic for checking which TLS library to use.
 .
   [ Antoine Beapré ]
   * switch to embedtls by default: linking across servers work (and not
     with gnutls) and there are no licensing issues (like openssl)
     (Closes: #705369)
Checksums-Sha1:
 06d649ea54eafa98223b4b47d50168e4200693c3 2042 charybdis_3.5.5-2.dsc
 7bce412201b41966ba7ef28cc0ccf76759a86937 12940 charybdis_3.5.5-2.debian.tar.xz
 50ba3ecff48a831194c081b5cfd8129ff277ec7c 2201150 charybdis-dbgsym_3.5.5-2_amd64.deb
 998eba12a44a0c125c72c3d7a45b23c92c2fdbe9 5883 charybdis_3.5.5-2_amd64.buildinfo
 dd5e55387a1ed0d82ef7c592605e17c66420bd2e 581850 charybdis_3.5.5-2_amd64.deb
Checksums-Sha256:
 2a46a3f463aff64c9fa0a110b8d6b11fa6e370aacc2a5e7cdd3019d8e78c7844 2042 charybdis_3.5.5-2.dsc
 33cb10e4523232b71fdccf4d5ba37ba26cf5986bbed746512fb609394b0546f5 12940 charybdis_3.5.5-2.debian.tar.xz
 4ed9f1af40c03d27a37a773e23e55e84afd4bdeb244f985a33395409591593c4 2201150 charybdis-dbgsym_3.5.5-2_amd64.deb
 c51b0e8cb3575a0850e214e0a811f252fe5801adbaf911351eabc616aa2b4b18 5883 charybdis_3.5.5-2_amd64.buildinfo
 5408ebdc24457af7a35e37622f5fc21041c5164c3f3ba6c33cfd04bd6eca70bf 581850 charybdis_3.5.5-2_amd64.deb
Files:
 fa4ac4424fd9ac87b9ddbf011acfef94 2042 net optional charybdis_3.5.5-2.dsc
 9f124bb7d4d7a1bfd8a26cdfcbd9972d 12940 net optional charybdis_3.5.5-2.debian.tar.xz
 bf6433ded8f2394671e42a827a10c931 2201150 debug extra charybdis-dbgsym_3.5.5-2_amd64.deb
 f04d607f5c93e0f3b8a85e66f18f9755 5883 net optional charybdis_3.5.5-2_amd64.buildinfo
 6fb65f54198fb8083cec7330ac9f6ed2 581850 net optional charybdis_3.5.5-2_amd64.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEjckBzmQUbASK1Q+7eSFSUnt1kh4FAlmDWn8ACgkQeSFSUnt1
kh57jQ/+MUyC576XGKfjmQeKWCCY4uMOVpoxFZjm9lp9JOPaX+aZ/jY6s75PDkUG
d7TlxL6hdshhor3es1yfFgTC1IZHYXSzbjHCUZQPpbCZFfF6Jx+m1fjUeMrzjSfS
Aki/GB/dRVKlV47dvcjaVgj5TAOH5SHoKCSpCtBMf6pLTnlHIIE/ey0HUHZY9LIA
5Vz7K2OEb4xvbQtrl8bKlqh/iphMI7wjVnDlFwwY8OSGUI5L3L1pdh+zY37EhqdU
qui/mjccwdmLSOBKqKMuGavgU+Yk9lCUl962QjqaqI2YqvaiYBU8RcpwKUKJjmUj
zjFA90jIGnl0q3NILSrfM4pjEX2YBRDPMa/ObDsckkx3nXScWBGo+8uzBE8hWM0y
Ip5X7y7eIDIXvh7CAISL9TCbICZI0FSPpvZRgPb2JPLyABo65YEu5A3SlJPgug1J
yxSWuCCaLC5lQ+oGP6a4R5eMG9AJ/MSwC33KaQzzWX0K/8iwan0xomvKkeFKlrm0
43BX3rCmILVIMow8JFC1mUwwb4Ay1eGttAFV0vBz1aeMOMML+ncu5K7KsW3/O0c3
f5TbMzJhGpJ7OANzkOLYWeLLY9F2U1lOL4QnHYAuGbAtmDv3FRrJ7QG33J/jVodw
t8t5H7+RSc2+zRx/bu7x3vnWJlNSc9IzeuNuVgXuQlQ4v3Efkc8=
=0M/d
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Wed, 06 Sep 2017 07:28:14 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Fri Nov 22 00:03:01 2024; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.