[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: libidn test packages [resent]



On 2016-04-16 18:46:50, Alessandro Ghedini wrote:
> On Tue, Apr 12, 2016 at 03:20:04PM -0400, Antoine Beaupré wrote:
>> (Fixed list address, sorry for the duplicate.)
>> 
>> Hi,
>> 
>> I have looked at porting the security fixes on the libidn package from
>> squeeze to wheezy. As usual, signed test packages are available here:
>> 
>> https://people.debian.org/~anarcat/debian/wheezy-lts/
>> 
>> And a debdiff is available for review by the security team:
>
> FWIW I already prepared wheezy and jessie packages for this a while ago:
> https://people.debian.org/~ghedo/libidn_1.25-2+deb7u1.diff
> https://people.debian.org/~ghedo/libidn_1.29-1+deb8u1.diff
>
> But never uploaded them because I couldn't get the jessie one to build.
>
> This was sort of "documented" in the dsa-needed.txt file and IIRC Tianon Gravi
> was also interested in this a while ago.

Interesting, it seems I missed that...

Your patchset differs from mine significantly. It seems you have reran
gnulib in there? I have found that it was easier to just add the missing
check code through patches and rerun autoconf, as it makes the patch
more readable...

Did the wheezy version compile and work correctly?

I have not worked on a jessie version so I can't comment on that...

Not sure how to handle the twin pacakges, sorry I missed your
packages...

A.

-- 
Freedom is being able to make decisions that affect mainly you. Power
is being able to make decisions that affect others more than you. If
we confuse power with freedom, we will fail to uphold real freedom.
                        - Richard Stallman


Reply to: