[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Adding autopkgtests for CVEs



Hi Chris,
On Mon, Sep 25, 2017 at 08:08:19AM +0100, Chris Lamb wrote:
> Hi -lts,
> 
> I recently had some success adding an autopkgtest for a CVE and
> thought I might share:
> 
>   https://bugs.debian.org/cgi-bin/bugreport.cgi?att=1;bug=874059;filename=874059.diff.txt;msg=29
> 
> You generate the uuencode input with "uuencode -m -".
> 
> Note that I added a "smoke test" for the non-CVE-related
> codepaths; if I just tested whether the reproducer was rejected,
> this could mask that I broke the regular operation of the package.

Great! Could you tag these as "ease-lts" so we see bugs adding
autopkgtests at a glimpse:

    https://bugs.debian.org/cgi-bin/pkgreport.cgi?tag=ease-lts;users=debian-lts@lists.debian.org

Cheers,
 -- Guido

> 
> 
> Best wishes,
> 
> -- 
>       ,''`.
>      : :'  :     Chris Lamb
>      `. `'`      lamby@debian.org / chris-lamb.co.uk
>        `-
> 


Reply to: