[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#830907: marked as done (RFS: pam-u2f/1.0.4-0.2 [NMU])



Your message dated Thu, 14 Jul 2016 22:12:37 +0000 (UTC)
with message-id <1175538016.5224578.1468534357617.JavaMail.yahoo@mail.yahoo.com>
and subject line Re: Bug#830907: RFS: pam-u2f/1.0.4-0.1 [NMU]
has caused the Debian Bug report #830907,
regarding RFS: pam-u2f/1.0.4-0.2 [NMU]
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
830907: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=830907
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: sponsorship-requests
Severity: normal

Dear mentors,

I am looking for a sponsor for my package "pam-u2f"

 * Package name    : pam-u2f
   Version         : 1.0.4-0.1
   Upstream Author : Yubico AG
 * URL             : https://developers.yubico.com/pam-u2f/
 * License         : BSD
   Section         : admin

It builds those binary packages:
  libpam-u2f - universal 2nd factor (U2F) PAM module
  pamu2fcfg  - universal 2nd factor (U2F) PAM module command-line helper tool

My prepared upload can be found on mentors.debian.net:

  https://mentors.debian.net/package/pam-u2f

Alternatively, one can download the package with dget:

    dget -x https://mentors.debian.net/debian/pool/main/p/pam-u2f/pam-u2f_1.0.4-0.1.dsc


This upload brings v1.0.4 to the archive, which fixes a potential
security issue (see [0] for details), and enables build-time hardening
features.

Moreover, it fixes a number of minor issues:
- use HTTPS for the Vcs-Git link;
- bump Standards-Version to 3.9.8 (no change required);
- install the pam_u2f(8) manpage in the corresponding package,
  rather than in pamu2fcfg.


I am aware that sponsored NMUs are not a sane way to maintain this
package in the long term.  As such, I reached out to the pkg-auth team,
applied for membership there, and suggested several changes to make the
maintainance of those packages easier.


Best,

  nicoo

[0] https://developers.yubico.com/pam-u2f/Release_Notes.html

--- End Message ---
--- Begin Message ---
Hi,

>It seems you signed and uploaded a package which does /not/ have

>the correct “Breaks” and “Replaces” dependencies.


yes indeed, the package was already ongoing when I got the issue
>I uploaded a version 1.0.4-0.2 to mentors which sets those.


thanks, I was waiting for it to go in incoming and grab the fix by myself :)

>Thanks again for the review and sponsoring, and thanks to lamby for
>telling me about incoming.debian.org and what to do in this situation.


thanks lamby from my side too, I was AFK, and I just sponsored the fix

BTW, please consider dropping autotools-dev if really useless.
Usually dh-autoreconf is a superset of it, but you need to check if it still builds of
course :)

cheers, and thanks for your contribution to Debian!
(and sorry for the double sponsoring, my fault)

G.

--- End Message ---

Reply to: