Bug#1068888: bookworm-pu: package zookeeper/3.8.0-11+deb12u2
- To: Salvatore Bonaccorso <carnil@debian.org>, 1068888@bugs.debian.org
- Cc: Bastien Roucariès <rouca@debian.org>, "Adam D. Barratt" <adam@adam-barratt.org.uk>
- Subject: Bug#1068888: bookworm-pu: package zookeeper/3.8.0-11+deb12u2
- From: Jonathan Wiltshire <jmw@debian.org>
- Date: Fri, 6 Dec 2024 14:49:31 +0000
- Message-id: <[🔎] Z1MO-xAyfW4ydhoY@powdarrmonkey.net>
- Reply-to: Jonathan Wiltshire <jmw@debian.org>, 1068888@bugs.debian.org
- In-reply-to: <ZnceVOmoAnuUIUs3@eldamar.lan>
- References: <2201300.DTlR5uhxpJ@portable-bastien> <Zm4adOik3ZGYZjLp@powdarrmonkey.net> <2201300.DTlR5uhxpJ@portable-bastien> <3474490.tzy3JR2A0P@portable-bastien> <2201300.DTlR5uhxpJ@portable-bastien> <9afa6a6ba0f14cc4f27bed5cf16db5e2c2afb9fe.camel@adam-barratt.org.uk> <2201300.DTlR5uhxpJ@portable-bastien> <ZnceVOmoAnuUIUs3@eldamar.lan> <2201300.DTlR5uhxpJ@portable-bastien>
Control: tag -1 confirmed
On Sat, Jun 22, 2024 at 08:56:20PM +0200, Salvatore Bonaccorso wrote:
> Hi Bastien,
>
> On Sun, Jun 16, 2024 at 12:50:59PM +0100, Adam D. Barratt wrote:
> > On Sun, 2024-06-16 at 11:12 +0000, Bastien Roucariès wrote:
> > > control: tag -1 - moreinfo
> > > Le samedi 15 juin 2024, 22:49:24 UTC Jonathan Wiltshire a écrit :
> > > > >
> > [...]
> > > > > zookeeper-3.8.0/debian/patches/0027-CVE-2024-23944-ZOOKEEPER-
> > > > > 4799-Refactor-ACL-check-in-.patch 1970-01-01
> > > > > 00:00:00.000000000 +0000
> > > > > +++ zookeeper-3.8.0/debian/patches/0027-CVE-2024-23944-ZOOKEEPER-
> > > > > 4799-Refactor-ACL-check-in-.patch 2024-03-25
> > > > > 08:30:56.000000000 +0000
> > > > > @@ -0,0 +1,1223 @@
> > > >
> > > >
> > > > This patch confuses me. It seems to contain a whole series of
> > > > nested
> > > > patches? How do they get applied to the source package?
> > >
> > > ???
> > >
> > > I do not understand, see patch 0027 joined it is a simple patch...
> >
> > Is the source of the confusion here potentially that the patch adds new
> > files, as well as changing existing ones?
>
> Any comments here? (I guess likely it will be now to late for 12.6,
> but maybe we can make it for 12.7?)
Yes, it's the diff-in-diff which confused me and then I lost track of the
whole thing. Sorry.
Please go ahead.
Thanks,
--
Jonathan Wiltshire jmw@debian.org
Debian Developer http://people.debian.org/~jmw
4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51
ed25519/0x196418AAEB74C8A1: CA619D65A72A7BADFC96D280196418AAEB74C8A1
Reply to: