Re: Regression in stretch update of ruby-activerecord 2:5.2.2.1+dfsg-1+deb10u4

2022-09-14 Thread Raphael Hertzog
Hi, On Tue, 13 Sep 2022, Abhijith PA wrote: > > Yes, that'd make sense. I'll start a separate thread for > > CVE-2022-32224. Roll back for now so there's no regression at least. > > I've disabled patch for CVE-2022-32224. Also tested against redmine. > Looks good for me. Can you give a smoke

Re: Regression in stretch update of ruby-activerecord 2:5.2.2.1+dfsg-1+deb10u4

2022-09-13 Thread Abhijith PA
Hey, On 12/09/22 04:08 PM, Utkarsh Gupta wrote: > Hi Abhijith, > > On Sat, Sep 10, 2022 at 11:31 PM Abhijith PA wrote: > > > Please don't upload yet. We either upload what I have or just rollback > > > the fix for CVE-2022-32224. Wait for the further decision or let me > > > handle that -

Re: Regression in stretch update of ruby-activerecord 2:5.2.2.1+dfsg-1+deb10u4

2022-09-12 Thread Utkarsh Gupta
Hi Abhijith, On Sat, Sep 10, 2022 at 11:31 PM Abhijith PA wrote: > > Please don't upload yet. We either upload what I have or just rollback > > the fix for CVE-2022-32224. Wait for the further decision or let me > > handle that - whatever works for you. :D > > Should I rollback CVE-2022-32224

Re: Regression in stretch update of ruby-activerecord 2:5.2.2.1+dfsg-1+deb10u4

2022-09-09 Thread Utkarsh Gupta
Hi Abhijith, On Fri, Sep 9, 2022 at 6:04 PM Abhijith PA wrote: > Can you share how autopkgtest.kali.org service setup and how > is it running. I am using https://ci.debian.net/doc/file.HACKING.html > to reproduce this. What is your rack server like and you also run any > proxy server. It's also

Re: Regression in stretch update of ruby-activerecord 2:5.2.2.1+dfsg-1+deb10u4

2022-09-09 Thread Abhijith PA
Hello Raphael, On 07/09/22 11:10 AM, Raphael Hertzog wrote: > Hello Abhijith and the LTS team, > > in Kali we have applied the last ruby-active* security updates and this > broke the web API part of autopkgtest.kali.org. Can you share how autopkgtest.kali.org service setup and how is it

Re: Regression in stretch update of ruby-activerecord 2:5.2.2.1+dfsg-1+deb10u4

2022-09-08 Thread Utkarsh Gupta
Hi Raphael, Abhijith, On Thu, Sep 8, 2022 at 3:18 PM Raphael Hertzog wrote: > Please coordinate with Utkarsh who seems to have worked on it yesterday > already. > > To both of you, it would be nice to document the fact that you work on it by > adding an entry in dla-needed.txt to avoid duplicate

Re: Regression in stretch update of ruby-activerecord 2:5.2.2.1+dfsg-1+deb10u4

2022-09-08 Thread Raphael Hertzog
Hello, On Thu, 08 Sep 2022, Abhijith PA wrote: > On 07/09/22 11:10 AM, Raphael Hertzog wrote: > > Hello Abhijith and the LTS team, > > > > in Kali we have applied the last ruby-active* security updates and this > > broke the web API part of autopkgtest.kali.org. > > Ok, I am on it. Please

Re: Regression in stretch update of ruby-activerecord 2:5.2.2.1+dfsg-1+deb10u4

2022-09-08 Thread Abhijith PA
Hello. On 07/09/22 11:10 AM, Raphael Hertzog wrote: > Hello Abhijith and the LTS team, > > in Kali we have applied the last ruby-active* security updates and this > broke the web API part of autopkgtest.kali.org. Ok, I am on it.

Regression in stretch update of ruby-activerecord 2:5.2.2.1+dfsg-1+deb10u4

2022-09-07 Thread Raphael Hertzog
Hello Abhijith and the LTS team, in Kali we have applied the last ruby-active* security updates and this broke the web API part of autopkgtest.kali.org. Specifically line 51 in /usr/share/rubygems-integration/all/gems/activerecord-5.2.2.1/lib/active_record/coders/yaml_column.rb makes a call to