Your message dated Fri, 10 Feb 2012 03:48:43 +0000
with message-id <[email protected]>
and subject line Bug#646343: fixed in leafpad 0.8.18.1-2
has caused the Debian Bug report #646343,
regarding leafpad: FTBFS with -Werror=format-security
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
646343: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=646343
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: leafpad
Version: 0.8.18.1-1
Severity: normal
User: [email protected]
Usertags: hardening-format-security hardening
the package leafpad fails to compile with the new hardened compiler
flags dpkg-buildflag outputs [0].
The problematic flag is: -Werror=format-security
See the ubuntu buildlog:
https://launchpadlibrarian.net/83144457/buildlog_ubuntu-precise-i386.leafpad_0.8.18.1-1_FAILEDTOBUILD.txt.gz
Snippet:
gcc -DHAVE_CONFIG_H -I. -I.. -DICONDIR=\"/usr/share/pixmaps\"
-D_FORTIFY_SOURCE=2 -pthread -I/usr/include/gtk-2.0
-I/usr/lib/x86_64-linux-gnu/gtk-2.0/include -I/usr/include/atk-1.0
-I/usr/include/gdk-pixbuf-2.0 -I/usr/include/pango-1.0
-I/usr/include/pixman-1 -I/usr/include/freetype2 -I/usr/include/libpng12
-I/usr/include/cairo -I/usr/include/gio-unix-2.0/
-I/usr/include/glib-2.0 -I/usr/lib/glib-2.0/include -g -O2
-fstack-protector --param=ssp-buffer-size=4 -Wformat -Wformat-security
-Werror=format-security -Wall -c -o leafpad-dialog.o `test -f 'dialog.c'
|| echo './'`dialog.c
dialog.c: In function 'run_dialog_message':
dialog.c:39:3: error: format not a string literal and no format
arguments [-Werror=format-security]
dialog.c: In function 'create_dialog_message_question':
dialog.c:64:3: error: format not a string literal and no format
arguments [-Werror=format-security]
cc1: some warnings being treated as errors
The buildflags are not exported in debian, but can be enabled e.g. by
adding this to debian/rules:
DPKG_EXPORT_BUILDFLAGS = 1
include /usr/share/dpkg/buildflags.mk
Please fix the issues and maybe also enable the hardened build in debian.
[0] http://lists.debian.org/debian-devel-announce/2011/09/msg00001.html
signature.asc
Description: OpenPGP digital signature
--- End Message ---
--- Begin Message ---
Source: leafpad
Source-Version: 0.8.18.1-2
We believe that the bug you reported is fixed in the latest version of
leafpad, which is due to be installed in the Debian FTP archive:
leafpad_0.8.18.1-2.debian.tar.gz
to main/l/leafpad/leafpad_0.8.18.1-2.debian.tar.gz
leafpad_0.8.18.1-2.dsc
to main/l/leafpad/leafpad_0.8.18.1-2.dsc
leafpad_0.8.18.1-2_amd64.deb
to main/l/leafpad/leafpad_0.8.18.1-2_amd64.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Jari Aalto <[email protected]> (supplier of updated leafpad package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Wed, 08 Feb 2012 07:03:31 -0500
Source: leafpad
Binary: leafpad
Architecture: source amd64
Version: 0.8.18.1-2
Distribution: unstable
Urgency: low
Maintainer: Jari Aalto <[email protected]>
Changed-By: Jari Aalto <[email protected]>
Description:
leafpad - GTK+ based simple text editor
Closes: 646343
Changes:
leafpad (0.8.18.1-2) unstable; urgency=low
.
* debian/compat
- Update to 9
* debian/control
- (Build-Depends): update to debhelper 9, dpkg-dev 1.16.1.
* debian/patches
- (20): Fix code for gcc hardened format specifiers.
* debian/rules
- Use hardened CFLAGS (FTBFS; Closes: #646343).
http://wiki.debian.org/ReleaseGoals/SecurityHardeningBuildFlags
Checksums-Sha1:
e3fe1c9d2dd456111b11bddee8bc1b493a04e455 1926 leafpad_0.8.18.1-2.dsc
08e8fe7428c4940d0b4a9eb2cbf9e416af9bd55a 8653 leafpad_0.8.18.1-2.debian.tar.gz
eb6cf88601063018da4b98dc6801ec646013f360 113738 leafpad_0.8.18.1-2_amd64.deb
Checksums-Sha256:
28bc6b2921cacd6d443bba325f5064bf1c9bb57e10a1b128284cb8e86a86effd 1926
leafpad_0.8.18.1-2.dsc
4c967343a0c26259165992c50cfdf2fecc7874687005e9b9415de2d096abe3a5 8653
leafpad_0.8.18.1-2.debian.tar.gz
a044a16ecfd8c9123810c7d27178e66d5da728ad159950a66df185f482025de0 113738
leafpad_0.8.18.1-2_amd64.deb
Files:
0448c4af74d5d481e990b07239df0b84 1926 editors optional leafpad_0.8.18.1-2.dsc
8c7657c800528513ee64cfefa8bbe59d 8653 editors optional
leafpad_0.8.18.1-2.debian.tar.gz
46e03b487426109f5a698e31d01f1e98 113738 editors optional
leafpad_0.8.18.1-2_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iQIcBAEBAgAGBQJPNJFmAAoJECHSBYmXSz6WJO8P/1ovwrk+GUwU0ce2qIcYRnOi
mD4nlJ9WIVysa2MiPMpv6J2+1F6BYBFK5I6T0a7AJIqyNJ7t26KCHPYbWYHhjRYO
bAa95Ges5O91r67Xia1cxWLB0uyUhXb+EeZke2jLcINtxkMHqZhzh5CNbgeFhup9
s2/WX/v5zfrf1+mTpWLOqD4PkdU3LNxtP9QF5jpuJKr4kmmAmMkvjdP3LxBGyb3Z
jBu2xXqaSBWj/SUslc/gEzPmxj/2BDfpbwqfBxkaYFNMZSCObsTQRPphNlYir0zx
Jue+gPzAPyWQBIAIyNCHnihttB0wA3V45mHdb1EUmemaoB/N8XUGwtgPVWeVWP56
c4Rw5PPfv9NFrDBhRlcXn5DtxUi1uw/8hZzdZCWRG/PNUu3BmX6U2+iP8+XX7qT3
kM25rNu2tHrmpIFnAWwZNYbJLNSuPKsxUALqaia4l9yey7k62PD8YeW4uTucGe2s
h6XEfivvHWTXUVb73cVr6B+YHS/isqstsjRbP+FahemCo8PUsS0kmP2jB7WiYIXK
HMCRW1ou8zxYAPKJhrsepw6GlBYewfKDtUXtFdHaop7AC9z1cXYwr0tEYKwUTQP0
jdi5idMzsk9/EPYoraK4PZsWqKoPk62wOJi3DpNuLiN+CCs1ftDcRtj2u0LcZQWY
E3ge02cTtaF/1WFxETMd
=9WXW
-----END PGP SIGNATURE-----
--- End Message ---