Your message dated Sat, 24 Mar 2012 14:48:53 +0000
with message-id <[email protected]>
and subject line Bug#646261: fixed in gimmix 0.5.7.1-4
has caused the Debian Bug report #646261,
regarding gimmix: FTBFS with -Werror=format-security
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
646261: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=646261
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: gimmix
Version: 0.5.7.1-3
Severity: normal
User: [email protected]
Usertags: hardening-format-security hardening
the package gimmix fails to compile with the new hardened compiler flags
dpkg-buildflag outputs [0].
The problematic flag is: -Werror=format-security
See the ubuntu buildlog:
https://launchpadlibrarian.net/83134274/buildlog_ubuntu-precise-i386.gimmix_0.5.7.1-3_FAILEDTOBUILD.txt.gz
Snippet:
gcc -DHAVE_CONFIG_H -I. -I.. -pthread -I/usr/include/gtk-2.0
-I/usr/lib/x86_64-linux-gnu/gtk-2.0/include -I/usr/include/atk-1.0
-I/usr/include/gdk-pixbuf-2.0 -I/usr/include/pango-1.0
-I/usr/include/pixman-1 -I/usr/include/freetype2 -I/usr/include/libpng12
-I/usr/include/taglib -I/usr/include/cairo -I/usr/include/gio-unix-2.0/
-I/usr/include/glib-2.0 -I/usr/lib/glib-2.0/include
-I/usr/include/libmpd-1.0/ -I/usr/include/libglade-2.0
-I/usr/include/libxml2 -DPREFIX=\"/usr\" -fPIC -D_FORTIFY_SOURCE=2 -g
-O2 -fstack-protector --param=ssp-buffer-size=4 -Wformat
-Wformat-security -Werror=format-security -DHAVE_TAGEDITOR -DHAVE_LYRICS
-DHAVE_COVER_PLUGIN -pipe -Wall -c gimmix-config.c
gimmix-config.c: In function 'gimmix_config_get_bool':
gimmix-config.c:96:3: warning: zero-length gnu_printf format string
[-Wformat-zero-length]
gimmix-config.c: In function 'gimmix_config_get_proxy_string':
gimmix-config.c:149:4: error: format not a string literal and no format
arguments [-Werror=format-security]
The buildflags are not exported in debian, but can be enabled e.g. by
adding this to debian/rules:
DPKG_EXPORT_BUILDFLAGS = 1
include /usr/share/dpkg/buildflags.mk
Please fix the issues and maybe also enable the hardened build in debian.
[0] http://lists.debian.org/debian-devel-announce/2011/09/msg00001.html
signature.asc
Description: OpenPGP digital signature
--- End Message ---
--- Begin Message ---
Source: gimmix
Source-Version: 0.5.7.1-4
We believe that the bug you reported is fixed in the latest version of
gimmix, which is due to be installed in the Debian FTP archive:
gimmix_0.5.7.1-4.debian.tar.gz
to main/g/gimmix/gimmix_0.5.7.1-4.debian.tar.gz
gimmix_0.5.7.1-4.dsc
to main/g/gimmix/gimmix_0.5.7.1-4.dsc
gimmix_0.5.7.1-4_amd64.deb
to main/g/gimmix/gimmix_0.5.7.1-4_amd64.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Vincent Legout <[email protected]> (supplier of updated gimmix package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Sat, 24 Mar 2012 15:00:43 +0100
Source: gimmix
Binary: gimmix
Architecture: source amd64
Version: 0.5.7.1-4
Distribution: unstable
Urgency: low
Maintainer: mpd maintainers <[email protected]>
Changed-By: Vincent Legout <[email protected]>
Description:
gimmix - graphical music player daemon (MPD) client using GTK+2
Closes: 646261
Changes:
gimmix (0.5.7.1-4) unstable; urgency=low
.
* Use my debian.org email address
* Update to debhelper 9 (debian/compat, debhelper Build-Depends)
* debian/rules: Enable all hardening flags
* ftbfs-hardening.patch: Added, fix ftbfs with -Werror=format-security
(Closes: #646261)
* fix_curl_segfault.patch: Added, fix segfault
* Standards-Version 3.9.3 (No changes)
Checksums-Sha1:
8f25f4ccf040b4d35c10f8095259b32b43a0ebef 1971 gimmix_0.5.7.1-4.dsc
07922452416a9c06c4208dc3f354eca8d8087dc5 5760 gimmix_0.5.7.1-4.debian.tar.gz
1ff57973d76af43aed28eb99a23a2681ede006ce 120488 gimmix_0.5.7.1-4_amd64.deb
Checksums-Sha256:
2c7a834e632148596ea8b1d168c144188c7b8e9812d5cc3024236c2489902233 1971
gimmix_0.5.7.1-4.dsc
5d108bc839834ac5748b94e1ee6ad7ba37b59a09f76707b10218285d2663302b 5760
gimmix_0.5.7.1-4.debian.tar.gz
09006c6a53f64b828b808f786dac1205ffafb933f4b98357ae4177e090fbfbc5 120488
gimmix_0.5.7.1-4_amd64.deb
Files:
93c01e780bc9e255df6e60c470162b7d 1971 sound optional gimmix_0.5.7.1-4.dsc
1100785668be9293a0dac1ffb3da7da0 5760 sound optional
gimmix_0.5.7.1-4.debian.tar.gz
e1355b0fc904f9aedfd8639204d2890c 120488 sound optional
gimmix_0.5.7.1-4_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQIcBAEBCAAGBQJPbdcLAAoJEGWYeJBYoj3pg24P/iZE9GlvCsUVfoNf+v2dxoTK
dfH3UE3ZR8xWvUjZ1Cx7sTf5/iCUiH3JydQdkDmkSAnZLkJG8GN6cXzTKDFGRmNp
97Orwxowav+JeiCT3sIcvbpK7ac4kpZBXCo86U4oFMJI5mCKhvye5fnNVkBy+RRM
2HPWPJbpIHjcKw3RDtkxxMqJZKWrCStB8WDYf4fEQZ8vR432BqWXyTenryr7JmtD
WkASHTL14HACu6jMa05fnFKrDvu1/7KkIUK1qEJSkQJGGMxJ3iZXe/PpSB8gR6b+
fO3MXM1DdKo7d4yr8ZDAK3dVAHiVbE0ljFPFKjinKaqSPT32eG5NQ1OMD8S97G2L
VWNLK01FD6u41lHn/Q2AveitQhCGE/mPXxNLlw9chkUF1VoJiZCfkAzAxFs9jIYq
obK9KoeQsq6ItbAnBJRhxKpqbvJbaxxYCD4g1B4ZPQYXgKmOI1aO57P5k1Qho226
kznOUnN9Ehu7IPYQyPy0Aj1+Ewpmuq8VlfZhMDqa2czK218RCMFatbqI6qVZTLDD
eh8688LhpHrmxmyzEWFFzrNye0f2zcaVOox7c66I7AbKnjD+0xKNnPJrQujDvHlM
MNyPqWkyGewrIYrDbNF3VbEPjpiK09G0NeLXMXpwdMSdROpxmNOWGchIhSusMjPz
XGBdwXvUxvzfslvfKUfW
=doF4
-----END PGP SIGNATURE-----
--- End Message ---