Your message dated Thu, 28 Feb 2019 01:06:22 +0000
with message-id <[email protected]>
and subject line Bug#923421: fixed in sogo 4.0.7-1
has caused the Debian Bug report #923421,
regarding start-stop-daemon: matching only on non-root pidfile 
/run/sogo/sogo.pid is insecure
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
923421: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=923421
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: sogo
Version: 4.0.5-3
Severity: important

Dear Maintainer,

i just ran in a problem which was already reported on other packages (#921557 
and #921016).
When i try to restart or stop sogod the initscript throws an error message as 
seen in the subject
and ceases to operate.

The attached patch resembles the solution of #921016 and works for me.

In other notes: The severity should probably really be "serious", but i could 
not easily find out 
how to feed it to the BTS.

Thanks for your good work,
niels
 

-- System Information:
Debian Release: buster/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 4.19.0-2-amd64 (SMP w/2 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8), 
LANGUAGE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: sysvinit (via /sbin/init)

Versions of packages sogo depends on:
ii  adduser               3.118
ii  gnustep-base-runtime  1.26.0-4
ii  libc6                 2.28-7
ii  libcurl3-gnutls       7.64.0-1
ii  libgcc1               1:8.2.0-21
ii  libglib2.0-0          2.58.3-1
ii  libgnustep-base1.26   1.26.0-4
ii  libgnutls30           3.6.6-2
ii  liblasso3             2.6.0-2+b2
ii  libmemcached11        1.0.18-4.2
ii  libobjc4              8.2.0-21
ii  libsbjson2.3          2.3.2-4+b1
ii  libsope1              4.0.5-2
ii  lsb-base              10.2018112800
ii  memcached             1.5.6-1
ii  sogo-common           4.0.5-3
ii  tmpreaper             1.6.14
ii  zip                   3.0-11+b1

sogo recommends no packages.

Versions of packages sogo suggests:
pn  postgresql | default-mysql-server | virtual-mysql-server  <none>

-- Configuration Files:
/etc/init.d/sogo changed [not included]
/etc/sogo/sogo.conf [not included] 

-- no debconf information
diff -u orig/debian/sogo.init patch/debian/sogo.init
--- orig/debian/sogo.init       2019-02-27 22:13:00.809760064 +0100
+++ patch/debian/sogo.init      2019-02-27 22:17:41.581975621 +0100
@@ -74,12 +74,12 @@
        ;;
   stop)
        log_daemon_msg "Stopping $DESC" "$NAME"
-       start-stop-daemon --stop --oknodo --pidfile $PIDFILE 
--retry=TERM/20/KILL/5
+       start-stop-daemon --stop --oknodo --pidfile $PIDFILE 
--retry=TERM/20/KILL/5 --user $USER
        log_end_msg 0
        ;;
   restart|force-reload)
        log_daemon_msg "Restarting $DESC" "$NAME"
-       start-stop-daemon --stop --oknodo --pidfile $PIDFILE 
--retry=TERM/20/KILL/5
+       start-stop-daemon --stop --oknodo --pidfile $PIDFILE 
--retry=TERM/20/KILL/5 --user $USER
         # Ensure run directory's existence and permissions
        if [ ! -d /run/sogo ]; then
             install -o $USER -g $GROUP -d /run/sogo

--- End Message ---
--- Begin Message ---
Source: sogo
Source-Version: 4.0.7-1

We believe that the bug you reported is fixed in the latest version of
sogo, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jordi Mallach <[email protected]> (supplier of updated sogo package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 28 Feb 2019 01:43:48 +0100
Source: sogo
Architecture: source
Version: 4.0.7-1
Distribution: unstable
Urgency: medium
Maintainer: Debian SOGo Maintainers 
<[email protected]>
Changed-By: Jordi Mallach <[email protected]>
Closes: 923421
Changes:
 sogo (4.0.7-1) unstable; urgency=medium
 .
   * New upstream release.
   * Fix stop and restart operations in init script. (Closes: #923421)
   * Mark sogo-common as M-A: foreign.
   * Update source lintian-overrides.
Checksums-Sha1:
 5d3389d589270e5c8e48dfbffc50e7eceb05f6e4 2135 sogo_4.0.7-1.dsc
 70993f335a1aa685721efa6dc2830a9f0a85b39f 34561851 sogo_4.0.7.orig.tar.gz
 0021b8e3faa8a12b5ea920aa07417ce21ecb90ea 15320 sogo_4.0.7-1.debian.tar.xz
 dd6f45d179d9c4331d9aa1e2915681f2cac54c61 7270 sogo_4.0.7-1_source.buildinfo
Checksums-Sha256:
 080254e8a3fbc985e72615bb3ca079e577a693fcc2c21cde353f82a20c4d4a61 2135 
sogo_4.0.7-1.dsc
 da75a51c38d8e34c4df7af0d643f1780a0ef8cacfa81b50028a8af9510cc0efd 34561851 
sogo_4.0.7.orig.tar.gz
 00d17347ddbc567cba11efdeebba6e28c6266877ab21af635c5f21276a1f9586 15320 
sogo_4.0.7-1.debian.tar.xz
 d6819dcdfc45ccea5e06bb6409388bf29e132fa611356d34c9510ec8e3f744a2 7270 
sogo_4.0.7-1_source.buildinfo
Files:
 c11bf7e9b60cea927d4a7e609d14c01d 2135 mail optional sogo_4.0.7-1.dsc
 9528263eb8f13cee637ff869ca21d81c 34561851 mail optional sogo_4.0.7.orig.tar.gz
 2d3f57fff7b71318e04db31472b0bd7a 15320 mail optional sogo_4.0.7-1.debian.tar.xz
 17a809b89b36226dc9c97f1c314cb472 7270 mail optional 
sogo_4.0.7-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJFBAEBCgAvFiEE6BdUhsApKYN8KGoWJVAvb8vjywQFAlx3Ly8RHGpvcmRpQGRl
Ymlhbi5vcmcACgkQJVAvb8vjywT2CA/9FgyRWUBVl29d0EWx/m9rl8bp3ogtqAIO
DgS7xYXaBbqKL3rV4BnszxrI53hkowSb34vn298miVUajbFNaRiiyguWatJutBSC
0SXhvQ/Uflqu7Nvq5NeXYsG3myjKEB3iZApbRoFBshzr/Jgbp+Ik5PwCB4QLJB/7
Tba8e+n+AZu63mY1mpwm5N49AOinDY20kNyN5ltW+3yEGzat70dSRzivBCPsJ29Y
gQKKNdElsFLcryaj6KKo4AzncE5WLqGlA9BIkwPpJV7+TSLqY8Rzj7AsBk/gdLiW
Eh0695e6APK90xXYlj/OEH4DtR0J2UrcM0c9skXWP08XEDo83lgjUR/MijPhr4JC
V1DcSL4TaALrel3/agUupUg/c6KnjjM0CFpiUdkaK44y69PJmpLwXxgPDHQMo5Pi
EooW38Oxq/h7Tyo6GW64iSBVcKrWCDtWnRULIN/N7c97kBGfVzPNj2BnHzJSxkr6
+phCtZJmUPwSd/gpQwB1pHKLKNZBaIVBrW/x+yQBxgAHoIO6elYbNC2iejsqY6pm
PPRJTTAqrNBFZZOQ8av1t7XVnCJDr9Zw78apMJKgMCvFs7gnEXTBzwGk8fRd4Drv
QlYZI2o6PnTHPUVD5ib3JEAdTPvzK3Gnxxf9OGIsq02q+UXUBtXSRMpUJDqlAyrr
XJfC6o5D+xc=
=Osvc
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to