Your message dated Wed, 28 Feb 2024 11:33:18 +0000
with message-id <[email protected]>
and subject line Bug#1062444: fixed in ima-evm-utils 1.4-1.3
has caused the Debian Bug report #1062444,
regarding ima-evm-utils: NMU diff for 64-bit time_t transition
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1062444: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1062444
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: ima-evm-utils
Version: 1.4-1.2
Severity: serious
Tags: patch pending
Justification: library ABI skew on upgrade
User: [email protected]
Usertags: time-t
Dear maintainer,
As part of the 64-bit time_t transition required to support 32-bit
architectures in 2038 and beyond
(https://wiki.debian.org/ReleaseGoals/64bit-time), we have identified
ima-evm-utils as a source package shipping runtime libraries whose ABI
either is affected by the change in size of time_t, or could not be
analyzed via abi-compliance-checker (and therefore to be on the safe
side we assume is affected).
To ensure that inconsistent combinations of libraries with their
reverse-dependencies are never installed together, it is necessary to
have a library transition, which is most easily done by renaming the
runtime library package.
Since turning on 64-bit time_t is being handled centrally through a change
to the default dpkg-buildflags (https://bugs.debian.org/1037136), it is
important that libraries affected by this ABI change all be uploaded close
together in time. Therefore I have prepared a 0-day NMU for ima-evm-utils
which will initially be uploaded to experimental if possible, then to
unstable after packages have cleared binary NEW.
Please find the patch for this NMU attached.
If you have any concerns about this patch, please reach out ASAP. Although
this package will be uploaded to experimental immediately, there will be a
period of several days before we begin uploads to unstable; so if information
becomes available that your package should not be included in the transition,
there is time for us to amend the planned uploads.
-- System Information:
Debian Release: trixie/sid
APT prefers unstable
APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Kernel: Linux 6.5.0-15-generic (SMP w/8 CPU threads; PREEMPT)
Kernel taint flags: TAINT_OOT_MODULE
Locale: LANG=C, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: unable to detect
diff -Nru ima-evm-utils-1.4/debian/changelog ima-evm-utils-1.4/debian/changelog
--- ima-evm-utils-1.4/debian/changelog 2022-01-24 17:33:09.000000000 +0000
+++ ima-evm-utils-1.4/debian/changelog 2024-02-01 15:02:04.000000000 +0000
@@ -1,3 +1,10 @@
+ima-evm-utils (1.4-1.3) experimental; urgency=medium
+
+ * Non-maintainer upload.
+ * Rename libraries for 64-bit time_t transition.
+
+ -- Graham Inggs <[email protected]> Thu, 01 Feb 2024 15:02:04 +0000
+
ima-evm-utils (1.4-1.2) unstable; urgency=high
* Non-maintainer upload.
diff -Nru ima-evm-utils-1.4/debian/control ima-evm-utils-1.4/debian/control
--- ima-evm-utils-1.4/debian/control 2022-01-24 17:32:41.000000000 +0000
+++ ima-evm-utils-1.4/debian/control 2024-02-01 15:02:04.000000000 +0000
@@ -33,7 +33,10 @@
With EVM, the security sensitive extended attributes are verified against
offline tampering.
-Package: libimaevm2
+Package: libimaevm2t64
+Provides: ${t64:Provides}
+Replaces: libimaevm2
+Breaks: libimaevm2 (<< ${source:Version})
Section: libs
Architecture: any
Multi-Arch: same
@@ -51,7 +54,7 @@
Section: libdevel
Architecture: any
Multi-Arch: same
-Depends: libimaevm2 (= ${binary:Version}), ${misc:Depends}
+Depends: libimaevm2t64 (= ${binary:Version}), ${misc:Depends}
Description: Linux IMA Extended Verification Module signing tools -
development files
Linux kernel integrity subsystem is comprised of a number of different
components including the Integrity Measurement Architecture (IMA), Extended
diff -Nru ima-evm-utils-1.4/debian/libimaevm2.install
ima-evm-utils-1.4/debian/libimaevm2.install
--- ima-evm-utils-1.4/debian/libimaevm2.install 2021-09-24 09:39:11.000000000
+0000
+++ ima-evm-utils-1.4/debian/libimaevm2.install 1970-01-01 00:00:00.000000000
+0000
@@ -1 +0,0 @@
-usr/lib/*/lib*.so.*
diff -Nru ima-evm-utils-1.4/debian/libimaevm2.symbols
ima-evm-utils-1.4/debian/libimaevm2.symbols
--- ima-evm-utils-1.4/debian/libimaevm2.symbols 2022-01-24 09:49:06.000000000
+0000
+++ ima-evm-utils-1.4/debian/libimaevm2.symbols 1970-01-01 00:00:00.000000000
+0000
@@ -1,19 +0,0 @@
-libimaevm.so.3 libimaevm2 #MINVER#
-* Build-Depends-Package: libimaevm-dev
- calc_keyid_v1@Base 1.3.1
- calc_keyid_v2@Base 1.3.1
- hash_algo_name@Base 1.3.1
- ima_calc_hash@Base 1.3.1
- ima_verify_signature@Base 1.3.1
- imaevm_do_hexdump@Base 1.3.1
- imaevm_get_hash_algo@Base 1.3.1
- imaevm_hash_algo_by_id@Base 1.3.1
- imaevm_hash_algo_from_sig@Base 1.3.1
- imaevm_hexdump@Base 1.3.1
- imaevm_params@Base 1.3.1
- init_public_keys@Base 1.3.1
- key2bin@Base 1.3.1
- read_pub_key@Base 1.3.1
- read_pub_pkey@Base 1.3.1
- sign_hash@Base 1.3.1
- verify_hash@Base 1.3.1
diff -Nru ima-evm-utils-1.4/debian/libimaevm2t64.install
ima-evm-utils-1.4/debian/libimaevm2t64.install
--- ima-evm-utils-1.4/debian/libimaevm2t64.install 1970-01-01
00:00:00.000000000 +0000
+++ ima-evm-utils-1.4/debian/libimaevm2t64.install 2021-09-24
09:39:11.000000000 +0000
@@ -0,0 +1 @@
+usr/lib/*/lib*.so.*
diff -Nru ima-evm-utils-1.4/debian/libimaevm2t64.lintian-overrides
ima-evm-utils-1.4/debian/libimaevm2t64.lintian-overrides
--- ima-evm-utils-1.4/debian/libimaevm2t64.lintian-overrides 1970-01-01
00:00:00.000000000 +0000
+++ ima-evm-utils-1.4/debian/libimaevm2t64.lintian-overrides 2024-02-01
15:02:04.000000000 +0000
@@ -0,0 +1 @@
+libimaevm2t64: package-name-doesnt-match-sonames libimaevm2
diff -Nru ima-evm-utils-1.4/debian/libimaevm2t64.symbols
ima-evm-utils-1.4/debian/libimaevm2t64.symbols
--- ima-evm-utils-1.4/debian/libimaevm2t64.symbols 1970-01-01
00:00:00.000000000 +0000
+++ ima-evm-utils-1.4/debian/libimaevm2t64.symbols 2024-02-01
15:02:04.000000000 +0000
@@ -0,0 +1,19 @@
+libimaevm.so.3 libimaevm2t64 #MINVER#
+* Build-Depends-Package: libimaevm-dev
+ calc_keyid_v1@Base 1.3.1
+ calc_keyid_v2@Base 1.3.1
+ hash_algo_name@Base 1.3.1
+ ima_calc_hash@Base 1.3.1
+ ima_verify_signature@Base 1.3.1
+ imaevm_do_hexdump@Base 1.3.1
+ imaevm_get_hash_algo@Base 1.3.1
+ imaevm_hash_algo_by_id@Base 1.3.1
+ imaevm_hash_algo_from_sig@Base 1.3.1
+ imaevm_hexdump@Base 1.3.1
+ imaevm_params@Base 1.3.1
+ init_public_keys@Base 1.3.1
+ key2bin@Base 1.3.1
+ read_pub_key@Base 1.3.1
+ read_pub_pkey@Base 1.3.1
+ sign_hash@Base 1.3.1
+ verify_hash@Base 1.3.1
--- End Message ---
--- Begin Message ---
Source: ima-evm-utils
Source-Version: 1.4-1.3
Done: Lukas Märdian <[email protected]>
We believe that the bug you reported is fixed in the latest version of
ima-evm-utils, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Lukas Märdian <[email protected]> (supplier of updated ima-evm-utils package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 28 Feb 2024 11:04:14 +0000
Source: ima-evm-utils
Architecture: source
Version: 1.4-1.3
Distribution: unstable
Urgency: medium
Maintainer: Dmitry Baryshkov <[email protected]>
Changed-By: Lukas Märdian <[email protected]>
Closes: 1062444
Changes:
ima-evm-utils (1.4-1.3) unstable; urgency=medium
.
* Non-maintainer upload.
* Rename libraries for 64-bit time_t transition. Closes: #1062444
Checksums-Sha1:
807bfff42fc86d93affd9231ffe3ad9b1281aec6 2150 ima-evm-utils_1.4-1.3.dsc
93ff3d020f8f4aa758268db6b3341a37cd85b1da 6068
ima-evm-utils_1.4-1.3.debian.tar.xz
cce36a04fac01b7d821052b7df169d1196e1cfbd 7263
ima-evm-utils_1.4-1.3_source.buildinfo
Checksums-Sha256:
b65f4990011a260c6b8b4f6fc1ccc9f13dc9f6a4cb25843bbd1f5aeac318691e 2150
ima-evm-utils_1.4-1.3.dsc
3959090bad780223a3c932e470568a04b2b45d868b08ae62eeff0a4e96325de7 6068
ima-evm-utils_1.4-1.3.debian.tar.xz
2515348a458c5a899a60dec90216a254cbb38ebb9f021ee8131f9372be0c9894 7263
ima-evm-utils_1.4-1.3_source.buildinfo
Files:
08142c158108d827424497a1a6df45ca 2150 utils optional ima-evm-utils_1.4-1.3.dsc
d8edf8472e5134d74079a1d4a21c2aee 6068 utils optional
ima-evm-utils_1.4-1.3.debian.tar.xz
20f1186b67c98ed061b7f4741ab1d888 7263 utils optional
ima-evm-utils_1.4-1.3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJFBAEBCgAvFiEE496GmCL5m2y8NfJ5v322IrMDrIsFAmXfE0IRHHNseW9uQGRl
Ymlhbi5vcmcACgkQv322IrMDrItBdxAAjHoUiILgza9U+loJqihkqMgyio7/me8e
As0XmWemhDC4JKq4IYtWPAljgHamNfq+HlvtEhrWbcve+GmcPdD69s4KbSGOloT5
Txzrzl8c30A2xfUtkxc0knKZmFPdZjK0GQgIP6a9LIekXxt/P3F8qnvdqDs0sbrq
hakQ6XSwiP1dihR3ilzi0BQZwX6AxBAXc8dvRkRkjnxGxuptu5dIcPgGV0YZaLzD
32XDltfGty3KVKrSZy19bDtoQLDYF1gvhPFkX3NskFVgVttTs6PqzPXMgOo04Cg5
EpFqW3vzs/Te4Pllzhf566LMG1TAvbHLInzFSMJ6F05hcOtMff1DRD6dEUqJR9f7
89E33sKnSbgMYvRMeBZus5bIBAUXKVNSnFGDPvJJkNsLLwQCzXsqtXyA3daqp8Cw
+SmxeKUk6dAbhuBFPvYH/z0tWBpwil4/yfd2EyteowG4+EI3mVnkd+DnprBbbCo/
IAyn247EB56D3yks0AXIfACVIUhFbkyXYvnF+KdIhQx22gWIs4q1qk0xJbbartU6
p4yY4pWY6rAhXfMm/O0olH++GhTApOszo1sLCZGOxMGQkL4bUEiMlIZwEPmAxl1z
crzp2PmGqnHnFvYr+DnQ2aquInEvMM0M66+9snKCnSYVEeJrAafYGXueGkbu83pC
x+hEVoiqkCo=
=gxRD
-----END PGP SIGNATURE-----
pgpig0f_e0TZ6.pgp
Description: PGP signature
--- End Message ---