Package: libhtp-dev,suricata
Version: libhtp-dev/0.5.15-1
Version: suricata/2.0.6-1
Severity: serious
User: trei...@debian.org
Usertags: edos-file-overwrite

Date: 2015-02-18
Architecture: amd64
Distribution: sid

Hi,

automatic installation tests of packages that share a file and at the
same time do not conflict by their package dependency relationships has
detected the following problem:



Extracting templates from packages: 88%
Extracting templates from packages: 100%
Selecting previously unselected package libdb5.3:amd64.
(Reading database ... 10938 files and directories currently installed.)
Preparing to unpack .../libdb5.3_5.3.28-9_amd64.deb ...
Unpacking libdb5.3:amd64 (5.3.28-9) ...
Selecting previously unselected package libgcrypt20:amd64.
Preparing to unpack .../libgcrypt20_1.6.2-4+b1_amd64.deb ...
Unpacking libgcrypt20:amd64 (1.6.2-4+b1) ...
Selecting previously unselected package libgmp10:amd64.
Preparing to unpack .../libgmp10_2%3a6.0.0+dfsg-6_amd64.deb ...
Unpacking libgmp10:amd64 (2:6.0.0+dfsg-6) ...
Selecting previously unselected package libnettle4:amd64.
Preparing to unpack .../libnettle4_2.7.1-5_amd64.deb ...
Unpacking libnettle4:amd64 (2.7.1-5) ...
Selecting previously unselected package libhogweed2:amd64.
Preparing to unpack .../libhogweed2_2.7.1-5_amd64.deb ...
Unpacking libhogweed2:amd64 (2.7.1-5) ...
Selecting previously unselected package libffi6:amd64.
Preparing to unpack .../libffi6_3.1-2+b2_amd64.deb ...
Unpacking libffi6:amd64 (3.1-2+b2) ...
Preparing to unpack .../libp11-kit0_0.20.7-1_amd64.deb ...
Unpacking libp11-kit0:amd64 (0.20.7-1) over (0.18.5-3) ...
Selecting previously unselected package libtasn1-6:amd64.
Preparing to unpack .../libtasn1-6_4.2-2_amd64.deb ...
Unpacking libtasn1-6:amd64 (4.2-2) ...
Selecting previously unselected package libgnutls-deb0-28:amd64.
Preparing to unpack .../libgnutls-deb0-28_3.3.8-5_amd64.deb ...
Unpacking libgnutls-deb0-28:amd64 (3.3.8-5) ...
Selecting previously unselected package libmagic1:amd64.
Preparing to unpack .../libmagic1_1%3a5.22+15-1_amd64.deb ...
Unpacking libmagic1:amd64 (1:5.22+15-1) ...
Selecting previously unselected package libpython2.7-minimal:amd64.
Preparing to unpack .../libpython2.7-minimal_2.7.9-1_amd64.deb ...
Unpacking libpython2.7-minimal:amd64 (2.7.9-1) ...
Selecting previously unselected package python2.7-minimal.
Preparing to unpack .../python2.7-minimal_2.7.9-1_amd64.deb ...
Unpacking python2.7-minimal (2.7.9-1) ...
Selecting previously unselected package python-minimal.
Preparing to unpack .../python-minimal_2.7.8-3_amd64.deb ...
Unpacking python-minimal (2.7.8-3) ...
Selecting previously unselected package mime-support.
Preparing to unpack .../mime-support_3.58_all.deb ...
Unpacking mime-support (3.58) ...
Selecting previously unselected package libexpat1:amd64.
Preparing to unpack .../libexpat1_2.1.0-6+b3_amd64.deb ...
Unpacking libexpat1:amd64 (2.1.0-6+b3) ...
Selecting previously unselected package libpython2.7-stdlib:amd64.
Preparing to unpack .../libpython2.7-stdlib_2.7.9-1_amd64.deb ...
Unpacking libpython2.7-stdlib:amd64 (2.7.9-1) ...
Selecting previously unselected package python2.7.
Preparing to unpack .../python2.7_2.7.9-1_amd64.deb ...
Unpacking python2.7 (2.7.9-1) ...
Selecting previously unselected package libpython-stdlib:amd64.
Preparing to unpack .../libpython-stdlib_2.7.8-3_amd64.deb ...
Unpacking libpython-stdlib:amd64 (2.7.8-3) ...
Processing triggers for man-db (2.7.0.2-5) ...
Setting up libpython2.7-minimal:amd64 (2.7.9-1) ...
Setting up python2.7-minimal (2.7.9-1) ...
Setting up python-minimal (2.7.8-3) ...
Selecting previously unselected package python.
(Reading database ... 11812 files and directories currently installed.)
Preparing to unpack .../python_2.7.8-3_amd64.deb ...
Unpacking python (2.7.8-3) ...
Selecting previously unselected package libcap-ng0:amd64.
Preparing to unpack .../libcap-ng0_0.7.4-2_amd64.deb ...
Unpacking libcap-ng0:amd64 (0.7.4-2) ...
Selecting previously unselected package libjansson4:amd64.
Preparing to unpack .../libjansson4_2.7-1_amd64.deb ...
Unpacking libjansson4:amd64 (2.7-1) ...
Selecting previously unselected package libltdl7:amd64.
Preparing to unpack .../libltdl7_2.4.2-1.11_amd64.deb ...
Unpacking libltdl7:amd64 (2.4.2-1.11) ...
Selecting previously unselected package libluajit-5.1-common.
Preparing to unpack .../libluajit-5.1-common_2.0.3+dfsg-3_all.deb ...
Unpacking libluajit-5.1-common (2.0.3+dfsg-3) ...
Selecting previously unselected package libluajit-5.1-2:amd64.
Preparing to unpack .../libluajit-5.1-2_2.0.3+dfsg-3_amd64.deb ...
Unpacking libluajit-5.1-2:amd64 (2.0.3+dfsg-3) ...
Selecting previously unselected package libnet1:amd64.
Preparing to unpack .../libnet1_1.1.6+dfsg-3_amd64.deb ...
Unpacking libnet1:amd64 (1.1.6+dfsg-3) ...
Selecting previously unselected package libnspr4:amd64.
Preparing to unpack .../libnspr4_2%3a4.10.7-1_amd64.deb ...
Unpacking libnspr4:amd64 (2:4.10.7-1) ...
Selecting previously unselected package libnss3:amd64.
Preparing to unpack .../libnss3_2%3a3.17.2-1.1_amd64.deb ...
Unpacking libnss3:amd64 (2:3.17.2-1.1) ...
Selecting previously unselected package libpcap0.8:amd64.
Preparing to unpack .../libpcap0.8_1.6.2-2_amd64.deb ...
Unpacking libpcap0.8:amd64 (1.6.2-2) ...
Selecting previously unselected package libyaml-0-2:amd64.
Preparing to unpack .../libyaml-0-2_0.1.6-3_amd64.deb ...
Unpacking libyaml-0-2:amd64 (0.1.6-3) ...
Selecting previously unselected package libhtp1.
Preparing to unpack .../libhtp1_0.5.15-1_amd64.deb ...
Unpacking libhtp1 (0.5.15-1) ...
Selecting previously unselected package libprelude2.
Preparing to unpack .../libprelude2_1.0.0-11.4_amd64.deb ...
Unpacking libprelude2 (1.0.0-11.4) ...
Selecting previously unselected package libnetfilter-queue1.
Preparing to unpack .../libnetfilter-queue1_1.0.2-2_amd64.deb ...
Unpacking libnetfilter-queue1 (1.0.2-2) ...
Selecting previously unselected package suricata.
Preparing to unpack .../suricata_2.0.6-1_amd64.deb ...
Unpacking suricata (2.0.6-1) ...
Selecting previously unselected package libhtp-dev.
Preparing to unpack .../libhtp-dev_0.5.15-1_amd64.deb ...
Unpacking libhtp-dev (0.5.15-1) ...
dpkg: error processing archive 
/var/cache/apt/archives/libhtp-dev_0.5.15-1_amd64.deb (--unpack):
 trying to overwrite '/usr/lib/x86_64-linux-gnu/pkgconfig/htp.pc', which is 
also in package suricata 2.0.6-1
dpkg-deb: error: subprocess paste was killed by signal (Broken pipe)
Processing triggers for man-db (2.7.0.2-5) ...
Errors were encountered while processing:
 /var/cache/apt/archives/libhtp-dev_0.5.15-1_amd64.deb
E: Sub-process /usr/bin/dpkg returned an error code (1)


This is a serious bug as it makes installation fail, and violates
sections 7.6.1 and 10.1 of the policy. An optimal solution would
consist in only one of the packages installing that file, and renaming
or removing the file in the other package. Depending on the
circumstances you might also consider Replace relations or file
diversions. If the conflicting situation cannot be resolved then, as a
last resort, the two packages have to declare a mutual
Conflict. Please take into account that Replaces, Conflicts and
diversions should only be used when packages provide different
implementations for the same functionality.

Here is a list of files that are known to be shared by both packages
(according to the Contents file for sid/amd64, which may be
slightly out of sync):

  /usr/include/htp/bstr.h
  /usr/include/htp/bstr_builder.h
  /usr/include/htp/htp.h
  /usr/include/htp/htp_base64.h
  /usr/include/htp/htp_config.h
  /usr/include/htp/htp_connection_parser.h
  /usr/include/htp/htp_core.h
  /usr/include/htp/htp_decompressors.h
  /usr/include/htp/htp_hooks.h
  /usr/include/htp/htp_list.h
  /usr/include/htp/htp_multipart.h
  /usr/include/htp/htp_table.h
  /usr/include/htp/htp_transaction.h
  /usr/include/htp/htp_urlencoded.h
  /usr/include/htp/htp_utf8_decoder.h
  /usr/include/htp/htp_version.h
  /usr/lib/x86_64-linux-gnu/libhtp.a
  /usr/lib/x86_64-linux-gnu/libhtp.so
  /usr/lib/x86_64-linux-gnu/pkgconfig/htp.pc

This bug has been filed against both packages. If you, the maintainers of
the two packages in question, have agreed on which of the packages will
resolve the problem please reassign the bug to that package. You may then
also register in the BTS that the other package is affected by the bug.

-Ralf.

PS: for more information about the detection of file overwrite errors
of this kind see http://edos.debian.net/file-overwrites/.


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to