[DRE-maint] Bug#653332: thin is unmaintained

2012-01-07 Thread Faidon Liambotis
On Mon, Dec 26, 2011 at 10:04:32PM -0800, Ryan Niebur wrote:
 On Tue, Dec 27, 2011 at 04:44:31AM +0200, Faidon Liambotis wrote:
  The package in its current version works for me. However, I believe it
  is unsuitable for a release (and hence inclusion in testing) as it's
  clearly lacking a maintainer. I'd suggest either to start working on it,
  or O/RFH it.
 
 okay, I will do this.

Do what? I haven't seen a move to either direction.

Regards,
Faidon




___
Pkg-ruby-extras-maintainers mailing list
Pkg-ruby-extras-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-ruby-extras-maintainers


[DRE-maint] Bug#629067: libactionpack-ruby: libactionpack update breaks redmine

2011-09-05 Thread Faidon Liambotis
reassign 629067 libactionpack-ruby
found 629067 rails/2.3.5-1.2+squeeze0.1
severity 629067 grave
thanks

On Fri, Jun 03, 2011 at 12:26:27PM +0200, Vincent-Xavier JUMEL wrote:
 Package: libactionpack-ruby
 Version: 2.3.5-1.2+squeeze0.1
 Severity: normal
 
 libactionpack update breaks redmine user view if hide_mail is not enabled.
 Redmine renderer fails on an inexistant html_safe method
 
 Workaround : change user preference to hidden mail
 psql update user_preference set hide_mail = 't' where hide_mail = 'f' ;

This was reassigned to ruby-actionpack-2.3 (present only in wheezy+) but
it's not really obvious why — no explanative mail was sent to the BTS
and the bug report remains unanswered.

If it affects another package in wheezy, then it should probably be
cloned/reassigned instead.

I'm reassigning it back and changing this severity: this was a security
update that broke an unrelated package (redmine) *in stable*. This is
/not/ acceptable according to the security team's guidelines.

You could say that either the fix should be adapted or that the call
sites (redmine) should be fixed. I'd vote for the first, though, since
we can't really know what else has been broken by this change (in the
archive, let alone user-installed applications...)

In any case, I'm adding redmine maintainers  the security team to the
Cc in case they have something useful to add.

Regards,
Faidon



___
Pkg-ruby-extras-maintainers mailing list
Pkg-ruby-extras-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-ruby-extras-maintainers

[DRE-maint] Bug#610288: thin: ActiveRecord session store doesn't work with Rails

2011-01-16 Thread Faidon Liambotis
Package: thin
Version: 1.2.4-1
Severity: grave
Tags: patch
Justification: renders package unusable

When using Rails, thin ignores the configuration directive of picking
ActiveRecord for a session store and falls back to a CookieStore instead
(which is limited to 4K among other things).

The bug is reported upstream[1] and the trivial one-line fix made it to
1.2.5. I've patched thin locally with the fix there and I confirm that
it fixes the issue.

The problem appears only with Rails = 2.3.5 but this is the version
that is present in the archive right now and will be released with
squeeze.

I presume that the biggest use case of thin is hosting Rails
applications, and hence I'm marking this as grave; feel free to
downgrade if you feel differently.

Regards,
Faidon

1: 
https://thin.lighthouseapp.com/projects/7212/tickets/111-activerecord-session-store-not-creating-new-records-with-thin-124-and-rails-222




___
Pkg-ruby-extras-maintainers mailing list
Pkg-ruby-extras-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/mailman/listinfo/pkg-ruby-extras-maintainers