hi Tyler, sorry for the long delay! >Thanks for the debdiffs! I'll need a little more info before I seriously begin sponsoring them. Note >that since tcpdump is in main, I'll still need to do my own QA.
sure, no problem (BTW I can upload in main too FWIW) >What investigation did you perform to feel comfortable in disabling the tests that were disabled? short story: the tests are *new* tests, and they need a new pcap to perform correctly (yes, the old pcap will fail and make tcpdump crash in such corner cases, this is the current status quo, and unless you want me to update libpcap won't change) the investigation is: Debian disabled the same tests to the same security uploads, against the same pcap versions (and I confirmed the tests were failing in Ubuntu too) long story: these new tests are e.g. catching some issues with *broken* pcap files, they were discovered after pcap was released, and "fixed" in new pcap versions. Of course they aren't faults in tcpdump, but tcpdump people like to catch them :) Debian usually when a test requires a new libpcap to succeed just bumps the bounds of the required pcap version, and lives happy. In this case we need to revert such bump and avoid such tests. They aren't regressions, probably you can just grab the pcap file from the source code, try to run against them and you will see the same failures. >What amount of testing did you perform? In which Ubuntu releases and in what environment (whether or >not in a VM, the CPU architecture, etc.)? everything is amd64, I did test them on Xenial (my primary system), and tcpdumped my network interface for some time (I can see the packets correctly). I setup a Trusty VM and a Yakkety one to test the same things. Everything has been working correctly. "sudo tcpdump -i interface" is my test. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1662177 Title: tcpdump multiple CVEs To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/tcpdump/+bug/1662177/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs