First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 189440
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Christian Hartmann <ian@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
perl-info output of perl-info text/plain Christoph Mende 2007-08-23 20:42 0000 3.36 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 189440 depends on: Show dependency tree
Bug 189440 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-08-19 09:42 0000
Notes:
* Major changes in release 0.32 (2007-08-15)

** Security fix
  Fix a possible race condition on a file created in /tmp.

app-text/po4a-0.32 is in portage now.

Security please advice. Thanks in advance!

------- Comment #1 From Stefan Cornelius (RETIRED) 2007-08-19 18:56:58 0000 -------
Thanks ian. arches, please test and mark stable if this suits your current
tree.

------- Comment #2 From Jeroen Roovers 2007-08-19 19:59:55 0000 -------
Stable for HPPA.

Seems like a couple of arches are missing in the CC field.

------- Comment #3 From Ferris McCormick 2007-08-19 20:37:04 0000 -------
Sparc stable --- all 134 tests pass and it creates its translations
successfully, installs as expected.

------- Comment #4 From Markus Ullmann 2007-08-21 12:18:42 0000 -------
On x86 I get this:

Safe to ignore?


t/20-sgml.............
#   Failed test 'normalisation test returns what is expected'
#   at t/20-sgml.t line 65.
# Failed (retval=256) on:
# diff -u  -I '^# SOME' -I '^# Test' -I '^"POT-Creation-Date: ' -I
'^"Content-Transfer-Encoding:' data-20/test2.pot tmp/po4a-normalize.po&& diff
-u  -I '^# SOME' -I '^# Test' -I '^"POT-Creation-Date: ' -I
'^"Content-Transfer-Encoding:' data-20/test2-normalized.sgml
tmp/po4a-normalize.output
# Was created with:
# perl -I../lib cd tmp && perl ../../po4a-normalize -f sgml
../data-20/test2.sgml
# Looks like you failed 1 test of 4.
dubious
        Test returned status 1 (wstat 256, 0x100)
DIED. FAILED test 4
        Failed 1/4 tests, 75.00% okay
t/21-dia..............ok
t/23-man..............ok
t/24-tex..............ok
t/25-xhtml............ok
t/26-ini..............ok
t/27-xml..............ok
Failed Test Stat Wstat Total Fail  List of Failed
-------------------------------------------------------------------------------
t/20-sgml.t    1   256     4    1  4
Failed 1/12 test scripts. 1/134 subtests failed.
Files=12, Tests=134, 14 wallclock secs (11.17 cusr +  2.26 csys = 13.43 CPU)
Failed 1/12 test programs. 1/134 subtests failed.

!!! ERROR: app-text/po4a-0.32 failed.
Call stack:
  ebuild.sh, line 1638:   Called dyn_test
  ebuild.sh, line 1047:   Called qa_call 'src_test'
  ebuild.sh, line 44:   Called src_test
  ebuild.sh, line 1328:   Called perl-module_src_test
  perl-module.eclass, line 155:   Called die

!!! test failed
!!! If you need support, post the topmost build error, and the call stack if
relevant.
!!! A complete build log is located at
'/var/log/portage/app-text:po4a-0.32:20070821-115122.log'.

+w+ emerge returned 1
+m+ all done
(tinderbox) localhost / #       

------- Comment #5 From Christoph Mende 2007-08-22 23:05:45 0000 -------
same test failures on amd64

------- Comment #6 From Pierre-Yves Rofes 2007-08-23 09:51:22 0000 -------
uncalling arches until this gets fixed, and cc'ing herd. Perl please advise.

------- Comment #7 From Christian Hartmann 2007-08-23 19:40:02 0000 -------
I'm unable to reproduce this error on any of my boxes.

Markus, Christoph:
Could you please provide the output of `perl-info` (you'd probably need to
emerge it first)?

------- Comment #8 From Christoph Mende 2007-08-23 20:42:52 0000 -------
Created an attachment (id=129007) [edit]
output of perl-info

------- Comment #9 From Christian Hartmann 2007-08-25 11:37:42 0000 -------
I'm now able to reproduce this bug and I've spend some time looking into it but
cannot explain what actually is causing this odd behaviour.

About to contact upstream.

------- Comment #10 From Christian Hartmann 2007-08-25 17:56:07 0000 -------
Could you please confirm that the tests now work fine in 0.32-r1?

------- Comment #11 From Christoph Mende 2007-08-25 18:04:04 0000 -------
test suite passes with -r1, amd64 stable

------- Comment #12 From Christian Hartmann 2007-08-26 15:09:26 0000 -------
Arches please stable app-text/po4a-0.32-r1.

------- Comment #13 From Pierre-Yves Rofes 2007-08-27 09:33:27 0000 -------
amd64 is already stable.

------- Comment #14 From Ferris McCormick 2007-08-27 11:46:28 0000 -------
Sparc stable (tests run successfully, and it can build itself).

------- Comment #15 From Jeroen Roovers 2007-08-27 20:57:26 0000 -------
Stable for HPPA.

------- Comment #16 From Markus Ullmann 2007-08-27 22:39:25 0000 -------
Stable on x86

------- Comment #17 From Pierre-Yves Rofes 2007-09-08 15:58:51 0000 -------
err, seems that some arches don't have a stable fixed version while they have a
vulnerable stable version. That's not too annoying since they aren't security
supported, but cc'ing so they can stable it eventually.

------- Comment #18 From Raúl Porcel 2007-09-13 17:20:50 0000 -------
I stabilized this the other day on ia64

------- Comment #19 From Raphael Marichez 2007-09-14 21:24:13 0000 -------
it's GLSA 200709-04. Thanks everybody.

arm, s390, feel free to stabilize whenever you want

First Last Prev Next    No search results available      Search page      Enter new bug