Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 252912 - app-crypt/pinentry bundles a copy of libassuan
Summary: app-crypt/pinentry bundles a copy of libassuan
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Crypto team [DISABLED]
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: bundled-libs
  Show dependency tree
 
Reported: 2008-12-29 01:12 UTC by Diego Elio Pettenò (RETIRED)
Modified: 2015-09-10 13:02 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
pinentry-0.9.4-r2.ebuild.diff (pinentry-0.9.4-r2.ebuild.diff,951 bytes, patch)
2015-06-18 20:03 UTC, Andreas Sturmlechner
Details | Diff
pinentry-0.9.4-system-libassuan-p1.patch (pinentry-0.9.4-system-libassuan-p1.patch,13.84 KB, patch)
2015-06-18 20:04 UTC, Andreas Sturmlechner
Details | Diff
pinentry-0.9.4-system-libassuan-p2.patch (pinentry-0.9.4-system-libassuan-p2.patch,18.79 KB, patch)
2015-06-18 20:05 UTC, Andreas Sturmlechner
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Diego Elio Pettenò (RETIRED) gentoo-dev 2008-12-29 01:12:12 UTC
And no, it's not linking statically to the system copy, it has its own source files it seems. Fantastic.
Comment 1 Ihar Hrachyshka 2009-08-31 20:45:31 UTC
Why do we provide only static libassuan version? Is there any real problems with linking software with shared libassuan?
Comment 2 Alon Bar-Lev (RETIRED) gentoo-dev 2013-01-12 19:37:36 UTC
Upstream is upstream for both libassuan and pinentry.
No idea why they provide libassuan within pinentry but usage of system libassuan should be supported by upstream first.
Comment 3 Diego Elio Pettenò (RETIRED) gentoo-dev 2013-01-13 14:02:55 UTC
These bugs need to stay open until the problem is solved, whether by upstream or us, because we use the bugs to track issues in case of security bugs.
Comment 4 Alon Bar-Lev (RETIRED) gentoo-dev 2013-01-13 14:06:26 UTC
(In reply to comment #3)
> These bugs need to stay open until the problem is solved, whether by
> upstream or us, because we use the bugs to track issues in case of security
> bugs.

Having a security bug will automatically trigger a CVE for all effected upstream components.

I don't see any reason to keep this open.

But not that it is at any harm.
Comment 5 Andreas Sturmlechner gentoo-dev 2015-06-18 20:03:19 UTC
Created attachment 405346 [details, diff]
pinentry-0.9.4-r2.ebuild.diff

Good news from upstream, bundled assuan was removed per following commit:

http://git.gnupg.org/cgi-bin/gitweb.cgi?p=pinentry.git;a=commit;h=302903f76b8d62b1e07219a203f7219cb3aff7d8
Comment 6 Andreas Sturmlechner gentoo-dev 2015-06-18 20:04:53 UTC
Created attachment 405348 [details, diff]
pinentry-0.9.4-system-libassuan-p1.patch

patch sliced in two halves so repoman is happy.
Comment 7 Andreas Sturmlechner gentoo-dev 2015-06-18 20:05:23 UTC
Created attachment 405350 [details, diff]
pinentry-0.9.4-system-libassuan-p2.patch
Comment 8 Alon Bar-Lev (RETIRED) gentoo-dev 2015-06-18 20:18:48 UTC
Thanks for the heads up!

We will wait for the next release.
Comment 9 Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-06-19 07:38:51 UTC
For tracking reference, the ML discussion on this is at http://lists.gnupg.org/pipermail/gnupg-devel/2015-June/029932.html
Comment 10 Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-09-10 13:02:39 UTC
Closing, this is included in 0.9.5 which is in tree