Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 48272 - metabug: glsa-check problems with SLOT and ranges
Summary: metabug: glsa-check problems with SLOT and ranges
Status: RESOLVED FIXED
Alias: None
Product: Portage Development
Classification: Unclassified
Component: Tools (show other bugs)
Hardware: All All
: High minor (vote)
Assignee: Portage Tools Team
URL:
Whiteboard:
Keywords:
: 48766 57133 (view as bug list)
Depends on:
Blocks:
 
Reported: 2004-04-18 15:51 UTC by Rafal Rzepecki
Modified: 2004-12-08 02:21 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Rafal Rzepecki 2004-04-18 15:51:20 UTC
I have Apache 1.3 merged, but glsa-check states that my system is affected by 200403-04 GLSA. This is obviously not true; a line in GLSA says:
Unaffected:        =1.3* >=2.0.49
Comment 1 Marius Mauch (RETIRED) gentoo-dev 2004-04-21 18:14:52 UTC
The problem is more general: if the unaffected range is inside the vulnerable range (as 1.3.* is inside <=2.0.48) glsa-check doesn't use that unaffected range. I'll see if I can find a solution that covers all cases.
Comment 2 Pavel Vondricka 2004-07-30 03:53:02 UTC
I have gentoo-dev-sources-2.6.7-r11, but glsa-check states that my system is affected by 200407-12 GLSA. But a line in GLSA says: Unaffected: >=2.6.7-r7
Comment 3 Geoff Leach 2004-08-11 19:05:19 UTC
Similar for me. glsa-check says 

200407-02 [N] Linux Kernel: Multiple vulnerabilities ( sys-kernel/rsbac-dev-sources sys-kernel/alpha-sources sys-kernel/ck-sources ... )

glsa-check  -d 200407-02 gives

Affected package:  sys-kernel/development-sources
Affected archs:    All
Vulnerable:        <2.6.7

I have development-sources-2.6.7 installed. 

I saw something similar with kdebase, where the version I have installed is not affected, but glsa-check want s to rebuild.
Comment 4 Geoff Leach 2004-08-11 19:26:29 UTC
A bit more searching in the forums and I see that the problem is due to glsa-check not yet handling slots properly. Slots have been a bit of a mystery to me, but I do see that I have several versions of developments-sources and kdebase installed in /var/db/pkg, including versions that are affected. Now I have to work out whether they can be pruned, and more generally have a closer look at slots ...
Comment 5 Marius Mauch (RETIRED) gentoo-dev 2004-08-21 11:54:27 UTC
*** Bug 57133 has been marked as a duplicate of this bug. ***
Comment 6 Marius Mauch (RETIRED) gentoo-dev 2004-08-21 11:54:54 UTC
*** Bug 48766 has been marked as a duplicate of this bug. ***
Comment 7 Marius Mauch (RETIRED) gentoo-dev 2004-12-08 02:21:01 UTC
The unaffected-in-vulnerable range should be fixed in 0.2.0_pre10, the kernel SLOT issue isn't a bug in my eyes.