Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 86547 - glsa-check reports usermode-sources-2.4.26-r13 incorrectly as affected
Summary: glsa-check reports usermode-sources-2.4.26-r13 incorrectly as affected
Status: RESOLVED FIXED
Alias: None
Product: Portage Development
Classification: Unclassified
Component: Tools (show other bugs)
Hardware: All All
: High minor (vote)
Assignee: Portage Tools Team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-03-24 10:16 UTC by Daniel Webert
Modified: 2005-04-30 08:51 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Webert 2005-03-24 10:16:13 UTC
sys-kernel/usermode-sources-2.4.26-r13 causes glsa alarm

if um-src-2.4.26-r13 (stable) is installed, glsa-check says: we have a problem w/ glsa-200403-02

<snip>
Affected package:  sys-kernel/usermode-sources
Affected archs:    All
Vulnerable:        <2.6.3-r1
Unaffected:        =2.4.24-r1 >=2.6.3-r1
</snip>
Comment 1 Daniel Webert 2005-03-24 10:18:57 UTC
glsa-200407-16 is also affected 

<snip>
Affected package:  sys-kernel/usermode-sources
Affected archs:    All
Vulnerable:        <2.6.6-r4
Unaffected:        >=~2.4.24-r6 >=~2.4.26-r3 >=2.6.6-r4
</snip>
Comment 2 Daniel Webert 2005-03-24 10:24:07 UTC
and 200408-24

<snip>
Affected package:  sys-kernel/usermode-sources
Affected archs:    All
Vulnerable:        <2.6.6-r6
Unaffected:        >=~2.4.24-r9 >=~2.4.26-r6 >=2.6.6-r6
</snip>

Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2005-04-02 05:04:03 UTC
Kernel GLSAs are buggy anyway...
I fixed GLSA 200403-02 because 2.4.26 versions were listed as affected while they were not.

That said, the other two GLSAs (200407-16 and 200408-24) are correct so 2.4.26-r13 should show correctly as unaffected on those. Make sure 

(1) you use a recent glsa-check
(2) you don't have any dupe slot affected kernel installed (qpkg -I -d -v | grep usermode-sources)
Comment 4 Daniel Webert 2005-04-02 07:21:02 UTC
1) yes
2) i have installed both 2.4.26-r13 and 2.6.8.1-r9
Comment 5 Thierry Carrez (RETIRED) gentoo-dev 2005-04-03 01:33:09 UTC
Then it's a glsa-check bug... reassigning to the portage tools team.

In the meantime I recommend injecting (--inject) the problematic GLSAs so that they don't show up as affected. 

Please also note that checking kernel GLSAs doesn't make much sense anyway since they check the installed sources and not the running kernel. That's one of many reasons why we are replacing them with a new alert system.
Comment 6 Marius Mauch (RETIRED) gentoo-dev 2005-04-07 20:53:11 UTC
Why do people have to use two-digit revision numbers exposing unbelievingly stupid bugs in my code like using string comparison to compare numbers?
Comment 7 Thierry Carrez (RETIRED) gentoo-dev 2005-04-25 01:47:12 UTC
Marius: does 0.2.1_pre1 fix this one too ?
Comment 8 Marius Mauch (RETIRED) gentoo-dev 2005-04-30 08:51:36 UTC
I think so.