Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 432144 (CVE-2012-2120)

Summary: <app-text/texlive-core-2015-r1: Insecure temporary file vulnerability (CVE-2012-2120)
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: aballier, spamfilter-1, tex, toralf
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B3 [noglsa cve]
Package list:
=app-text/texlive-2015 =dev-texlive/texlive-basic-2015 =dev-texlive/texlive-bibtexextra-2015 =dev-texlive/texlive-context-2015 =dev-texlive/texlive-fontsextra-2015 =dev-texlive/texlive-fontsrecommended-2015 =dev-texlive/texlive-fontutils-2015 =dev-texlive/texlive-formatsextra-2015 =dev-texlive/texlive-games-2015 =dev-texlive/texlive-genericextra-2015 =dev-texlive/texlive-genericrecommended-2015 =dev-texlive/texlive-humanities-2015 =dev-texlive/texlive-langafrican-2015 =dev-texlive/texlive-langarabic-2015 =dev-texlive/texlive-langchinese-2015 =dev-texlive/texlive-langcjk-2015 =dev-texlive/texlive-langcyrillic-2015 =dev-texlive/texlive-langczechslovak-2015-r1 =dev-texlive/texlive-langenglish-2015 =dev-texlive/texlive-langeuropean-2015 =dev-texlive/texlive-langfrench-2015 =dev-texlive/texlive-langgerman-2015 =dev-texlive/texlive-langgreek-2015 =dev-texlive/texlive-langindic-2015 =dev-texlive/texlive-langitalian-2015 =dev-texlive/texlive-langjapanese-2015 =dev-texlive/texlive-langkorean-2015 =dev-texlive/texlive-langother-2015 =dev-texlive/texlive-langpolish-2015 =dev-texlive/texlive-langportuguese-2015 =dev-texlive/texlive-langspanish-2015 =dev-texlive/texlive-latexextra-2015-r1 =dev-texlive/texlive-latexrecommended-2015-r1 =dev-texlive/texlive-latex-2015 =dev-texlive/texlive-luatex-2015 =dev-texlive/texlive-mathextra-2015 =dev-texlive/texlive-metapost-2015 =dev-texlive/texlive-music-2015 =dev-texlive/texlive-omega-2015 =dev-texlive/texlive-pictures-2015-r2 =dev-texlive/texlive-plainextra-2015 =dev-texlive/texlive-pstricks-2015 =dev-texlive/texlive-publishers-2015 =dev-texlive/texlive-science-2015 =dev-texlive/texlive-xetex-2015 =dev-libs/kpathsea-6.2.1_p20150521-r2 =dev-libs/ptexenc-1.3.3_p20150521 =app-text/ps2pkm-1.7_p20150521 =app-text/dvipsk-5.995_p20150521 =dev-tex/bibtexu-3.71_p20150521 =app-text/ttf2pk2-2.0_p20150521 =app-text/texlive-core-2015-r1 =app-text/teckit-2.5.6 =dev-tex/pgf-3.0.1 =app-text/xdvik-22.87.03 =dev-tex/tex4ht-20090611_p1038-r4 =dev-tex/cjk-latex-4.8.4
Runtime testing required: ---
Bug Depends on: 604400    
Bug Blocks: 555220, 571330, 594314, 630544, 644388    

Description GLSAMaker/CVETool Bot gentoo-dev 2012-08-20 23:30:52 UTC
CVE-2012-2120 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2120):
  latex2man in texlive-extra-utils 2011.20120322, and possibly other versions
  or packages, when used with the H or T option, allows local users to
  overwrite arbitrary files via a symlink attack on a temporary file.
Comment 1 Yury German Gentoo Infrastructure gentoo-dev 2014-11-23 14:14:38 UTC
Maintainer's does the stable version: 2012-r1 contains the fixes? If so please advise so we can get the bug out.

If it does not have the fix please advise what version is ready to go stable that has the security fixes.

Reference:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=668779
Comment 2 Alexis Ballier gentoo-dev 2014-11-24 09:44:56 UTC
it doesnt seem fixed even in tl 2014; might be worth poking upstream

(bug is really minor i think)
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2016-11-23 01:04:24 UTC
I contacted the author of latex2man.
Comment 4 Alexis Ballier gentoo-dev 2016-12-05 14:36:18 UTC
commit fcf4ed88aa06db4717d827e5586b876fc10f739a
Author: Alexis Ballier <aballier@gentoo.org>
Date:   Mon Dec 5 15:34:47 2016 +0100

    app-text/texlive-core: apply debian patch to fix unsafe /tmp usage. Bug #432144.
    
 


app-text/texlive-core-2015-r1




so, now we should get the whole texlive 2015 stable
Comment 5 Thomas Deutschmann (RETIRED) gentoo-dev 2016-12-05 17:55:36 UTC
@ Maintainer(s): Thank you for the rev bump!

Can you please provide a list of all packages which need to be stabilized? Stabilization will happen in this bug.
Comment 6 Alexis Ballier gentoo-dev 2017-01-16 18:28:06 UTC
(sorry for the noise, I'm trying to see if the stable-bot can help having a proper list)
Comment 7 Alexis Ballier gentoo-dev 2017-01-21 14:10:06 UTC
okey, so here is a complete list of texlive 2015 packages; ccing arches, let's see what the bot finds out
Comment 8 Alexis Ballier gentoo-dev 2017-01-21 14:13:42 UTC
Toralf: the kpathsea version in this list might break building some of its reverse dependencies; could you please check if a stable tree with this package list stable is fine in that regard ?
Comment 9 Toralf Förster gentoo-dev 2017-01-21 14:39:50 UTC
(In reply to Alexis Ballier from comment #8)

I just setup a new stable image (but with gcc-5.40) and the package list will be started with the packages names given in that bug report
Comment 10 Stabilization helper bot gentoo-dev 2017-01-21 15:18:48 UTC
An automated check of this bug failed - repoman reported dependency errors (486 lines truncated): 

> dependency.bad app-text/texlive/texlive-2015.ebuild: RDEPEND: alpha(default/linux/alpha/13.0) ['>=app-text/xdvik-22.87', '>=dev-tex/tex4ht-20090611_p1038-r3']
> dependency.bad app-text/texlive/texlive-2015.ebuild: RDEPEND: alpha(default/linux/alpha/13.0/desktop) ['>=app-text/xdvik-22.87', '>=dev-tex/tex4ht-20090611_p1038-r3']
> dependency.bad app-text/texlive/texlive-2015.ebuild: RDEPEND: alpha(default/linux/alpha/13.0/desktop/gnome) ['>=app-text/xdvik-22.87', '>=dev-tex/tex4ht-20090611_p1038-r3']
> dependency.bad dev-texlive/texlive-pictures/texlive-pictures-2015-r2.ebuild: DEPEND: hppa(default/linux/hppa/13.0) ['>=dev-tex/pgf-3.0.1']
> dependency.bad dev-texlive/texlive-pictures/texlive-pictures-2015-r2.ebuild: RDEPEND: hppa(default/linux/hppa/13.0) ['>=dev-tex/pgf-3.0.1']
> dependency.bad app-text/texlive-core/texlive-core-2015-r1.ebuild: DEPEND: alpha(default/linux/alpha/13.0) ['>=app-text/teckit-2.5.3']
> dependency.bad app-text/texlive-core/texlive-core-2015-r1.ebuild: RDEPEND: alpha(default/linux/alpha/13.0) ['>=app-text/teckit-2.5.3']
> dependency.bad app-text/texlive-core/texlive-core-2015-r1.ebuild: DEPEND: alpha(default/linux/alpha/13.0/desktop) ['>=app-text/teckit-2.5.3']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
Comment 11 Alexis Ballier gentoo-dev 2017-01-21 16:43:37 UTC
Dropping ia64 & sparc for now, we'll need to readd later because of bug #604400
Comment 12 Stabilization helper bot gentoo-dev 2017-01-21 17:15:41 UTC
An automated check of this bug failed - repoman reported dependency errors: 

> dependency.bad app-text/texlive/texlive-2015.ebuild: RDEPEND: hppa(default/linux/hppa/13.0) ['>=dev-tex/cjk-latex-4.8.4']
Comment 13 Alexis Ballier gentoo-dev 2017-01-21 18:56:29 UTC
readding ia64 & sparc:

https://qa-reports.gentoo.org/output/gentoo-ci/3c3d3614d/output.html#app-text/texlive
https://qa-reports.gentoo.org/output/gentoo-ci/3c3d3614d/output.html#app-text/texlive-core


broken deps are already included in that list

so you can just proceed here and remove the mask for bug #604400
Comment 14 Stabilization helper bot gentoo-dev 2017-01-21 19:17:13 UTC
An automated check of this bug failed - repoman reported dependency errors (318 lines truncated): 

> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
Comment 15 Agostino Sarubbo gentoo-dev 2017-01-21 21:41:46 UTC
amd64 stable
Comment 16 Agostino Sarubbo gentoo-dev 2017-01-21 21:54:09 UTC
x86 stable
Comment 17 Stabilization helper bot gentoo-dev 2017-01-21 22:12:15 UTC
An automated check of this bug failed - repoman reported dependency errors (318 lines truncated): 

> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
Comment 18 Tobias Klausmann (RETIRED) gentoo-dev 2017-01-22 08:18:56 UTC
Stable on alpha.
Comment 19 Stabilization helper bot gentoo-dev 2017-01-22 09:11:47 UTC
An automated check of this bug failed - repoman reported dependency errors (318 lines truncated): 

> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
Comment 20 Agostino Sarubbo gentoo-dev 2017-01-22 15:25:23 UTC
ppc stable
Comment 21 Stabilization helper bot gentoo-dev 2017-01-22 16:08:47 UTC
An automated check of this bug failed - repoman reported dependency errors (318 lines truncated): 

> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
Comment 22 Michael Weber (RETIRED) gentoo-dev 2017-01-29 19:49:24 UTC
*** Bug 602426 has been marked as a duplicate of this bug. ***
Comment 23 Jeroen Roovers (RETIRED) gentoo-dev 2017-01-31 15:48:10 UTC
Stable for HPPA.
Comment 24 Stabilization helper bot gentoo-dev 2017-01-31 16:10:26 UTC
An automated check of this bug failed - repoman reported dependency errors (318 lines truncated): 

> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
Comment 25 Michael Weber (RETIRED) gentoo-dev 2017-02-17 07:28:43 UTC
ppc64 stable.
Comment 26 Stabilization helper bot gentoo-dev 2017-02-17 08:06:56 UTC
An automated check of this bug failed - repoman reported dependency errors (318 lines truncated): 

> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
Comment 27 Michael Weber (RETIRED) gentoo-dev 2017-02-20 14:12:13 UTC
arm stable.
Comment 28 Stabilization helper bot gentoo-dev 2017-02-20 15:06:34 UTC
An automated check of this bug failed - repoman reported dependency errors (318 lines truncated): 

> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: ia64(default/linux/ia64/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
Comment 29 Thomas Deutschmann (RETIRED) gentoo-dev 2017-03-05 13:37:07 UTC
Dropping ia64 for the moment which has some problems with Ruby.

Maintainers/ATs can decide to start re-keywording once new texlive has been stabilized and problems for ia64 are resolved.
Comment 30 Stabilization helper bot gentoo-dev 2017-03-05 14:04:51 UTC
An automated check of this bug failed - repoman reported dependency errors (102 lines truncated): 

> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: RDEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langkorean/texlive-langkorean-2015.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: RDEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ps2pkm/ps2pkm-1.7_p20150521.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: RDEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langchinese/texlive-langchinese-2015.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: RDEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/dvipsk/dvipsk-5.995_p20150521.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: RDEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad dev-texlive/texlive-langjapanese/texlive-langjapanese-2015.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-texlive/texlive-langcjk-2015', '>=app-text/texlive-core-2015']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: RDEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
> dependency.bad app-text/ttf2pk2/ttf2pk2-2.0_p20150521.ebuild: DEPEND: sparc(default/linux/sparc/13.0) ['>=dev-libs/kpathsea-6.2.1']
Comment 31 Thomas Deutschmann (RETIRED) gentoo-dev 2017-03-05 14:26:37 UTC
Dropping sparc for the same reason.
Comment 32 Alexis Ballier gentoo-dev 2017-03-05 15:19:52 UTC
(In reply to Thomas Deutschmann from comment #29)
> Dropping ia64 for the moment which has some problems with Ruby.

(In reply to Thomas Deutschmann from comment #31)
> Dropping sparc for the same reason.

Are sparc & ia64 profiles going to be demoted to dev ?

If no, how do you expect cleanup of vulnerable versions to happen ?
Comment 33 Thomas Deutschmann (RETIRED) gentoo-dev 2017-03-06 10:27:56 UTC
(In reply to Alexis Ballier from comment #32)
> (In reply to Thomas Deutschmann from comment #29)
> > Dropping ia64 for the moment which has some problems with Ruby.
> 
> (In reply to Thomas Deutschmann from comment #31)
> > Dropping sparc for the same reason.
> 
> Are sparc & ia64 profiles going to be demoted to dev ?
> 
> If no, how do you expect cleanup of vulnerable versions to happen ?

Council decided in December 2016 to allow security project to drop security coverage for sparc/ia64 if these arches can't keep up.

After talking with both ATs about texlive (well, only Agostino) it became clear that texlive won't go stable on ia64/sparc anytime soon. So it is time to drop the packages for these architectures.

Do whatever works for you: Either drop ia64/sparc keyword, even for already stable texlive package which will be needed for cleanup or apply package.masks to indicate a security problem.
Comment 34 Alexis Ballier gentoo-dev 2017-03-06 10:39:35 UTC
(In reply to Thomas Deutschmann from comment #33)
> Do whatever works for you: Either drop ia64/sparc keyword, even for already
> stable texlive package which will be needed for cleanup or apply
> package.masks to indicate a security problem.

Nothing like this will work. If the profiles remain marked as "stable" this will break all the revdeps needing anything latex, creating fatal repoman warnings for those packages; there are quite a few, even for those arches I think.

You should ask the so-called council to rethink a bit this decision: Either mark those profiles as dev or forget about security cleanup.
Comment 35 Kristian Fiskerstrand (RETIRED) gentoo-dev 2017-03-06 11:12:34 UTC
(In reply to Alexis Ballier from comment #34)
> (In reply to Thomas Deutschmann from comment #33)
> > Do whatever works for you: Either drop ia64/sparc keyword, even for already
> > stable texlive package which will be needed for cleanup or apply
> > package.masks to indicate a security problem.
> 
> Nothing like this will work. If the profiles remain marked as "stable" this
> will break all the revdeps needing anything latex, creating fatal repoman
> warnings for those packages; there are quite a few, even for those arches I
> think.
> 
> You should ask the so-called council to rethink a bit this decision: Either
> mark those profiles as dev or forget about security cleanup.

The latter, cleanup isn't really security critical, so bugs stay open a bit longer, but it doesn't impact user security and can be filtered on by whiteboard keywords. ia64/sparc not being security supported means GLSAs can go out and other processing can be done as usual without waiting for the arches.
Comment 36 Kristian Fiskerstrand (RETIRED) gentoo-dev 2017-03-06 11:17:09 UTC
(In reply to Kristian Fiskerstrand from comment #35)
> (In reply to Alexis Ballier from comment #34)
> > (In reply to Thomas Deutschmann from comment #33)
> > > Do whatever works for you: Either drop ia64/sparc keyword, even for already
> > > stable texlive package which will be needed for cleanup or apply
> > > package.masks to indicate a security problem.
> > 
> > Nothing like this will work. If the profiles remain marked as "stable" this
> > will break all the revdeps needing anything latex, creating fatal repoman
> > warnings for those packages; there are quite a few, even for those arches I
> > think.
> > 
> > You should ask the so-called council to rethink a bit this decision: Either
> > mark those profiles as dev or forget about security cleanup.
> 
> The latter, cleanup isn't really security critical, so bugs stay open a bit
> longer, but it doesn't impact user security and can be filtered on by
> whiteboard keywords. ia64/sparc not being security supported means GLSAs can
> go out and other processing can be done as usual without waiting for the
> arches.

To elaborate, in case it isn't clear from the above. The mask for the package is done by the GLSA in this case, so no external mask necessary (or wanted)
Comment 37 Yury German Gentoo Infrastructure gentoo-dev 2017-04-30 21:01:05 UTC
Maintainer(s), please drop the vulnerable version(s).
Comment 38 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-08-06 14:32:28 UTC
Ping:

No updates since 05/17.

Security Team Padawan
ChrisADR