Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 711908 - dev-dotnet/libgdiplus-6.0.2 stabilisation
Summary: dev-dotnet/libgdiplus-6.0.2 stabilisation
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Stabilization (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: dotnet project
URL:
Whiteboard:
Keywords: STABLEREQ
Depends on:
Blocks: CVE-2019-15133
  Show dependency tree
 
Reported: 2020-03-08 21:28 UTC by Andreas Sturmlechner
Modified: 2020-06-26 13:18 UTC (History)
0 users

See Also:
Package list:
dev-dotnet/libgdiplus-6.0.2 dev-lang/mono-6.6.0.161
Runtime testing required: No
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Sturmlechner gentoo-dev 2020-03-08 21:28:00 UTC
Please consider stabilisation, otherwise this will soon be the only package blocking media-libs/giflib security cleanup.
Comment 1 Andreas Sturmlechner gentoo-dev 2020-03-18 20:34:49 UTC
...actually 5.6.1-r1 is the *only* version depending on old <media-libs/giflib-5.1.9 which is weird, older versions do not restrict in that way.

And it is only ~arch - so please clean up if possible.
Comment 2 Larry the Git Cow gentoo-dev 2020-03-25 21:30:19 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1fa78949e3a48ee281bb462f705debf31b34ac80

commit 1fa78949e3a48ee281bb462f705debf31b34ac80
Author:     Thomas Deutschmann <whissi@gentoo.org>
AuthorDate: 2020-03-25 21:29:04 +0000
Commit:     Thomas Deutschmann <whissi@gentoo.org>
CommitDate: 2020-03-25 21:30:10 +0000

    Revert "media-libs/giflib: security cleanup (bug #711272)"
    
    This reverts commit d5eac496a50b7aeb6e2d156658348ac8cfb505bf.
    
    Bug: https://bugs.gentoo.org/711272
    Bug: https://bugs.gentoo.org/711908
    Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>

 media-libs/giflib/Manifest            |  1 +
 media-libs/giflib/giflib-5.1.4.ebuild | 65 +++++++++++++++++++++++++++++++++++
 2 files changed, 66 insertions(+)
Comment 3 Stabilization helper bot gentoo-dev 2020-03-25 22:00:30 UTC
An automated check of this bug failed - repoman reported dependency errors (36 lines truncated): 

> dependency.bad dev-dotnet/libgdiplus/libgdiplus-6.0.2.ebuild: DEPEND: arm(default/linux/arm/17.0) ['dev-lang/mono']
> dependency.bad dev-dotnet/libgdiplus/libgdiplus-6.0.2.ebuild: DEPEND: ppc64(default/linux/powerpc/ppc64/17.0/64bit-userland) ['dev-lang/mono']
> dependency.bad dev-dotnet/libgdiplus/libgdiplus-6.0.2.ebuild: DEPEND: ppc64(default/linux/powerpc/ppc64/17.0/64bit-userland/desktop) ['dev-lang/mono']
Comment 4 Agostino Sarubbo gentoo-dev 2020-03-27 16:31:38 UTC
x86 stable
Comment 5 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2020-03-31 08:28:15 UTC
amd64 stable
Comment 6 Matt Turner gentoo-dev 2020-04-28 21:18:28 UTC
FWIW, ppc/ppc64 are broken.

ppc fails to build. There's an upstream patch that fixes it, but it doesn't apply to mono-6.6.0.

ppc64 fails mono's tests with what looks to be a scary message.

I assume our one dotnet maintainer is awol?
Comment 7 Andreas Sturmlechner gentoo-dev 2020-05-23 13:03:58 UTC
Safe assumption by now.
Comment 8 Andreas Sturmlechner gentoo-dev 2020-06-26 13:18:00 UTC
Cleanup of old versions was done, abandoning stabilisation.