[UVFe] Import firebird2.0 2.0.3.12981.ds1-1 from Debian unstable (main)

Bug #139007 reported by Luca Falavigna
6
Affects Status Importance Assigned to Milestone
firebird2.0 (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Import firebird2.0 2.0.3.12981.ds1-1 from Debian unstable.
Ubuntu component: universe
Debian component: main

Rationale: new upstream version fixes seven security related issues reported in CVE reports, some of them could lead to file access or causing DoS attacks.

No Ubuntu changes.

Debian changelog (since 2.0.1.12855.ds1-7):
firebird2.0 (2.0.3.12981.ds1-1) unstable; urgency=medium

  * New upstream relese-candidate
  * Contains fixes for the following security issues: CVE-2007-3527,
    CVE-2007-4664, CVE-2007-4665, CVE-2007-4666, CVE-2007-4667, CVE-2007-4668,
    CVE-2007-4669.
    (Closes: #441405) -- Several Firebird vulnerabilities discovered
  * Refreshed patches
    cvs-client-crash-on-remote-shutdown.patch
    no-rpath.patch
    link-as-needed
    fix-os-detection.patch
    inet-trust-localhost.patch
    create-run-dir.patch
    use-debian-icu.patch
    use-debian-editline.patch
    cvs-powerpc-double-define.patch
  * Dropped patches not needed any more
    + link-with-g++.patch -- upstream reorg
    + cvs-common_classes_alloc.cpp-unaligned.patch -- included in the
      release
    + cvs-jrd.cpp-crash-on-srervices-and-conventional-api-usage.patch --
      included in the release
    + cvs-sparc-jrd_sort.patch -- included in the release
    + cvs-remote-alignment.patch -- included in the release
  * autoboot.patch -- re-generated
  * Updated debian/get-orig-source.sh
    + use pre-release upstream download area
  * Applied patch to Hungarian translation from Tamas TEVESZ
  * debian/make_packages.sh - deduce upstream version from debian/changelog to
    avoid the need of manually changing a variable after each new upstream
    release
  * Updated debian/watch with new pre-release URLs; more version mangling
  * Dropped unused lintian overrides
  * Drop libgds.so compatibility symlink (upstream dropped it after 1.5)

 -- Damyan Ivanov <email address hidden> Mon, 10 Sep 2007 15:27:59 +0300

firebird2.0 (2.0.1.12855.ds1-9) unstable; urgency=low

  * Build-Depend on libicu36-dev (from libicu34-dev)
  * [clean-after-build.sh] do not remove build_no.h

 -- Damyan Ivanov <email address hidden> Mon, 09 Jul 2007 13:16:03 +0300

firebird2.0 (2.0.1.12855.ds1-8) unstable; urgency=low

  * Detect missing debconf in .postrm/purge and don't remove any
    password/security/database files. Spit messages about that.
    Closes: #431852 depends on non-essential package debconf in postrm
    Thanks to Michael Ablassmeier

 -- Damyan Ivanov <email address hidden> Mon, 09 Jul 2007 13:01:14 +0300

Revision history for this message
Luca Falavigna (dktrkranz) wrote :
Revision history for this message
Luca Falavigna (dktrkranz) wrote :
Revision history for this message
Luca Falavigna (dktrkranz) wrote :
Revision history for this message
Chuck Short (zulcss) wrote :

+1 from me

Revision history for this message
Scott Kitterman (kitterman) wrote :

Ack from me too. Approved.

Changed in firebird2.0:
status: New → Confirmed
Revision history for this message
Andrea Veri (av) wrote :

This package gonna FTBFS on some archs (like sparc and ia64, in debian too[1]), so we need to find out a fix for this, turning this into a merge. Bug assigned to Luca Falavigna.

[1] http://buildd.debian.org/build.php?arch=&pkg=firebird2.0

Changed in firebird2.0:
assignee: nobody → dktrkranz
description: updated
Revision history for this message
Luca Falavigna (dktrkranz) wrote :

Debian package provide port-ia64.patch, which should fix ia64 FTBFS. It is not enabled because Debian Maintainer decided not to enable anymore:
 firebird2.0 (2.0.1.12855.ds1-6) unstable; urgency=low

   * Upload to unstable
     + Stop applying patches for unofficial ports
       (arm, hppa, mips, mipsel, ia64)
     + Update autoboot.patch

 -- Damyan Ivanov <email address hidden> Tue, 15 May 2007 17:49:20 +0300

Anyway, if we look at http://snapshot.debian.net/archive/pool/f/firebird2.0/binary-ia64/Packages.gz, we see ia64 binary packages have been built (at least 2.0.1.12855.ds1-5 did), so it should ok to enable that patch again.

Regarding sparc FTBFS, Andrea checked on sparky and it should be ok now.

Changed in firebird2.0:
assignee: dktrkranz → nobody
Revision history for this message
Daniel Holbach (dholbach) wrote :

Uploading it.

Revision history for this message
Luca Falavigna (dktrkranz) wrote :

firebird2.0 (2.0.3.12981.ds1-1ubuntu1) gutsy; urgency=low

  * Resync with Debian unstable after UVFe approval in LP: #139007
  * Enable port-ia64.patch to avoid FTBFS on ia64
  * Update Maintainer field in debian/control

firebird2.0 (2.0.3.12981.ds1-1) unstable; urgency=medium

  * New upstream relese-candidate
  * Contains fixes for the following security issues: CVE-2007-3527,
    CVE-2007-4664, CVE-2007-4665, CVE-2007-4666, CVE-2007-4667, CVE-2007-4668,
    CVE-2007-4669.
    (Closes: #441405) -- Several Firebird vulnerabilities discovered
  * Refreshed patches
    cvs-client-crash-on-remote-shutdown.patch
    no-rpath.patch
    link-as-needed
    fix-os-detection.patch
    inet-trust-localhost.patch
    create-run-dir.patch
    use-debian-icu.patch
    use-debian-editline.patch
    cvs-powerpc-double-define.patch
  * Dropped patches not needed any more
    + link-with-g++.patch -- upstream reorg
    + cvs-common_classes_alloc.cpp-unaligned.patch -- included in the
      release
    + cvs-jrd.cpp-crash-on-srervices-and-conventional-api-usage.patch --
      included in the release
    + cvs-sparc-jrd_sort.patch -- included in the release
    + cvs-remote-alignment.patch -- included in the release
  * autoboot.patch -- re-generated
  * Updated debian/get-orig-source.sh
    + use pre-release upstream download area
  * Applied patch to Hungarian translation from Tamas TEVESZ
  * debian/make_packages.sh - deduce upstream version from debian/changelog to
    avoid the need of manually changing a variable after each new upstream
    release
  * Updated debian/watch with new pre-release URLs; more version mangling
  * Dropped unused lintian overrides
  * Drop libgds.so compatibility symlink (upstream dropped it after 1.5)

firebird2.0 (2.0.1.12855.ds1-9) unstable; urgency=low

  * Build-Depend on libicu36-dev (from libicu34-dev)
  * [clean-after-build.sh] do not remove build_no.h

firebird2.0 (2.0.1.12855.ds1-8) unstable; urgency=low

  * Detect missing debconf in .postrm/purge and don't remove any
    password/security/database files. Spit messages about that.
    Closes: #431852 depends on non-essential package debconf in postrm
    Thanks to Michael Ablassmeier

 -- Luca Falavigna <email address hidden> Wed, 12 Sep 2007 21:33:14 +0200

Changed in firebird2.0:
status: Confirmed → Fix Released
Revision history for this message
Andrea Veri (av) wrote :

luca, it seems something went wrong on this package while applying patches causing a FTBFS on all archs. Assigning it to you again to find out a fix for this.
Good work.

Changed in firebird2.0:
assignee: nobody → dktrkranz
status: Fix Released → In Progress
Revision history for this message
Andrea Veri (av) wrote :

unsubsribing u-u-s, I'll follow luca on this and sponsor him when a new debdiff will be provided.

Revision history for this message
Andrea Veri (av) wrote :

forgot to say that it keeps FTBFS on sparc, just tested on sparky. (works on debian but not in ubuntu). Luca can you try to find out a fix for this too?

Revision history for this message
Michael Bienia (geser) wrote :

I looked into filing an UVFe for firebird2.0 too, but it failed building on amd64 for me.

You might also want to look on bug #135756 when preparing the next upload.

Revision history for this message
Luca Falavigna (dktrkranz) wrote :

I attach a new debdiff, which fixes previous FTBFS errors and disables sparc build because it requires a porting work in order to be successfully built. amd64 build was fine on my PPA, so it should be ok to upload it.

Changed in firebird2.0:
assignee: dktrkranz → nobody
status: In Progress → Confirmed
Revision history for this message
Andrea Veri (av) wrote :

Uploaded. For now we can keep sparc disabled until we find a good solution to re-enable it in the near future. At least we fix the FTBFS in all archs of firebird2.0 2.0.3.12981.ds1-1ubuntu1 revision. Luca please investigate Bug #135756 and provide a debdiff in case is needed to fix that issue. Thanks for your work.

Revision history for this message
Luca Falavigna (dktrkranz) wrote :

It keeps FTBFS on some ports, but I will manage this issue separately.

Changed in firebird2.0:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.