Your message dated Mon, 23 Jun 2025 14:30:34 +0100
with message-id <26713.22266.696700.127...@chiark.greenend.org.uk>
and subject line Re: Bug#932871: rpush improvements for tag2upload
has caused the Debian Bug report #932871,
regarding rpush improvemnts for tag2upload
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
932871: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=932871
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: dgit-infrastructure
Version: 9.5
User: d...@packages.debian.org
Usertags: rsn

Quoting myself:

   It would probably be worthwhile checking critical fields, so that the
   signer cannot be tricked into signing things that the original
   git-debpush user could not have done.  I looked at the code and I
   think this is
     1 we need a slightly stronger syntax check for the Maintainer
        when we construct the git tagger line
     2 we should cross-check the source package name in all
        relevant places
     3 it would be easy to cross-check the version too.

1 is easy.  2 involves dgit rpush honouring -p.  3 means a new version
option I think.

We should also check the syntax of all the signed things are right.  I
think this means feeding eg buildinfo and changes and dsc to a deb822
parser, which we probably mostly already do.

None of this is particularly difficult.

-- 
Ian Jackson <ijack...@chiark.greenend.org.uk>   These opinions are my own.

If I emailed you from an address @fyvzl.net or @evade.org.uk, that is
a private address which bypasses my fierce spamfilter.

--- End Message ---
--- Begin Message ---
We have done this, I think.

-- 
Ian Jackson <ijack...@chiark.greenend.org.uk>   These opinions are my own.  

Pronouns: they/he.  If I emailed you from @fyvzl.net or @evade.org.uk,
that is a private address which bypasses my fierce spamfilter.

--- End Message ---

Reply via email to