Control: tags -1 - moreinfo Control: retitle -1 unblock: mbedtls/2.4.2-1 Hi,
On 13/03/17 20:20, Niels Thykier wrote: > James Cowgill: >> Hi, >> >> I am wondering whether it's possible to include mbedtls 2.4.2 in >> stretch. While it does fix an RC security bug (#857560), it also >> contains a lot of other stuff - all of it bugfixes though. [...] > Hi, > > I have reviewed it and I agree that upstream release looks preferable > with one remark: > > * The test suite appears to be "time-bombed" via > "tests/data_files/test-ca2_cat-future-invalid.crt". > * Ideally, the buildability should not expire. > * Furthermore, its "expire" date is "Sep 22 15:49:49 2023" which is > uncomfortably close stretch's expected EOL on the LTS release > (Said EOL is currently estimated to some time in 2022 and counting). Thanks for discovering that! I've adjusted the package to run the testsuite inside faketime until upstream fixes this. > Please resolve that, upload and remove the moreinfo tag once the upload > has been processed and built on all relevant release architectures. Uploaded, and built on all release arches. Thanks, James
signature.asc
Description: OpenPGP digital signature