Package: pass-otp
Version: 1.2.0-5
Severity: serious
User: debian...@lists.debian.org
Usertags: piuparts replaces-without-breaks
Control: affects -1 + pass-extension-otp

Hi,

during a test with piuparts and DOSE tools I noticed your package causes
removal of files that also belong to another package.
This is caused by using Replaces without corresponding Breaks.

The installation sequence to reproduce this problem is

  apt-get install pass-extension-otp/stable
  # (1)
  apt-get install pass-otp/testing
  apt-get remove pass-otp
  # (2)

The list of installed files at points (1) and (2) should be identical,
but the following files have disappeared:

  /usr/lib/password-store/extensions/otp.bash
  /usr/share/bash-completion/completions/pass-otp
  /usr/share/man/man1/pass-otp.1.gz

This is a serious bug violating policy 7.6, see
https://www.debian.org/doc/debian-policy/ch-relationships.html#overwriting-files-and-replacing-packages-replaces
and also see the footnote that describes this incorrect behavior:
https://www.debian.org/doc/debian-policy/ch-relationships.html#id13

The pass-otp package has the following relationships with pass-extension-otp:

  Conflicts: n/a
  Breaks:    n/a
  Replaces:  pass-extension-otp (<< 1.2.0-5~)

>From the attached log (scroll to the bottom...):

0m56.3s ERROR: FAIL: After purging files have disappeared:
  /usr/lib/password-store/extensions/otp.bash    owned by: pass-otp
  /usr/share/bash-completion/completions/pass-otp        owned by: pass-otp
  /usr/share/man/man1/pass-otp.1.gz      owned by: pass-otp

0m56.3s ERROR: FAIL: After purging files have been modified:
  /var/lib/dpkg/info/pass-extension-otp.list     not owned


cheers,

Andreas

Attachment: pass-extension-otp=1.2.0-2_pass-otp=1.2.0-5.log.gz
Description: application/gzip

Reply via email to