On 04/05/2023 09.46, Axel Beckert wrote:
So currently the overall impact seems not that big, neither for the bug nor for the proposed fix.
The list of packages using it is short, but the one I encountered it for the first time (pkgconf) has a huge number of rdepends. I'm not sure why it hasn't been caught the first time the new pkgconf was tested ... but then again, I haven't kept an eye on piuparts for a long time ...
But since piuparts might report failures because of that, I do see the reasoning for the RC severity despite the previous bug report was just "normal" — probably the reason why I forgot about it. :-/ Admittedly I'm not keen on modifying debsums behaviour at this stage of the freeze. Then again, your patch is small and clear.
Working around it in piuparts would have been much more involved (or mean disabling the debsums test).
I'll see that I make some testing and then an upload with that patch and request a freeze exception latest at the upcoming weekend.
Thanks. Andreas