Source: libfcgi Version: 2.4.2-2 Severity: serious Tags: patch pending Justification: library ABI skew on upgrade User: debian-...@lists.debian.org Usertags: time-t
Dear maintainer, As part of the 64-bit time_t transition required to support 32-bit architectures in 2038 and beyond (https://wiki.debian.org/ReleaseGoals/64bit-time), we have identified libfcgi as a source package shipping runtime libraries whose ABI either is affected by the change in size of time_t, or could not be analyzed via abi-compliance-checker (and therefore to be on the safe side we assume is affected). To ensure that inconsistent combinations of libraries with their reverse-dependencies are never installed together, it is necessary to have a library transition, which is most easily done by renaming the runtime library package. Since turning on 64-bit time_t is being handled centrally through a change to the default dpkg-buildflags (https://bugs.debian.org/1037136), it is important that libraries affected by this ABI change all be uploaded close together in time. Therefore I have prepared a 0-day NMU for libfcgi which will initially be uploaded to experimental if possible, then to unstable after packages have cleared binary NEW. Please find the patch for this NMU attached. If you have any concerns about this patch, please reach out ASAP. Although this package will be uploaded to experimental immediately, there will be a period of several days before we begin uploads to unstable; so if information becomes available that your package should not be included in the transition, there is time for us to amend the planned uploads. -- System Information: Debian Release: trixie/sid APT prefers unstable APT policy: (500, 'unstable'), (500, 'testing'), (1, 'experimental') Architecture: amd64 (x86_64) Kernel: Linux 6.5.0-14-generic (SMP w/12 CPU threads; PREEMPT) Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE Locale: LANG=C, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set Shell: /bin/sh linked to /usr/bin/dash Init: systemd (via /run/systemd/system)
diff -Nru libfcgi-2.4.2/debian/changelog libfcgi-2.4.2/debian/changelog --- libfcgi-2.4.2/debian/changelog 2020-01-01 00:00:01.000000000 +0000 +++ libfcgi-2.4.2/debian/changelog 2024-02-01 00:25:42.000000000 +0000 @@ -1,3 +1,10 @@ +libfcgi (2.4.2-2.1) experimental; urgency=medium + + * Non-maintainer upload. + * Rename libraries for 64-bit time_t transition. + + -- Steve Langasek <vor...@debian.org> Thu, 01 Feb 2024 00:25:42 +0000 + libfcgi (2.4.2-2) unstable; urgency=medium * Move to unstable: no changes required. diff -Nru libfcgi-2.4.2/debian/control libfcgi-2.4.2/debian/control --- libfcgi-2.4.2/debian/control 2020-01-01 00:00:01.000000000 +0000 +++ libfcgi-2.4.2/debian/control 2024-02-01 00:25:42.000000000 +0000 @@ -12,7 +12,7 @@ Package: libfcgi-dev Section: libdevel Architecture: any -Depends: libfcgi0ldbl (= ${binary:Version}), ${misc:Depends} +Depends: libfcgi0t64 (= ${binary:Version}), ${misc:Depends} Multi-Arch: same Description: header files of FastCGI FastCGI is a language independent, scalable, open extension @@ -22,13 +22,15 @@ This package contains the header files, symlinks and static libraries which are needed to develop applications based on libfcgi. -Package: libfcgi0ldbl -Provides: libfcgi +Package: libfcgi0t64 +Breaks: libfcgi0ldbl (<< ${source:Version}) +Provides: libfcgi, ${t64:Provides} +X-Time64-Compat: libfcgi0ldbl Architecture: any Depends: ${shlibs:Depends}, ${misc:Depends} Recommends: libfcgi-bin (= ${binary:Version}) Conflicts: libfcgi0, libfcgi0c2 -Replaces: libfcgi0, libfcgi0c2 +Replaces: libfcgi0ldbl, libfcgi0, libfcgi0c2 Multi-Arch: same Description: shared library of FastCGI FastCGI is a language independent, scalable, open extension @@ -41,8 +43,8 @@ Section: utils Architecture: any Depends: ${shlibs:Depends}, ${misc:Depends} -Breaks: libfcgi0ldbl (<< 2.4.0-8.4) -Replaces: libfcgi0ldbl (<< 2.4.0-8.4) +Breaks: libfcgi0t64 (<< 2.4.0-8.4) +Replaces: libfcgi0t64 (<< 2.4.0-8.4) Multi-Arch: foreign Description: FastCGI bridge from CGI FastCGI is a language independent, scalable, open extension diff -Nru libfcgi-2.4.2/debian/libfcgi0ldbl.install libfcgi-2.4.2/debian/libfcgi0ldbl.install --- libfcgi-2.4.2/debian/libfcgi0ldbl.install 2020-01-01 00:00:01.000000000 +0000 +++ libfcgi-2.4.2/debian/libfcgi0ldbl.install 1970-01-01 00:00:00.000000000 +0000 @@ -1 +0,0 @@ -usr/lib/*/lib*.so.* diff -Nru libfcgi-2.4.2/debian/libfcgi0ldbl.lintian-overrides libfcgi-2.4.2/debian/libfcgi0ldbl.lintian-overrides --- libfcgi-2.4.2/debian/libfcgi0ldbl.lintian-overrides 2020-01-01 00:00:01.000000000 +0000 +++ libfcgi-2.4.2/debian/libfcgi0ldbl.lintian-overrides 1970-01-01 00:00:00.000000000 +0000 @@ -1,6 +0,0 @@ -# There is no need to split this package to multiple ones: -libfcgi0ldbl: package-name-doesnt-match-sonames libfcgi++0 libfcgi0 - -# Active phase of library development passed long time ago. Now it is just in -# passively maintenance mode without changing of API and ABI. -libfcgi0ldbl: no-symbols-control-file usr/lib/x86_64-linux-gnu/libfcgi*.so.0.0.0 diff -Nru libfcgi-2.4.2/debian/libfcgi0t64.install libfcgi-2.4.2/debian/libfcgi0t64.install --- libfcgi-2.4.2/debian/libfcgi0t64.install 1970-01-01 00:00:00.000000000 +0000 +++ libfcgi-2.4.2/debian/libfcgi0t64.install 2020-01-01 00:00:01.000000000 +0000 @@ -0,0 +1 @@ +usr/lib/*/lib*.so.* diff -Nru libfcgi-2.4.2/debian/libfcgi0t64.lintian-overrides libfcgi-2.4.2/debian/libfcgi0t64.lintian-overrides --- libfcgi-2.4.2/debian/libfcgi0t64.lintian-overrides 1970-01-01 00:00:00.000000000 +0000 +++ libfcgi-2.4.2/debian/libfcgi0t64.lintian-overrides 2024-02-01 00:25:42.000000000 +0000 @@ -0,0 +1,7 @@ +# There is no need to split this package to multiple ones: +libfcgi0t64: package-name-doesnt-match-sonames libfcgi++0 libfcgi0 + +# Active phase of library development passed long time ago. Now it is just in +# passively maintenance mode without changing of API and ABI. +libfcgi0t64: no-symbols-control-file usr/lib/x86_64-linux-gnu/libfcgi*.so.0.0.0 +libfcgi0t64: package-name-doesnt-match-sonames libfcgi0ldbl