Your message dated Fri, 15 May 2020 10:06:33 +0000 with message-id <e1jzxef-0001bd...@fasolo.debian.org> and subject line Bug#960663: fixed in softhsm2 2.6.1-2 has caused the Debian Bug report #960663, regarding softhsm2: crash/lockdown in openconnect due to atexit use to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact ow...@bugs.debian.org immediately.) -- 960663: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=960663 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems
--- Begin Message ---Package: softhsm2 Version: 2.6.1-1 Severity: serious Justification: causes test failure and FTBFS on reverse dependency Forwarded: https://github.com/opendnssec/SoftHSMv2/issues/548 Dear Maintainer(s), As highlighted by Debian CI, the new version of softhsm2 causes a breakage in src:openconnect - a test hangs and never completes. It seems the root cause is the registration of atexit() handlers. Upstream issue and 2 PRs to fix it: https://github.com/opendnssec/SoftHSMv2/issues/548 https://github.com/opendnssec/SoftHSMv2/pull/550 https://github.com/opendnssec/SoftHSMv2/pull/551 In the meanwhile, I'll disable the unit test in openconnect so that I can upload a new version - there's a security issue to fix, and softhsm is only a sub-functionality of the package. -- Kind regards, Luca Boccassi
signature.asc
Description: This is a digitally signed message part
--- End Message ---
--- Begin Message ---Source: softhsm2 Source-Version: 2.6.1-2 Done: =?utf-8?b?T25kxZllaiBTdXLDvQ==?= <ond...@debian.org> We believe that the bug you reported is fixed in the latest version of softhsm2, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 960...@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Ondřej Surý <ond...@debian.org> (supplier of updated softhsm2 package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmas...@ftp-master.debian.org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 15 May 2020 11:41:43 +0200 Source: softhsm2 Architecture: source Version: 2.6.1-2 Distribution: unstable Urgency: medium Maintainer: Debian DNS Team <team+...@tracker.debian.org> Changed-By: Ondřej Surý <ond...@debian.org> Closes: 942419 960663 Changes: softhsm2 (2.6.1-2) unstable; urgency=medium . * Explicitly enable ECC and EDDSA curves (Closes: #942419) * Fix Use after free on ENGINE_finish(rdrand_engine) (Closes: #960663) Checksums-Sha1: e89b28e5d8c8cc54072e363586f8e91d40a815d3 2398 softhsm2_2.6.1-2.dsc a846e54c6b75e0c9ac72494091560854ffc66386 10640 softhsm2_2.6.1-2.debian.tar.xz 90ed0c36dad9baef19ea25afe270c417ab0c9450 8026 softhsm2_2.6.1-2_amd64.buildinfo Checksums-Sha256: a37271cfd60bd5b21cedde736986924dbc646558721f9d053be2d75f43cea5c4 2398 softhsm2_2.6.1-2.dsc 6c19550bcc501edac6f1c06636619fffdd11a5bf10f89e32300576281ad335e9 10640 softhsm2_2.6.1-2.debian.tar.xz 353788901279da8c82534ebbfd40ce4402d708f7d401d0e8d8e4a51a7031110c 8026 softhsm2_2.6.1-2_amd64.buildinfo Files: f75e4ca369f773244eccfc58297ad666 2398 admin optional softhsm2_2.6.1-2.dsc 7a2a4badf9ecdb9451ea4064a5b3f491 10640 admin optional softhsm2_2.6.1-2.debian.tar.xz 0b11dd1e3d519cedbf81112176dc2a58 8026 admin optional softhsm2_2.6.1-2_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEEw2Gx4wKVQ+vGJel9g3Kkd++uWcIFAl6+ZKBfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEMz NjFCMUUzMDI5NTQzRUJDNjI1RTk3RDgzNzJBNDc3RUZBRTU5QzIACgkQg3Kkd++u WcKlfxAAsn4sWotRgxcQA8z3fR2MIUcJwkgPSIyyTL7y1SPhT5YcDizGZNTxUuNH a0thPeM4TomuRRRKAipMLuhv+U4s6OjZuR23n02SnouIt/26tCtPEvgmjJpkPIYO 4k0XHUF34Z21JdbpTTGlhNa74DbFaDjsORm4qTiNWSibF9P42WfrzS1wAgmAi0Gj Yc0kaEEYDdWLVkRq7l/jZZrtDrl+LrA61DMOLTItAVi2FCsawUBsVW6kYqPs3kIS EQ1QAd9rurAA4ZZbm+8pUdh9ufVGHouLacac2EFCZwj+1MWJbyAsFukaqcS5QL1W ogt0a0y0IbJVFSJea6JPys0d8bhKY0sXxvUryUh+loG4Lrup0rgmeu9FIZvza50i BCb5mBaX2VmF1kc7gIVNXDpSJhWS4OgBNLZ9MBLoxiibqDYRsNxouDl2oBOi1Es7 fbPpaGJbVYUNcERYGM8P93n5L/PMJFT4u66kZPdYsQjvOr8Kiy1EraMtDXCBZTUf Mb+kroHHK6eYCANebr3Dg6hip4eoF2sGD48JbApTDW/3m7Ylb7QexEuGAijRq66L OSBRvM++OjoGCyT2kWEUmoNwg1FQd+CcY9nWmlwu8WwABrjml+r6pRvrIQk3NjvY C6S+zsoeermVEOAKe7MEhGK6j8kAQbxMiEhTuBkzPdVr99A5iJk= =/xZP -----END PGP SIGNATURE-----
--- End Message ---