Your message dated Sat, 19 Feb 2022 17:02:07 +0000
with message-id <e1nlt7x-000isk...@fasolo.debian.org>
and subject line Bug#1005230: fixed in chromium 98.0.4758.102-1~deb11u1
has caused the Debian Bug report #1005230,
regarding chromium: essential dependencies (libgtk-3-0) no longer depended on
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
1005230: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1005230
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: chromium
Version: 98.0.4758.80-1~deb11u1
Severity: grave
Justification: renders package unusable
X-Debbugs-Cc: t...@security.debian.org
Hi,
Jumping from chromium 90 to 98 causes many dependencies to be
uninstalled. After this chromium fails to start with
"trace/breakpoint trap".
stracing shows chromium looking for - but not finding -
gtk related packages.
Manually reinstalling those dependencies declared by chromium 90
allows 98 to start again.
I think libgtk-3-0 is one of those essential missing dependencies.
There may be others.
I'm running sway, which might explain why those dependencies are
not pulled in by other packages.
Thanks for your work!
C.
-- System Information:
Debian Release: 11.2
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 5.10.0-11-amd64 (SMP w/4 CPU threads)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages chromium depends on:
ii chromium-common 98.0.4758.80-1~deb11u1
ii libasound2 1.2.4-1.1
ii libatk-bridge2.0-0 2.38.0-1
ii libatk1.0-0 2.36.0-2
ii libatomic1 10.2.1-6
ii libatspi2.0-0 2.38.0-4
ii libc6 2.31-13+deb11u2
ii libcairo2 1.16.0-5
ii libcups2 2.3.3op2-3+deb11u1
ii libdbus-1-3 1.12.20-2
ii libdrm2 2.4.104-1
ii libevent-2.1-7 2.1.12-stable-1
ii libexpat1 2.2.10-2
ii libflac8 1.3.3-2
ii libfontconfig1 2.13.1-4.2
ii libfreetype6 2.10.4+dfsg-1
ii libgbm1 20.3.5-1
ii libgcc-s1 10.2.1-6
ii libglib2.0-0 2.66.8-1
ii libharfbuzz0b 2.7.4-1
ii libicu67 67.1-7
ii libjpeg62-turbo 1:2.0.6-4
ii libjsoncpp24 1.9.4-4
ii liblcms2-2 2.12~rc1-2
ii libminizip1 1.1-8+b1
ii libnspr4 2:4.29-1
ii libnss3 2:3.61-1+deb11u2
ii libopenjp2-7 2.4.0-3
ii libopus0 1.3.1-0.1
ii libpango-1.0-0 1.46.2-3
ii libpng16-16 1.6.37-3
ii libpulse0 14.2-2
ii libre2-9 20210201+dfsg-1
ii libsnappy1v5 1.1.8-1
ii libstdc++6 10.2.1-6
ii libwebp6 0.6.1-2.1
ii libwebpdemux2 0.6.1-2.1
ii libwebpmux3 0.6.1-2.1
ii libx11-6 2:1.7.2-1
ii libxcb1 1.14-3
ii libxcomposite1 1:0.4.5-1
ii libxdamage1 1:1.1.5-2
ii libxext6 2:1.3.3-1.1
ii libxfixes3 1:5.0.3-2
ii libxkbcommon0 1.0.3-2
ii libxml2 2.9.10+dfsg-6.7
ii libxrandr2 2:1.5.1-1
ii libxslt1.1 1.1.34-4
ii zlib1g 1:1.2.11.dfsg-2
Versions of packages chromium recommends:
ii chromium-sandbox 98.0.4758.80-1~deb11u1
Versions of packages chromium suggests:
pn chromium-driver <none>
pn chromium-l10n <none>
pn chromium-shell <none>
Versions of packages chromium-common depends on:
ii libc6 2.31-13+deb11u2
ii libstdc++6 10.2.1-6
ii libx11-6 2:1.7.2-1
ii libxext6 2:1.3.3-1.1
ii x11-utils 7.7+5
ii xdg-utils 1.1.3-4.1
ii zlib1g 1:1.2.11.dfsg-2
Versions of packages chromium-common recommends:
ii chromium-sandbox 98.0.4758.80-1~deb11u1
pn fonts-liberation <none>
ii libgl1-mesa-dri 20.3.5-1
pn libu2f-udev <none>
pn notification-daemon <none>
pn system-config-printer <none>
ii upower 0.99.11-2
Versions of packages chromium-sandbox depends on:
ii libc6 2.31-13+deb11u2
-- no debconf information
--- End Message ---
--- Begin Message ---
Source: chromium
Source-Version: 98.0.4758.102-1~deb11u1
Done: Andres Salomon <dilin...@debian.org>
We believe that the bug you reported is fixed in the latest version of
chromium, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1005...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Andres Salomon <dilin...@debian.org> (supplier of updated chromium package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Tue, 15 Feb 2022 20:15:03 -0500
Source: chromium
Architecture: source
Version: 98.0.4758.102-1~deb11u1
Distribution: bullseye-security
Urgency: high
Maintainer: Debian Chromium Team <chrom...@packages.debian.org>
Changed-By: Andres Salomon <dilin...@debian.org>
Closes: 954824 970571 1005230 1005466
Changes:
chromium (98.0.4758.102-1~deb11u1) bullseye-security; urgency=high
.
* Enable pipewire support in webrtc (closes: #954824).
* Enable optimize_webui. This UI speed improvement was originally
disabled due to nodejs deps, but recent upstream changes makes those
deps necessary either way (closes: #970571).
* Switch to using bundled node modules, to deal with (frequent) build
failures (closes: #1005466).
* Manually depend on xdg-desktop-portal-* packages. The file saving
dialog needs a UI toolkit (closes: #1005230).
* New upstream security release.
- CVE-2022-0603: Use after free in File Manager.
Reported by Chaoyuan Peng (@ret2happy).
- CVE-2022-0604: Heap buffer overflow in Tab Groups. Reported by Krace.
- CVE-2022-0605: Use after free in Webstore API.
Reported by Thomas Orlita.
- CVE-2022-0606: Use after free in ANGLE.
- CVE-2022-0606: Use after free in ANGLE. Reported by Cassidy Kim of
Amber Security Lab, OPPO Mobile Telecommunications Corp. Ltd.
- CVE-2022-0607: Use after free in GPU. Reported by 0x74960.
- CVE-2022-0608: Integer overflow in Mojo.
Reported by Sergei Glazunov of Google Project Zero.
- CVE-2022-0609: Use after free in Animation. Reported by
Adam Weidemann and Clément Lecigne of Google's Threat Analysis Group.
- CVE-2022-0610: Inappropriate implementation in Gamepad API.
Reported by Anonymous.
Checksums-Sha1:
a10615c243fe10738ccb5ebe48b8ee518e69b159 3714
chromium_98.0.4758.102-1~deb11u1.dsc
7eef940a3971cdeee336cd39a8b80393c2d1cf06 527215312
chromium_98.0.4758.102.orig.tar.xz
2b90b6baba3d4ba0e857b57e0b42f24850b12485 215384
chromium_98.0.4758.102-1~deb11u1.debian.tar.xz
c3aa5db517e83e01c9cf284303d3114f93c5ee65 20365
chromium_98.0.4758.102-1~deb11u1_source.buildinfo
Checksums-Sha256:
d50ac6d07186e38b432ddfdf23ad8692bb8382b1aa1cd252d54145d65c635aae 3714
chromium_98.0.4758.102-1~deb11u1.dsc
ff05a6111b189fa99c60c2887e7129bf6b11cdff1a5d7ac38e473668c70a0654 527215312
chromium_98.0.4758.102.orig.tar.xz
9735b488cfe2feb66a3ced285774a0c14d6158f78b3c1f0dad93dbfd293b60aa 215384
chromium_98.0.4758.102-1~deb11u1.debian.tar.xz
eccaa9edb45dd4206fd2bd6579f16dbb4dbb332351a8b5a023730963737b988a 20365
chromium_98.0.4758.102-1~deb11u1_source.buildinfo
Files:
76042dd832e164bbe56208466bec96c5 3714 web optional
chromium_98.0.4758.102-1~deb11u1.dsc
a2e94ce03be789833a6641e842936377 527215312 web optional
chromium_98.0.4758.102.orig.tar.xz
7467c040ac054fec66db0794ace6243f 215384 web optional
chromium_98.0.4758.102-1~deb11u1.debian.tar.xz
eb11847d581c4a490575c2438d6e0fa6 20365 web optional
chromium_98.0.4758.102-1~deb11u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmINkAMUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjdVghAAjM9Mht03JilwERcgs5JjCYNj5ilo
34No3DiMyzPIBw+q+HgxhGikOR8VFYlfz/HVPq0HNkWS+tVtmqyax17YZ3EULITF
CaezYsnK3Ub7rgcTe6Y5gV+YxRa4BNEMwm1BbJGHzA0zIEkXzwAPKo+HI+eqnUFV
9XF3RAwRKE7fYuOzkkZaWDROvsRnwCDKtA4xkSFifKeImNK68ls0cORyp4Sa8sKz
rT/16LBavqb6nr+iePdr2zPYuaCFQNVmAIQZbH4eOwqrVHGSKChQSPnqf4N8bRBt
BO6ys+Un80q0koyVNEuVHL1ebe3ogrfzZkXz74+OkjDIBvncO6uqfYWgMfFzx3pd
yYI+NWvhtIaZ5ms4E2Cfijdx+m2UHE5NjwqkHkyQxCqMk1MiQbYyye3omMWxJ51i
DbSAhhBAKJTa2soYDmznBZgIjUyeGw2o3yCF3h1TgueDExZ4TUk+Xyc0fqBsPTLZ
sI7lRaUMvR5vadBHQ4wpm40gTK7czbtqB5RG9oA/jTR8BtPH5ya3rqOEg2xe+ybe
yCeDXIF27r0z/SoD8XnMvcsSksgmvTVL/3FjmqK4e1wE5Hju74hsdFpOK14CxJFp
EUKkDOr+MAGn+PM38iyEA86WdYgShkmb6kM1ypnki5+wMyZNI5dB3l5dgDqIA50/
HGrqDJvgk93hUZI=
=/24V
-----END PGP SIGNATURE-----
--- End Message ---