- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2022-07-09 10:51:30 UTC
- Severity:
- normal
- Tags:
Hi Stable Release Managers, [X-Debbugs-CC'ed as well Matthias so he can veto or ack from his maintainer point of view]. There was a request in #1003012 to fix an issue in bash corrupting multibyte characters in command substitutions. While looking at it I'm proposing here instead of only picking the 014 patch, to pick up all the changes done since from the bullseye release on top and so proposing a rebuilding of 5.1-6 which was expoed in testing for awhile now. Only change reverted would be the bump of standards version but still including the drop of the pre-wheezy preinst for the "dash-as-sh"-transition. Attached is the resulting debdiff as proposed with the rebuild. Matthias, Stable release managers what do you think on the update? Regards, Salvatore
Hi Matthias, hi SRM'ers Opinions on it? Regards, Salvatore
Control: tag -1 moreinfo I'm unconvinced. Dropping the preinst seems way out of scope for a stable update, as for the other changes it's unclear to me what their impact/risk is. Cheers, Julien
Hi Julien, This is why I hoped to see what Matthias thinks. The alternative would clearly be to only cherry pick the fix for #1003012 and do 5.1-2+deb11u1 with it. Regards, Salvatore
Hi Julien Okay attached the alternative, and only cherry-pick the 014 patch upstream to address #1003012. Would that be acceptable instead? Regards, Salvatore
Control: tag -1 confirmed That's fine, thanks. Cheers, Julien
Hi Julien, Thanks Julien. Uploaded. Regards, Salvatore
package release.debian.org tags 1006504 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: bash Version: 5.1-2+deb11u1 Explanation: fix 1-byte buffer overflow read, causing corrupted multibyte characters in command substitutions
package release.debian.org tags 1006504 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: bash Version: 5.1-2+deb11u1 Explanation: fix 1-byte buffer overflow read, causing corrupted multibyte characters in command substitutions
(re-sending with fixed bug numbers) Hi, The updates discussed in these bugs were included in today's bullseye point release. Regards, Adam