#1033132 crowdsec: insufficient dependency on libsqlite3-0

Package:
crowdsec
Source:
crowdsec
Description:
lightweight and collaborative security engine
Submitter:
Cyril Brulebois
Date:
2023-03-19 00:09:03 UTC
Severity:
normal
#1033132#5
Date:
2023-03-17 22:06:25 UTC
From:
To:
Package: crowdsec
Version: 1.4.2-1
Severity: important

Hi,

This report is the counterpart of #1033029 (old crowdsec can't work with
newer libsqlite3-0 due to now-invalid assumptions in the Ent stack):
new crowdsec embeds a newer Ent stack that relies on features introduced
in sqlite3 3.35.0, which is between bullseye's and bookworm's versions:
https://www.sqlite.org/lang_returning.html

This was found when checking the upgrade path between bullseye and
bookworm, crowdsec 1.4.x vs. libsqlite3-0 3.34.1-3 triggers this:

    Setting up crowdsec (1.4.6-1+b1) ...
    I: Registering to LAPI (/etc/crowdsec/local_api_credentials.yaml)
    WARN[0000] CreateMachine : near "RETURNING": syntax error
    FATA[17-03-2023 23:01:45] unable to create machine: creating machine 'fae6c46c0fba4f11992f09676aa9d748': unable to insert row
    dpkg: error processing package crowdsec (--install):
     installed crowdsec package post-installation script subprocess returned error exit status 1
    Errors were encountered while processing:
     crowdsec

The dependency on libsqlite3-0 is one of the few dependencies obtained
by linking against system libraries:

    Depends: ca-certificates, libc6 (>= 2.34), libsqlite3-0 (>= 3.12.0)

The next step for me is to check whether hardcoding a dependency on
libsqlite3-0 (>= 3.35.0) results in a suitable upgrade path from
bullseye.


Cheers,

#1033132#8
Date:
2023-03-18 12:48:01 UTC
From:
To:
Hello,

Bug #1033132 in crowdsec reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/go-team/packages/crowdsec/-/commit/41cc6d0802ff3bd9158b18e3f7bdee963b1ee5e7
This ensures Ent-generated SQLite queries are understood: otherwise, we
would get a dependency on libsqlite3-0 (>= 3.12.0) via shlibs, which is
clearly not enough.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1033132

#1033132#15
Date:
2023-03-19 00:04:14 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
crowdsec, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1033132@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Cyril Brulebois <cyril@debamax.com> (supplier of updated crowdsec package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 19 Mar 2023 00:25:07 +0100
Source: crowdsec
Architecture: source
Version: 1.4.6-3
Distribution: unstable
Urgency: medium
Maintainer: Cyril Brulebois <cyril@debamax.com>
Changed-By: Cyril Brulebois <cyril@debamax.com>
Closes: 1033132 1033138
Changes:
 crowdsec (1.4.6-3) unstable; urgency=medium
 .
   * When performing an upgrade from pre-1.4.x versions, apply a workaround
     to avoid losing CAPI decisions for several hours (Closes: #1033138):
     delete alert(s) matching “Community blocklist”, and if at least one
     deletion occurred, restart the daemon to force an immediate pull.
   * Hardcode libsqlite3-0 (>= 3.35.0) in Depends to ensure Ent-generated
     SQLite queries are understood (Closes: #1033132): otherwise, we would
     get a dependency on libsqlite3-0 (>= 3.12.0) via shlibs, which is
     clearly not enough.
   * Backport upstream patch to fix building in the past/in the future (as
     seen with reproducible builds), no longer hardcoding the expected year
     for yearless timestamps:
      - 0016-try-to-make-reproducible-build-work-2119.patch
Checksums-Sha1:
 8087a76c9d90ef1f2cf7a770f881dc0aec01572f 4936 crowdsec_1.4.6-3.dsc
 19481cf28b5fcd5c8edf0838ed947ca439c3f6a9 27520 crowdsec_1.4.6-3.debian.tar.xz
 fe406b2a8de1f2bde4e2073db859b22dec5c244f 7644 crowdsec_1.4.6-3_source.buildinfo
Checksums-Sha256:
 5b3b628bc710fb3d66108df8bb355a1faf763888614c913c2df509c9151a2fa8 4936 crowdsec_1.4.6-3.dsc
 d843030fbeb60f311fb4f0e38973744a0206ad02a3357cff3e3e610daf2ead90 27520 crowdsec_1.4.6-3.debian.tar.xz
 cf925ad3c16c14c59d1a4f8c67e173c02f46d6675e24c88a3e26b68d8222d477 7644 crowdsec_1.4.6-3_source.buildinfo
Files:
 81e78f7238677b178054d89692bcd98b 4936 golang optional crowdsec_1.4.6-3.dsc
 5d55f1e7e9786eef4245f6dc3f79ddd1 27520 golang optional crowdsec_1.4.6-3.debian.tar.xz
 e1793305012eef8e3c70ae68b61766e8 7644 golang optional crowdsec_1.4.6-3_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJEBAEBCgAuFiEEtg6/KYRFPHDXTPR4/5FK8MKzVSAFAmQWTkUQHGtpYmlAZGVi
aWFuLm9yZwAKCRD/kUrwwrNVIAn6D/9D40z28v4sm/iIA9TNgRkqi/r0IsXXuxrr
O34jj6QC2GfN99TC1LYOswVF4vp8myTl1CLB5Y80wHlXe5q60Czxc1lWnpzmT42l
1lG12LfC50aa+jSUVDD3l1r0VtCDmN48u4+B62IXgiz9l3z6W8Eoe7EMKO/Vr3sP
xhiNyNRfmP8pBg9iLsoTGPOpmN0pcykSVwuX9EDtUqUeWzcYGvm7Wd7FZpq3ux6G
8q69xX5a1EsMd2MgVK71O7C7CreYFplK/oFvWoFlrANyzeSOU2nPwOGowvt2o3Kq
PYmLYX5sI3GyWHPU0qIODt3xMC0lNPCQvVP/XIAg0W6DSP0elGL0LhwaUS+0wAB5
WAsdHetB9cRwhPLEHaLAQqizLsn8phNrGf5FwHZGZy0Awkd+uLT/4mCSeSViEDMx
IOhEgm/ytTfDgrETh04jesq8L4b09WSqRS14YP6atqhShhuVZy7kdwoungQEHhi0
eI0Ctu/321h7hYLMBHniwrQ0O/hMsCv9vxbxMPLr8zTv+6lUViQu3BVn1udSIZIW
hli8r49bwj/Cjt09XrKTB0MDPWz64JmaOgbJ2s5NM+a5Gl65KZmMfr+lAAMEmRXh
Qfg5x4VoK21S4FIywR5XXvuC5bZC9jzdbLON8oqvWv0z4O4fPHniqA1xh/HV04cQ
8QFD6Y7Xgw==
=fAb6
-----END PGP SIGNATURE-----