#1059352 src:apt: fails to migrate to testing for too long: autopkgtest regression on armhf

#1059352#5
Date:
2023-12-23 07:46:27 UTC
From:
To:
Dear maintainer(s),

The Release Team considers packages that are out-of-sync between testing
and unstable for more than 30 days as having a Release Critical bug in
testing [1]. Your package src:apt has been trying to migrate for 31 days
[2]. Hence, I am filing this bug. The version in unstable fails its own
autopkgtest on armhf.

If a package is out of sync between unstable and testing for a longer
period, this usually means that bugs in the package in testing cannot be
fixed via unstable. Additionally, blocked packages can have impact on
other packages, which makes preparing for the release more difficult.
Finally, it often exposes issues with the package and/or
its (reverse-)dependencies. We expect maintainers to fix issues that
hamper the migration of their package in a timely manner.

This bug will trigger auto-removal when appropriate. As with all new
bugs, there will be at least 30 days before the package is auto-removed.

I have immediately closed this bug with the version in unstable, so if
that version or a later version migrates, this bug will no longer affect
testing. I have also tagged this bug to only affect sid and trixie, so
it doesn't affect (old-)stable.

If you believe your package is unable to migrate to testing due to
issues beyond your control, don't hesitate to contact the Release Team.

Paul

[1] https://lists.debian.org/debian-devel-announce/2023/06/msg00001.html
[2] https://qa.debian.org/excuses.php?package=apt

#1059352#16
Date:
2023-12-23 19:40:42 UTC
From:
To:
I know this is automated but I feel lije it would be sensible to scan
the logs for well known bugs so that you don't end up filing bugs
against every package broken by valgrind's missing support for the new
NOP sequences in binutils.

Like this work is tracked in
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1057693

and normally we would forcemerge this into it.

#1059352#21
Date:
2023-12-24 06:31:42 UTC
From:
To:
Hi Julian,

It's *mostly* automated.

I do *some* minor triaging, but I didn't know this to be a common
problem. Where do you think I should have picked this up?

Anyways, this bug is already closed (when I submitted) and because apt
is a key package, it doesn't even do anything against apt, so the bug
serves mostly for tracking purposes.

Paul

#1059352#26
Date:
2024-01-08 09:28:37 UTC
From:
To:
Control: clone -1 -2
Control: reassign -2 valgrind
Control: retitle -2 valgrind: armhf is broken

This is a release critical bug in valgrind. valgrind does not understand
the new toolchain defaults like stack clash protection on armhf and just
segfaults (in Ubuntu we have partially recovered by disabling stack
clash protection but it crashes on invalid writes there, I suppose we
need to rebuild some more apt dependencies without the flag...).

As there doesn't appear to be any progress on the valgrind or toolchain
sides to fix these issues, I'll go and disable valgrind on armhf in the
next apt upload, but I am cloning this to valgrind to make it clear that
it's horribly borked.

#1059352#33
Date:
2024-01-08 10:49:29 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
apt, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1059352@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Julian Andres Klode <jak@debian.org> (supplier of updated apt package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 08 Jan 2024 10:32:31 +0100
Source: apt
Architecture: source
Version: 2.7.8
Distribution: unstable
Urgency: medium
Maintainer: APT Development Team <deity@lists.debian.org>
Changed-By: Julian Andres Klode <jak@debian.org>
Closes: 959093 1053887 1059352
Changes:
 apt (2.7.8) unstable; urgency=medium
 .
   [ Gábor Németh ]
   * Add 'dist-clean' command to remove packages and list files (Closes:
     #959093); this is experimental and does not yet have docs or tests.
 .
   [ David Kalnischkies ]
   * Have Grp.FindPreferredPkg return very foreign pkgs as last resort
   * Improve and test distclean implementation
   * Do not store .diff_Index files in update
 .
   [ Tianyu Chen ]
   * apt-pkg/cacheset.cc: set ShowErrors to true when no version matched
     (Closes: #1053887)
 .
   [ Julian Andres Klode ]
   * Do not silently ignore directories for reserved file names
   * test: Disable valgrind on armhf, incompatible with stack clash protector
     (Closes: #1059352)
Checksums-Sha1:
 b5c252874da42a2985f2b149081364625654bc13 2931 apt_2.7.8.dsc
 a2627f78fcc431246c212563e772a054cce31cca 2347516 apt_2.7.8.tar.xz
 5dbfae1081692701f582b8e9d4273b99e5e5d1fb 7671 apt_2.7.8_source.buildinfo
Checksums-Sha256:
 10d656d98dc7f4da284c13b2784ca2fa65ed91769a5480fd832c2364447beb87 2931 apt_2.7.8.dsc
 9c09a2c1f18489fb430d616b93e6df5a15f61473856a789d5e3cce0ad2195dc6 2347516 apt_2.7.8.tar.xz
 06a53bd868c7f193ae9517ffad8c4a87fc21fc16a2c342302d1b93ecd756c78e 7671 apt_2.7.8_source.buildinfo
Files:
 bcefe1823b63620226dc0458c9aa8c19 2931 admin required apt_2.7.8.dsc
 9804a9f61adaa99511cf93c0d61d01d5 2347516 admin required apt_2.7.8.tar.xz
 f105a708a0d7a8bd801ca68ff6a2aa4a 7671 admin required apt_2.7.8_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJDBAEBCgAtFiEET7WIqEwt3nmnTHeHb6RY3R2wP3EFAmWb0poPHGpha0BkZWJp
YW4ub3JnAAoJEG+kWN0dsD9xPs8P/jDlkuVzGsHtQKUjQMxjwiVctf8JX/5f5HZ0
WLOpF+CNUqVgDdRfUmBkh2TK2WG1e3F9DPFPuteSAoxdEVhmtb+qhnGSEDk0DakC
TQIXgVGg+/7kiHk+ZV4Dud0pYc9Gz/AZXkDdf5S23o2sZetPCxFJRduMCvZdHYV3
LT2KRn1fo4KdtuM02mXZzDn36n2cMAvhqdgOhtZ1wNC0WUIwTL3fAm1uazzlqQ5g
1h0LKM3RHNhIzy46Ae5SpxxCMQffMvXNsBjQahzBLy4JX7KVKAW60lfKUUz3SmYk
tvAlRMq8bK2ugnDs58g59gOLytb+fQyG/GOyJWaKm+//uE5Z8FtCVn3VEKYoy+2/
ABifXMJmXjKktqhF3DDkPtMIQ/Bb4i01uZS02JkUdD9/b/VfjIhd3nByRK2zFkPy
IPCRXc6kOTeTWynEYdwB7ETlSt/97dYH1aOvcKo2U/VK9HaACak8nFtS7CkMig4j
VLzi/WU0DvhNzpB3stuahiwLJ/7IqdSuPs5h23Al4shfXohZJ49ES2Z3e1XLh4No
ngNGwe2JtPJ0QcptdDxZ7CLddnSKAHFK8WPBe0FB9nrEtd5S4Eqt/e6iIBQbJNi6
foEb3yKaFx0pK4+2FCetGpB+Z6nSebXmaDekyWEtyciB87A21DaeS4UsR7j6Ecss
coYb8jYC
=yDyX
-----END PGP SIGNATURE-----

#1059352#38
Date:
2024-01-08 17:05:17 UTC
From:
To:
Hello Paul and Julian,

Note that there are three distinct valgrind problems mentioned here:

- on armhf, flagging accesses below the stack pointer as illegal. This
  came up after enabling stack-clash-protection on armhf. I added a
  suppression for this problem in valgrind 1:3.20.0-2, so we shouldn't
  be seeing those anymore. For reference:
https://lists.debian.org/debian-arm/2023/12/msg00007.html

- on i386, valgrind was failing due to new nop patterns that it didn't
  know about. This is https://bugs.debian.org/1057693 and was fixed by
  Aurelien in 1:3.20.0-2.1

- on armhf, a segfault when testing apt. I don't think this issue is
  widespread at all: in fact I'm not aware of any other instances except
  for apt. After going through all armhf CI failures caused by segfaults, apt
  seems to be the only one with valgrind in the picture. Just to be
  clear: I'm not saying that the problem is trivial, just that AFAIK it's
  not widespread. I'm including the relevant CI logs below for
  reference. Also I'm attaching the horrible script I've written to fetch
  all armhf CI failures in case anyone wants to poke around.

722s ==221367== Copyright (C) 2002-2022, and GNU GPL'd, by Julian Seward et al.
722s ==221367== Using Valgrind-3.20.0 and LibVEX; rerun with -h for copyright info
722s ==221367== Command: /usr/bin/apt-get update -o Acquire::Queue-Mode=access
722s ==221367==
722s ==221367==
722s ==221367== Process terminating with default action of signal 11 (SIGSEGV)
722s ==221367==  Access not within mapped region at address 0xFE7F2A9C
722s ==221367==    at 0x4938838: ReadMessages(int, std::vector<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> >, std::allocator<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > > >&) (in /usr/lib/arm-linux-gnueabihf/libapt-pkg.so.6.0.0)
722s ==221367==  If you believe this happened as a result of a stack
722s ==221367==  overflow in your program's main thread (unlikely but
722s ==221367==  possible), you can try to increase the size of the
722s ==221367==  main thread stack using the --main-stacksize= flag.
722s ==221367==  The main thread stack size used in this run was 8388608.
722s ==221367==
722s ==221367== HEAP SUMMARY:
722s ==221367==     in use at exit: 119,915 bytes in 1,882 blocks
722s ==221367==   total heap usage: 11,673 allocs, 9,791 frees, 868,849 bytes allocated
722s ==221367==
722s ==221367== LEAK SUMMARY:
722s ==221367==    definitely lost: 0 bytes in 0 blocks
722s ==221367==    indirectly lost: 0 bytes in 0 blocks
722s ==221367==      possibly lost: 0 bytes in 0 blocks
722s ==221367==    still reachable: 119,915 bytes in 1,882 blocks
722s ==221367==         suppressed: 0 bytes in 0 blocks
722s ==221367== Rerun with --leak-check=full to see details of leaked memory
722s ==221367==
722s ==221367== For lists of detected and suppressed errors, rerun with: -s
722s ==221367== ERROR SUMMARY: 0 errors from 0 contexts (suppressed: 42821 from 965)
722s Segmentation fault
722s FAIL: exitcode 139