- Submitter:
- Andrea Pappacoda
- Date:
- 2025-08-13 09:19:03 UTC
- Severity:
- normal
- Tags:
Hi, the github.com/mitchellh/hashstructure go package exists twice in Debian, under the names golang-github-mitchellh-hashstructure and golang-github-mitchellh-hashstructure-v2. Regardless of the name, they both ship upstream version 2.0.2. This is creating issues with packages which need the v1 version to build, as they're going to get the incompatible v2 version instead, provided by this package. Since having the same library twice in the archive isn't really useful, I'd recommend to either: 1. File a removal bug against this package, removing it from the archive. 2. Make an upload downgrading the upstream version of this package to v1 again, either with an epoch or a +really version suffix. Since v1 is discouraged upstream, and no package in Debian requires it (as this package is providing v2 anyway), I'd just advise to drop it from the archive. Please let me know if I have misunderstood something. Bye!
control: tags -1 + moreinfo Hmm, yes this is less than ideal. There appear to be no actual reverse dependencies on golang-github-mitchellh-hashstructure-v2-dev, while golang-github-mitchellh-hashstructure-dev has 47. I'd suggest modifying this bug into a RM request for golang-github- mitchellh-hashstructure-v2-dev; CC'ing Arthur who had originally uploaded the v2 package for an ACK from him first. Mathias
Hi, I remember that at that time around may 2025 there was something (that I can't remember now) blocking the migration of golang-github- mitchellh-hashstructure-dev to 2.0.2 and I then decided to create a new package. In the end both packages got into debian with less than 1 month difference and I probably just switched the packages I was working to point to the golang-github- mitchellh-hashstructure-dev, that's why there are no reverse dependencies to v2. So since both are in the same version I think we should remove golang-github-mitchellh-hashstructure-v2-dev.
Small correction may 2024*
Hi Mathias, Oh, that's higher than I though. Are you counting direct dependencies, or transitive ones too? When hashstructure-v2 was uploaded, hashstructure was still at v1. So maybe it made sense to have two packages back then? Still, hashstructure declares an unversioned import path, while it is incompatible with packages depending on v1 (such as a package which a friend of mine is trying to work on as his first package -- no ITP yet, I haven't yet introduced him to the concept). Shouldn't then hashstructure declare a /v2 import path, and hence be renamed too? This was my reasoning when asking to drop the unversioned (v1) package. Let me know if it makes sense! Bye :)
I ran `build-rdeps golang-github-mitchellh-hashstructure-dev` in a sid container, which includes both direct and transitive dependencies. Most of the golang packages in Debian have unversioned import paths, which does mean that all dependencies in the archive need to use the same major version of the library. Individual golang libraries vary widely in how well they follow semantic versioning. Given that all packages in the archive currently use v2 from the unversioned package, I think that RM'ing golang-github-mitchellh-hashstructure-v2-dev is the correct path forward. Mathias
control: retitle -1 RM: golang-github-mitchellh-hashstructure-v2 -- ROM; duplicate control: reassign -1 ftp.debian.org control: severity -1 normal golang-github-mitchellh-hashstructure-v2 became an accidental duplicate of the contents of golang-github-mitchellh-hashstructure after the other package was updated to the current upstream version. Since there are no reverse dependencies of golang-github-mitchellh- hashstructure-v2, please remove it from the archive. Thanks, Mathias
Ack. Got it. I'm still quite new to Go packaging, and coming from C libraries these kinds of unversioned dependencies are a bit odd for me. But: agree that the RM of the unused package makes sense now! Thanks for the explanation, bye :)
We believe that the bug you reported is now fixed; the following package(s) have been removed from unstable: golang-github-mitchellh-hashstructure-v2 | 2.0.2-2 | source golang-github-mitchellh-hashstructure-v2-dev | 2.0.2-2 | all------------------- Reason ------------------- ROM; duplicate ---------------------------------------------- Note that the package(s) have simply been removed from the tag database and may (or may not) still be in the pool; this is not a bug. The package(s) will be physically removed automatically when no suite references them (and in the case of source, when no binary references it). Please also remember that the changes have been done on the master archive and will not propagate to any mirrors until the next dinstall run at the earliest. Packages are usually not removed from testing by hand. Testing tracks unstable and will automatically remove packages which were removed from unstable when removing them from testing causes no dependency problems. The release team can force a removal from testing if it is really needed, please contact them if this should be the case. We try to close bugs which have been reported against this package automatically. But please check all old bugs, if they were closed correctly or should have been re-assigned to another package. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1109682@bugs.debian.org. The full log for this bug can be viewed at https://bugs.debian.org/1109682 This message was generated automatically; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org. Debian distribution maintenance software pp. Thorsten Alteholz (the ftpmaster behind the curtain)