Simon Josefsson writes ("Re: [tag2upload 578] failed, python-securesystemslib 1.3.0-1"):
Thanks for writing in. So I saw.
I tried git-debpush from dgit.git#main on your package and it didn't
fail any check. dgit --gbp build-source reproduces the error message.
It's a long time ago, but my memory of the reason I wrote this in dgit
is as follows. I saw the frequent presence of packages with changes
to the toplevel .gitignore, but without any patch for that.
I inferred, perhaps wrongly, that gbp-based workflows are *supposed*
to omit such patches.
I experimentally removed this error check from my local dgit. When I
did that it was able to build a .dsc (and it passed the new git==dsc
correspondence check).
I propose that rather than changing git-debpush to detect this
situation, we change dgit (and thus the tga2upload service) to accept
it.
Then --quilt=unapplied will be (just) for people who want to *insist*
that their maintainer git tree *does* contain such patches, and
--quilt=gbp will tolerate it either way.
Sean, Simon, what do you think?
This change also applies to git-dpm. I propose to retain it there, at
least until we get a report from a git-dpm user. git-dpm has a
different model - generally, patches-applied - so it is probably
responsible for making (or not making) such patches.
The root cause of all this nonsense is #908747 in dpkg-source.
Ian.
Ian Jackson <ijackson@chiark.greenend.org.uk> writes: I have no preference here. I have had a long-term mental todo item to understand what on earth is happening with top-level .gitignore in the intersection between gbp vs dgit vs Go's dh-make-golang defaults. But as this does not seem to trigger any critical failure (until now) and no QA tool complain about it (except possibly the PTS patch queue notifier), I've tended to just ignore it as yet another weird thing. Is what is triggering this to happen the following patch? https://salsa.debian.org/python-team/packages/python-securesystemslib/-/blob/debian/latest/debian/patches/02_rm_vendored_gitignore.diff?ref_type=heads I don't understand what problem the patch is trying to solve, so I could try to just remove it and see if anything breaks. Or make some other changes to the git packaging on Salsa to make tag2upload behave smoother. /Simon
Ian Jackson writes ("Bug#1111696: --quilt=gbp should maybe tolerate .gitignore patches"):
check
Simon Josefsson writes ("Bug#1111696: --quilt=gbp should maybe tolerate .gitignore patches"):
Yes. But that doesn't mean the patch is wrong.
IMO, it is wrong of gbp and dpkg-source (#908747) to permit the
maintainer to edit .gitignore and then upload a source package without
that changed .gitignore.
The .gitignore is part of the preferred form for modification, so
omitting edits to it from our published source code is a DFSG
violation. (It's a minor one, but even so, this is quite WTF.)
Because (unlike previous tools) dgit and tag2upload insist on
git==dsc, dgit must somehow resolve this discrepancy.
For "3.0 (quilt)" packages, dgit must convert the git to
patches-applied, implying that there is a "split view" - the
maintainer git and dgit view have different content. That split view
provides somewhere to hide the bump in the carpet. So dgit in
--quilt=gbp mode makes a patch for the .gitignore changes, and uploads
a dsc containing the edited .gitignore (and that patch).
For native package formats, it is sufficient simply to suppress
dpkg-source's default ignore rule. This forces dgit to have wrappers
for build tools, and can occasionally cause trouble. See eg #998394.
Presumabloy the .gitignore was edited for a reason. Incomplete
.gitignore files are common and if fixing them is made easy,
developers often do so.
I don't know what the right thing to do in this package, but for
dgit/tag2upload I think the right thing is to continue the strategy of
avoiding ocean-boiling. Hence this bug :-).
Ian.
We believe that the bug you reported is fixed in the latest version of
dgit, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1111696@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Ian Jackson <ijackson@chiark.greenend.org.uk> (supplier of updated dgit package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 24 Aug 2025 11:43:28 +0100
Source: dgit
Architecture: source
Version: 13.13
Distribution: unstable
Urgency: medium
Maintainer: Debian tag2upload Delegates <dgit-owner@debian.org>
Changed-By: Ian Jackson <ijackson@chiark.greenend.org.uk>
Closes: 1111194 1111504 1111527 1111696
Changes:
dgit (13.13) unstable; urgency=medium
.
tag2upload:
* git-debpush: Don't become confused and warn about nonexistent pristine-tar
metadata. Closes: #1111504. [Sean Whitton; report from Birger Schacht]
* git-debpush: Make submodule check precise.
Closes: #1111194. [Report from Simon McVittie]
* dgit, t2u: --quilt=gbp no longer minds patches editing .gitignore
Closes: #1111696. [Report from Simon Josefsson]
* dgit: Reject --quilt=baredebian+barball in tag2upload builder mode.
.
i18n [Américo Monteiro]:
* dgit-user(7) manpage: Provide Portuguese translation.
* git-deborig(1): Update Portuguese translation. Closes: #1111527.
.
Documentation:
* git-debpush(1): Fix link markup. [Sean Whitton]
* git-debpush(1): Add references to other tag2upload docs. [Sean Whitton]
* dgit(7): Give advice for if upstream source relies on gitattributes.
* dgit-nmu-simple(7): Document this as the best way to do a git-based NMU.
* git-debpush(1): Document --quilt=unapplied, not just --quilt=gbp.
* changelog: 13.12: Add missing Closes for #1108181. [Sean Whitton]
.
dgit bugfix:
* dgit: baredebian: Fix diff instruction if upstream files discrepant.
.
Packaging improvements:
* git-deborig: Replace several Perl module dependencies
with inline code and/or use of Dgit::Core. [Sean Whitton]
.
Testing:
* git-deborig: New tests. [Sean Whitton]
* git-debpush: Test that we push the upstream tag. Re #1111305.
* CI: Disable some more useless jobs.
* CI: add t2u-integration-trixie job.
.
Other changes:
* git-deborig: Improve an error message. [Sean Whitton]
* Internal tidying and refactoring. [Sean Whitton and Ian Jackson]
Checksums-Sha1:
71672e643670e101739762e3ae81a0e14dd1ba95 2519 dgit_13.13.dsc
e76586fc73a0a2550d26380967cec670509200da 806445 dgit_13.13.tar.gz
bfa9aaa4086bd42011e2d6d368b27adaca63acf0 1029984 dgit_13.13.git.tar.xz
996549c0bca4a7b6e724fb9e274ad0cb46ca091f 18034 dgit_13.13_source.buildinfo
Checksums-Sha256:
dd9112c14ed49f183d2bf27d7c52276a21cbc8c2bcb35a4e3c7ce4a5dbcda9d4 2519 dgit_13.13.dsc
5a7551692c8d9cc27ce08ce0ef44411a28fa974edb85c0588f717b0c4e3eae1e 806445 dgit_13.13.tar.gz
c497478f8582155efc6749c438d34f1260c4a6408784b25769354d475eb3ad88 1029984 dgit_13.13.git.tar.xz
9a27cff474354a426959315929dbffcff3fa959dcc5879eb6ba712265d5a7b23 18034 dgit_13.13_source.buildinfo
Files:
13c26e70f8285f9e7ff6c0be62a219b9 2519 devel optional dgit_13.13.dsc
e6d90a4f1b240b98f96cb296c912724d 806445 devel optional dgit_13.13.tar.gz
35a54d2251c5e2e97ad18af8d4a61918 1029984 devel optional dgit_13.13.git.tar.xz
3b96dffa6e7de387d21ad02dadd718d3 18034 devel optional dgit_13.13_source.buildinfo
Git-Tag-Info: tag=937352782edf8d25b5c6d7f3de1180e8566b7c40 fp=559ae46c2d6b6d3265e7cba1e3e3392348b50d39
Git-Tag-Tagger: Ian Jackson <ijackson@chiark.greenend.org.uk>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmirBPwACgkQYG0ITkaD
wHnSiBAAvpwy+CwIjftch1a7PO5Du30rb40g113jJryAAu1Qn+wVIAgoCr/1BL8C
s66ZpBpb1V7iec4ivwyU2id5pib2BNrN/KgH/qaXtvd/CoMBV9iP1+UOrqGaCjBL
4AqLLzVT/52T5vdcDR8t3MzZOayypr70Fre8RSXmg0rFjQOW4a25fkti7hIP583Z
5sKPwT9bwvWmNekvi8uUK69KWoVmwsQnBCzrXr6TggoSt4J16xkREXZOW+mulVeY
qdzG+5RtAlUdfwSbCgi4Eev6Gjj33SuIp35YFzoWnL6UJNcAZo1pD4KUCiH7bPXX
JqCThfdeqNzxYVOyzKnQNwRU1Tu65P1aumOdZJaNo5z3y6WXiyx1hxrH2bh8sbdX
WEMQjEuDXdUrixBRDDhFaMhRm3T8WKuXMnBsjFobhzZiVblEu22epjkTYf8mlZu6
z2sGqRvgkaCNNthglRgFOWQxy2udJDOTOP6R/jm9swS2/5LIEqwCmQCHR1AY+2rL
NpS8McFV8+zYkc8Sbel/JAvjWMaEAU4wBGbByc5I9NI88Ag5BsXEq/PKh4TixsC0
MD3ZCUxnQRvN0m0/8w2XIK23XDAxlnb/1i5SpWze7a/87+7PDg1cLK0GJ0i/7NVr
Umltm5KG8BrZIfsNCQVui3qyN9SMumsH/g6eiMXENnySvgPJd90=
=ARrq
-----END PGP SIGNATURE-----