#1143480 python3-protobuf: please use versions that match upstream; do not strip the major version #1143480
- Package:
- python3-protobuf
- Source:
- python3-protobuf
- Description:
- Python 3 bindings for protocol buffers
- Submitter:
- Ansgar
- Date:
- 2026-08-09 16:33:01 UTC
- Severity:
- normal
The python3-protobuf packages in Debian experimental switched to a different version scheme: ``` $ rmadison -s unstable,experimental -a amd64 python3-protobuf python3-protobuf | 3.21.12-16 | unstable | amd64 python3-protobuf | 36.0~rc1-1+b1 | experimental | amd64 ``` But 36.0~rc1 is not the version number that is used by upstream for releases on Pypi. The current version there is 7.36.0rc1. Debian omits the major version part. I think that is confusing and python3-protobuf versions should match the versions that upstream uses for Pypi releases. Everything else seems to be very fragile for versioned dependencies on python3-protobuf. (This might require that src:protobuf overrides the "Version" field for some binary packages.) Ansgar
Hi Ansgar, It follows upstream versioning [1]. Under v36.0-rc1 it lists Python. As noted, Debian packaging comes from the upstream repository [2] where it has 36.0 RC1 as version number. Does the package version matter on Python version detection? I think dependant packages may check the version number directly: $ python3 7 36 0 Can you show me examples of such packages? I've never done a package binary version override. Cheers, Laszlo/GCS [1] https://github.com/protocolbuffers/protobuf/releases [2] https://github.com/protocolbuffers/protobuf/tree/v36.0-rc1/python
Hi,
Please see https://protobuf.dev/support/version-support/
Different languages have breaking changes at independent versions. So
the major version is language-dependent.
">= 6, < 7" which are not satisfied by a version introducing breaking
changes.
This cannot be expressed on the Debian package level when the major
version is omitted.
It also makes mapping version requirements from other packages harder:
upstreams will use the Protobuf upstream versions that include the
major version. That would not be correct for Debian packaging.
Hmm, packages like src:gcc-defaults and src:linux-signed-amd64 should
do that. The relevant part is passing `-- -v{binary-version}` to
`dh_gencontrol`.
I guess something like
```
dh_gencontrol -- -v7.$(DEB_VERSION)
```
might work? (With DEB_VERSION from /usr/share/dpkg/pkg-info.mk.) Though
one might not want to hardcode the "7." part or at least trigger an
error when this changed upstream.
The upstream part seem to be maintained in files like
- https://github.com/protocolbuffers/protobuf/blob/main/protobuf_version.bzl
- https://github.com/protocolbuffers/protobuf/blob/main/version.json
Upstream changes seem to update version numbers in quite a lot of places at once:
https://github.com/protocolbuffers/protobuf/commit/4b269eb436f138aac5f2a189f290ad132aebfba5
So I'm not sure which is the best place to check.
Ansgar
Hi Ansgar, OK, for the time being I have changed the packaging. Now I produce individually versioned language bindings packages for Java, Python and Ruby. Not yet for PHP, that's a known overlook. If you have time, please check for the updated package [1]. So this means even if language bindings have different major versions, those might be just 'visual' differences. Versions are changed in lock-step, not individually. Cheers, Laszlo/GCS [1] dget -x https://people.debian.org/~gcs/protobuf_36.0~rc2-1.dsc
We believe that the bug you reported is fixed in the latest version of
protobuf, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143480@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <gcs@debian.org> (supplier of updated protobuf package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 04 Aug 2026 16:30:29 +0200
Source: protobuf
Architecture: source
Version: 36.0~rc2-1
Distribution: experimental
Urgency: medium
Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Closes: 1143480
Changes:
protobuf (36.0~rc2-1) experimental; urgency=medium
.
* New major upstream release candidate version.
* Update patches.
* Build Java bindings for version 9 of runtime.
* Build versioned Java, PHP, Python and Ruby language binding packages
(closes: #1143480).
Checksums-Sha1:
43dfdca9ee816fc8e3d9bd765d3ca4e285ab2560 3147 protobuf_36.0~rc2-1.dsc
66a67b1abefcf194bbf669cf0a7a20852a2903c2 7335869 protobuf_36.0~rc2.orig.tar.gz
b602a026d6a7f6d2da47dfd114eda35061af1196 39112 protobuf_36.0~rc2-1.debian.tar.xz
Checksums-Sha256:
ab7dfc2c1458c570fbe22d3a520a7bcfa1c7e876b203c51822deb6dcfc8143e3 3147 protobuf_36.0~rc2-1.dsc
46f5c52302d4af9b4a02c0f7d495167c72b0225b99b2ac3938f857f2f51435c5 7335869 protobuf_36.0~rc2.orig.tar.gz
c1f2ebc1aa81b305dfd57292f972ddb21230d47a3714daf859b25d457b062aa3 39112 protobuf_36.0~rc2-1.debian.tar.xz
Files:
ab87edb08a54f2a8c147d36e16e0eabb 3147 devel optional protobuf_36.0~rc2-1.dsc
8f60908043751e87d71aa09d38a6745d 7335869 devel optional protobuf_36.0~rc2.orig.tar.gz
6d1a564ca8f9039fadf74de918cb9f43 39112 devel optional protobuf_36.0~rc2-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIyBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAmp4KxwACgkQ3OMQ54ZM
yL/aLw/4yZJG1KqByH3Dt+0VUBEoxGycbjL5xS8iS9qCGHVMoLDSO0E6S8f9wtD0
9XzR1RnrRAnMYyczyTgmb+ZvaASMLv2MpLJdVf+RUQpR1rTAnOw7XI5nw6dXcZNE
DpP/leU+klqImOODPcryxelK5SLcz8yDtfhRjaCosF6CfudjWI3IXwmg2s2+VqEE
DLUj2NYSO1ZpDxP/0o7E/jndWoYjcSS68FX7kjNnna4s10q0f29IMWZ6gmagADoT
k767ZGfR9qxEGgBB1c6Ia5DiRBWyrvufs4wqdPCYKrCs4v5iGxQushogjw8H1jvB
Uz7AtXAxqZlhfFj1YNDfN6pgxhL3jYeNhsZKm8zPWuKWOM3QvD35qKqo6RVYMupf
dPKu4r3NYQDOyevRniF8kfUygOw9iI0RErK2jh5mP9rkpy6LdF5k+3pgqqKykYlC
yXUK2q5Kw5n+huxYVDZwB4zCJcRW+1hTCleKgLPUjEYQD7/Oy7bgyTq61pPpFTSJ
WWxnh7s0mj7LZD16/oZSQEA8Y+k9xwQaSgur/wBJuaLQp0/t8ndcepYKF+/swaX0
rYdZWxQQci5IWMAbjr/Gfb/KDRTBqk4vKEBybLkt9I+mZX4zWW54y7ABbs2diaKE
7vzAEWrsqp/+jIAQQ54RS+sEipGKtd8Is4WG1l6FHlH8ms7AhQ==
=08bj
-----END PGP SIGNATURE-----
Hi, Please note that you might need to request removal of the old binary packages from experimental as the versions are going backwards: from 36.x back to 7.36.x. (I think this is fine for experimental; no need to add an epoch.) Ansgar