#828903 auditd embeds a copy of libev

Package:
src:audit
Source:
audit
Submitter:
Nicolas Braud-Santoni
Date:
2023-08-29 16:15:10 UTC
Severity:
normal
Tags:
#828903#5
Date:
2016-06-28 20:28:07 UTC
From:
To:
Dear Maintainer,

The audit source package ships a (custom, patched) copy of libev.

Moreover, it is not listed in the security team's list of code copies:

https://anonscm.debian.org/viewvc/secure-testing/data/embedded-code-copies?view=markup


I discovered the issue while preparing a DEP5 copyright file for
the audit source package, and more generally fixing all Lintian
warnings while preparing a patch for #759604.


Best,

  nicoo

#828903#12
Date:
2022-12-15 16:08:30 UTC
From:
To:
Control: severity -1 important
Control: tags -1 patch

I think this is an important issue and have included a patch.
Would you please consider to apply this before the bookworm freeze?

#828903#21
Date:
2022-12-16 11:20:41 UTC
From:
To:
Hello,

Le 15/12/22 à 17:08, Bastian Germann a écrit :

Do you think you could bring that upstream?

Not sure we want to carry this patch forever

#828903#26
Date:
2022-12-16 11:43:46 UTC
From:
To:
Am 16.12.22 um 12:20 schrieb Laurent Bigonville:

Usually, projects have their reasons to vendor libraries (mostly, convenience or CI-related).
The patch is not complete in the sense that it still reads the .m4 file from the vendored library.
So I do not think this has a high chance to be considered for upstream inclusion.
However, I can try to hand in one that gets rid of the vendoring completely (not happening in a
timeframe before bookworm freeze).

If you do not want to include the patch for now then please at least make sure the embedded libev is
registered with the Security Team.