Bug#1145445: trixie-pu: package libdbd-csv-perl/0.6200-1+deb13u1

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.perl
Message-ID <178764907495.2080309.10939901664380195449.reportbug__15311.4008413226$1787649214$gmane$org@eldamar.lan>
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected], [email protected], [email protected], [email protected]
Control: affects -1 + src:libdbd-csv-perl
User: [email protected]
Usertags: pu

Hi SRM,

When updating libdbi-perl in unstable to a new upstream version
libdbd-csv-perl had new failures in tests, which were test only fixes
neede, cf. #1139509.

As we are planning to rebase libdbi-perl in trixie via a DSA on
upstream suggestion to address various CVEs, libdbd-csv-perl will hit
the same issue.

The patch upstream adapts the tests in t/70_csv.t to pass with newer
DBI versions.

I tested both the upload isolated on debusine:
https://debusine.debian.net/debian/developers/work-request/1094128/
and as well in context of an updated libdbi-perl version:
https://debusine.debian.net/debian/developers-carnil-dbi/work-request/1094167/

I'm thus proposing the update for the test only changes for
libdbd-csv-perl via the upcoming point release.

Regards,
Salvatore
libdbd-csv-perl_0.6200-1+deb13u1.debdiff (text/plain, 3.7 KB)
diff -Nru libdbd-csv-perl-0.6200/debian/changelog libdbd-csv-perl-0.6200/debian/changelog
--- libdbd-csv-perl-0.6200/debian/changelog	2025-01-31 23:49:06.000000000 +0000
+++ libdbd-csv-perl-0.6200/debian/changelog	2026-08-23 11:42:48.000000000 +0000
@@ -1,3 +1,12 @@
+libdbd-csv-perl (0.6200-1+deb13u1) trixie; urgency=medium
+
+  * Team upload.
+
+  [ gregor herrmann ]
+  * Add patch from upstream Git to fix test failure. (Closes: #1139509)
+
+ -- Salvatore Bonaccorso <[email protected]>  Sun, 23 Aug 2026 13:42:48 +0200
+
 libdbd-csv-perl (0.6200-1) unstable; urgency=medium
 
   * Import upstream version 0.6200.
diff -Nru libdbd-csv-perl-0.6200/debian/patches/0001-New-test-for-DBI-1.648-CVE-fix.patch libdbd-csv-perl-0.6200/debian/patches/0001-New-test-for-DBI-1.648-CVE-fix.patch
--- libdbd-csv-perl-0.6200/debian/patches/0001-New-test-for-DBI-1.648-CVE-fix.patch	1970-01-01 00:00:00.000000000 +0000
+++ libdbd-csv-perl-0.6200/debian/patches/0001-New-test-for-DBI-1.648-CVE-fix.patch	2026-08-23 11:42:48.000000000 +0000
@@ -0,0 +1,78 @@
+From ae091790398088a66b22fa572856bfeb4db4c78a Mon Sep 17 00:00:00 2001
+From: "H.Merijn Brand - Tux" <[email protected]>
+Date: Thu, 28 May 2026 10:06:33 +0200
+Subject: [PATCH] New test for DBI-1.648 CVE fix
+
+Origin: https://github.com/perl5-dbi/DBD-CSV/commit/ae091790398088a66b22fa572856bfeb4db4c78a
+Bug: https://github.com/perl5-dbi/DBD-CSV/issues/12
+Bug-Debian: https://bugs.debian.org/1139509
+
+---
+ t/70_csv.t | 24 +++++++++++++++++++++++-
+ t/lib.pl   |  3 +--
+ 3 files changed, 26 insertions(+), 4 deletions(-)
+
+diff --git a/t/70_csv.t b/t/70_csv.t
+index 30d2d59..a65385a 100644
+--- a/t/70_csv.t
++++ b/t/70_csv.t
+@@ -3,6 +3,7 @@
+ use strict;
+ use warnings;
+ use Test::More;
++use File::Spec;
+ 
+ BEGIN { use_ok ("DBI"); }
+ do "./t/lib.pl";
+@@ -85,12 +86,33 @@ ok ($dbh = Connect ($dsn),			"connect");
+ # Check, whether the csv_tables->{$tbl}{file} attribute works
+ like (my $def4 = TableDefinition ($tbl4, @tbl_def),
+ 	qr{^create table $tbl4}i,		"table definition");
+-ok ($dbh->{csv_tables}{$tbl4}{file} = DbFile ($tbl4), "set table/file");
++{   my $dbf4 = DbFile ($tbl4);
++    my $dbd4 = DbDir ();
++
++    $dbh->{f_dir_search} = [ $dbd4 ];
++    ok ($dbh->{csv_tables}{$tbl4}{file} = $dbf4, "set table/file");
++    }
+ ok ($dbh->do ($def4),				"create table");
+ ok (-f DbFile ($tbl4),				"does exists");
+ 
+ ok ($dbh->do ("drop table $tbl4"),		"drop table");
+ 
++if ($DBI::VERSION ge "1.648") {
++    ok (my $tbl5 = FindNewTable ($dbh),			"find new test table");
++    my $dir5 = File::Spec->catdir (DbDir (), "not-in-scope");
++    mkdir $dir5;
++    ok (my $dbf5 = File::Spec->catdir ($dir5, $tbl5),	"in bad location");
++    ok (!-f $dbf5,					"does not exist");
++    ok ($dbh->{csv_tables}{$tbl5}{file} = $dbf5,	"set to illegal location");
++    {   my @d;
++	local $SIG{__DIE__}  = sub { push @d => @_ };
++	local $dbh->{PrintError} = 0;
++	eval { $dbh->do ("create table $tbl5 (x char)"); };
++	like ("@d", qr{is unsafe and not allowed},	"unsafe caught");
++	};
++    rmdir $dir5;
++    }
++
+ ok ($dbh->disconnect,				"disconnect");
+ undef $dbh;
+ 
+diff --git a/t/lib.pl b/t/lib.pl
+index 9050d91..74e3f0f 100644
+--- a/t/lib.pl
++++ b/t/lib.pl
+@@ -116,8 +116,7 @@ END { DbCleanup (); }
+ 
+     my $testtable = "testaa";
+ 
+-    sub FindNewTable
+-    {
++    sub FindNewTable {
+ 	my $dbh = shift;
+ 
+ 	my @tables = defined $listTablesHook ? $listTablesHook->($dbh)
+-- 
+2.53.0
+
diff -Nru libdbd-csv-perl-0.6200/debian/patches/series libdbd-csv-perl-0.6200/debian/patches/series
--- libdbd-csv-perl-0.6200/debian/patches/series	1970-01-01 00:00:00.000000000 +0000
+++ libdbd-csv-perl-0.6200/debian/patches/series	2026-08-23 11:42:48.000000000 +0000
@@ -0,0 +1 @@
+0001-New-test-for-DBI-1.648-CVE-fix.patch
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.