Bug#1146443: trixie-pu: package libmodule-cpants-analyse-perl/1.02-1+deb13u1
gregor herrmann <[email protected]>
| Newsgroups | gmane.linux.debian.devel.release |
|---|---|
| Message-ID | <178830076162.12516.1311315420145874521.reportbug__11257.3973064841$1788300947$gmane$org@jadzia.comodo.priv.at> |
Package: release.debian.org Severity: normal Tags: trixie X-Debbugs-Cc: [email protected] Control: affects -1 + src:libmodule-cpants-analyse-perl User: [email protected] Usertags: pu -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 I've uploaded libmodule-cpants-analyse-perl/1.02-1+deb13u1 to trixie, in the hope that in can be included in the upcoming point release. This upload has been prepared in cooperation with ntyni and carnil and is part of the Perl no-DSA security fixes, as decribed in #1146369. This upload fixes #1146144. libmodule-cpants-analyse-perl has a trivial test-only regression with the new Archive-Tar in src:perl. The update is needed to prevent a FTBFS in trixie. The update includes one trivial patch, taken from upstream Git / the 1.03 release, and works with older and newer versions of Archive::Tar. Changelog entry: #v+ libmodule-cpants-analyse-perl (1.02-1+deb13u1) trixie; urgency=medium * Add 0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch. Backport fix for interoperability with Archive::Tar >= 3.08. Patch taken from upstream Git as included in 1.03. (Closes: #1146144) -- gregor herrmann <[email protected]> Mon, 31 Aug 2026 16:01:08 +0200 #v- Full debdiff attached. Thanks in advance, gregor -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmqXTdlfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ qgZJpw/8CJOchus6xHGQf3EFuFV4MmPbCbRyZQhccyPupo0zZtsLvLcpjPURQqfw G+k2nquz7nqG02yFFirWG50fLFRN1eQEXvtZg2gyaZ15JpWZEGy+hftv9EWLmsy+ 7qCwvX0YQNSpG3MhyPIsAuA8g5urrcQSrUq5cpG2vsMn55Dzk+UgY7CfuIqICIw6 7HvNrjPese7xTlH6y6ZfyGbuw0/f5EzE6Y9Mq7EmnH4pGsCJ1OVSXf92/Mq+DT2X sFTVDH2D2nk+OIjnFnvgykTKIhRbiitZTDVr3VZnboUsdUi1WdgU5KzZakMPevPz dEnLTzeW7jJvGzOMrpPVyCOWfZiTSYc7s626LTSRMHtXXaOXgHAF4W11diA2cphV qMuUGOi6lHsC3KF0elX4MWIf2oFSO+zVzI8adtybVk7J/c58vjuWSc75ABkV0Rxk 33uh6fNwBmokTWGrHEKEgHgRUzAJqH9yiScV2Hf8mdMa04Agl8ohcr3RJua4KzoM WhouOF7sm2WHDXRv1MEPleoUi2RIRTD2qX08SW08x4oiH+oIRi5js3h3DUC2auU/ xqyVgFa8bdiqgUFT2/qEv2qvnhcTjQD4wdF0p6GNZ0MYqXpdLAzT6d+DVZ6h7YH2 JF68kgWNjINC2nxco8Np4yU7WanThxvPRQNjwzxhWTxo9gQSX4o= =yn90 -----END PGP SIGNATURE-----
libmodule-cpants-analyse-perl_1.02-1+deb13u1.diff
(text/plain, 3.3 KB)
diff -Nru libmodule-cpants-analyse-perl-1.02/debian/changelog libmodule-cpants-analyse-perl-1.02/debian/changelog --- libmodule-cpants-analyse-perl-1.02/debian/changelog 2023-10-29 01:44:09.000000000 +0200 +++ libmodule-cpants-analyse-perl-1.02/debian/changelog 2026-08-31 16:01:08.000000000 +0200 @@ -1,3 +1,12 @@ +libmodule-cpants-analyse-perl (1.02-1+deb13u1) trixie; urgency=medium + + * Add 0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch. + Backport fix for interoperability with Archive::Tar >= 3.08. + Patch taken from upstream Git as included in 1.03. + (Closes: #1146144) + + -- gregor herrmann <[email protected]> Mon, 31 Aug 2026 16:01:08 +0200 + libmodule-cpants-analyse-perl (1.02-1) unstable; urgency=medium [ Debian Janitor ] diff -Nru libmodule-cpants-analyse-perl-1.02/debian/patches/0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch libmodule-cpants-analyse-perl-1.02/debian/patches/0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch --- libmodule-cpants-analyse-perl-1.02/debian/patches/0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch 1970-01-01 01:00:00.000000000 +0100 +++ libmodule-cpants-analyse-perl-1.02/debian/patches/0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch 2026-08-31 16:01:08.000000000 +0200 @@ -0,0 +1,53 @@ +From fed1a10a9d9170bce71777745d504cd427692e2d Mon Sep 17 00:00:00 2001 +From: Paul Howarth <[email protected]> +Date: Fri, 29 May 2026 11:51:34 +0100 +Subject: [PATCH] Use relative rather than absolute symlink in + t/analyse/manifest.t + +Archive::Tar since version 3.08 will refuse to extract absolute symlinks +unless $Archive::Tar::INSECURE_EXTRACT_MODE is set, leading to this test +suite failure: + +Symlink 'Module-CPANTS-Analyse-Test-0.01/MANIFEST.lnk' has absolute target. Not extracting under SECURE EXTRACT MODE at /usr/share/perl5/vendor_perl/Archive/Any/Lite.pm line 130. +t/analyse/manifest.t ..... +Dubious, test returned 1 (wstat 256, 0x100) +Failed 1/14 subtests + +This problem can be avoided by using relative symlinks: + MANIFEST.lnk -> MANIFEST +rather than absolute symlinks: + MANIFEST.lnk -> /path/to/tmpdir/MANIFEST +in the test. + + +Bug-Debian: https://bugs.debian.org/1146144 + +--- + t/analyse/manifest.t | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/t/analyse/manifest.t b/t/analyse/manifest.t +index b8981ee..1c21a5b 100644 +--- a/t/analyse/manifest.t ++++ b/t/analyse/manifest.t +@@ -57,7 +57,7 @@ test_distribution { + MANIFEST + EOF + +- eval { symlink "$dir/MANIFEST", "$dir/MANIFEST.lnk" }; ++ eval { symlink "MANIFEST", "$dir/MANIFEST.lnk" }; + if ($@) { + diag "symlink is not supported"; + return; +@@ -73,7 +73,7 @@ test_distribution { + MANIFEST + EOF + +- eval { symlink "$dir/MANIFEST", "$dir/MANIFEST.lnk" }; ++ eval { symlink "MANIFEST", "$dir/MANIFEST.lnk" }; + if ($@) { + diag "symlink is not supported"; + return; +-- +2.55.0 + diff -Nru libmodule-cpants-analyse-perl-1.02/debian/patches/series libmodule-cpants-analyse-perl-1.02/debian/patches/series --- libmodule-cpants-analyse-perl-1.02/debian/patches/series 1970-01-01 01:00:00.000000000 +0100 +++ libmodule-cpants-analyse-perl-1.02/debian/patches/series 2026-08-31 16:01:08.000000000 +0200 @@ -0,0 +1 @@ +0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch