Bug#1146443: trixie-pu: package libmodule-cpants-analyse-perl/1.02-1+deb13u1

gregor herrmann <[email protected]>
Newsgroups gmane.linux.debian.devel.release
Message-ID <178830076162.12516.1311315420145874521.reportbug__11257.3973064841$1788300947$gmane$org@jadzia.comodo.priv.at>
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected]
Control: affects -1 + src:libmodule-cpants-analyse-perl
User: [email protected]
Usertags: pu

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

I've uploaded libmodule-cpants-analyse-perl/1.02-1+deb13u1 to trixie, 
in the hope that in can be included in the upcoming point release.

This upload has been prepared in cooperation with ntyni and carnil 
and is part of the Perl no-DSA security fixes, as decribed in 
#1146369.

This upload fixes #1146144.

libmodule-cpants-analyse-perl has a trivial test-only regression with 
the new Archive-Tar in src:perl. The update is needed to prevent a 
FTBFS in trixie.

The update includes one trivial patch, taken from upstream Git / the 1.03 
release, and works with older and newer versions of Archive::Tar.

Changelog entry:

#v+
libmodule-cpants-analyse-perl (1.02-1+deb13u1) trixie; urgency=medium

  * Add 0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch.
    Backport fix for interoperability with Archive::Tar >= 3.08.
    Patch taken from upstream Git as included in 1.03.
    (Closes: #1146144)

 -- gregor herrmann <[email protected]>  Mon, 31 Aug 2026 16:01:08 +0200
#v-

Full debdiff attached.


Thanks in advance,
gregor

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEE0eExbpOnYKgQTYX6uzpoAYZJqgYFAmqXTdlfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEQx
RTEzMTZFOTNBNzYwQTgxMDREODVGQUJCM0E2ODAxODY0OUFBMDYACgkQuzpoAYZJ
qgZJpw/8CJOchus6xHGQf3EFuFV4MmPbCbRyZQhccyPupo0zZtsLvLcpjPURQqfw
G+k2nquz7nqG02yFFirWG50fLFRN1eQEXvtZg2gyaZ15JpWZEGy+hftv9EWLmsy+
7qCwvX0YQNSpG3MhyPIsAuA8g5urrcQSrUq5cpG2vsMn55Dzk+UgY7CfuIqICIw6
7HvNrjPese7xTlH6y6ZfyGbuw0/f5EzE6Y9Mq7EmnH4pGsCJ1OVSXf92/Mq+DT2X
sFTVDH2D2nk+OIjnFnvgykTKIhRbiitZTDVr3VZnboUsdUi1WdgU5KzZakMPevPz
dEnLTzeW7jJvGzOMrpPVyCOWfZiTSYc7s626LTSRMHtXXaOXgHAF4W11diA2cphV
qMuUGOi6lHsC3KF0elX4MWIf2oFSO+zVzI8adtybVk7J/c58vjuWSc75ABkV0Rxk
33uh6fNwBmokTWGrHEKEgHgRUzAJqH9yiScV2Hf8mdMa04Agl8ohcr3RJua4KzoM
WhouOF7sm2WHDXRv1MEPleoUi2RIRTD2qX08SW08x4oiH+oIRi5js3h3DUC2auU/
xqyVgFa8bdiqgUFT2/qEv2qvnhcTjQD4wdF0p6GNZ0MYqXpdLAzT6d+DVZ6h7YH2
JF68kgWNjINC2nxco8Np4yU7WanThxvPRQNjwzxhWTxo9gQSX4o=
=yn90
-----END PGP SIGNATURE-----
libmodule-cpants-analyse-perl_1.02-1+deb13u1.diff (text/plain, 3.3 KB)
diff -Nru libmodule-cpants-analyse-perl-1.02/debian/changelog libmodule-cpants-analyse-perl-1.02/debian/changelog
--- libmodule-cpants-analyse-perl-1.02/debian/changelog	2023-10-29 01:44:09.000000000 +0200
+++ libmodule-cpants-analyse-perl-1.02/debian/changelog	2026-08-31 16:01:08.000000000 +0200
@@ -1,3 +1,12 @@
+libmodule-cpants-analyse-perl (1.02-1+deb13u1) trixie; urgency=medium
+
+  * Add 0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch.
+    Backport fix for interoperability with Archive::Tar >= 3.08.
+    Patch taken from upstream Git as included in 1.03.
+    (Closes: #1146144)
+
+ -- gregor herrmann <[email protected]>  Mon, 31 Aug 2026 16:01:08 +0200
+
 libmodule-cpants-analyse-perl (1.02-1) unstable; urgency=medium
 
   [ Debian Janitor ]
diff -Nru libmodule-cpants-analyse-perl-1.02/debian/patches/0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch libmodule-cpants-analyse-perl-1.02/debian/patches/0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch
--- libmodule-cpants-analyse-perl-1.02/debian/patches/0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch	1970-01-01 01:00:00.000000000 +0100
+++ libmodule-cpants-analyse-perl-1.02/debian/patches/0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch	2026-08-31 16:01:08.000000000 +0200
@@ -0,0 +1,53 @@
+From fed1a10a9d9170bce71777745d504cd427692e2d Mon Sep 17 00:00:00 2001
+From: Paul Howarth <[email protected]>
+Date: Fri, 29 May 2026 11:51:34 +0100
+Subject: [PATCH] Use relative rather than absolute symlink in
+ t/analyse/manifest.t
+
+Archive::Tar since version 3.08 will refuse to extract absolute symlinks
+unless $Archive::Tar::INSECURE_EXTRACT_MODE is set, leading to this test
+suite failure:
+
+Symlink 'Module-CPANTS-Analyse-Test-0.01/MANIFEST.lnk' has absolute target. Not extracting under SECURE EXTRACT MODE at /usr/share/perl5/vendor_perl/Archive/Any/Lite.pm line 130.
+t/analyse/manifest.t .....
+Dubious, test returned 1 (wstat 256, 0x100)
+Failed 1/14 subtests
+
+This problem can be avoided by using relative symlinks:
+  MANIFEST.lnk -> MANIFEST
+rather than absolute symlinks:
+  MANIFEST.lnk -> /path/to/tmpdir/MANIFEST
+in the test.
+
+
+Bug-Debian: https://bugs.debian.org/1146144
+
+---
+ t/analyse/manifest.t | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/t/analyse/manifest.t b/t/analyse/manifest.t
+index b8981ee..1c21a5b 100644
+--- a/t/analyse/manifest.t
++++ b/t/analyse/manifest.t
+@@ -57,7 +57,7 @@ test_distribution {
+ MANIFEST
+ EOF
+ 
+-  eval { symlink "$dir/MANIFEST", "$dir/MANIFEST.lnk" };
++  eval { symlink "MANIFEST", "$dir/MANIFEST.lnk" };
+   if ($@) {
+     diag "symlink is not supported";
+     return;
+@@ -73,7 +73,7 @@ test_distribution {
+ MANIFEST
+ EOF
+ 
+-  eval { symlink "$dir/MANIFEST", "$dir/MANIFEST.lnk" };
++  eval { symlink "MANIFEST", "$dir/MANIFEST.lnk" };
+   if ($@) {
+     diag "symlink is not supported";
+     return;
+-- 
+2.55.0
+
diff -Nru libmodule-cpants-analyse-perl-1.02/debian/patches/series libmodule-cpants-analyse-perl-1.02/debian/patches/series
--- libmodule-cpants-analyse-perl-1.02/debian/patches/series	1970-01-01 01:00:00.000000000 +0100
+++ libmodule-cpants-analyse-perl-1.02/debian/patches/series	2026-08-31 16:01:08.000000000 +0200
@@ -0,0 +1 @@
+0001-Use-relative-rather-than-absolute-symlink-in-t-analy.patch
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.