• Bug#772204: dput: .orig.tar.gz for non -1 package for security-master

    From Ben Finney@21:1/5 to Ben Finney on Mon Apr 8 00:10:01 2024
    Control: severity -1 minor
    Control: tags -1 - moreinfo
    Control: merge 706607 -1

    On 28-Aug-2016, Ben Finney wrote:

    Is this behaviour the same problem reported in [bug#706607], or is that a separate problem?

    On the assumption that bug#706607 reports the same problem, I am merging
    this bug report with that one.

    If there is a change needed, that is not covered by the report in
    bug#706607 (and that I did not parse correctly from this bug report),
    please feel free to describe it separately in a new bug report.

    --
    \ “Progress might have been all right once, but it's gone on too |
    `\ long.” —Ogden Nash | _o__) |
    Ben Finney <bignose@debian.org>

    -----BEGIN PGP SIGNATURE-----

    iQIzBAABCAAdFiEEYVng8p4vpBLgeVxz+bRqrIRCDIIFAmYTFEUACgkQ+bRqrIRC DILTnhAAv0cBL+83ODMrUNj6CT2x/8VxdHy9tlb7NaOV+QZmum2mUmdxvUXiuEpM vAwllAfy0tzZ6VtmFOFCAUF2y4/zQU7vwkp8sns/dXEzzSo5kmsNfv1rjHeV0p0T WQnhViB/uOcYTbg1wVonmH3aiFK0fvsVTbt2pr3SpYiTg0UPXycUKrdGJs/2sjSW myiIFudY8zs6YPXugZkDZh2mgTIvamyUsn+SVgRvXKDm++vhccXIgUPupgyF7SQ1 4rjBE9bBL7QlM/AfClpJ9MGjShegjEyl7bnzdAg55UlDU8FMlYsxm6eNNiiajsYK z4yCVvso9+cuMPEq1j/07CxIz6FFz1hwJ4JdzObMhxwg6x+Mn2OdisFUQvk4qq5o 8bWF+RWaOPwKrgiyJsfbEbpUtgTX88WqRkBdqjY4KSypNvi1OTehQ/yjZypQsF/h 6zE98LZ9pedwt3bPQNp81EKBh1aDYRyUKdGuTP0V0+5IDjQmhzLiUZUWBRoWDahV hSXR6L3hb2Tv/ojJzxnwBmW2GstCjyy5AULDho4PjTBUhleCfFOFrvvxSooe1u2z sBSjefJHMI0NGbTDBd3kIBraY1RY/lqPVJ0UFZIQkP9UYQxyORLDgWLpsYzOUD8
  • From Osamu Aoki@21:1/5 to Ben Finney on Mon Apr 8 03:50:01 2024
    Hi Ben,

    Thanks for thinking about dput.

    (TBH, I don't use dput/dupload much since I use dgit)

    On Mon, 2024-04-08 at 07:46 +1000, Ben Finney wrote:
    Control: severity -1 minor
    Control: tags -1 - moreinfo
    Control: merge 706607 -1

    On 28-Aug-2016, Ben Finney wrote:

    Is this behaviour the same problem reported in [bug#706607], or is that a separate problem?

    FYI:

    These 2 bug reports are not talking the same triggering conditions.  But fix may
    be a single path since these are around the same message. So merging these are valid action :-)

    * https://bugs.debian.org/772204
    * This is for security upload situation
    * Upload requires to have orig.tar.gz for all security uploads
    * Adjusting message is requested to be clear.

    * https://bugs.debian.org/706607#21
    * This is for normal upload case.
    * Upload doesn't require to have orig.tar.gz for usual uploads.
    * Bug hits when used for derivative dists which uses -0 or similar as "revision"

    Here, "revision" means string matched for P<debian_version>.

    If I understand correctly, requiring orig.tar.gz upload for "revision" -1 is only for uploading to Debian repository. Ubuntu or other derivatives such as Kali start their "revision" from -0 or similar.

    706607 talks interesting corner case for the upstream version which may contain "-" in it.

    706607 talks valid phrase adjustment but that's not enough to address situation described in 772204.

    In light of these, I think following are needed.

    Action 1:
    * Fix REGEX to accommodate -0 variants and upstream version with "-".

    Action 2:
    * Adjust message to address rejection condition and repository policy


    I hope you addressed both pending actions.

    Regards,

    Osamu

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Ben Finney@21:1/5 to Osamu Aoki on Mon Apr 8 04:30:01 2024
    On 08-Apr-2024, Osamu Aoki wrote:
    * Adjust message to address rejection condition and repository policy

    Where (what URL) can I find the current repository policy, with enough precision to implement a conformant upload program?

    --
    \ “It is wrong to think that the task of physics is to find out |
    `\ how nature *is*. Physics concerns what we can *say* about |
    _o__) nature…” —Niels Bohr | Ben Finney <bignose@debian.org>

    -----BEGIN PGP SIGNATURE-----

    iQIzBAABCAAdFiEEYVng8p4vpBLgeVxz+bRqrIRCDIIFAmYTUsQACgkQ+bRqrIRC DIKzLBAAvRoO2acDoi0SN89gBjQZ9dTRVhErsby+haf/aiQeCmSbckpfnYs6SodH 6qI+AGiGt8B9BAlYwbekXVXWGzqFL3q+nRkRKhS+TFAMWI04n2kXLDwTMT3YKuAA SVxQXTcThe4uQEMGgnt9rK8BuuQLuLor2EK1DoqeaekJjTP3dtGg4FD066RXJOiG ZXJozbIyYa8zL0kuGdgDulzW4ZpsrwN0DrqUcqgZT+opNFuTqU0sLhxKJ+NZSDQ9 LDHcLOjtyXhvGP1SWUYpPM6NooP+8N+9zBh09JugTSOutPNSFL9vdMO/6MqNnd/x C2fC0L1sun/UV49fPA1NT/n3oaO3PUSLGqV+FY6Q+GMMthOwACN9ej44pu3wVY8K +NCUW1zxjUKW5h4+sUs3REGg2Gv8Ojc/MqGvFtmf3RYCGBtllmT41pDBglmWzfHZ 3fdz1ghNmnav9zfYeK1w4RSR0RyRWRNRbJSxmLRtae7H9srNplZfldOldEqgzKfE Lu52YiJMn7zzWLOno2DtM44JI+wU8yDdK8gJhchDIlSRrVbrWuiPm0ZY+e8F5+S0 GxVy298rVBbIyz226KTdcL+MGZ+MyzwdNxyoK/eOzb2Y/9zmFSuVrc+bxraxt