[Pkg-rust-maintainers] Bug#1135328: trixie-pu: package rustc/1.85.1+dfsg1-1+deb13u1
Fabian Grünbichler
debian at fabian.gruenbichler.email
Fri May 1 08:03:27 BST 2026
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: rustc at packages.debian.org, debian at fabian.gruenbichler.email
Control: affects -1 + src:rustc
User: release.debian.org at packages.debian.org
Usertags: pu
[ Reason ]
Trixie originally shipped with 1.85.0. There was an upstream stable update of
1.85.1 shortly after, which would fix building the Linux kernel for 32-bit arm
targets. Additionally, the vendored copy of rust-tar used by cargo was affected
by a security issue.
[ Impact ]
rustdoc for certain targets is broken, the tar CVE would remain unfixed.
[ Tests ]
There's an extensive test suite upstream that is also executed as part of the
package build. I triggered a test run of autopkgtests using debusine that is
still running.
[ Risks ]
The fixes are fairly minimal and well-tested. But this is still a toolchain
package we are talking about.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable (filtered and unfiltered)
[x] the issue is verified as fixed in unstable
[ Changes ]
Import of upstream "hotfix" 1.85.1 release, consisting of 5 changes
- two are relating to the rustdoc bug referenced in d/changelog
- one affects libstd for windows
- one affects custom targets (not used in packaging context, a downgrade of a
vendored dependency, which accounts for 10k of the 11k debdiff lines
- one affects just the build of the toolchain itself
Backport of the rust-tar CVE fixes adapted for the vendored version
[ Other info ]
The 1.85.1 upgrade would make the Rust-For-Linux people happy - they use Debian
stable's version as baseline, but missed that we were still on 1.85.0 and not
1.85.1 which they test with.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: rustc_1.85.1+dfsg1-1+deb13u1.debdiff
Type: application/octet-stream
Size: 418460 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-rust-maintainers/attachments/20260501/6a73f044/attachment-0002.obj>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: rustc_1.85.1+dfsg1-1+deb13u1.debdiff.filtered
Type: application/octet-stream
Size: 54565 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-rust-maintainers/attachments/20260501/6a73f044/attachment-0003.obj>
More information about the Pkg-rust-maintainers
mailing list