Bug#688765: libpri and hardening flags [was: Re: Bug#688765: FTBFS if built twice in a row]

Tzafrir Cohen tzafrir.cohen at xorcom.com
Wed Sep 26 12:20:23 UTC 2012


Dear Release Team,

On Wed, Sep 26, 2012 at 01:43:32AM +0200, Tzafrir Cohen wrote:
> On Tue, Sep 25, 2012 at 03:36:47PM +0200, Helmut Grohne wrote:
> > Source: libpri
> > Version: 1.4.12-2
> > Severity: serious
> > Justification: fails to build from source
> > 
> > The upstream Makefile creates a version.c which is not removed
> > during (make) clean. Thus the second attempt to build the package
> > fails with a message from dpkg-source saying that local changes
> > (to version.c) were detected and the build is aborted. Since the
> > package uses dh, the fix is as simple as:
> 
> > echo version.c >> debian/clean
> 
> Applied, thanks for the report.

While rebuilding to fix this, I noticed the lintian notice regarding
hardening flags.

The package use a custom Makefile, which was easy enough to fix. It is
a library that is used in a PSTN module of the Asterisk telephony server
and thus is network facing for a liberal definition of "network" (the N
in PSTN[1]).

Note that libss7 is likely to be similar: both a similar build system
and a similar relation to the network.


So, should I go ahead and include this fix as well?

[1] http://en.wikipedia.org/wiki/PSTN

-- 
               Tzafrir Cohen
icq#16849755              jabber:tzafrir.cohen at xorcom.com
+972-50-7952406           mailto:tzafrir.cohen at xorcom.com
http://www.xorcom.com  iax:guest at local.xorcom.com/tzafrir



More information about the Pkg-voip-maintainers mailing list