[Pkg-xmpp-devel] Bug#989283: prosody: upgrade overwrites changed files in /etc without asking

Thorsten Glaser tg at mirbsd.de
Mon May 31 02:13:13 BST 2021


Package: prosody
Version: 0.11.2-1+deb10u2
Severity: serious
Justification: Policy 10.7.3

The recent security upgrade (0.11.2-1 → 0.11.2-1+deb10u2)
overwrote the configuration files prosody/certs/localhost.{crt,key}
without asking, notifying, or anything. This is a Policy violation:

10.7.3. Behavior[40]¶

   Configuration file handling must conform to the following behavior:
     * local changes must be preserved during a package upgrade, and

Please make sure to fix this!

-- System Information:
Debian Release: 10.9
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.19.0-16-amd64 (SMP w/1 CPU core)
Locale: LANG=C, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE=C (charmap=UTF-8)
Shell: /bin/sh linked to /bin/lksh
Init: sysvinit (via /sbin/init)

Versions of packages prosody depends on:
ii  adduser                             3.118
ii  libc6                               2.28-10
ii  libidn11                            1.33-2.2
ii  libssl1.1                           1.1.1d-0+deb10u6
ii  lsb-base                            10.2019051400
ii  lua-bitop [lua5.2-bitop]            1.0.2-5
ii  lua-expat [lua5.2-expat]            1.3.0-4
ii  lua-filesystem [lua5.2-filesystem]  1.6.3-1
ii  lua-sec [lua5.2-sec]                0.7-1
ii  lua-socket [lua5.2-socket]          3.0~rc1+git+ac3201d-4
ii  lua5.2                              5.2.4-1.1+b2
ii  ssl-cert                            1.0.39

Versions of packages prosody recommends:
pn  lua5.2-event  <none>

Versions of packages prosody suggests:
pn  lua-dbi-mysql       <none>
pn  lua-dbi-postgresql  <none>
pn  lua-dbi-sqlite3     <none>
pn  lua-zlib            <none>

-- Configuration Files:
/etc/init.d/prosody changed [not included]
/etc/prosody/conf.avail/example.com.cfg.lua [Errno 13] Permission denied: '/etc/prosody/conf.avail/example.com.cfg.lua'
/etc/prosody/conf.avail/localhost.cfg.lua [Errno 13] Permission denied: '/etc/prosody/conf.avail/localhost.cfg.lua'
/etc/prosody/prosody.cfg.lua [Errno 13] Permission denied: '/etc/prosody/prosody.cfg.lua'

-- no debconf information


More information about the Pkg-xmpp-devel mailing list