[Pkg-xmpp-devel] Bug#989283: prosody: upgrade overwrites changed files in /etc without asking
Thorsten Glaser
tg at mirbsd.de
Mon May 31 02:13:13 BST 2021
Package: prosody
Version: 0.11.2-1+deb10u2
Severity: serious
Justification: Policy 10.7.3
The recent security upgrade (0.11.2-1 → 0.11.2-1+deb10u2)
overwrote the configuration files prosody/certs/localhost.{crt,key}
without asking, notifying, or anything. This is a Policy violation:
10.7.3. Behavior[40]¶
Configuration file handling must conform to the following behavior:
* local changes must be preserved during a package upgrade, and
Please make sure to fix this!
-- System Information:
Debian Release: 10.9
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 4.19.0-16-amd64 (SMP w/1 CPU core)
Locale: LANG=C, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE=C (charmap=UTF-8)
Shell: /bin/sh linked to /bin/lksh
Init: sysvinit (via /sbin/init)
Versions of packages prosody depends on:
ii adduser 3.118
ii libc6 2.28-10
ii libidn11 1.33-2.2
ii libssl1.1 1.1.1d-0+deb10u6
ii lsb-base 10.2019051400
ii lua-bitop [lua5.2-bitop] 1.0.2-5
ii lua-expat [lua5.2-expat] 1.3.0-4
ii lua-filesystem [lua5.2-filesystem] 1.6.3-1
ii lua-sec [lua5.2-sec] 0.7-1
ii lua-socket [lua5.2-socket] 3.0~rc1+git+ac3201d-4
ii lua5.2 5.2.4-1.1+b2
ii ssl-cert 1.0.39
Versions of packages prosody recommends:
pn lua5.2-event <none>
Versions of packages prosody suggests:
pn lua-dbi-mysql <none>
pn lua-dbi-postgresql <none>
pn lua-dbi-sqlite3 <none>
pn lua-zlib <none>
-- Configuration Files:
/etc/init.d/prosody changed [not included]
/etc/prosody/conf.avail/example.com.cfg.lua [Errno 13] Permission denied: '/etc/prosody/conf.avail/example.com.cfg.lua'
/etc/prosody/conf.avail/localhost.cfg.lua [Errno 13] Permission denied: '/etc/prosody/conf.avail/localhost.cfg.lua'
/etc/prosody/prosody.cfg.lua [Errno 13] Permission denied: '/etc/prosody/prosody.cfg.lua'
-- no debconf information
More information about the Pkg-xmpp-devel
mailing list