<feed xmlns='http://www.w3.org/2005/Atom'>
<title>apt, branch 1.1.exp11</title>
<subtitle>Debians commandline package manager</subtitle>
<id>https://git.kalnischkies.de/apt/atom?h=1.1.exp11</id>
<link rel='self' href='https://git.kalnischkies.de/apt/atom?h=1.1.exp11'/>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/'/>
<updated>2015-08-27T15:55:44Z</updated>
<entry>
<title>Release 1.11~exp11</title>
<updated>2015-08-27T15:55:44Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2015-08-27T15:55:19Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=bf33c3bd991be704494a060730f8370fd9cad52c'/>
<id>urn:sha1:bf33c3bd991be704494a060730f8370fd9cad52c</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Fix test-security-no-remote-status</title>
<updated>2015-08-27T13:01:05Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2015-08-27T13:00:02Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=15d9f7e76020775fc87f2b2546ba7570c58e8111'/>
<id>urn:sha1:15d9f7e76020775fc87f2b2546ba7570c58e8111</id>
<content type='text'>
Gbp-Dch: ignore
</content>
</entry>
<entry>
<title>Do not parse Status fields from remote sources</title>
<updated>2015-08-27T12:51:47Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2015-08-21T16:00:37Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=1c73b0fc41c23a08994ef1464c529e0aacff16de'/>
<id>urn:sha1:1c73b0fc41c23a08994ef1464c529e0aacff16de</id>
<content type='text'>
This could allow an attacker to mark a package as installed in a
remote package index, as long as the package was not listed in
the dpkg status file.

This way, an attacker could force the installation of a package
during a dist-upgrade, by providing two packages in an index,
an older marked as installed, and a newer - apt would "upgrade"
to the newer version.
</content>
</entry>
<entry>
<title>Merge branch 'feature/extractar-filefd' into debian/experimental</title>
<updated>2015-08-27T11:58:14Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2015-08-27T11:58:14Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=f19d6a77f60b876e5453614d24886aabdd242ef6'/>
<id>urn:sha1:f19d6a77f60b876e5453614d24886aabdd242ef6</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Use compressor support from FileFd for ExtractTar instead of programs</title>
<updated>2015-08-27T11:45:57Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2014-03-15T22:03:14Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=3564c2f4cfd9cbca6114da15c27f73efd08df78c'/>
<id>urn:sha1:3564c2f4cfd9cbca6114da15c27f73efd08df78c</id>
<content type='text'>
This way we do not depend on the decompressor programs anymore.
</content>
</entry>
<entry>
<title>Add test for using ExtractTar on compressed files</title>
<updated>2015-08-27T11:45:57Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2014-03-16T13:48:39Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=992a1e83eb3fa4a7e6a19288e7c0af7c5d2b25c0'/>
<id>urn:sha1:992a1e83eb3fa4a7e6a19288e7c0af7c5d2b25c0</id>
<content type='text'>
Git-Dch: ignore
</content>
</entry>
<entry>
<title>Always close compressed files in FileFd</title>
<updated>2015-08-27T11:45:57Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2014-03-16T13:48:11Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=2da8aae5550440742674758280f2d339ba612a31'/>
<id>urn:sha1:2da8aae5550440742674758280f2d339ba612a31</id>
<content type='text'>
We dup() the file descriptor when opening compressed files, so we
always need to close the dup()ed one. Furthermore, not unsetting
the d-pointer causes issues when running OpenDescriptor() multiple
times on the same file descriptor.
</content>
</entry>
<entry>
<title>install: Set a local deb as the candidate for that package</title>
<updated>2015-08-27T11:27:44Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2015-08-26T22:28:47Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=848fd2a65fa2aef296d44c9a19b89ac272ca12fe'/>
<id>urn:sha1:848fd2a65fa2aef296d44c9a19b89ac272ca12fe</id>
<content type='text'>
This ensures that we can install .deb files that are not the
candidate for a given package.
</content>
</entry>
<entry>
<title>cacheset: Prefer the depcache over the policy again</title>
<updated>2015-08-27T11:13:13Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2015-08-27T11:10:02Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=b6192267c23ffda1b9c8328537a5f2c83e176c26'/>
<id>urn:sha1:b6192267c23ffda1b9c8328537a5f2c83e176c26</id>
<content type='text'>
By preferring the policy over the depcache, we ignore any changes
we made in the depcache, which makes it impossible for code to
change the candidate used here.

This basically reverts commit 2fbfb111312257fa5fc29b0c2ed386fb712f960e:

 prefer the Policy if it is built instead of the DepCache and
 if DepCache is not available as fallback built the Policy

But it also cleans the code up a bit, by removing one level
of nesting.
</content>
</entry>
<entry>
<title>debian/rules: Only do parallel build if specified in DEB_BUILD_OPTIONS</title>
<updated>2015-08-27T10:58:47Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2015-08-26T23:10:34Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=1476c59e4b93239176a2d4874ec950b489c924b2'/>
<id>urn:sha1:1476c59e4b93239176a2d4874ec950b489c924b2</id>
<content type='text'>
It was not nice to use 2 * number of cores in all cases.

Thanks: Jakub Wilk for the suggestion
</content>
</entry>
</feed>
