<feed xmlns='http://www.w3.org/2005/Atom'>
<title>apt/test, branch 1.1.exp11</title>
<subtitle>Debians commandline package manager</subtitle>
<id>https://git.kalnischkies.de/apt/atom?h=1.1.exp11</id>
<link rel='self' href='https://git.kalnischkies.de/apt/atom?h=1.1.exp11'/>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/'/>
<updated>2015-08-27T13:01:05Z</updated>
<entry>
<title>Fix test-security-no-remote-status</title>
<updated>2015-08-27T13:01:05Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2015-08-27T13:00:02Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=15d9f7e76020775fc87f2b2546ba7570c58e8111'/>
<id>urn:sha1:15d9f7e76020775fc87f2b2546ba7570c58e8111</id>
<content type='text'>
Gbp-Dch: ignore
</content>
</entry>
<entry>
<title>Do not parse Status fields from remote sources</title>
<updated>2015-08-27T12:51:47Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2015-08-21T16:00:37Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=1c73b0fc41c23a08994ef1464c529e0aacff16de'/>
<id>urn:sha1:1c73b0fc41c23a08994ef1464c529e0aacff16de</id>
<content type='text'>
This could allow an attacker to mark a package as installed in a
remote package index, as long as the package was not listed in
the dpkg status file.

This way, an attacker could force the installation of a package
during a dist-upgrade, by providing two packages in an index,
an older marked as installed, and a newer - apt would "upgrade"
to the newer version.
</content>
</entry>
<entry>
<title>Merge branch 'feature/extractar-filefd' into debian/experimental</title>
<updated>2015-08-27T11:58:14Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2015-08-27T11:58:14Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=f19d6a77f60b876e5453614d24886aabdd242ef6'/>
<id>urn:sha1:f19d6a77f60b876e5453614d24886aabdd242ef6</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Add test for using ExtractTar on compressed files</title>
<updated>2015-08-27T11:45:57Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2014-03-16T13:48:39Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=992a1e83eb3fa4a7e6a19288e7c0af7c5d2b25c0'/>
<id>urn:sha1:992a1e83eb3fa4a7e6a19288e7c0af7c5d2b25c0</id>
<content type='text'>
Git-Dch: ignore
</content>
</entry>
<entry>
<title>install: Set a local deb as the candidate for that package</title>
<updated>2015-08-27T11:27:44Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2015-08-26T22:28:47Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=848fd2a65fa2aef296d44c9a19b89ac272ca12fe'/>
<id>urn:sha1:848fd2a65fa2aef296d44c9a19b89ac272ca12fe</id>
<content type='text'>
This ensures that we can install .deb files that are not the
candidate for a given package.
</content>
</entry>
<entry>
<title>allow explicit dis/enable of IndexTargets in sources options</title>
<updated>2015-08-27T09:27:45Z</updated>
<author>
<name>David Kalnischkies</name>
<email>david@kalnischkies.de</email>
</author>
<published>2015-08-27T08:41:19Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=e6a12ff73a2e3246b9e475d9772e88c79a6249f7'/>
<id>urn:sha1:e6a12ff73a2e3246b9e475d9772e88c79a6249f7</id>
<content type='text'>
While Target{,-Add,-Remove} is available for configuring IndexTargets
already, allow Targets to be mentioned explicitely as yes/no options as
well, so that the Target 'Contents' can be disabled via 'Contents: no'
as well as 'Target-Remove: Contents'.
</content>
</entry>
<entry>
<title>use always priv-dropping for changelog download as root</title>
<updated>2015-08-27T09:27:45Z</updated>
<author>
<name>David Kalnischkies</name>
<email>david@kalnischkies.de</email>
</author>
<published>2015-08-23T11:46:35Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=d12561703c7776f665b68c91bddb28dea0728894'/>
<id>urn:sha1:d12561703c7776f665b68c91bddb28dea0728894</id>
<content type='text'>
First of, the temporary directory we download the changelog to needs to
be owned by _apt, but that also means that we don't need to check if we
could/should drop privs as the download happens to a dedicated tempdir
and only after that it is moved to its final location by a privileged user.
</content>
</entry>
<entry>
<title>fix various typos reported by codespell</title>
<updated>2015-08-27T09:27:44Z</updated>
<author>
<name>David Kalnischkies</name>
<email>david@kalnischkies.de</email>
</author>
<published>2015-08-22T14:22:08Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=3a8776a37af38127fb04565959e8e0e449eb04a4'/>
<id>urn:sha1:3a8776a37af38127fb04565959e8e0e449eb04a4</id>
<content type='text'>
Reported-By: codespell
</content>
</entry>
<entry>
<title>just-in-time removal of broken essential packages</title>
<updated>2015-08-27T09:24:07Z</updated>
<author>
<name>David Kalnischkies</name>
<email>david@kalnischkies.de</email>
</author>
<published>2015-08-21T17:59:33Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=9106d7c9692e91622a828f382b85fe592bfec81d'/>
<id>urn:sha1:9106d7c9692e91622a828f382b85fe592bfec81d</id>
<content type='text'>
We deal with Conflicts in SmartUnpack in pretty much the same way, but
Breaks weren't handled in SmartConfigure so that the remove was sheduled
after the configuration of the package breaking the to-be-removed.

Closes: 796070
</content>
</entry>
<entry>
<title>test for #796070: downgrades involving essential packages</title>
<updated>2015-08-27T09:24:07Z</updated>
<author>
<name>Julian Andres Klode</name>
<email>jak@debian.org</email>
</author>
<published>2015-08-19T10:56:12Z</published>
<link rel='alternate' type='text/html' href='https://git.kalnischkies.de/apt/commit/?id=313f7d4ad08831de0a95a88ee4d62795aaad8a0c'/>
<id>urn:sha1:313f7d4ad08831de0a95a88ee4d62795aaad8a0c</id>
<content type='text'>
Git-Dch: Ignore
</content>
</entry>
</feed>
