Hi!

On Sat, 2026-09-26 at 15:51:37 +0900, Simon Richter wrote:
> Package: dpkg
> Version: 1.22.22
> Severity: normal
> Tags: upstream
> X-Debbugs-Cc: [email protected]

> rust-derivre 0.3.12-1 proudly declares in its debian/control:
> 
>     Section: FIXME-(packages."(name)".section)
> 
> which leads to a dsc file containing
> 
>     Package-List:
>      derivre deb FIXME-(packages."(name)".section) optional arch=any
>      librust-derivre-dev deb rust optional arch=any
> 
> I suspect that should be rejected earlier. You are in good company though,
> the archive does not detect this either, and takes over the Package-List:
> as a Binary tag into the Sources file -_- .

Yes, thanks for the report! This has been a common problem in dpkg,
where many things historically have not been validated, which means
we then get garbage/unexpected values. The problem is always when
introducing validation, where it breaks people's workflows. :/

I started a local branch with erroring in dpkg itself, and then also in
the various dpkg-dev tools, but I need to revisit the latter to centralize
the validation triggering point (so to do it during field transfer,
instead of having to call the validation functions explicitly all over
the place).

For now I've made the validators accept only:

  Section → ^[[:alnum:][:digit:]-]+$
  Priority → ^[[:alpha:]-]+$

But re-reading that now, I should probably disallow starting and ending
'-'. And I'm not sure whether these are going to be too strong anyway (I
suspect someone might be using weird values for these… :/ ).

Thanks,
Guillem

Reply via email to