Your message dated Sat, 15 Aug 2009 18:32:26 +0000
with message-id <e1mco3g-00084q...@ries.debian.org>
and subject line Bug#523516: fixed in roundup 1.4.9-0
has caused the Debian Bug report #523516,
regarding Upgrading to roundup 1.4.4-4+lenny1 breaks pagination entirely
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
523516: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=523516
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: roundup
Version: 1.4.4-4+lenny1
Severity: grave

Howdy!

I just upgraded to 1.4.4-4+lenny1 to fix the security issues.

However, it broke pagination entirely; when going to queries like 
http://code.creativecommons.org/issues/issue?status=-1,1,2,3,4,5,6,7&@sort=-activity&@search_text=&@dispname=Show%20All&@filter=status&@group=priority&@columns=id,activity,title,creator,assignedto,status&@pagesize=50&@startwith=0&assignedto=5
 
, Roundup would only show me seven results.

I created a local 1.4.4-4+lenny1.1 that removes 
19_bogus_pagination_request.dpatch from debian/patches/00list and rebuilt 
the package, and now pagination works properly for me.

I have to run for now, but I think that some quick experimentation should 
allow you to reproduce this. I have a hunch that the problem is that this 
code is suspect:

-                self.pagesize = int(self.form[name].value)
+                try:
+                    self.pagesize = int(self.form.getfirst(name))

should it not be:

-                self.pagesize = int(self.form[name].value)
+                try:
+                    self.pagesize = int(self.form[name].value)

?

Anyway, upstream's bug tracker is down so I can't check. But this security 
package introduced some pretty tragic breakage!

-- System Information:
Debian Release: 5.0
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.26-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages roundup depends on:
ii  adduser                       3.110      add and remove users and groups
ii  python                        2.5.2-3    An interactive high-level object-o
ii  python-central                0.6.8      register and build utility for Pyt

roundup recommends no packages.

Versions of packages roundup suggests:
ii  libapache2-mod-python      3.3.1-7       Python-embedding module for Apache
ii  python-gdbm                2.5.2-1       GNU dbm database support for Pytho
ii  python-mysqldb             1.2.2-7       A Python interface to MySQL
ii  python-openssl             0.7-2         Python wrapper around the OpenSSL 
ii  python-psycopg2            2.0.7-4       Python module for PostgreSQL
ii  python-pyme                0.8.1+clean-1 Python interface to the GPGME GnuP
ii  python-sqlite              1.0.1-7       python interface to SQLite 2
ii  python-tz                  2008c-2       Python version of the Olson timezo
ii  python-xapian              1.0.7-3.1     Xapian search engine interface for
ii  runit                      2.0.0-1       a UNIX init scheme with service su

-- no debconf information



--- End Message ---
--- Begin Message ---
Source: roundup
Source-Version: 1.4.9-0

We believe that the bug you reported is fixed in the latest version of
roundup, which is due to be installed in the Debian FTP archive:

roundup_1.4.9-0.diff.gz
  to pool/main/r/roundup/roundup_1.4.9-0.diff.gz
roundup_1.4.9-0.dsc
  to pool/main/r/roundup/roundup_1.4.9-0.dsc
roundup_1.4.9-0_all.deb
  to pool/main/r/roundup/roundup_1.4.9-0_all.deb
roundup_1.4.9.orig.tar.gz
  to pool/main/r/roundup/roundup_1.4.9.orig.tar.gz



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 523...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Toni Mueller <t...@debian.org> (supplier of updated roundup package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Mon, 10 Aug 2009 10:09:11 +0200
Source: roundup
Binary: roundup
Architecture: source all
Version: 1.4.9-0
Distribution: unstable
Urgency: high
Maintainer: Toni Mueller <t...@debian.org>
Changed-By: Toni Mueller <t...@debian.org>
Description: 
 roundup    - an issue-tracking system
Closes: 523516 529832 540629
Changes: 
 roundup (1.4.9-0) unstable; urgency=high
 .
   * New upstream, fixes several functional and security problems.
     For the full list of changes, including security fixes, most of
     which don't have a CVE number attached, please see upstream's
     CHANGES.txt file. Closes: #529832, #523516, #540629
   * Added the old 'detectors' examples from earlier roundup versions
     (upstream issue #2550574) back in.
Checksums-Sha1: 
 2f8bf6722c606cfa28dcf1bc2072510dae4fd0ca 1024 roundup_1.4.9-0.dsc
 9270c7bee3d0da0baf0b8f2b10c4a875e51426e7 1256691 roundup_1.4.9.orig.tar.gz
 1d4b648bf6b602d340f7a3f359b34d3eb2bed613 21631 roundup_1.4.9-0.diff.gz
 322d527e2e4191fe1f0b6cd543133848f94b54e0 1423392 roundup_1.4.9-0_all.deb
Checksums-Sha256: 
 1a03b29dcb24b1079ce2d024096a243c792482a0f6f2ebb5505d595744c57dbe 1024 
roundup_1.4.9-0.dsc
 4cd65fa25adc3686ceacb7b7cc087c524de91353232f53b7d5bae1b12b2bba69 1256691 
roundup_1.4.9.orig.tar.gz
 a8e99cd2aabadacfe80c5ba6860d4f94f55a0efcde0ae5f8771eeb2e897bf964 21631 
roundup_1.4.9-0.diff.gz
 4d0ff96106709d7936d18bc11ce65767252414b39c8f65113e92ddc87c1867ee 1423392 
roundup_1.4.9-0_all.deb
Files: 
 d07eb217e1fdcd45f1a39262d95533d1 1024 web optional roundup_1.4.9-0.dsc
 5c5ec2c64782f9fbf4e5f5ee2ad482e0 1256691 web optional roundup_1.4.9.orig.tar.gz
 19db2b42a24596dfca5ba8007e468cdc 21631 web optional roundup_1.4.9-0.diff.gz
 c8689fc9cc8bcf68f3d7febf5a8628ce 1423392 web optional roundup_1.4.9-0_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iD8DBQFKhv5ZfoEUoHXLGtIRAn8vAJ92bCq5DTLhP/6b55Q1+I9J2B7SrQCbBvuo
iycej0iK4lQkc/d4GCsMzZY=
=52OM
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to