Package: shim-signed
Version: 1.28+nmu2+0.9+1474479173.6c180c6-1
Severity: serious
User: debian...@lists.debian.org
Usertags: piuparts replaces-without-breaks

Hi,

during a test with piuparts and DOSE tools I noticed your package causes
removal of files that also belong to another package.
This is caused by using Replaces without corresponding Breaks.

The installation sequence to reproduce this problem is

  apt-get install shim/stretch
  # (1)
  apt-get install shim-signed/sid
  apt-get remove shim-signed
  # (2)

The list of installed files at points (1) and (2) should be identical,
but the following files have disappeared:

  /usr/lib/shim/fbx64.efi.signed
  /usr/lib/shim/mmx64.efi.signed

This is a serious bug violating policy 7.6, see
https://www.debian.org/doc/debian-policy/ch-relationships.html#overwriting-files-and-replacing-packages-replaces
and also see the footnote that describes this incorrect behavior:
https://www.debian.org/doc/debian-policy/ch-relationships.html#id13

The shim-signed package has the following relationships with shim:

  Conflicts: n/a
  Breaks:    n/a
  Replaces:  shim (= 0.9+1474479173.6c180c6-1)

>From the attached log (scroll to the bottom...):

1m16.4s ERROR: FAIL: After purging files have disappeared:
  /usr/lib/shim/fbx64.efi.signed         owned by: shim-signed
  /usr/lib/shim/mmx64.efi.signed         owned by: shim-signed

1m16.4s ERROR: FAIL: After purging files have been modified:
  /var/lib/dpkg/info/shim.list   not owned


cheers,

Andreas

Attachment: shim=0.9+1474479173.6c180c6-1_shim-signed=1.28+nmu2+0.9+1474479173.6c180c6-1.log.gz
Description: application/gzip

Reply via email to