Discussion:
Processed: bookworm-pu: package mariadb 1:10.11.10-0+deb12u1
Add Reply
Debian Bug Tracking System
2024-11-06 05:30:01 UTC
Reply
Permalink
affects -1 + src:mariadb
Bug #1086798 [release.debian.org] bookworm-pu: package mariadb 1:10.11.10-0+deb12u1
Added indication that 1086798 affects src:mariadb
--
1086798: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1086798
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Otto Kekäläinen
2025-02-20 00:00:01 UTC
Reply
Permalink
Control: retitle -1 bookworm-pu: package mariadb 1:10.11.11-0+deb12u1

Upstream 10.11.11 version is now out, so I will repurpose this for the
preparation of 1:10.11.11-0+deb12u1, currently in progress at
https://salsa.debian.org/mariadb-team/mariadb-server/-/merge_requests/98
Debian Bug Tracking System
2025-02-20 00:00:01 UTC
Reply
Permalink
Post by Otto Kekäläinen
retitle -1 bookworm-pu: package mariadb 1:10.11.11-0+deb12u1
Bug #1086798 [release.debian.org] bookworm-pu: package mariadb 1:10.11.10-0+deb12u1
Changed Bug title to 'bookworm-pu: package mariadb 1:10.11.11-0+deb12u1' from 'bookworm-pu: package mariadb 1:10.11.10-0+deb12u1'.
--
1086798: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1086798
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Otto Kekäläinen
2025-02-24 06:20:01 UTC
Reply
Permalink
Control: tags -1 -moreinfo

New version currently in review at
https://salsa.debian.org/mariadb-team/mariadb-server/-/merge_requests/98

mariadb (1:10.11.11-0+deb12u1) bookworm; urgency=medium

[ Otto KekÀlÀinen ]
* New upstream version 10.11.11. Includes fixes for several defects
as noted at https://mariadb.com/kb/en/mariadb-10-11-11-release-notes/ as
well the following security issues:
- CVE-2025-21490
* This release includes upstream version 10.11.10, with fixes for regressions
as noted at https://mariadb.com/kb/en/mariadb-10-11-10-release-notes/
* Includes fix for main.having_cond_pushdown test failure on s390x which also
affected builds in Debian (https://jira.mariadb.org/browse/MDEV-34650)
* Previous version 10.11.7 included fix for InnoDB hang (Closes: #1069895)
* Include Debian packaging bugfixes done upstream:
- MDEV-35907: debian-start script fails when using non-standard socket path
- Set CAP_IPC_LOCK capability if possible
* Update server trace to include new parameters and values. This includes now
MariaDB client parameter 'quick-max-column-width' and new MariaDB Server
parameters 'innodb-log-file-mmap' and 'optimizer-join-limit-pref-ratio'.
Also the parameters 'innodb-lru-flush-size' and
'innodb-purge-rseg-truncate-frequency' seems to have been removed, while
'optimizer-adjust-secondary-key-costs' got new default values.
* Update configuration traces to match innodb_log_file_mmap changes done in
MDEV-35785
* Update configuration traces with new query allocator values from MDEV-35750
* Skip test main.mysqld--help-aria due to MDEV-34733
* Include several restart/shutdown related fixes that have been in Debian
unstable in MariaDB 11.4 for a long time, and which are likely needed to
avoid occasional shutdown issues, in particular on upgrades (LP: #2034125)
in both Debian and Ubuntu
- Make SysV init more verbose in case of MariaDB start failures
(Related: #1033234)
- Limit check of running mysqld/mariadbd to system users (Closes: #1032047)
- When shutting down 'mariadbd', fallback to 'mysqld'
* Add Lintian overrides for new upstream documentation JavaScript files
* Make d/watch more specific to circumvent bug in .10 vs .11 detection

[ Phil Dibowitz ]
* Add some info on getting back to passwordless root (Closes: #1088133)

-- Otto KekÀlÀinen <***@debian.org> Tue, 18 Feb 2025 16:56:41 -0800


± git diff --stat debian/1%10.11.9-0+deb12u1...HEAD -- debian
debian/additions/debian-start
| 6 ++--
debian/changelog
| 42 +++++++++++++++++++++++-
debian/control
| 6 ++--
debian/gbp.conf
| 2 +-
debian/mariadb-server-core.postinst
| 49 ++++++++++++++++++++++++++++
debian/mariadb-server.README.Debian
| 20 ++++++++++++
debian/mariadb-server.mariadb.init
| 23 +++++++++++--
debian/mariadb-server.postrm
| 11 ++++++-
debian/mariadb-server.preinst
| 11 ++++++-
debian/patches/0025-Change-the-default-optimization-from-O3-to-O2-in-mys.patch
| 54 -------------------------------
debian/patches/fix-spelling-rocksdb.patch
| 6 ++--
debian/patches/mroonga-mrn-lib-dirs-path-reproducible-build.patch
| 4 +--
debian/patches/rocksdb-kfreebsd.patch
| 20 ++++++------
debian/patches/series
| 1 -
debian/salsa-ci.yml
| 144 ++-------------------------------------------------------------------------------
debian/source/lintian-overrides
| 5 +--
debian/tests/control
| 6 ++--
debian/tests/traces/mariadb-verbose-help.expected
| 4 +++
debian/tests/traces/mariadbd-verbose-help.expected
| 37 ++++++++++++++-------
debian/unstable-tests.amd64
| 1 +
debian/unstable-tests.arm64
| 1 +
debian/unstable-tests.ppc64el
| 1 +
debian/watch
| 2 +-
23 files changed, 215 insertions(+), 241 deletions(-)

± git diff --stat debian/1%10.11.9-0+deb12u1...HEAD > debdiff.stat
± xz debdiff.stat
± git diff debian/1%10.11.9-0+deb12u1...HEAD > debdiff.diff
± xz debdiff.diff

33K debdiff.stat.xz
3,3M debdiff.diff.xz

The debdiff is so large that I am only attaching the stat to this message.
Otto Kekäläinen
2025-02-27 02:30:01 UTC
Reply
Permalink
Hi release team,

The MR https://salsa.debian.org/mariadb-team/mariadb-server/-/merge_requests/98
has been reviewed (thanks Sylvain) and I think it is ready to be
uploaded to stable-proposed-updates.

I've attached the output `git diff debian/1%10.11.9-0+deb12u1 --
debian > debian-1%10.11.9-0+deb12u1.diff`.

As there are quite a few changes, they may need additional
justification on why they are all indeed necessary bugfixes, and also
how their quality has been assured:

- Upstream MariaDB is a large project and cherry-picking only security
fixes is not feasible. As we skipped 10.11.10, this has now changes
from two upstream maintenance releases.

- Upstream releases included fixes in the Debian packaging. Debian
should also include these changes to avoid deviating from upstream.
They are relatively safe to include, as upstream has already published
them and there are no reported regressions.

- Several users in Debian reported service restart issues that have
been fixed in unstable for a long time, and those fixes have proven to
be correct. These fixes should also be included in the stable update,
and were indeed proposed during the Bookworm freeze, but the fixes
were new at the time and at the time not proven, so they were left out
of Bookworm. Currently Debian users are not reporting this, but we can
see that the equivalent Ubuntu 24.04 version has multiple apport
reports about the same issue, and it is likely Debian users are also
affected.

- All the changes in this release have already shipped in MariaDB
11.4.5 in Debian unstable, and no regressions have been reported so
far.

- The updates have been tested with an extensive Bookworm-specific
Salsa CI pipeline that includes multiple install/upgrade scenarios
that are relevant for this package with a service and presistent data.
Some of the changes are purely related to testing. They are not
strictly necessary for Bookworm itself, but they help keep the Salsa
CI pipeline fully green, thus indirectly help ensure that any future
regressions in Bookworm uploads can be easily detected.

- One README update is included as some users reported issues with
accessing their database as root user, which is a severe usability
issue and the README update will mitigate it.

- One patch of low importance was dropped as rewriting the patch is
riskier than just dropping it and aligning with upstream changes in
the domain. Other patches were refreshed to make future upstream
imports easier, even though refreshing patches isn't strictly
necessary for a single Bookworm update.

Let me know if you have further questions.

Also note that the sooner this can be uploaded to
stable-updates-proposed, the more time we will have to collect
build/test/user feedback and potentially catch any potential
regressions before the next point release in actual stable-updates.

Thanks!
Adam D. Barratt
2025-03-01 11:00:01 UTC
Reply
Permalink
Control: tags -1 + confirmed
Post by Otto Kekäläinen
The MR
https://salsa.debian.org/mariadb-team/mariadb-server/-/merge_requests/98
has been reviewed (thanks Sylvain) and I think it is ready to be
uploaded to stable-proposed-updates.
Please go ahead, bearing in mind that the window for 12.10 closes next
weekend.
Post by Otto Kekäläinen
Also note that the sooner this can be uploaded to
stable-updates-proposed, the more time we will have to collect
build/test/user feedback and potentially catch any potential
regressions before the next point release in actual stable-updates.
I don't think you mean stable-updates here [
https://lists.debian.org/debian-devel-announce/2011/03/msg00010.html ]

Regards,

Adam
Debian Bug Tracking System
2025-03-01 11:00:01 UTC
Reply
Permalink
Post by Adam D. Barratt
tags -1 + confirmed
Bug #1086798 [release.debian.org] bookworm-pu: package mariadb 1:10.11.11-0+deb12u1
Added tag(s) confirmed.
--
1086798: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1086798
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Otto Kekäläinen
2025-03-02 02:20:01 UTC
Reply
Permalink
Hi,
Post by Adam D. Barratt
Please go ahead, bearing in mind that the window for 12.10 closes next
weekend.
Thanks! Upload is done
(https://tracker.debian.org/news/1623097/accepted-mariadb-1101111-0deb12u1-source-into-proposed-updates/)
but I don't see builds happening at
https://buildd.debian.org/status/package.php?p=mariadb&suite=bookworm.
I guess I will see the build results next weekend?
Post by Adam D. Barratt
Post by Otto Kekäläinen
Also note that the sooner this can be uploaded to
stable-updates-proposed, the more time we will have to collect
build/test/user feedback and potentially catch any potential
regressions before the next point release in actual stable-updates.
I don't think you mean stable-updates here [
https://lists.debian.org/debian-devel-announce/2011/03/msg00010.html ]
Right, I meant proposed-updates -> stable (bookworm).
Adam D. Barratt
2025-03-02 10:20:01 UTC
Reply
Permalink
Post by Otto Kekäläinen
Hi,
Post by Adam D. Barratt
Please go ahead, bearing in mind that the window for 12.10 closes next
weekend.
Thanks! Upload is done
(
https://tracker.debian.org/news/1623097/accepted-mariadb-1101111-0deb1
2u1-source-into-proposed-updates/)
but I don't see builds happening at
https://buildd.debian.org/status/package.php?p=mariadb&suite=bookworm
.
I guess I will see the build results next weekend?
No, you just needed to wait for a dinstall after the SRM accepted mail
in the bug log, as usual for *pu. The builds are there now, so will be
on mirrors after the 13:52 dinstall.

Regards,

Adam

Debian Bug Tracking System
2025-02-24 06:20:01 UTC
Reply
Permalink
tags -1 -moreinfo
Bug #1086798 [release.debian.org] bookworm-pu: package mariadb 1:10.11.11-0+deb12u1
Removed tag(s) moreinfo.
--
1086798: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1086798
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Adam D Barratt
2025-03-01 20:30:01 UTC
Reply
Permalink
package release.debian.org
tags 1086798 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==============

Package: mariadb
Version: 10.11.11-0+deb12u1

Explanation: new upstream stable release; fix denial of service issue [CVE-2025-21490]
Loading...