Bug 2214208
| Summary: | RUSTSEC-2023-0020: const-cstr is unmaintained | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Fabio Valentini <decathorpe> |
| Component: | libblkio | Assignee: | Stefan Hajnoczi <stefanha> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | rawhide | CC: | afaria, rjones, stefanha |
| Target Milestone: | --- | Keywords: | Reopened |
| Target Release: | --- | Flags: | rjones:
needinfo?
(stefanha) |
| Hardware: | Unspecified | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | 1.3.0 libblkio-1.3.0-2.fc40 libblkio-1.3.0-2.fc39 | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-08-14 13:51:37 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2177737 | ||
|
Description
Fabio Valentini
2023-06-12 09:51:46 UTC
The const-cstr crate dependency was dropped upstream in libblkio 1.3.0. There is no Fedora libblkio 1.3.0 package yet because I was waiting for dependencies with the right version to become available in Fedora. I've moved this BZ back to ASSIGNED for now. Once libblkio 1.3.0 is packaged in Fedora this issue will be solved. Since 1.3.0 has been shipped in Rawhide, can we close this now? (In reply to Stefan Hajnoczi from comment #1) > The const-cstr crate dependency was dropped upstream in libblkio 1.3.0. It wasn't dropped from the spec file though: https://src.fedoraproject.org/rpms/libblkio/blob/rawhide/f/libblkio.spec#_45 Note that the %cargo_generate_buildrequires macro now supports workspaces, you should be able to use it instead of hard-coding the Rust dependencies. Just for the sake of moving this bug along I did a scratch build which removes the const-cstr build dependency: https://koji.fedoraproject.org/koji/taskinfo?taskID=104829509 If successful I guess we should push this change, close the bug, and look at using %cargo_generate_buildrequires in future. F40: https://koji.fedoraproject.org/koji/taskinfo?taskID=104830518 F39: https://koji.fedoraproject.org/koji/taskinfo?taskID=104830783 FEDORA-2023-fbe9134000 has been submitted as an update to Fedora 40. https://bodhi.fedoraproject.org/updates/FEDORA-2023-fbe9134000 FEDORA-2023-fbe9134000 has been pushed to the Fedora 40 stable repository. If problem still persists, please make note of it in this bug report. FEDORA-2023-a39b6b6db7 has been submitted as an update to Fedora 39. https://bodhi.fedoraproject.org/updates/FEDORA-2023-a39b6b6db7 FEDORA-2023-a39b6b6db7 has been pushed to the Fedora 39 stable repository. If problem still persists, please make note of it in this bug report. |