-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 16:50:10 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: armhf Version: 1.14.8-1~deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Changes: flatpak (1.14.8-1~deb12u1) bookworm; urgency=medium . * Backport upstream stable release for Debian 12 * Changes relative to 1.14.4-1+deb12u1 in bookworm-security: - New upstream stable release 1.14.6 + Don't parse `` as though it was the application name + Install a tmpfiles.d snippet to clean up /var/tmp/flatpak-cache-* during boot + Stop http transfers if a download in progress becomes very slow + Silence warnings when using GLib 2.77.0 or later + Bypass page cache for backend requests in revokefs, fixing installation errors with libostree 2023.4 or later + Show AppStream metadata in `flatpak remote-info` as intended, fixing a regression in 1.9.1 + Don't let Flatpak apps inherit $VK_DRIVER_FILES or $VK_ICD_FILENAMES from the host system, which would be wrong in the sandbox + Fix forward-compatibility with libappstream 0.17.x and 1.0 + Fix a memory leak + Fix some compiler warnings + Make the test failure produce a clearer message if a required tool is missing + Don't force `GIO_USE_VFS=local` for programs launched via flatpak-spawn + Documentation improvements - New upstream stable release 1.14.7 + Automatically reload D-Bus session bus configuration when apps are installed or upgraded, ensuring that any new .service files get picked up + Allow apps to be run if the D-Bus system bus is missing or non-functional + Add several more environment variables to the list not inherited into the sandbox: * $LD_AUDIT, $LD_PRELOAD for ld.so * $__EGL_VENDOR_LIBRARY_DIRS, etc. for EGL * $VK_ADD_DRIVER_FILES, etc. for Vulkan * $container, when running Flatpak inside a container manager + Use xdg-desktop-portal-gnome, if installed, to detect whether apps are running in the background + If an app's data is migrated to a new name and then deleted, don't try to migrate it again, avoiding a recursive symlink loop + Don't leak temporary variable $new_dirs from /etc/profile.d/flatpak.sh into user shell sessions + Avoid an out-of-bounds left-shift (which is technically undefined behaviour) when hashing object names + Fix critical warnings "GFileInfo created without standard::is-symlink" when using /var/lib/flatpak/extension with testing/unstable glib2.0 + Fix validation of documentation against Docbook DTD + Fix a misleading comment in the test for CVE-2024-32462 + Fix a double-free in the test suite + Skip more tests if bubblewrap works but FUSE doesn't - New upstream stable release 1.14.8 + Respin of 1.14.7 reverting unintended submodule changes - d/control: Move dbus-system-bus from Depends to Recommends. `flatpak run` no longer has a working system bus as a hard requirement (verified in `podman run --privileged --rm -it debian:sid-slim`) - Drop CVE-2024-32462 patches, included in the upstream stable release - debian/test.sh: Disable http proxy if used, to ensure we can reach a HTTP server on localhost during automated tests * Changes relative to 1.14.8-1 in unstable: - Revert polkitd dependencies to polkitd | policykit-1 as previously used in bookworm - Revert pkgconf dependencies to pkg-config as previously used in bookworm - Revert location of systemd unit to /lib/systemd/system as previously used in bookworm, dropping versioned dependency on debhelper 13.11.6~ - Revert changes related to Debian 13 GIR XML packaging policy Checksums-Sha1: a99cdaf5c4e613e84570b13ec7e19f80abbb1748 6111164 flatpak-dbgsym_1.14.8-1~deb12u1_armhf.deb 95cf6e7119b45e2fab606e2c088b9a5fbc59cde0 9498384 flatpak-tests-dbgsym_1.14.8-1~deb12u1_armhf.deb a6ae4924009f9cfd33ba978118463d54c0c5dd35 967988 flatpak-tests_1.14.8-1~deb12u1_armhf.deb 254702fcedbe3998a14d9f86a26b2c50874ec6da 14300 flatpak_1.14.8-1~deb12u1_armhf-buildd.buildinfo 0b4f24ce4348188a426ce896f1b976695163df9c 1240196 flatpak_1.14.8-1~deb12u1_armhf.deb 56525ddc8d42d8f6bf5efd1f8d8f585ed7fa36ef 24968 gir1.2-flatpak-1.0_1.14.8-1~deb12u1_armhf.deb 1d0988b397346438fb6192cf0d458eec17069f08 68364 libflatpak-dev_1.14.8-1~deb12u1_armhf.deb 514237d894635ed6420d6464230ca5aff3dfd05d 1482292 libflatpak0-dbgsym_1.14.8-1~deb12u1_armhf.deb a61fc7d65ed36d27de22fc60401ab8b86f7fe794 310624 libflatpak0_1.14.8-1~deb12u1_armhf.deb Checksums-Sha256: d19b1d2a4ba6feb65989053cc9b7dafe2a18ca016b085cf39e2086283927572f 6111164 flatpak-dbgsym_1.14.8-1~deb12u1_armhf.deb 36d10e542a326b1b5a1b0a466fece66c5312fd7deed38188726aa7b18ef1df66 9498384 flatpak-tests-dbgsym_1.14.8-1~deb12u1_armhf.deb d84eba4c1c95d99341b0bffbb26fbb8c6910032c6b637cd5fd0e18c1b6f28619 967988 flatpak-tests_1.14.8-1~deb12u1_armhf.deb 975313cdc990d9e9e02264cbf2a71ea08c58e7af3308cc0e9eb395ee3c6c9477 14300 flatpak_1.14.8-1~deb12u1_armhf-buildd.buildinfo 340ebdcb5ccf3fdcd0ec96234b018cc33d960b5ad51b4944376145d66c247a22 1240196 flatpak_1.14.8-1~deb12u1_armhf.deb 2bb5fcfa94cfa0fe7a8adc396011264bf9f67448045de93e7251450234785659 24968 gir1.2-flatpak-1.0_1.14.8-1~deb12u1_armhf.deb 338a86d54f13488b60c975954228d7d94ed959aabda537b9d20d719aedeabac5 68364 libflatpak-dev_1.14.8-1~deb12u1_armhf.deb d7eee9f308e9a86e6d245d13f4b854a8d30f032a89ba8cc5acce2780ccd45697 1482292 libflatpak0-dbgsym_1.14.8-1~deb12u1_armhf.deb 159ac2339e79a050eec5e9154a53455cbfe4ab2ca0d28d994768ec53e7b26ae4 310624 libflatpak0_1.14.8-1~deb12u1_armhf.deb Files: 8da07c243311583c56bf9c626b2cdab6 6111164 debug optional flatpak-dbgsym_1.14.8-1~deb12u1_armhf.deb 8c40a60eeff16b7a44526a1feb314fef 9498384 debug optional flatpak-tests-dbgsym_1.14.8-1~deb12u1_armhf.deb 33578d29892b612e49202ab6c77388fd 967988 misc optional flatpak-tests_1.14.8-1~deb12u1_armhf.deb 2a98001b4002c4b423aff2cd0eaf8f61 14300 admin optional flatpak_1.14.8-1~deb12u1_armhf-buildd.buildinfo 736ac40b7adb46a593a217e539c6e166 1240196 admin optional flatpak_1.14.8-1~deb12u1_armhf.deb 6efa32b0e937462c4a6213297afd8ba7 24968 introspection optional gir1.2-flatpak-1.0_1.14.8-1~deb12u1_armhf.deb 4dc4b935ea22cdefb5bc6361ee1135cb 68364 libdevel optional libflatpak-dev_1.14.8-1~deb12u1_armhf.deb da4ed4a4553205704ff2cb326d5e42a8 1482292 debug optional libflatpak0-dbgsym_1.14.8-1~deb12u1_armhf.deb 405825fd01a0939ccada7c87e4f1ca79 310624 libs optional libflatpak0_1.14.8-1~deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEw2TRpv7HYIvK+TsIbEMdCP/rlD8FAmZuDOUACgkQbEMdCP/r lD8zxBAA5l1QjAxD5A9Dy/OhXn76QhPr/hs+QqfIyIiILpwH2XE2G+jyp9t8TYI2 7rb6UTTLXB6qlXB3KVDhOKAK1Gc/cLzTWWUy27yaKUq4G0Hvvp9WUULVPXQsOU73 FGwuXWS22I2ygFVqhkZD6YnBTdUHE2UiXuyqMtmcYDTr6vRIQxI6Qa4OoWT8rpQC JbEl0GgGTj1N/EuI4l2/DCbrnADbFzNc/F3LGuiwQ7HQpwUw58yfa2CqyqJZuSWC gfYPozsJ3G57DZNAKqVmiUCF92p7J3q1vOilgYd1vWGqIA/jtOurc21B08CJeQaR B6Q7TJLVthM5R4UINsl8m9VM1k9NqNQ9Euk0KVg8kO9QhSs5XxuOvrO1KZOJGxnT JWvxigD6wZGBq7M7F/cjHY97kzWIAhTLmnUg9LeL6LFDzuX07+TZTA9BRQsqEwPu neScVKmgyuPcqMGnyj+LfuicWJCTw1ZhmRo9ok6vP8aMemivwnMvXsWbCsNJhZ6D QizBQesk+hKtNdNbXgGIdv7YdjQTjWzggiiLN1gdvviPupMhFHvbjyzMGiwL5t+e /9XAT3aVmHP4JRgQI+4yIp/VvszMx1hFKIocIbhgZXMGN89BR/gzTSfMtij/JHoJ ojgL4NNOD+CZZMZbqMKOEMNa6kBhJK+UC/i4kgX/2irNRIu20co= =jIeD -----END PGP SIGNATURE-----