-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 16:50:10 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: arm64 Version: 1.14.8-1~deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-conova-04) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Changes: flatpak (1.14.8-1~deb12u1) bookworm; urgency=medium . * Backport upstream stable release for Debian 12 * Changes relative to 1.14.4-1+deb12u1 in bookworm-security: - New upstream stable release 1.14.6 + Don't parse `` as though it was the application name + Install a tmpfiles.d snippet to clean up /var/tmp/flatpak-cache-* during boot + Stop http transfers if a download in progress becomes very slow + Silence warnings when using GLib 2.77.0 or later + Bypass page cache for backend requests in revokefs, fixing installation errors with libostree 2023.4 or later + Show AppStream metadata in `flatpak remote-info` as intended, fixing a regression in 1.9.1 + Don't let Flatpak apps inherit $VK_DRIVER_FILES or $VK_ICD_FILENAMES from the host system, which would be wrong in the sandbox + Fix forward-compatibility with libappstream 0.17.x and 1.0 + Fix a memory leak + Fix some compiler warnings + Make the test failure produce a clearer message if a required tool is missing + Don't force `GIO_USE_VFS=local` for programs launched via flatpak-spawn + Documentation improvements - New upstream stable release 1.14.7 + Automatically reload D-Bus session bus configuration when apps are installed or upgraded, ensuring that any new .service files get picked up + Allow apps to be run if the D-Bus system bus is missing or non-functional + Add several more environment variables to the list not inherited into the sandbox: * $LD_AUDIT, $LD_PRELOAD for ld.so * $__EGL_VENDOR_LIBRARY_DIRS, etc. for EGL * $VK_ADD_DRIVER_FILES, etc. for Vulkan * $container, when running Flatpak inside a container manager + Use xdg-desktop-portal-gnome, if installed, to detect whether apps are running in the background + If an app's data is migrated to a new name and then deleted, don't try to migrate it again, avoiding a recursive symlink loop + Don't leak temporary variable $new_dirs from /etc/profile.d/flatpak.sh into user shell sessions + Avoid an out-of-bounds left-shift (which is technically undefined behaviour) when hashing object names + Fix critical warnings "GFileInfo created without standard::is-symlink" when using /var/lib/flatpak/extension with testing/unstable glib2.0 + Fix validation of documentation against Docbook DTD + Fix a misleading comment in the test for CVE-2024-32462 + Fix a double-free in the test suite + Skip more tests if bubblewrap works but FUSE doesn't - New upstream stable release 1.14.8 + Respin of 1.14.7 reverting unintended submodule changes - d/control: Move dbus-system-bus from Depends to Recommends. `flatpak run` no longer has a working system bus as a hard requirement (verified in `podman run --privileged --rm -it debian:sid-slim`) - Drop CVE-2024-32462 patches, included in the upstream stable release - debian/test.sh: Disable http proxy if used, to ensure we can reach a HTTP server on localhost during automated tests * Changes relative to 1.14.8-1 in unstable: - Revert polkitd dependencies to polkitd | policykit-1 as previously used in bookworm - Revert pkgconf dependencies to pkg-config as previously used in bookworm - Revert location of systemd unit to /lib/systemd/system as previously used in bookworm, dropping versioned dependency on debhelper 13.11.6~ - Revert changes related to Debian 13 GIR XML packaging policy Checksums-Sha1: da5d18e333bf6e40156b211bba420ae4c617147c 6535108 flatpak-dbgsym_1.14.8-1~deb12u1_arm64.deb 49d279e5aeea3fc601e86e316bfd664f5b10e179 10241964 flatpak-tests-dbgsym_1.14.8-1~deb12u1_arm64.deb 77ff03dc7e7093e5859eb04b0e600d037a60c3f6 1089452 flatpak-tests_1.14.8-1~deb12u1_arm64.deb 4b774713d44edfcaf909666c6ed724d06c7e1ffb 14430 flatpak_1.14.8-1~deb12u1_arm64-buildd.buildinfo ef58a4b6559b992ecf9d0adf8823aa8d1598e139 1323752 flatpak_1.14.8-1~deb12u1_arm64.deb 7fd3d35fe908ae28c7bbbfb7aa118967f6e8deae 24976 gir1.2-flatpak-1.0_1.14.8-1~deb12u1_arm64.deb d681a4b77a7a464950cd177e57baca032ffca2d4 68360 libflatpak-dev_1.14.8-1~deb12u1_arm64.deb ab18e48dce58609dc46b07b8ebf71c333171f829 1524124 libflatpak0-dbgsym_1.14.8-1~deb12u1_arm64.deb 2342b306e8342a7e7b714b4909d8a502ab0c024c 322596 libflatpak0_1.14.8-1~deb12u1_arm64.deb Checksums-Sha256: c925cd233f369a06db376088d9d3a2b23c4bb97bf5adad7d6316920f25d7e388 6535108 flatpak-dbgsym_1.14.8-1~deb12u1_arm64.deb 95db57a3c4fc5f858b9f318485a43b8f78a2a50ad40da4c0f3b7824ce282cd48 10241964 flatpak-tests-dbgsym_1.14.8-1~deb12u1_arm64.deb 232188304ff25d8eb22cc66afb42e460da09fb62fdd620b6ff78ef44628b0693 1089452 flatpak-tests_1.14.8-1~deb12u1_arm64.deb 0ad7ee0ad8250756d92d5287dbae68a171232b9a0b8797874199ad621a4d1639 14430 flatpak_1.14.8-1~deb12u1_arm64-buildd.buildinfo 68715e1d99270afeef4fd0149cc5a8bbee74332597d0aa3f70acd9ceb58c835f 1323752 flatpak_1.14.8-1~deb12u1_arm64.deb 63badabd2cf233c6b46a4b14bffc0524a235fad45e74804d75e253acf930d62f 24976 gir1.2-flatpak-1.0_1.14.8-1~deb12u1_arm64.deb 89e4571e47486f31bef0326dc728e1945be85952960011c46132dafa4dde590d 68360 libflatpak-dev_1.14.8-1~deb12u1_arm64.deb d7233e1ea89696e79310f12b4226179d3195001523f28414d6a94e47472a0b04 1524124 libflatpak0-dbgsym_1.14.8-1~deb12u1_arm64.deb ab32f0ed6999430bfbe7ffb5f85ed4a40b3591c23711f32d05a2c2a23dc4da14 322596 libflatpak0_1.14.8-1~deb12u1_arm64.deb Files: 14e4181ceacf4e46323e62e59ce9212e 6535108 debug optional flatpak-dbgsym_1.14.8-1~deb12u1_arm64.deb 864b1ed192ab06db4fb82ecc13dc5ee0 10241964 debug optional flatpak-tests-dbgsym_1.14.8-1~deb12u1_arm64.deb 924d6a7e5a78ade749e4766c66f75aee 1089452 misc optional flatpak-tests_1.14.8-1~deb12u1_arm64.deb 3c29ffa659e691eef68059faeb418835 14430 admin optional flatpak_1.14.8-1~deb12u1_arm64-buildd.buildinfo 7ff4718c1edaf7263e3e99fd7fb6fb41 1323752 admin optional flatpak_1.14.8-1~deb12u1_arm64.deb 1731b59221cc74dcb227c681597f4b67 24976 introspection optional gir1.2-flatpak-1.0_1.14.8-1~deb12u1_arm64.deb 2134507c49f596a50a4b27290e4f618e 68360 libdevel optional libflatpak-dev_1.14.8-1~deb12u1_arm64.deb 3fc7273ded9f6b2a02947a25c4bb8ab9 1524124 debug optional libflatpak0-dbgsym_1.14.8-1~deb12u1_arm64.deb c0ba795e7c34680f87cc2821cd18cde8 322596 libs optional libflatpak0_1.14.8-1~deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEElif5H+pIB11ZS5Aay8vyjiVDuNYFAmZuCsoACgkQy8vyjiVD uNbDew/9ESDXzV9zx8nliHVs8BMt78i9MqhUP38RgCOUJYsUqY2VWW3U2zg2CNI1 EbHsA4eX2QiMc+lrga2gxJAt7ToxT20pYlbZiRsE5TJnhb1wxrEqTGzaTssFfjCW Vb6oJIRw0R+v7gx2KTzEbJ5y1V/zdrvteEry1J0MPrQsoTPEZRmE6ICuDk4CvShl M/c5bg1G8Ty1uWMLhrcXsWR8lt0jD0v16/+IX2m8T6eWISC6mqkNNtdQAdgCONV5 McNmxUw1pKw168pfOXD6amb/4DhR+qRsPTcgAGyGHx8JSQnn7+aFCjV2RvhR24S9 L1CTeEsi6E46IC1x5PktR2DcoFEXh5Wjgd5NfS7lN2dSeT0gV9HfwdutEH/ie4XC dtoYZNtOb2THoQ0Z7qq3D3dh9hjrePqCdtrjQaLaILSdyCRZFEtY/6QKgMBQyt8e Znkx3aT87I9c2sUx8LB90Awms7MCspsJYV2y9qfuje8c9yYoh6oKoelLunclSYrf ASNGjHPob0sJmTtJnNfgrGrCI/smVOwOnKN/xNBF6DqpYbZBY/7IGOsI0Wc+avFZ W10mdIeWqSjG3gkXj5ACww3aKzGytrCTFLxzimxSUA0zQ4GAc7+bMcQms8BRFhU2 VAmY61pAx3DGGghSBbdRwfu5kJzTRsdltiRsvOOE9UJBWaZPYBA= =yYi2 -----END PGP SIGNATURE-----