Debian Patches
Status for golang-github-notaryproject-notation-go/1.3.2-4
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| 0001-Fix-overflow-on-32-bit-architectures.patch | Fix overflow on 32-bit architectures On 32-bit architectures, math.MaxInt64 overflows int in VerifyOptions.MaxSignatureAttempts. Use math.MaxInt instead. |
Reinhard Tartler <siretart@tauware.de> | yes | upstream | upstream, https://github.com/notaryproject/notation-go/commit/a48f22835cb593d4a8ab6032f141a64de01e278d | 2026-09-25 |
| 0002-Allow-skipping-tests-that-connect-to-the-internet.patch | Allow skipping tests that connect to the internet In isolated or offline build environments (such as Debian package build chroots), tests that attempt DNS lookups or external TCP connections fail. Skip the test when dialing external hosts fails. |
Reinhard Tartler <siretart@tauware.de> | not-needed | debian | 2026-09-25 | |
| 0003-Skip-tests-that-fail-on-unknown-certificate-status.patch | Skip tests that fail on unknown certificate status In offline build environments, authentic timestamp verification cannot reach OCSP or CRL revocation endpoints over the internet, causing tests to fail with "revocation status is unknown". Skip the subtests when this revocation error occurs. |
Reinhard Tartler <siretart@tauware.de> | not-needed | 2026-09-25 | ||
| 0004-disable-network-tests.patch | Disable network tests Disable TestSignWithTimestamping which attempts to access timestamping authorities over the internet, failing in offline build environments. |
Santiago Vila <sanvila@debian.org> | not-needed | debian | 2026-09-25 | |
| 0005-Fix-mockRemoteClient-blob-upload-Location.patch | Fix mockRemoteClient to return valid Location and Request matching registry host In oras-go >= 2.6.2 (GHSA-jxpm-75mh-9fp7), blob upload location validation requires the Location header to match the registry host. Because mockRemoteClient previously returned an http.Response with an empty Request and a relative Location ("test"), Location() could not resolve the host, leading to test failures in TestPushSignature and TestPushSignatureImageManifest. Passing the original req as Response.Request and providing a valid Location path under /v2/test/blobs/uploads/ allows Location() to resolve properly against the request URL and pass host validation in oras-go. |
Reinhard Tartler <siretart@tauware.de> | yes | debian upstream | 2026-09-25 | |
| 0006-Escape-double-quotes-in-test-DN-per-RFC-4514.patch | Escape double quotes in test DN to comply with RFC 4514 In go-ldap >= 3.4.14, unescaped double quotes in DN strings are strictly rejected per RFC 4514 Section 2.4. In the Go string literal for validDN3, `\"` produced an unescaped literal `"` in the DN string rather than an escaped quotation mark `\"`, causing parsing to fail with `got unescaped character: '"'`. Escaping the double quotes properly as `\\\"` ensures validDN3 represents a valid RFC 4514 DN. |
Reinhard Tartler <siretart@tauware.de> | yes | debian | 2026-09-25 |
All known versions for source package 'golang-github-notaryproject-notation-go'
- 1.3.2-4 (forky, sid)
