pages tagged planet debianBeuc's Bloghttps://blog.beuc.net/tags/planet_debian/Beuc's Blogikiwiki2021-02-12T09:33:36ZGodot GDScript REPLhttps://blog.beuc.net/posts/Godot_GDScript_REPL/2021-02-12T09:33:36Z2021-02-12T09:33:36Z
<p><a href="https://godotengine.org/asset-library/asset/857"><img src="https://www.beuc.net/godot-repl/godot-repl-screenshot.png" alt="" /></a></p>
<p>When experimenting with Godot and its GDScript language, I realized that I missed a good old REPL (Read-Eval-Print Loop) to familiarize myself with the language and API.</p>
<p>This is now possible with this new Godot Editor plugin <img src="https://blog.beuc.net/smileys/smile.png" alt=":)" /></p>
<p>Try it at:<br />
<a href="https://godotengine.org/asset-library/asset/857">https://godotengine.org/asset-library/asset/857</a></p>
Android SDK 11 Rebuildhttps://blog.beuc.net/posts/Android_SDK_11_Rebuild/2021-01-30T09:25:35Z2021-01-30T09:25:35Z
<p><a href="https://android-rebuilds.beuc.net/"><img src="https://www.beuc.net/images/arebuilds.png" alt="" /></a></p>
<p>Android Rebuilds provides <a href="https://android-rebuilds.beuc.net/About/">freely-licensed</a> builds of Android development tools from a Mountain View-based company.<br />
Proprietary binaries are rebuilt from source, build recipes are reverse-engineered.</p>
<p>SDK 11 (API 30) is mostly available, as <a href="https://gitlab.com/android-rebuilds/auto/tree/master/sdk-11.0.0">unattended Docker build scripts</a>, <a href="https://android-rebuilds.beuc.net/SDK_11.0.0/">build documentation</a> as well as <a href="https://android-rebuilds.beuc.net/">convenience binaries</a>.<br />
Only the x86 system image currently fails to build.</p>
Android Emulator Rebuildhttps://blog.beuc.net/posts/Android_Emulator_Rebuild/2021-01-23T13:02:13Z2021-01-23T13:02:13Z
<p><a href="https://android-rebuilds.beuc.net/"><img src="https://www.beuc.net/images/arebuilds.png" alt="" /></a></p>
<p>Android Rebuilds provides <a href="https://blog.beuc.net/posts/Rebuilding_Android_proprietary_SDK_binaries/">freely-licensed</a> builds of Android development tools from a Mountain View-based company.</p>
<p>The Emulator package moved to a separate component and build system.</p>
<p>Emulator 30 is now available, as <a href="https://gitlab.com/android-rebuilds/auto/tree/master/emu-30">unattended Docker build scripts</a>, <a href="https://android-rebuilds.beuc.net/Emulator_30/">build documentation</a> as well as <a href="https://android-rebuilds.beuc.net/">convenience binaries</a>.</p>
git filter-branch and --state-branch - how?https://blog.beuc.net/posts/git_filter-branch_and_--state-branch_-_how__63__/2020-10-04T10:18:57Z2020-10-04T10:18:57Z
<p>I'm mirroring and reworking a large Git repository with <a href="https://git-scm.com/docs/git-filter-branch">git filter-branch</a> (conversion ETA: 20h), and I was wondering how to use <code>--state-branch</code> which is supposed to speed-up later updates, or split a large conversion in several updates.</p>
<p>The documentation is pretty terse, the option can produce weird results (like an identity mapping that breaks all later updates, or calling the expensive <code>tree-filter</code> but discarding the results), <a href="https://github.com/concrete5/incremental-filter-branch">wrappers</a> are convoluted, but I got something to work so I'll share <img src="https://blog.beuc.net/smileys/smile.png" alt=":)" /></p>
<p>The main point is: run the initial script and the later updates in the same configuration, which means the target branch needs to be reset to the upstream branch each time, before it's rewritten again by <code>filter-branch</code>. In other words, don't re-run it on the rewritten branch, nor attempt some <a href="https://stackoverflow.com/questions/2296047/repeatedly-using-git-filter-branch-to-rewrite-new-commits">complex</a> merge/cherry-pick.</p>
<pre><code>git fetch
git branch --no-track -f myrewrite origin/master
git filter-branch \
--xxx-filter ... \
--xxx-filter ... \
--state-branch refs/heads/filter-branch/myrewrite \
-d /dev/shm/filter-branch/$$ -f \
myrewrite
</code></pre>
<p>Updates restart from scratch but only take a few seconds to skim through all the already-rewritten commits, and maintain a stable history.</p>
<p>Note that if the process is interrupted, the state-branch isn't modified, so it's not a stop/resume feature. If you want to split a lenghty conversion, you could simulate multiple upstream updates by checking out successive points in history (e.g. per year using <code>$(git rev-list -1 --before='2020-01-01 00:00:00Z')</code>).</p>
<p><code>--state-branch</code> isn't meant to rewrite in reverse chronological order either, because all commit ids would constantly change. Still, you can rewrite only the recent history for a quick discardable test.</p>
<p>Be cautious when using/deleting rewritten branches, especially during early tests, because Git tends to save them to multiple places which may desync (e.g. <code>.git/refs/heads/</code>, <code>.git/logs/refs/</code>, <code>.git/packed-refs</code>). Also remember to delete the <code>state-branch</code> between different tests. Last, note the unique temporary directory <code>-d</code> to avoid ruining concurrent tests ^_^'</p>
Debian LTS and ELTS - September 2020https://blog.beuc.net/posts/Debian_LTS_and_ELTS_-_September_2020/2020-10-01T16:26:43Z2020-10-01T16:08:50Z
<p><a href="https://wiki.debian.org/LTS"><img src="https://blog.beuc.net/posts/Debian-LTS-2-256.png" width="256" height="256" alt="Debian LTS Logo" class="img" align="right" /></a></p>
<p>Here is my transparent report for my work on the <a href="https://wiki.debian.org/LTS">Debian Long Term Support (LTS)</a> and <a href="https://wiki.debian.org/LTS/Extended%20project">Debian Extended Long Term Support (ELTS)</a>, which extend the security support for past Debian releases, as a paid contributor.</p>
<p>In September, the monthly sponsored hours were split evenly among contributors depending on their max availability - I was assigned 19.75h for LTS (out of my 30 max; all done) and 20h for ELTS (out of my 20 max; all done).</p>
<p><em>ELTS - Jessie</em></p>
<ul>
<li>qemu: jessie triage: finish work started in August</li>
<li>qemu: backport 5 CVE fixes, perform virtual and physical testing, security upload <a href="https://deb.freexian.com/extended-lts/updates/ela-283-1-qemu/">ELA-283-1</a></li>
<li>libdbi-perl: global triage: clarifications, confirm <a href="https://rt.cpan.org/Public/Bug/Display.html?id=99508#txn-1911578">incomplete</a> and attempt to get upstream action, request <a href="https://blog.beuc.net/tags/planet_debian/CVE-2014-10402">new CVE</a> following discussion with security team</li>
<li>libdbi-perl: backport 5 CVE fixes, test, security upload <a href="https://deb.freexian.com/extended-lts/updates/ela-285-1-libdbi-perl/">ELA-285-1</a></li>
</ul>
<p><em>LTS - Stretch</em></p>
<ul>
<li>qemu: stretch triage, while working on ELTS update; mark several CVEs unaffected, update patch/status</li>
<li>wordpress: global triage: reference new patches, request proper <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25286">CVE</a> to fix our temporary tracking</li>
<li>wordpress: revamp package: upgrade to upstream's stable 4.7.5->4.7.18 to ease future updates, re-apply missing patches, fix past regression and notify maintainer, security upload <a href="https://lists.debian.org/debian-lts-announce/2020/09/msg00011.html">DLA-2371-1</a></li>
<li>libdbi-perl: common work with ELTS, security upload <a href="https://lists.debian.org/debian-lts-announce/2020/09/msg00026.html">DLA-2386-1</a></li>
<li>public IRC <a href="http://meetbot.debian.net/debian-lts/2020/debian-lts.2020-09-24-14.58.html">team meeting</a></li>
</ul>
<p><em>Documentation/Scripts</em></p>
<ul>
<li><a href="https://wiki.debian.org/LTS/TestSuites/wordpress">LTS/TestSuites/wordpress</a>: new page with testsuite import and manual tests</li>
<li><a href="https://wiki.debian.org/LTS/TestSuites/qemu">LTS/TestSuites/qemu</a>: minor update</li>
<li><a href="https://wiki.debian.org/Sympa">wiki.d.o/Sympa</a>: update Sympa while using it as a libdbi-perl reverse-dep test (update for newer versions, explain how to bootstrap admin access)</li>
<li><a href="https://www.debian.org/lts/security/2020/">www.d.o/lts/security</a>: import a couple missing announcements and notify uploaders about procedures</li>
<li><a href="https://lists.debian.org/debian-lts/2020/09/msg00024.html">Check status</a> for pdns-recursor, following user request</li>
<li><a href="https://lists.debian.org/debian-lts/2020/09/msg00028.html">Check status</a> for golang-1.7 / CVE-2019-9514 / CVE-2019-9512</li>
<li><a href="https://lists.debian.org/debian-lts/2020/09/msg00051.html">Attempt</a> to improve cooperation after seeing my work discarded and redone as-is, which sadly isn't the first time; no answer</li>
<li>Historical analysis of our CVE fixes: experiment to gather per-CVE tracker history</li>
</ul>
Debian LTS and ELTS - August 2020https://blog.beuc.net/posts/Debian_LTS_and_ELTS_-_August_2020/2020-09-01T10:48:31Z2020-09-01T10:48:31Z
<p><a href="https://wiki.debian.org/LTS"><img src="https://blog.beuc.net/posts/Debian-LTS-2-256.png" width="256" height="256" alt="Debian LTS Logo" class="img" align="right" /></a></p>
<p>Here is my transparent report for my work on the <a href="https://wiki.debian.org/LTS">Debian Long Term Support (LTS)</a> and <a href="https://wiki.debian.org/LTS/Extended%20project">Debian Extended Long Term Support (ELTS)</a>, which extend the security support for past Debian releases, as a paid contributor.</p>
<p>In August, the monthly sponsored hours were split evenly among contributors depending on their max availability - I was assigned 21.75h for LTS (out of my 30 max; all done) and 14.25h for ELTS (out of my 20 max; all done).</p>
<p>We had a <em>Birds of a Feather</em> <a href="https://meetings-archive.debian.net/pub/debian-meetings/2020/DebConf20/72-debian-lts-bof.webm">videoconf</a> <a href="https://debconf20.debconf.org/talks/72-debian-lts-bof/">session</a> at DebConf20, sadly with varying quality for participants (from very good to unusable), where we shared the first results of the LTS survey.</p>
<p>There were also discussions about evaluating our security reactivity, which proved surprisingly hard to estimate (neither CVE release date and criticality metrics are accurate nor easily available), and about when it is appropriate to use public naming in procedures.</p>
<p>Interestingly ELTS gained new supported packages, thanks to a new sponsor -- so far I'd seen the opposite, because we were close to the EOL.</p>
<p>As always, there were opportunities to de-dup work through mutual cooperation with the Debian Security team, and LTS/ELTS similar updates.</p>
<p><em>ELTS - Jessie</em></p>
<ul>
<li>Fresh build VMs</li>
<li>rails/redmine: investigate <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=964432">issue</a>, initially no-action as it can't be reproduced on Stretch and isn't supported in Jessie; <a href="https://lists.debian.org/debian-lts/2020/08/msg00053.html">follow-up</a> when it's supported again</li>
<li>ghostscript: global triage: identify upstream fixed version, distinguish CVEs fixed within a single patch, bisect non-reproducible CVEs, reference missing commit (including at <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16299">MITRE</a>)</li>
<li>ghostscript: fix 25 CVEs, security upload <a href="https://deb.freexian.com/extended-lts/updates/ela-262-1-ghostscript/">ELA-262-1</a></li>
<li>ghostscript: cross-check against the later DSA-4748-1 (almost identical)</li>
<li>software-properties: jessie triage: mark back for update, at least for consistency with Debian Stretch and Ubuntu (all suites)</li>
<li>software-properties: security upload <a href="https://deb.freexian.com/extended-lts/updates/ela-266-1-software-properties/">ELA-266-1</a></li>
<li>qemu: global triage: update status and patch/regression/reproducer links for 6 pending CVEs</li>
<li>qemu: jessie triage: fix 4 'unknown' lines for qemu following changes in package attribution for XSA-297, work continue in September</li>
</ul>
<p><em>LTS - Stretch</em></p>
<ul>
<li>sane-backends: global triage: sort and link patches for 7 CVEs</li>
<li>sane-backends: fix dep-8 test and <a href="https://bugs.debian.org/968369">notify</a> the maintainer,</li>
<li>sane-backends: security upload <a href="https://lists.debian.org/debian-lts-announce/2020/08/msg00029.html">DLA-2332-1</a></li>
<li>ghostscript: security upload <a href="https://lists.debian.org/debian-lts-announce/2020/08/msg00032.html">DLA 2335-1</a> (cf. common ELTS work)</li>
<li>ghostscript: rebuild ("give back") on armhf, blame armhf, <a href="https://lists.debian.org/debian-lts/2020/08/msg00040.html">get told</a> it was a concurrency / build system issue -_-'</li>
<li>software-properties: security upload <a href="https://lists.debian.org/debian-lts-announce/2020/08/msg00035.html">DLA 2339-1</a> (cf. common ELTS work)</li>
<li>wordpress: global triage: reference regression for CVE-2020-4050</li>
<li>wordpress: stretch triage: update past CVE status, work continues in September with probably an upstream upgrade 4.7.5 -> 4.7.18</li>
<li>nginx: cross-check my July update against the later DSA-4750-1 (same fix)</li>
<li>DebConf BoF + IRC follow-up</li>
</ul>
<p><em>Documentation/Scripts</em></p>
<ul>
<li>Clarify/link <a href="https://salsa.debian.org/lts-team/lts-extra-tasks">salsa:lts-team/lts-extra-tasks</a> against <a href="https://salsa.debian.org/freexian-team/project-funding">salsa:freexian-team/project-funding</a> (description)</li>
<li>Historical analysis of our CVE fixes: check feasibility</li>
<li><a href="https://salsa.debian.org/webmaster-team/webwml/-/blob/master/english/security/find-missing-advisories">webwml:find-missing-advisories</a>: handle missing trailing slash, print DSA/DLA date, print affected package rather than committer</li>
<li><a href="https://lists.debian.org/debian-lts/2020/08/msg00031.html">discussion</a> on public naming (shaming?)</li>
<li><a href="https://wiki.debian.org/LTS/TestSuites/sane-backends">LTS/TestsSuites/sane-backends</a>: test with more complex DEP-8/autopkgtest setup</li>
</ul>
Planet upgradehttps://blog.beuc.net/posts/Planet_upgrade/2020-08-15T06:55:30Z2020-08-15T06:55:30Z
<p><a href="https://planet.gnu.org/"><img src="https://blog.beuc.net/posts/planet.gnu.org-logo.png" width="124" height="140" alt="planet.gnu.org logo" class="img" align="right" /></a></p>
<p>The system running <a href="https://planet.gnu.org/">planet.gnu.org</a> was upgraded/reinstalled to Debian 10 "buster" <img src="https://blog.beuc.net/smileys/smile.png" alt=":)" /><br />
<a href="https://git.savannah.nongnu.org/cgit/gnues/planet-infra.git/">Documentation</a> was updated.</p>
<p>Let me know if you notice any issue - <a href="https://lists.gnu.org/mailman/listinfo/planet">planet@gnu.org</a>.</p>
<p>For the next upgrade, we'll have to decide whether to takeover Planet Venus and upgrade it to Python 3, or migrate to another Planet software.<br />
Suggestions/help welcome <img src="https://blog.beuc.net/smileys/smile.png" alt=":)" /></p>
Debian LTS and ELTS - July 2020https://blog.beuc.net/posts/Debian_LTS_and_ELTS_-_July_2020/2020-08-03T13:52:10Z2020-08-03T13:52:10Z
<p><a href="https://wiki.debian.org/LTS"><img src="https://blog.beuc.net/posts/Debian-LTS-2-256.png" width="256" height="256" alt="Debian LTS Logo" class="img" align="right" /></a></p>
<p>Here is my transparent report for my work on the <a href="https://wiki.debian.org/LTS">Debian Long Term Support (LTS)</a> and <a href="https://wiki.debian.org/LTS/Extended%20project">Debian Extended Long Term Support (ELTS)</a>, which extend the security support for past Debian releases, as a paid contributor.</p>
<p>In July, the monthly sponsored hours were split evenly among contributors depending on their max availability - I was assigned 25.25h for LTS (out of 30 max; all done) and 13.25h for ELTS (out of 20 max; all done).</p>
<p>We shifted suites: welcome Stretch LTS and Jessie ELTS. The LTS->ELTS switch happened at the start of the month, but the oldstable->LTS switch happened later (after finalizing and flushing proposed-updates to a last point release), causing some confusion but nothing major.</p>
<p><em>ELTS - Jessie</em></p>
<ul>
<li>New local build setup</li>
<li>ELTS buildds: request timezone harmonization</li>
<li>Reclassify in-progress updates from jessie-LTS to jessie-ELTS</li>
<li>python3.4: finish preparing update, security upload <a href="https://deb.freexian.com/extended-lts/updates/ela-239-1-python3.4/">ELA 239-1</a></li>
<li>net-snmp: global triage: bisect CVE-2019-20892 to identify affected version, jessie/stretch not-affected</li>
<li>nginx: global triage: clarify CVE-2013-0337 status; locate CVE-2020-11724 original patch and regression tests, update <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11724">MITRE</a></li>
<li>nginx: security upload <a href="https://deb.freexian.com/extended-lts/updates/ela-247-1-nginx/">ELA-247-1</a> with 2 CVEs</li>
</ul>
<p><em>LTS - Stretch</em></p>
<ul>
<li>Reclassify in-progress/needed updates from stretch/oldstable to stretch-LTS</li>
<li>rails: upstream security: follow-up on CVE-2020-8163 (RCE) on <a href="https://github.com/rails/rails/issues/39301#issuecomment-653746696">upstream bug tracker</a> and create <a href="https://github.com/rails/rails/pull/39806">pull request</a> for 4.x (merged), hence getting some upstream review</li>
<li>rails: global security: continue <a href="https://lists.debian.org/debian-lts/2020/07/threads.html#00033">coordinating</a> upload in multiple Debian versions, prepare <a href="https://lists.debian.org/debian-lts/2020/07/msg00065.html">fixes</a> for common stretch/buster vulnerabilities in buster</li>
<li>rails: security upload <a href="https://lists.debian.org/debian-lts-announce/2020/07/msg00013.html">DLA-2282</a> fixing 3 CVEs</li>
<li>python3.5: security upload <a href="https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html">DLA-2280-1</a> fixing 13 pending non-critical vulnerabilities, and its test suite</li>
<li>nginx: security upload <a href="https://lists.debian.org/debian-lts-announce/2020/07/msg00014.html">DLA-2283</a> (cf. common ELTS work)</li>
<li>net-snmp: global triage (cf. common ELTS work)</li>
<li>public IRC <a href="http://meetbot.debian.net/debian-lts/2020/debian-lts.2020-07-30-14.59.html">monthly team meeting</a></li>
<li>reach out to clarify the intro from last month's report, following unsettled feedback during meeting</li>
</ul>
<p><em>Documentation/Scripts</em></p>
<ul>
<li>ELTS/README.how-to-release-an-update: fix typo</li>
<li>ELTS buildd: attempt to diagnose slow perfs, provide comparison with Debian and local builds</li>
<li><a href="https://wiki.debian.org/LTS/Meetings">LTS/Meetings</a>: improve presentation</li>
<li><a href="https://wiki.debian.org/SourceOnlyUpload">SourceOnlyUpload</a>: clarify/de-dup pbuilder doc</li>
<li><a href="https://wiki.debian.org/LTS/Development">LTS/Development</a>: reference build logs URL, reference proposed-updates issue during dists switch, reference new-upstream-versioning discussion, multiple jessie->stretch fixes and clean-ups</li>
<li><a href="https://wiki.debian.org/LTS/Development/Asan">LTS/Development/Asan</a>: drop wheezy documentation</li>
<li>Warn about jruby <a href="https://lists.debian.org/debian-lts/2020/07/msg00084.html">mis-triage</a></li>
<li>Provide feedback for <a href="https://lists.debian.org/debian-lts/2020/07/msg00087.html">ksh/CVE-2019-14868</a></li>
<li>Provide feedback for <a href="https://lists.debian.org/debian-lts/2020/07/msg00086.html">condor update</a></li>
<li><a href="https://wiki.debian.org/LTS/TestSuites/nginx">LTS/TestsSuites/nginx</a>: test with new request smuggling test cases</li>
</ul>
Debian LTS and ELTS - June 2020https://blog.beuc.net/posts/Debian_LTS_and_ELTS_-_June_2020/2020-07-01T14:19:14Z2020-07-01T14:19:14Z
<p><a href="https://wiki.debian.org/LTS"><img src="https://blog.beuc.net/posts/Debian-LTS-2-256.png" width="256" height="256" alt="Debian LTS Logo" class="img" align="right" /></a></p>
<p>Here is my transparent report for my work on the <a href="https://wiki.debian.org/LTS">Debian Long Term Support (LTS)</a> and <a href="https://wiki.debian.org/LTS/Extended%20project">Debian Extended Long Term Support (ELTS)</a>, which extend the security support for past Debian releases, as a paid contributor.</p>
<p>In June, the monthly sponsored hours were split evenly among contributors depending on their max availability - I was assigned 30h for LTS (out of 30 max; all done) and 5.25h for ELTS (out of 20 max; all done).</p>
<p>While LTS is part of the Debian project, fellow contributors sometimes surprise me: suggestion to vote for sponsors-funded projects with concorcet was only met with overhead concerns, and there were requests for executive / business owner decisions (we're currently heading towards consultative vote); I heard concerns about discussing non-technical issues publicly (IRC team meetings are <a href="https://wiki.debian.org/LTS/Meetings">public</a> though); the private mail infrastructure was moved from self-hosting straight to Google; when some got an issue with Debian Social for our first video conference, there were immediate suggestions to move to Zoom...<br />
Well, we do need some people to make those LTS firmware updates in non-free <img src="https://blog.beuc.net/smileys/smile.png" alt=":)" /></p>
<p>Also this was the last month before shifting suites: goodbye to Jessie LTS and Wheezy ELTS, welcome Stretch LTS and Jessie ELTS.</p>
<p><em>ELTS - Wheezy</em></p>
<ul>
<li>mysql-connector-java: improve testsuite setup; prepare wheezy/jessie/stretch triple builds; <a href="https://lists.debian.org/debian-lts/2020/06/msg00008.html">coordinate</a> versioning scheme with security-team; security upload <a href="https://deb.freexian.com/extended-lts/updates/ela-234-1-mysql-connector-java/">ELA 234-1</a></li>
<li>ntp: wheezy+jessie triage: 1 ignored (too intrusive to backport); 1 postponed (hard to exploit, no patch)</li>
<li>Clean-up (ditch) wheezy VMs <img src="https://blog.beuc.net/smileys/smile.png" alt=":)" /></li>
</ul>
<p><em>LTS - Jessie</em></p>
<ul>
<li>mysql-connector-java: see common work in ELTS</li>
<li>mysql-connector-java: security uploads <a href="https://lists.debian.org/debian-lts-announce/2020/06/msg00015.html">DLA 2245-1</a> (LTS) and <a href="https://www.debian.org/security/2020/dsa-4703">DSA 4703</a> (oldstable)</li>
<li>ntp: wheezy+jessie triage (see ELTS)</li>
<li>rails: global triage, backport 2 patches, security upload <a href="https://lists.debian.org/debian-lts-announce/2020/06/msg00022.html">DLA 2251-1</a></li>
<li>rails: global security: <a href="https://lists.debian.org/debian-lts/2020/06/msg00055.html">prepare</a> stretch/oldstable update</li>
<li>rails: new important CVE on unmaintained 4.x, fixes introduce several regressions, propose <a href="https://github.com/rails/rails/issues/39301#issuecomment-648885623">new fix</a> to upstream, update stretch proposed update [and jessie, but rails will turn out unsupported in ELTS]</li>
<li>python3.4: prepare update to fix all pending non-criticial issues, 5/6 ready</li>
<li>private video<code>^W^W</code>public IRC <a href="http://meetbot.debian.net/debian-lts/2020/debian-lts.2020-06-25-15.22.html">team meeting</a></li>
</ul>
<p><em>Documentation/Scripts</em></p>
<ul>
<li><a href="https://wiki.debian.org/LTS/TestSuites/mysql-connector-java">LTS/TestsSuites/mysql-connector-java</a>: improve testsuite setup for better coverage</li>
<li><a href="https://wiki.debian.org/LTS/TestSuites/tiff">LTS/TestSuites/tiff</a>: document package maintainer's (extensive) tests</li>
<li><a href="https://wiki.debian.org/LTS/TestSuites/rails">LTS/TestSuites/rails</a>: first version</li>
<li><a href="https://wiki.debian.org/LTS/TestSuites/python">LTS/TestSuites/python</a>: how to run individual test</li>
<li><a href="https://wiki.debian.org/LTS/Development#CVE_triaging_in_the_LTS_release">LTS/Development</a>: clarifications on grouping fixes and validating patches</li>
<li>internal discussion on (not) capping LTS-funded hours</li>
<li>discussion on <a href="https://lists.debian.org/debian-lts/2020/06/msg00027.html">unbound</a> and <a href="https://lists.debian.org/debian-lts/2020/06/msg00004.html">freerdp</a> EOL</li>
<li>tzdata, libdatetime-timezone-perl: check and <a href="https://lists.debian.org/debian-lts/2020/06/msg00066.html">explain</a> delayed update workflow</li>
<li>ELTS: update <a href="https://deb.freexian.com/extended-lts/tracker/status/release/elts">new tracker URL</a> in documentation</li>
</ul>
Debian LTS and ELTS - May 2020https://blog.beuc.net/posts/Debian_LTS_and_ELTS_-_May_2020/2020-06-02T11:29:02Z2020-06-02T11:29:02Z
<p><a href="https://wiki.debian.org/LTS"><img src="https://blog.beuc.net/posts/Debian-LTS-2-256.png" width="256" height="256" alt="Debian LTS Logo" class="img" align="right" /></a></p>
<p>Here is my transparent report for my work on the <a href="https://wiki.debian.org/LTS">Debian Long Term Support (LTS)</a> and <a href="https://wiki.debian.org/LTS/Extended%20project">Debian Extended Long Term Support (ELTS)</a>, which extend the security support for past Debian releases, as a paid contributor.</p>
<p>In May, the monthly sponsored hours were split evenly among contributors depending on their max availability - I was assigned 17.25h for LTS (out of 30 max; all done) and 9.25h for ELTS (out of 20 max; all done).</p>
<p>A survey will be published very shortly to gather feedback from all parties involved in LTS (users, other Debian teams...) -- let us know what you think, so we start the forthcoming new (Stretch) LTS cycle in the best conditions <img src="https://blog.beuc.net/smileys/smile.png" alt=":)" /></p>
<p>Discussion is progressing on funding & governance of larger LTS-related projects. Who should decide: contributors, Freexian, sponsors? Do we fund with a percentage or by capping resources allocated on security updates? I voiced concerns over funding these at the expense of smaller, more organic, more recurrent tasks that are less easy to specify but greatly contribute to the overall quality nevertheless.</p>
<p><em>ELTS - Wheezy</em></p>
<ul>
<li>mysql-connector-java: upgrade to 5.1.49, refresh patches, document/run test suite, prepare upload, prepare upgrade path (+ see LTS)</li>
<li>CVE-2020-3810/apt: triage (affected), <a href="https://lists.debian.org/debian-lts/2020/05/msg00056.html">enquire</a> about failing test, run testsuite, security upload <a href="https://deb.freexian.com/extended-lts/updates/ela-228-1-apt/">ELA 228-1</a></li>
</ul>
<p><em>LTS - Jessie</em></p>
<ul>
<li>ansible: global triage: finish last month's triage, fix affected versions, provide reproducer</li>
<li>ansible: backport patches to early version, security upload <a href="https://lists.debian.org/debian-lts-announce/2020/05/msg00005.html">DLA 2202-1</a></li>
<li>mysql-connector-java: <a href="https://lists.debian.org/debian-lts/2020/05/msg00010.html">propose 5.1.49 update</a> to all dists (+ see ELTS)</li>
<li>CVE-2019-20637/varnish: global triage: <a href="https://varnish-cache.org/lists/pipermail/varnish-misc/2020-May/026859.html">ping</a> upstream, get PoC, determine <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=956305">status</a> for all Debian dists, jessie not-affected</li>
<li>public IRC <a href="https://wiki.debian.org/LTS/Meetings">team meeting</a></li>
</ul>
<p><em>Documentation/Scripts</em></p>
<ul>
<li><a href="https://wiki.debian.org/LTS/TestSuites/mysql-connector-java">LTS/TestsSuites/mysql-connector-java</a>: first version</li>
<li><a href="https://wiki.debian.org/LTS/Development#Claim_a_DLA_ID_in_DLA.2Flist">LTS/Development</a>: what to tidy/not-tidy in data/CVE/list after an upload</li>
<li><a href="https://wiki.debian.org/LTS/Development#Triage_new_security_issues">LTS/Development</a>: clarify CVE triaging following internal discussion</li>
<li><a href="https://lists.debian.org/debian-lts/2020/05/msg00053.html">Answer</a> request wrt. openstack/keystone support</li>
<li>dsa-needed.txt: fix stale entry, check on affected LTS developer's well being <img src="https://blog.beuc.net/smileys/smile4.png" alt=";)" /></li>
</ul>