Re: Bug#1004452: bullseye-pu: package gnupg2/2.2.27-2+deb11u1

2022-03-17 Thread Daniel Kahn Gillmor
On Thu 2022-03-17 17:49:04 +, Adam D. Barratt wrote:
> On Sat, 2022-02-19 at 22:24 -0500, Daniel Kahn Gillmor wrote:
>> On Sat 2022-02-19 17:09:21 +, Adam D. Barratt wrote:
>> > Control: tags -1 + confirmed d-i
>> > 
> [...]
>> > That looks fine to me, but will need a d-i ack as the package
>> > builds a
>> > udeb; tagging and CCing accordingly.
>> 
>> Understood -- i'll wait for a d-i ack before uploading.
>
> As we're getting very close to the window for 11.3 closing, please feel
> free to upload.

I've just uploaded gnupg2/2.2.27-2+deb11u1 to bullseye now.  Please let
me know if there are any problems.

thanks for your ongoing work maintaining debian stable!

 --dkg


signature.asc
Description: PGP signature


Re: Bug#1005949: bullseye-pu: package glibc/2.31-13+deb11u3

2022-03-17 Thread Aurelien Jarno
On 2022-03-17 17:49, Adam D. Barratt wrote:
> On Tue, 2022-03-15 at 20:33 +, Adam D. Barratt wrote:
> > Control: tags -1 + confirmed d-i
> > 
> > On Thu, 2022-02-17 at 23:15 +0100, Aurelien Jarno wrote:
> > > There are multiple fixes in this upload:
> > > - 4 security bugs
> > > - a fix to avoid preinst script failure when running on kernel
> > > x.y.z
> > >   with z > 255. 
> > > - a fix to avoid changes to /etc/nsswitch.conf to be reverted on
> > > upgrade
> > > 
> > > [ Impact ]
> > > Installation will be left vulnerable to security issues and upgrade
> > > from buster will fail when running recent upstream stable kernels.
> > > 
> > 
> > This looks OK to me, thanks.
> > 
> > As glibc produces a udeb, this will want a KiBi-ack; CCing and
> > tagging
> > accordingly.
> 
> As we're getting very close to the window for 11.3 closing, please feel
> free to upload.

Thanks, I have just uploaded it.

-- 
Aurelien Jarno  GPG: 4096R/1DDD8C9B
aurel...@aurel32.net http://www.aurel32.net



Re: Bug#1007746: buster-pu: package glibc/2.28-10+deb10u1

2022-03-17 Thread Aurelien Jarno
On 2022-03-17 17:51, Adam D. Barratt wrote:
> Control: tags -1 + confirmed d-i
> 
> On Wed, 2022-03-16 at 00:50 +0100, Aurelien Jarno wrote:
> > A big part of the changes have been in the buster git branch for many
> > months, but I failed to submit the package for a point release up to
> > now. What triggered me to look at it again is breakage in the preinst
> > script when running on kernel x.y.z with z > 255.
> > 
> > In other changes are just an (old) pull from the stable branch,
> > fixing
> > a few important bugs.
> 
> Please go ahead, thanks.
> 
> As glibc produces a udeb, I'm tagging the bug and CCing accordingly.
> 

Thanks for the review despite the close deadline. I have just uploaded
it.

-- 
Aurelien Jarno  GPG: 4096R/1DDD8C9B
aurel...@aurel32.net http://www.aurel32.net



Re: Bug#1007714: bullseye-pu: package openssh/1:8.4p1-5+deb11u1

2022-03-17 Thread Adam D. Barratt
Control: tags -1 + confirmed d-i

On Tue, 2022-03-15 at 15:20 +, Colin Watson wrote:
> OpenSSH in stable breaks on 32-bit architectures (at least armhf,
> reportedly also i386) after upgrading libc6 to the version in
> bookworm,
> due to changes in its system call interface that affect OpenSSH's
> seccomp sandbox.  See https://bugs.debian.org/1004427.
> 
> [ Impact ]
> Without this change, I'm concerned that sshd may be unavailable
> during
> part of an upgrade from bullseye to bookworm (or even make the
> machine
> inaccessible, if it's headless and the upgrade fails).  Getting the
> sandbox tweak into bullseye at this stage would reduce that risk.
> 

Please go ahead.

As openssh builds a udeb, I'm CCing KiBi and tagging the bug
accordingly.

Regards,

Adam



Re: Bug#1007746: buster-pu: package glibc/2.28-10+deb10u1

2022-03-17 Thread Adam D. Barratt
Control: tags -1 + confirmed d-i

On Wed, 2022-03-16 at 00:50 +0100, Aurelien Jarno wrote:
> A big part of the changes have been in the buster git branch for many
> months, but I failed to submit the package for a point release up to
> now. What triggered me to look at it again is breakage in the preinst
> script when running on kernel x.y.z with z > 255.
> 
> In other changes are just an (old) pull from the stable branch,
> fixing
> a few important bugs.

Please go ahead, thanks.

As glibc produces a udeb, I'm tagging the bug and CCing accordingly.

Regards,

Adam



Re: Bug#1005949: bullseye-pu: package glibc/2.31-13+deb11u3

2022-03-17 Thread Adam D. Barratt
On Tue, 2022-03-15 at 20:33 +, Adam D. Barratt wrote:
> Control: tags -1 + confirmed d-i
> 
> On Thu, 2022-02-17 at 23:15 +0100, Aurelien Jarno wrote:
> > There are multiple fixes in this upload:
> > - 4 security bugs
> > - a fix to avoid preinst script failure when running on kernel
> > x.y.z
> >   with z > 255. 
> > - a fix to avoid changes to /etc/nsswitch.conf to be reverted on
> > upgrade
> > 
> > [ Impact ]
> > Installation will be left vulnerable to security issues and upgrade
> > from buster will fail when running recent upstream stable kernels.
> > 
> 
> This looks OK to me, thanks.
> 
> As glibc produces a udeb, this will want a KiBi-ack; CCing and
> tagging
> accordingly.

As we're getting very close to the window for 11.3 closing, please feel
free to upload.

Regards,

Adam



Re: Bug#1004452: bullseye-pu: package gnupg2/2.2.27-2+deb11u1

2022-03-17 Thread Adam D. Barratt
On Sat, 2022-02-19 at 22:24 -0500, Daniel Kahn Gillmor wrote:
> On Sat 2022-02-19 17:09:21 +, Adam D. Barratt wrote:
> > Control: tags -1 + confirmed d-i
> > 
[...]
> > That looks fine to me, but will need a d-i ack as the package
> > builds a
> > udeb; tagging and CCing accordingly.
> 
> Understood -- i'll wait for a d-i ack before uploading.

As we're getting very close to the window for 11.3 closing, please feel
free to upload.

Regards,

Adam