Re: Accepted pcs 0.10.1-2+deb10u1 (source) into oldstable

2022-09-14 Thread Valentin Vidic
On Wed, Sep 14, 2022 at 10:55:29PM +0200, Sylvain Beucler wrote: > You can certainly give it a try if you have the time. > The description adapted from the DSA sounds good. > > Feel free to ask here or at #debian-lts if you have further questions. Ok, mail sent to debian-lts-announce, will check

Re: Accepted pcs 0.10.1-2+deb10u1 (source) into oldstable

2022-09-14 Thread Valentin Vidic
On Wed, Sep 14, 2022 at 06:46:47PM +0200, Sylvain Beucler wrote: > Hello Valentin, > > Thank you for claiming 'pcs' in dla-needed.txt and uploading a fixed > version. > > LTS uploads follow a procedure which notably involves reserving a DLA in the > security tracker and sending announcements to t

Re: Accepted pcs 0.10.1-2+deb10u1 (source) into oldstable

2022-09-14 Thread Sylvain Beucler
Hello, On 14/09/2022 22:43, Valentin Vidic wrote: On Wed, Sep 14, 2022 at 06:46:47PM +0200, Sylvain Beucler wrote: Thank you for claiming 'pcs' in dla-needed.txt and uploading a fixed version. LTS uploads follow a procedure which notably involves reserving a DLA in the security tracker and sen

Re: Updating OpenStack compute (aka src:nova) in Buster

2022-09-14 Thread Thomas Goirand
On 9/14/22 13:37, Emilio Pozuelo Monfort wrote: Hi Thomas, On 11/09/2022 12:50, Thomas Goirand wrote: Hi, In the OpenStack team git, there are updates for nova 2:18.1.0-6+deb10u1 (CVE-2019-14433/ OSSA-2019-003). Can someone pick it up and upload it to Buster? It was never accepted in Buster

Re: Accepted pcs 0.10.1-2+deb10u1 (source) into oldstable

2022-09-14 Thread Sylvain Beucler
Hello Valentin, Thank you for claiming 'pcs' in dla-needed.txt and uploading a fixed version. LTS uploads follow a procedure which notably involves reserving a DLA in the security tracker and sending announcements to the mailing list and website, see: https://lts-team.pages.debian.net/wiki/

Re: [SECURITY] [DLA 3107-1] sqlite3 security update

2022-09-14 Thread Chris Lamb
Hi Moritz, > In the case of DLA uploads you should rather even wait a little longer; > since there's no queue and if you've made a source upload for a large > package it might take some time until it's built. Ah, that makes sense. Because of that, I'll actually block announcements until the packa

Re: Bug#961654: buster-pu: package bzip2/1.0.6-9.2~deb10u1

2022-09-14 Thread Santiago R.R.
El 14/09/22 a las 13:58, Emilio Pozuelo Monfort escribió: > On 13/09/2022 16:46, Sylvain Beucler wrote: > > Hi, > > > > IIUC this is about fixing 2 non-security bugs, that were introduced > > prior to buster's initial release. > > > > I personally don't think this fits the LTS project scope. > >

Re: Bug#961654: buster-pu: package bzip2/1.0.6-9.2~deb10u1

2022-09-14 Thread Chris Frey
On Wed, Sep 14, 2022 at 01:54:40PM +0200, Emilio Pozuelo Monfort wrote: > Your top-commit looks very similar to the one from Santiago on [1]. I'd > rather use that to give him credit as he proposed the fix first (plus using > CPPFLAGS seems more correct for this flag). In addition to that, the comm

Re: Bug#961654: buster-pu: package bzip2/1.0.6-9.2~deb10u1

2022-09-14 Thread Emilio Pozuelo Monfort
On 13/09/2022 16:46, Sylvain Beucler wrote: Hi, IIUC this is about fixing 2 non-security bugs, that were introduced prior to buster's initial release. I personally don't think this fits the LTS project scope. Maybe other LTS members will have a different opinion. We've had bugfix updates fr

Re: Bug#961654: buster-pu: package bzip2/1.0.6-9.2~deb10u1

2022-09-14 Thread Emilio Pozuelo Monfort
Hi Chris, On 14/09/2022 05:48, Chris Frey wrote: On the other hand, the fix has been known since 2019 and looks like a prime problem for an LTS newbie volunteer like me. I have created the fix based on the Debian/bzip2 repo, the fix is in the debian/buster branch. git clone http://digo

Re: Updating OpenStack compute (aka src:nova) in Buster

2022-09-14 Thread Emilio Pozuelo Monfort
Hi Thomas, On 11/09/2022 12:50, Thomas Goirand wrote: Hi, In the OpenStack team git, there are updates for nova 2:18.1.0-6+deb10u1 (CVE-2019-14433/ OSSA-2019-003). Can someone pick it up and upload it to Buster? It was never accepted in Buster due to the difficulties communicating with the S

Re: [SECURITY] [DLA 3107-1] sqlite3 security update

2022-09-14 Thread Moritz Muehlenhoff
On Wed, Sep 14, 2022 at 11:34:57AM +0200, Santiago Ruano Rincón wrote: > If I am not wrong, DLAs should be claimed/announced once the upload has > been completed and accepted. I think this is documented here: > > https://wiki.debian.org/LTS/Development#Announce_the_update > > "Only when you have

Re: Bug#961654: buster-pu: package bzip2/1.0.6-9.2~deb10u1

2022-09-14 Thread Holger Levsen
On Tue, Sep 13, 2022 at 04:46:14PM +0200, Sylvain Beucler wrote: > IIUC this is about fixing 2 non-security bugs, that were introduced prior to > buster's initial release. > > I personally don't think this fits the LTS project scope. > Maybe other LTS members will have a different opinion. I do t

Re: [SECURITY] [DLA 3107-1] sqlite3 security update

2022-09-14 Thread Santiago Ruano Rincón
El 14/09/22 a las 08:04, Chris Lamb escribió: > Chris Lamb wrote: > > >> Did you forget to upload this? I don't see any sqlite3 update in > >> buster-security (or maybe it was rejected or something). > > > > I didn't forget. Rather, it was REJECTED late last night and I re- > > uploaded first thi

Re: [SECURITY] [DLA 3107-1] sqlite3 security update

2022-09-14 Thread Chris Lamb
Chris Lamb wrote: >> Did you forget to upload this? I don't see any sqlite3 update in >> buster-security (or maybe it was rejected or something). > > I didn't forget. Rather, it was REJECTED late last night and I re- > uploaded first thing this morning. ... and I just got the ACCEPTED. :) Rega