Bug#863915: unblock: webkit2gtk/2.16.3-2

2017-06-05 Thread Adam D. Barratt
On Fri, 2017-06-02 at 11:52 -0400, Jeremy Bicha wrote: > Here's my thinking as to how the first webkit2gtk stable update could work. > > 1. A new webkit2gtk point release is released. > 2. Since regressions are generally found within the first week and to > try to limit the work needed by the SRMs

Bug#863915: unblock: webkit2gtk/2.16.3-2

2017-06-05 Thread Moritz Mühlenhoff
Adam wrote: > I'm not entirely sure how you think p-u is better placed to do so, given > the amount of visible testing packages from it get before a point > release. It's not necessarily for the additional testing done on p-u (although I personally use it like that and probably others well), bu

Bug#863915: unblock: webkit2gtk/2.16.3-2

2017-06-02 Thread Jeremy Bicha
I apologize for not personally trying hard to push this through, but if we don't unblock 2.16.3 in the next few days, it makes the Stable Release process more difficult since we can't "practice" with easier webkit2gtk point releases first. Proposal for initial webkit2gtk updates in Debian 9 --

Bug#863915: unblock: webkit2gtk/2.16.3-2

2017-06-02 Thread Jeremy Bicha
On Fri, Jun 2, 2017 at 3:58 AM, Adam D. Barratt wrote: > On 2017-06-02 8:32, Adam D. Barratt wrote: >> There's a huge leap from there to you assuming that SRM will be happy >> to do this without any form of actual discussion. Unblock bugs are >> *not* the way to have that discussion, and two weeks

Bug#863915: unblock: webkit2gtk/2.16.3-2

2017-06-02 Thread Carlos Alberto Lopez Perez
On 02/06/17 14:47, Carlos Alberto Lopez Perez wrote: >> Also it'd be nice to know what kind of automated testing is happening. I know >> WebKit has an extensive test suite (including layout tests) that upstream >> continuously runs for development series. I don't know if that's the same for >> stab

Bug#863915: unblock: webkit2gtk/2.16.3-2

2017-06-02 Thread Carlos Alberto Lopez Perez
On 02/06/17 10:27, Emilio Pozuelo Monfort wrote: > Hi Jeremy, > > On 01/06/17 23:15, Jeremy Bicha wrote: >> Please unblock package webkit2gtk for inclusion in Debian 9.0. >> >> unblock webkit2gtk/2.16.3-2 >> >> Justification >> -- >> Three known publicized security vulnerabilities

Bug#863915: unblock: webkit2gtk/2.16.3-2

2017-06-02 Thread Emilio Pozuelo Monfort
Hi Jeremy, On 01/06/17 23:15, Jeremy Bicha wrote: > Please unblock package webkit2gtk for inclusion in Debian 9.0. > > unblock webkit2gtk/2.16.3-2 > > Justification > -- > Three known publicized security vulnerabilities have been fixed in > 2.16.3: CVE-2017-2496, CVE-2017-2539 an

Bug#863915: unblock: webkit2gtk/2.16.3-2

2017-06-02 Thread Adam D. Barratt
On 2017-06-02 8:32, Adam D. Barratt wrote: There's a huge leap from there to you assuming that SRM will be happy to do this without any form of actual discussion. Unblock bugs are *not* the way to have that discussion, and two weeks before release is a really poor time to attempt to do so. Part

Bug#863915: unblock: webkit2gtk/2.16.3-2

2017-06-02 Thread Adam D. Barratt
On 2017-06-01 22:15, Jeremy Bicha wrote: Please unblock package webkit2gtk for inclusion in Debian 9.0. [...] Sadly, Debian's security packaging infrastructure is not set up to test this kind of update very well. I'm not entirely sure how you think p-u is better placed to do so, given the am