kernel security upgrades

2005-03-25 Thread Andreas Barth
Hi, this mail consists of two parts: First, I describe my understanding of how any kernel upgrade currently works. Please feel free to cluebat me if I got it wrong. After that, I list some ideas how we can minimize the amount of work for the security team once sarge is hard frozen, and the roun

Re: a kernel plan for sarge and beyond ... (Was Re: ABI-changing kernel security fixes for sarge)

2005-03-25 Thread Andreas Barth
* Steve Langasek ([EMAIL PROTECTED]) [050325 02:05]: > On Thu, Mar 24, 2005 at 03:30:01PM -0500, Andres Salomon wrote: > > That is irritating, but less so than rebooting and discovering you need to > > run `module-assistant auto-install ` to compile a module for an ABI > > change (and if the machin

Re: Shouldn't kernel-image-2.6.x-y-z depend on alsa-base ?

2005-03-25 Thread Thomas Hood
The ALSA maintenance team has just released alsa-driver version 1.0.8+1.0.9rc2-1 to experimental. This includes a new binary package linux-sound-base which takes over from alsa-base the job of blacklisting OSS modules when installed. The capability has been added to it to blacklist ALSA modules i

Bug#301188: [workaround]: initrd-tools: tries to install module qla6322 which is missing in kernel 2.6.11.x

2005-03-25 Thread Harald Dunkel
Torsten Werner wrote: the driver for the QLogic adapter 6322 is now merged with qla6312 and mkinitrd failes to run with kernels >= 2.6.11 because it still tries to find the qla6322 module. The problem is that mkinitrd tries to guess the harddisk driver for 2.6.11 using the current (I guess 2.6.10?)

Bug#301372: kernel-source-2.6.8: [CAN-2005-0839] Insecure restriction of access to the N_MOUSE line disciple for TTYs

2005-03-25 Thread Moritz Muehlenhoff
Package: kernel-source-2.6.8 Version: 2.6.8-15 Severity: grave Tags: security Kernels before 2.6.11 do not properly restrict access to the N_MOUSE line disciple for TTYs, which allows local users to inject mouse or keyboard events into other's users sessions and possibly gain extended privileges.

Re: 2.4.27-9

2005-03-25 Thread Thiemo Seufer
Horms wrote: > I have finally finished wading through the bug reports and > put togther kernel-source-2.4.27 2.4.27-9 and > kernel-image-2.4.27-i386 2.4.27-9. > > This update does _NOT_ contain ABI breakage, > although one symbol has been added to the ABI. > That is, the fix for CAN-2005-0449 has

Processed: cloning 301374, retitle -1 to need to hit enter 4 times at kernels prompt for root floppy on sparc32 ...

2005-03-25 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.8.11 > clone 301374 -1 Bug#301374: Package: installation-reports - Floppy Boot Error Bug 301374 cloned as bug 301386. > retitle -1 need to hit enter 4 times at kernels prompt for root flopp

Bug#299055: Installation report for Dell PowerEdge 1850

2005-03-25 Thread Loïc Minier
Hi, On Fri, Mar 11, 2005, Joey Hess wrote: > Many people have reported problems with initrd-tools and megaraid2. Most > of those bugs have already been reassigned to the initrd-tools package > (#278887, #284230, #282793, #287019). Sadly, it looks like nobody over > there is working on them

Re: kernel-image-2.6.8-ia64 ABI reversion

2005-03-25 Thread dann frazier
On Thu, 2005-03-24 at 19:37 -0800, Steve Langasek wrote: > On Thu, Mar 24, 2005 at 06:22:32PM -0700, dann frazier wrote: > > I'm trying to decide what I want to do about the ia64 kernel ABI. I > > rev'd it from -2 (currently in sarge) to -3 to turn off PREEMPT > > (prevents at least one user trigg

Re: kernel security upgrades

2005-03-25 Thread Joey Hess
Andreas Barth wrote: > [What changes to d-i need to be done for a security upload?] Besides building the udebs, if the abi changes we have to update rootskel, base-installer, and the debian-installer build system. > The d-i changes are only finalized with the next point release - but well, > that

Re: kernel security upgrades

2005-03-25 Thread Andreas Barth
* Joey Hess ([EMAIL PROTECTED]) [050325 17:05]: > Andreas Barth wrote: > > [What changes to d-i need to be done for a security upload?] > Besides building the udebs, if the abi changes we have to update rootskel, > base-installer, and the debian-installer build system. >> [...] > Not quite accura

Re: kernel security upgrades

2005-03-25 Thread Martin Schulze
Andreas Barth wrote: > Ok, summarising this means for me: > > If we change the abi for d-i, than a lot of work at a lot of places > needs to be done. Definitly possible, but not the thing we want to do > for each security upgrade. On the other side, as long as we keep the > old kernel around, an

Re: kernel security upgrades

2005-03-25 Thread Andreas Barth
* Martin Schulze ([EMAIL PROTECTED]) [050325 17:50]: > Andreas Barth wrote: > > Ok, summarising this means for me: > > > > If we change the abi for d-i, than a lot of work at a lot of places > > needs to be done. Definitly possible, but not the thing we want to do > > for each security upgrade.

Re: ABI-changing kernel security fixes for sarge

2005-03-25 Thread Martin Zobel-Helas
Hi Martin, On Friday, 25 Mar 2005, Martin 'Joey' Schulze wrote: > Matthew Wilcox wrote: > > On Wed, Mar 23, 2005 at 04:09:42PM +0100, Frank Lichtenheld wrote: > > Absolutely. It's bound to happen again. We also need to figure out > > how to do driver updates during sarge's lifetime. I suspect v

Bug#301425: Kernel BUG at traps:310 on Dell PW 670

2005-03-25 Thread Daniel Nilsson
Package: kernel-image-2.6.8-10-em64t-p4 Version: 2.6.8-11 The following kernel trap happens on a Dell Precision Workstation 670 using the kernel compiled for em64t. It happens with both the -smp kernel and the single CPU kernel and it doesn't seem to depend upen whether or not HT is turned on or o

Processed: kernel

2005-03-25 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > reassign #300956 kernel-image-2.6.8-2-k7 Bug#300956: kernel-image-2.6.8-1-k7: XFS oops with NFS Warning: Unknown package 'kernel-image-2.6.8-1-k7' Bug reassigned from package `kernel-image-2.6.8-1-k7' to `kernel-image-2.6.8-2-k7'. > -- Stopping proces

Processed: reassign to existing package

2005-03-25 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > reassign 300716 kernel-image-2.4.27-powerpc Bug#300716: kernel-image-2.4.27-powerpc-pmac: Error messages about ip length disagreeing Warning: Unknown package 'kernel-image-2.4.27-powerpc-pmac' Bug reassigned from package `kernel-image-2.4.27-powerpc-pm

Re: kernel-image-2.6.8-ia64 ABI reversion

2005-03-25 Thread Steve Langasek
On Fri, Mar 25, 2005 at 08:45:40AM -0700, dann frazier wrote: > On Thu, 2005-03-24 at 19:37 -0800, Steve Langasek wrote: > > On Thu, Mar 24, 2005 at 06:22:32PM -0700, dann frazier wrote: > > > I'm trying to decide what I want to do about the ia64 kernel ABI. I > > > rev'd it from -2 (currently in

Processed: 2.6.11 doesn't exist yet

2005-03-25 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > reassign #301004 kernel Bug#301004: [nat] 2.6.11 breaks local transparent caches Warning: Unknown package 'kernel-source-2.6.11' Bug reassigned from package `kernel-source-2.6.11' to `kernel'. > -- Stopping processing here. Please contact me if you ne

Bug#288180: nis kills sparc64

2005-03-25 Thread Steve Langasek
Discussion on IRC about fixing this for release: joeyh: we have non-security-related RC bugs in the sparc kernel that aren't fixed in kernel-image-2.6.8-sparc 2.6.8-6. Is rebuilding d-i for a sparc update only better or worse than rebuilding for everything? (Can we do

Re: Bug#282035: xserver-xfree86: [kbd] Logitech "Internet Navigator Special Edition" / "Elite" USB Keyboard missing 4 buttons

2005-03-25 Thread Branden Robinson
retitle 282035 kernel: AT keyboard driver doesn't recognize some fancy Logitech keyboard keys reassign 282035 kernel thanks On Sun, Dec 19, 2004 at 09:31:58PM +0100, Stephane Chauveau wrote: > I have a simular keyboard and I investigated the problem a few months ago. > This is a kernel problem. >

Processed: Re: Bug#282035: xserver-xfree86: [kbd] Logitech "Internet Navigator Special Edition" / "Elite" USB Keyboard missing 4 buttons

2005-03-25 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > retitle 282035 kernel: AT keyboard driver doesn't recognize some fancy > Logitech keyboard keys Bug#282035: xlibs: Logitech "Internet Navigator Special Edition" / "Elite" USB Keyboard missing 4 buttons Changed Bug title. > reassign 282035 kernel Bug#

Processing of kernel-source-2.4.27_2.4.27-9_i386.changes

2005-03-25 Thread Archive Administrator
kernel-source-2.4.27_2.4.27-9_i386.changes uploaded successfully to localhost along with the files: kernel-source-2.4.27_2.4.27-9.dsc kernel-source-2.4.27_2.4.27-9.diff.gz kernel-patch-debian-2.4.27_2.4.27-9_all.deb kernel-doc-2.4.27_2.4.27-9_all.deb kernel-source-2.4.27_2.4.27-9_all.deb

Processing of kernel-image-2.4.27-i386_2.4.27-9_i386.changes

2005-03-25 Thread Archive Administrator
kernel-image-2.4.27-i386_2.4.27-9_i386.changes uploaded successfully to localhost along with the files: kernel-image-2.4.27-i386_2.4.27-9.dsc kernel-image-2.4.27-i386_2.4.27-9.tar.gz kernel-headers-2.4.27-2_2.4.27-9_i386.deb kernel-pcmcia-modules-2.4.27-2-586tsc_2.4.27-9_i386.deb kernel-

Bug#296905: marked as done (CAN-2005-0531: Buffer overflow in atm_get_addr)

2005-03-25 Thread Debian Bug Tracking System
Your message dated Sat, 26 Mar 2005 01:47:47 -0500 with message-id <[EMAIL PROTECTED]> and subject line Bug#296905: fixed in kernel-source-2.4.27 2.4.27-9 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the cas

Bug#296700: marked as done ([CAN-2005-0204]: AMD64, allows local users to write to privileged IO ports via OUTS instruction)

2005-03-25 Thread Debian Bug Tracking System
Your message dated Sat, 26 Mar 2005 01:47:47 -0500 with message-id <[EMAIL PROTECTED]> and subject line Bug#296700: fixed in kernel-source-2.4.27 2.4.27-9 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the cas

Bug#296639: marked as done (kernel-source-2.4.27: nforce[23] backport of acpi_skip_timer_override)

2005-03-25 Thread Debian Bug Tracking System
Your message dated Sat, 26 Mar 2005 01:47:47 -0500 with message-id <[EMAIL PROTECTED]> and subject line Bug#296639: fixed in kernel-source-2.4.27 2.4.27-9 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the cas

kernel-image-2.4.27-i386_2.4.27-9_i386.changes ACCEPTED

2005-03-25 Thread Debian Installer
Accepted: kernel-build-2.4.27-2_2.4.27-9_i386.deb to pool/main/k/kernel-image-2.4.27-i386/kernel-build-2.4.27-2_2.4.27-9_i386.deb kernel-headers-2.4.27-2-386_2.4.27-9_i386.deb to pool/main/k/kernel-image-2.4.27-i386/kernel-headers-2.4.27-2-386_2.4.27-9_i386.deb kernel-headers-2.4.27-2-586tsc

Bug#291536: marked as done (kernel-source-2.4.27[-8]: Contains dummy file ':')

2005-03-25 Thread Debian Bug Tracking System
Your message dated Sat, 26 Mar 2005 01:47:47 -0500 with message-id <[EMAIL PROTECTED]> and subject line Bug#291536: fixed in kernel-source-2.4.27 2.4.27-9 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the cas

kernel-source-2.4.27_2.4.27-9_i386.changes ACCEPTED

2005-03-25 Thread Debian Installer
Accepted: kernel-doc-2.4.27_2.4.27-9_all.deb to pool/main/k/kernel-source-2.4.27/kernel-doc-2.4.27_2.4.27-9_all.deb kernel-patch-debian-2.4.27_2.4.27-9_all.deb to pool/main/k/kernel-source-2.4.27/kernel-patch-debian-2.4.27_2.4.27-9_all.deb kernel-source-2.4.27_2.4.27-9.diff.gz to pool/main/

Re: 2.4.27-9

2005-03-25 Thread Horms
On Fri, Mar 25, 2005 at 02:19:34PM +0100, Thiemo Seufer wrote: > Horms wrote: > > I have finally finished wading through the bug reports and > > put togther kernel-source-2.4.27 2.4.27-9 and > > kernel-image-2.4.27-i386 2.4.27-9. > > > > This update does _NOT_ contain ABI breakage, > > although o