RFT: squid3 3.5.23-5+deb9u2, please test

2020-07-01 Thread Markus Koschany
Hello, I have uploaded a new version of squid3 for Stretch to people.debian.org. https://people.debian.org/~apo/lts/squid3/stretch/ It contains many bug fixes. Let me know if you find any regressions from the current released version 3.5.23-5+deb9u1. Regards, Markus signature.asc Descriptio

Re: Possible clashing of work

2020-07-01 Thread Moritz Muehlenhoff
On Wed, Jul 01, 2020 at 09:20:51PM +0530, Utkarsh Gupta wrote: > 1. imagemagick/oldstable > > Right now, this package has been claimed in dla-needed.txt by Markus > and in dsa-needed.txt by jmm. Yeah, this is currently WIP and should be released soon. The buster-security update is already release

Re: Steps for Debian Jessie LTS end-of-life

2020-07-01 Thread Utkarsh Gupta
On Wed, Jul 1, 2020 at 11:02 PM Emilio Pozuelo Monfort wrote: > jessie ELTS is already open (because jessie LTS should not). Having both > receiving updates is actually more confusing, if you ask me. I concur. It'd be fairly confusing to figure out what goes where, given that ELTS has opened its

Re: Steps for Debian Jessie LTS end-of-life

2020-07-01 Thread Markus Koschany
Am 01.07.20 um 19:31 schrieb Emilio Pozuelo Monfort: [...] > Perhaps it would have made sense to not EOL jessie until stretch had actually > become LTS. ^^ This. I don't understand why we don't wait for Stretch becoming LTS, having upload privileges for

Re: Steps for Debian Jessie LTS end-of-life

2020-07-01 Thread Emilio Pozuelo Monfort
On 01/07/2020 19:26, Markus Koschany wrote: > > Am 01.07.20 um 19:14 schrieb Ansgar: >> On Wed, 2020-07-01 at 18:38 +0200, Markus Koschany wrote: >>> Am 01.07.20 um 11:27 schrieb Ansgar: since LTS for Jessie has ended according to [1], can we disable uploads and prepare for archiving the

Re: Steps for Debian Jessie LTS end-of-life

2020-07-01 Thread Markus Koschany
Am 01.07.20 um 19:14 schrieb Ansgar: > On Wed, 2020-07-01 at 18:38 +0200, Markus Koschany wrote: >> Am 01.07.20 um 11:27 schrieb Ansgar: >>> since LTS for Jessie has ended according to [1], can we disable uploads >>> and prepare for archiving the release? > [...] >> Please wait another week with t

Re: Steps for Debian Jessie LTS end-of-life

2020-07-01 Thread Ansgar
On Wed, 2020-07-01 at 18:38 +0200, Markus Koschany wrote: > Am 01.07.20 um 11:27 schrieb Ansgar: > > since LTS for Jessie has ended according to [1], can we disable uploads > > and prepare for archiving the release? [...] > Please wait another week with the deactivation of jessie-security. This > e

Re: Possible clashing of work

2020-07-01 Thread Utkarsh Gupta
On Wed, Jul 1, 2020 at 10:27 PM Markus Koschany wrote: > Please don't drop imagemagick or squid3 from dla-needed.txt or any other > package. This should be done by the people who have claimed the packages > because they know what they are working on. In less than two weeks we > will have completed

Re: Possible clashing of work

2020-07-01 Thread Markus Koschany
Am 01.07.20 um 18:48 schrieb Utkarsh Gupta: [...] > Let me know what you think. Please don't drop imagemagick or squid3 from dla-needed.txt or any other package. This should be done by the people who have claimed the packages because they know what they are working on. In less than two weeks we

Re: Possible clashing of work

2020-07-01 Thread Utkarsh Gupta
Hi Markus, On Wed, Jul 1, 2020 at 10:00 PM Markus Koschany wrote: > > 1. imagemagick/oldstable > > Please shout back if I should not. > Thanks for being proactive. Actually I am working on Jessie and Stretch. Great! Since ImageMagick warrants a DSA for Stretch, I am going to drop it from dla-nee

Re: Steps for Debian Jessie LTS end-of-life

2020-07-01 Thread Markus Koschany
Hello, Am 01.07.20 um 11:27 schrieb Ansgar: > Hi, > > since LTS for Jessie has ended according to [1], can we disable uploads > and prepare for archiving the release? > > I want to: > > 1. Stop accepting anything. > 2. Have one Release with no Valid-Until for archive.d.o (to try to >make so

Re: Possible clashing of work

2020-07-01 Thread Markus Koschany
Hello, Am 01.07.20 um 17:50 schrieb Utkarsh Gupta: [...] > > Right now, this package has been claimed in dla-needed.txt by Markus > and in dsa-needed.txt by jmm. > Although I think jmm is working on Stretch and Markus is working on > Jessie. But to be very explicit (since explicit is better than

Possible clashing of work

2020-07-01 Thread Utkarsh Gupta
Hi Markus, LTS, and Security team folks, I write this with my LTS FD hat on and with a reference of IRC text from #debian-lts earlier today, where it was decided to "disable uploads to jessie-security" (Emilio will send a separate mail for that!). With regards to the current transition of Jessie

Re: Steps for Debian Jessie LTS end-of-life

2020-07-01 Thread Emilio Pozuelo Monfort
On 01/07/2020 12:40, Emilio Pozuelo Monfort wrote: > On 01/07/2020 11:27, Ansgar wrote: >> 5. Import to archive.d.o >> 6. Remove from security.d.o >> >> I can do (1), (2), (4) fairly quickly; the buildd team would need to >> look at (3). Not sure when (5) and (6) happen, but it's never wrong to >>

Re: Steps for Debian Jessie LTS end-of-life

2020-07-01 Thread Moritz Muehlenhoff
On Wed, Jul 01, 2020 at 11:27:38AM +0200, Ansgar wrote: > Hi, > > since LTS for Jessie has ended according to [1], can we disable uploads > and prepare for archiving the release? > > I want to: > > 1. Stop accepting anything. > 2. Have one Release with no Valid-Until for archive.d.o (to try to >

(E)LTS report for June

2020-07-01 Thread Emilio Pozuelo Monfort
Hi, During the month of June I spent 4h on LTS working on: - reviewed stretch-lts MR - prepared batik update - CVE triaging - started working on a lts no-dsa review script As for ELTS I spent 9h working on: - final changes to distro-config branch improvements, and deployment - prepared batik up

Re: Steps for Debian Jessie LTS end-of-life

2020-07-01 Thread Emilio Pozuelo Monfort
Hi Ansgar, On 01/07/2020 11:27, Ansgar wrote: > Hi, > > since LTS for Jessie has ended according to [1], can we disable uploads > and prepare for archiving the release? Yes, let's do this. > > I want to: > > 1. Stop accepting anything. > 2. Have one Release with no Valid-Until for archive.d.o

Steps for Debian Jessie LTS end-of-life

2020-07-01 Thread Ansgar
Hi, since LTS for Jessie has ended according to [1], can we disable uploads and prepare for archiving the release? I want to: 1. Stop accepting anything. 2. Have one Release with no Valid-Until for archive.d.o (to try to make some people happy...). 3. Have w-b/buildds no longer look at jessie

LTS report for June 2020

2020-07-01 Thread Adrian Bunk
Hours worked: 17 hours DLAs released: DLA 2262 qemu CVE-2020-1983 CVE-2020-13361 CVE-2020-13362 CVE-2020-13765 DLA 2266 nss CVE-2020-12399 CVE-2020-12402 DLA 2267 libmatio CVE-2019-17533