Debian LTS report for July 2024

2024-08-02 Thread Lee Garrett
cornercases when using ftf[1] VMs with autopkgtest, and found a rather intricate bug in autopkgtest that I reported in [2]. I fixed a bug in the freexian CLI when displaying available packages. [3] Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett

Re: Debian LTS report for June 2024

2024-07-11 Thread Lee Garrett
Hi Chime, On 11.07.24 19:18, Chime Hart wrote: Hi Lee-and-All: I am not a programmer, nor a developer, just an enthusiastic Linux fan. What I am wondering is how do you decide what packages to work on? LTS work is mainly sponsored by Freexian, who in turn has customers paying for long-term

Debian LTS report for June 2024

2024-07-11 Thread Lee Garrett
-4237 Which I will upload once I have fixed the remaining CVEs. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team [0] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1069891 [1] https://bugs.debian.org/cgi-bin/bugreport.cgi

Debian (E)LTS report for May 2024

2024-06-02 Thread Lee Garrett
to commitments on the Mini-Debconf Berlin [0]. I intend to release the update in the next week. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team [0] https://wiki.debian.org/DebianEvents/de/2024/MiniDebconfBerlin

Debian (E)LTS report for April 2024

2024-05-04 Thread Lee Garrett
-14 layout to ease with collaboration. The updates for bullseye and buster will be released shortly. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team

Debian LTS report for November 2023

2023-12-12 Thread Lee Garrett
Hi everyone, I spent time on samba, and will hopefully be able to resume work on it beginning of next week. Regards, Lee Garrett, Debian LTS Team

Debian (E)LTS report for October 2023

2023-11-02 Thread Lee Garrett
an update for bullseye. Regards, Lee Garrett, Debian LTS Team

Debian LTS report for September 2023

2023-10-03 Thread Lee Garrett
] https://listman.redhat.com/archives/libguestfs/2023-September/thread.html#32556 Regards, Lee Garrett, Debian LTS Team

[SECURITY] [DLA 3563-1] samba security update

2023-09-14 Thread Lee Garrett
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3563-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Lee Garrett September 12, 2023

Debian LTS report for August 2023

2023-09-09 Thread Lee Garrett
://lists.debian.org/debian-lts/2023/08/msg00027.html [1] https://github.com/ansible-collections/community.libvirt/issues/156 https://github.com/ansible-collections/community.libvirt/pull/157 [2] https://tracker.debian.org/news/1460347/ Regards, Lee Garrett, Debian LTS Team

samba status update

2023-08-22 Thread Lee Garrett
Hello everyone, I'll summarize the status of the recent samba discussion about support, it's package status, and functional tests in this mail. == samba support scope & discussions == The

Debian (E)LTS report for June 2023

2023-08-13 Thread Lee Garrett
tests that involve multiple VMs (and possibly different OSes) interacting with each other, as this currently can't be easily achieved in autopkgtest. Thanks to the sponsors for financing this work, and to Freexian for coordinating! [0] https://tracker.debian.org/pkg/rhsrvany Regards, Lee

Call for your samba config

2023-07-27 Thread Lee Garrett
Hi, regarding the netlogon fix for samba in LTS, there's a fix underway. I'm however asking LTS users to send me info about their setup. This should include: - their smb.conf (redacting any sensitive info of course) - role of the samba server (e.g. AD DC, NT4-style DC, just file server, etc.)

Debian LTS report for June 2023

2023-07-11 Thread Lee Garrett
In June I worked on samba QA, building a testing framework, implemented with ansible and libvirt/qemu, to test samba against common Windows systems. Thanks to the sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team

Debian LTS report for March 2023

2023-04-08 Thread Lee Garrett
In March I worked on the following issues for samba: - CVE-2020-10704 - CVE-2020-10730 - CVE-2020-10745 - CVE-2020-10760 - CVE-2020-14303 I have also reviewed a DLA notice written by Bastien. Thanks to the sponsors for financing this work, and to Freexian for coordinating! Regards, Lee

[SECURITY] [DLA 3351-1] apache2 security update

2023-03-03 Thread Mark Lee Garrett
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-3351-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Lee Garrett March 03, 2023

Debian LTS report for February 2023

2023-03-02 Thread Lee Garrett
In February I worked on the following issues for apache2: - CVE-2022-37436 - CVE-2021-33193 I have just uploaded the final update 2.4.38-3+deb10u9. I also worked on samba: - CVE-2016-2124 - CVE-2019-10218 - CVE-2019-14833 - CVE-2019-14847 - CVE-2019-14861 - CVE-2019-14870 - CVE-2019-14902 -

Debian LTS report for January 2023

2023-02-20 Thread Lee Garrett
In January I worked on the following issues for apache2: - CVE-2006-20001 - CVE-2022-36760 - CVE-2022-37436 (WIP) Thanks to the sponsors for financing this work, and to Freexian for coordinating! Regards, Lee

LTS work - December 2021 / Jan 2022

2022-02-04 Thread Lee Garrett
Hi everyone, In December I worked for 11.45 hours on: - Fixing a regression introduced by the fix of CVE-2019-10206. - Updating the patch for CVE-2020-10684, as it was incomplete. In January I did not work on LTS. Greetings, Lee

Re: LTS work - November 2021

2021-12-12 Thread Lee Garrett
On 12/12/2021 01:21, Utkarsh Gupta wrote: > Hiya, > > On Sun, Dec 12, 2021 at 3:42 AM Lee Garrett wrote: >> In November I worked for 9 hours on: >> - triaging ansible CVEs >> - fixing CVE-2019-10206, CVE-2019-14856

LTS work - November 2021

2021-12-11 Thread Lee Garrett
Hi everyone, In November I worked for 9 hours on: - triaging ansible CVEs - fixing CVE-2019-10206, CVE-2019-14856, CVE-2020-10684 in stretch Greetings, Lee

Re: Security updates of ansible in buster and stretch

2021-02-01 Thread Lee Garrett
Hi Markus, On 28/01/2021 00:02, Markus Koschany wrote: > Hello Lee, hello security team, > > I have been working on security updates of ansible in Stretch and my intention > was to fix the remaining issues in Buster as well. However testing those > upstream patches proved to be rather difficult

Re: Jessie update of ansible (minor security issues)?

2019-08-31 Thread Lee Garrett
Hi Mike! (please don't CC Michael, he is not active on the ansible package anymore and asked to be removed from uploaders.) On 30/08/2019 12:09, Mike Gabriel wrote: > The Debian LTS team recently reviewed the security issue(s) affecting your > package in Jessie: >