[Bug 2108942] Re: [MIR] ptyxis

2025-08-12 Thread Alessandro Astone
Julian already updated ubuntu-meta:
https://launchpad.net/ubuntu/+source/ubuntu-meta/1.557

** Changed in: ubuntu-meta (Ubuntu)
   Status: In Progress => Fix Released

** Changed in: ubuntu-meta (Ubuntu)
 Assignee: Alessandro Astone (aleasto) => (unassigned)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2108942

Title:
  [MIR] ptyxis

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ptyxis/+bug/2108942/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 2108942] Re: [MIR] ptyxis

2025-08-11 Thread Alessandro Astone
Attaching debdiff for updating ubuntu-meta accordingly. This is
generated by ./update.

** Also affects: ubuntu-meta (Ubuntu)
   Importance: Undecided
   Status: New

** Changed in: ubuntu-meta (Ubuntu)
   Status: New => In Progress

** Changed in: ubuntu-meta (Ubuntu)
 Assignee: (unassigned) => Alessandro Astone (aleasto)

** Changed in: ubuntu-meta (Ubuntu)
Milestone: None => ubuntu-25.10-feature-freeze

** Changed in: ubuntu-meta (Ubuntu)
   Importance: Undecided => High

** Patch added: "ubuntu-meta_1.557.debdiff"
   
https://bugs.launchpad.net/ubuntu/+source/ubuntu-meta/+bug/2108942/+attachment/5898358/+files/ubuntu-meta_1.557.debdiff

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2108942

Title:
  [MIR] ptyxis

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ptyxis/+bug/2108942/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 2108942] Re: [MIR] ptyxis

2025-08-11 Thread Christian Ehrhardt
No required tasks to overcome, security also approved, showing up in component 
mismatches.
Thereby all is ready to be promoted

Single version, nothing waiting in proposed:

$ rmadison -u ubuntu -s questing,questing-proposed ptyxis
 ptyxis | 48.5-1 | questing/universe | source, amd64, arm64, armhf, ppc64el, 
riscv64, s390x

Promoting

$ ./change-override --component main --suite questing --source-and-binary ptyxis
Override component to main
ptyxis 48.5-1 in questing: universe/misc -> main
ptyxis 48.5-1 in questing amd64: universe/gnome/optional/100% -> main
ptyxis 48.5-1 in questing arm64: universe/gnome/optional/100% -> main
ptyxis 48.5-1 in questing armhf: universe/gnome/optional/100% -> main
ptyxis 48.5-1 in questing ppc64el: universe/gnome/optional/100% -> main
ptyxis 48.5-1 in questing riscv64: universe/gnome/optional/100% -> main
ptyxis 48.5-1 in questing s390x: universe/gnome/optional/100% -> main
Override [y|N]? y
7 publications overridden.


** Changed in: ptyxis (Ubuntu)
   Status: Fix Committed => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2108942

Title:
  [MIR] ptyxis

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ptyxis/+bug/2108942/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 2108942] Re: [MIR] ptyxis

2025-08-11 Thread Alessandro Astone
** Changed in: ptyxis (Ubuntu)
   Status: New => Fix Committed

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2108942

Title:
  [MIR] ptyxis

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ptyxis/+bug/2108942/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 2108942] Re: [MIR] ptyxis

2025-08-07 Thread Sudhakar Verma
** Changed in: ptyxis (Ubuntu)
 Assignee: Ubuntu Security Team (ubuntu-security) => (unassigned)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2108942

Title:
  [MIR] ptyxis

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ptyxis/+bug/2108942/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 2108942] Re: [MIR] ptyxis

2025-08-06 Thread Sudhakar Verma
Here's the bug.md

Security team ACK for promoting ptyxis to main. Its a good terminal emulator
candidate to replace GNOME Terminal.

** Attachment added: "BUG.md"
   
https://bugs.launchpad.net/ubuntu/+source/ptyxis/+bug/2108942/+attachment/5897074/+files/BUG.md

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2108942

Title:
  [MIR] ptyxis

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ptyxis/+bug/2108942/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 2108942] Re: [MIR] ptyxis

2025-04-29 Thread Seth Arnold
** Tags added: sec-6210

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2108942

Title:
  [MIR] ptyxis

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ptyxis/+bug/2108942/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 2108942] Re: [MIR] ptyxis

2025-04-25 Thread Christian Ehrhardt
Review for Source Package: ptyxis

[Summary]
MIR team ACK under the nont gating constraint to please have a look at
the recommended TODOs.

This does need a security review, so I'll assign ubuntu-security

List of specific binary packages to be promoted to main: ptyxis
Specific binary packages built, but NOT to be promoted to main: n/a

Required TODOs:
- n/a

Recommended TODOs:
- #1 There is (so far AFAICS) no appamor for any terminal. And one might argue
 that the terminal is just rendering between user and the shell. But in
 return should that not make it easy to create one? Not a requirement but
 having a look if it is possible would be great if this is meant to be the
 primary for the next LTS.
- #2 The package should get a team bug subscriber before being promoted
- #3 very low prio, the build log is full of "substitution variable ... unused, 
but is defined"
 I doubt that is a problem, but just have a look and ensure this isn't an 
oversight.

[Rationale, Duplication and Ownership]
- There is no other package in main providing the same functionality. Sure
  there are other terminals but it was outlined in the report why this one
  is requested. I understand and agree that this does not mean gnome-terminal
  would immediately go to universe. It should once think it can but in this case
  I think it does not "have to".
- A team is committed to own long term maintenance of this package => Desktop
- The rationale given in the report seems valid and useful for Ubuntu

[Dependencies]
OK:
- no other Dependencies to MIR due to this
  none of the dependencies (Depends
  and Recommends) that are present after build are not in main
- no -dev/-debug/-doc packages that need exclusion
- No dependencies in main that are only superficially tested requiring
  more tests now.

Problems: None

[Embedded sources and static linking]
OK:
- no embedded source present
- no static linking
- does not have unexpected Built-Using entries
- not a go package, no extra constraints to consider in that regard
- not a rust package, no extra constraints to consider in that regard

Problems: None

[Security]
OK:
- history of CVEs does not look concerning
- does not run a daemon as root
- does not use webkit1,2
- does not use lib*v8 directly
- does not parse data formats (files [images, video, audio,
  xml, json, asn.1], network packets, structures, ...) from
  an untrusted source.
- does not expose any external endpoint (port/socket/... or similar)
- does not process arbitrary web content
- does not use centralized online accounts
- does not integrate arbitrary javascript into the desktop
- does not deal with system authentication (eg, pam), etc)
- does not deal with security attestation (secure boot, tpm, signatures)
- does not deal with cryptography (en-/decryption, certificates,
  signing, ...)

Problems:
- one could say it parses text and control characters, not sure if that
  counts as for that it will mostly use the same libs the other terminals
  use (not part of ptyxis itself)
- this makes appropriate (for its exposure) use of established risk
  mitigation features. To be clear, AFAICS there is none so it it is
  debatable. One might say the actual "doing" of anything reasonable is
  by the shell in it. Yet on the other hand, that might mean a profile
  might be easy to write. If there is anything bad, breaking the terminal
  rendering code would be quite an attack. Output of commands could create the
  flow that causes it. Worth to add to suggestions to think about it, but
  not more sever than that.

=> I'm not entirely sure on my judgement here, and the policy says in that case
   we should assign it for a security review which I'll do.

[Common blockers]
OK:
- does not FTBFS currently
- This does not need special HW for build or test
- no new python2 dependency

Problems:
- does not have a test suite that runs at build time
- does not have a non-trivial test suite that runs as autopkgtest
You've outlined the struggles to test that in classic automated fashion,
and while it isn't impossible the infrastructure currently does not provide
what you'd need. The test plan 
https://wiki.ubuntu.com/DesktopTeam/TestPlans/Terminal
is fine if it will be executed. Thanks for defining that - ack.

[Packaging red flags]
OK:
- Ubuntu does not carry a delta
- symbols tracking not applicable for this kind of code (no lib)
- debian/watch is present and looks ok
- Upstream update history is good
- Debian/Ubuntu update history is good
- the current release is packaged
- promoting this does not seem to cause issues for MOTUs that so far
  maintained the package
- no massive Lintian warnings
- debian/rules is rather clean
- It is not on the lto-disabled list

Problems: None

[Upstream red flags]
OK:
- no Errors/warnings during the build
- no incautious use of malloc/sprintf (as far as we can check it)
- no use of sudo, gksu, pkexec, or LD_LIBRARY_PATH (usage is OK inside
  tests)
- no use of user nobody
- no use of setuid / se

[Bug 2108942] Re: [MIR] ptyxis

2025-04-24 Thread Jeremy Bícha
** Changed in: ptyxis (Ubuntu)
   Status: Incomplete => New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2108942

Title:
  [MIR] ptyxis

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ptyxis/+bug/2108942/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 2108942] Re: [MIR] ptyxis

2025-04-24 Thread Jeremy Bícha
** Description changed:

  [Availability]
  The package ptyxis is already in Ubuntu universe.
  The package ptyxis build for the architectures it is designed to work on.
  It currently builds and works for all Ubuntu architectures except for i386 
where it is not needed.
  Link to package https://launchpad.net/ubuntu/+source/ptyxis
  
  [Rationale]
  - The package ptyxis is required in Ubuntu main for modernizing Ubuntu 
Desktop's terminal
  - The package ptyxis will generally be useful for a large part of our user 
base
  - Package ptyxis covers the same use case as gnome-terminal, but is better 
because [below], thereby we want to replace it.
  + Simpler preferences dialog but still full of features
  + Improved theming
  + Uses gtk4 (gnome-terminal will eventually switch to gtk4)
- + Part of the GNOME ecosystem. GNOME's default terminal is currently GNOME 
Console which isn't really suitable for us. I think GNOME will eventually 
switch to Ptyxis as the default terminal because both gnome-terminal and 
gnome-console aren't ideal for GNOME. Fedora Workstation switched from 
gnome-terminal to Ptyxis in 2024.
+ + Part of the GNOME ecosystem. GNOME's default terminal is currently GNOME 
Console which isn't really suitable for us (too few features that we care 
about). I think GNOME will eventually switch to Ptyxis as the default terminal 
because both gnome-terminal and gnome-console aren't ideal for GNOME. Fedora 
Workstation switched from gnome-terminal to Ptyxis in 2024.
  
  - There is no other/better way to solve this that is already in main or
  should go universe->main instead of this.
  
  - The binary packages ptyxis needs to be in main to achieve Ubuntu Desktop's 
goal of modernizing the pre-installed terminal app
  - All binary packages built by ptyxis need to be in main (there is only one 
binary package)
  
  - The package ptyxis is required in Ubuntu main no later than August 14
  due to Ubuntu 25.10 Feature Freeze. We want early feedback in 25.10
  before 26.04 LTS.
  
  [Security]
  - No CVEs/security issues in this software in the past
+ + https://security-tracker.debian.org/tracker/source-package/ptyxis
  
- RULE: - Check for security relevant binaries, services and behavior.
- RULE:   If any are present, this requires a more in-depth security review.
- RULE:   Demonstrating that common isolation/risk-mitigation patterns are used
- RULE:   will help to raise confidence. For example a service running as root
- RULE:   open to the network will need to be considered very carefully. The 
same
- RULE:   service dropping the root permissions after initial initialization,
- RULE:   using various systemd isolation features and having a default active
- RULE:   apparmor profile is much less concerning and can speed up acceptance.
- RULE:   This helps Ubuntu, but you are encouraged to consider working with
- RULE:   Debian and upstream to get those security features used at wide scale.
- RULE: - It might be impossible for the submitting team to check this perfectly
- RULE:   (the security team will), but you should be aware that deprecated
- RULE:   security algorithms like 3DES or TLS/SSL 1.1 are not acceptable.
- RULE:   If you think a package might do that it would be great to provide a
- RULE:   hint for the security team like "Package may use deprecated crypto"
- RULE:   and provide the details you have about that.
- TODO: - no `suid` or `sgid` binaries
- TODO-A: - no executables in `/sbin` and `/usr/sbin`
- TODO-B: - Binary TBD in sbin is no problem because TBD
- TODO-A: - Package does not install services, timers or recurring jobs
- TODO-B: - Package does install services, timers or recurring jobs
- TODO-B:   TBD (list services, timers, jobs)
- TODO: - Security has been kept in mind and common isolation/risk-mitigation
- TODO:   patterns are in place utilizing the following features:
- TODO:   TBD (add details and links/examples about things like dropping
- TODO:   permissions, using temporary environments, restricted users/groups,
- TODO:   seccomp, systemd isolation features, apparmor, ...)
- TODO-A: - Packages does not open privileged ports (ports < 1024).
- TODO-B: - Packages open privileged ports (ports < 1024), but they have
- TODO-B:   a reason to do so (TBD)
- TODO-A: - Package does not expose any external endpoints
- TODO-B: - Package does expose an external endpoint, it is
- TODO-B:   TBD endpoint + TBD purpose
- TODO: - Packages does not contain extensions to security-sensitive software
- TODO:   (filters, scanners, plugins, UI skins, ...)
+ - no `suid` or `sgid` binaries
+ - no executables in `/sbin` and `/usr/sbin`
  
- RULE: The package should not use deprecated security algorithms like 3DES or
- RULE: TLS/SSL 1.1. The security team is the one responsible to check this,
- RULE: but if you happen to spot something it helps to provide a hint.
- RULE: Provide whatever made you suspicious as details along that statement.
- RULE: Or remove the following lines entirely if you did not 

[Bug 2108942] Re: [MIR] ptyxis

2025-04-24 Thread Jeremy Bícha
W: ptyxis: changelog-distribution-does-not-match-changes-file unstable != 
plucky [usr/share/doc/ptyxis/changelog.Debian.gz:1]
W: ptyxis changes: distribution-and-changes-mismatch plucky unstable
I: ptyxis: hardening-no-fortify-functions [usr/libexec/ptyxis-agent]
I: ptyxis source: out-of-date-standards-version 4.7.0 (released 2024-04-07) 
(current is 4.7.2)
I: ptyxis source: repackaged-source-not-advertised [debian/copyright]

https://lintian.debian.org/tags/hardening-no-fortify-functions.html
admits that there are false positives for this Lintian warning. We do
enable all hardening flags in debian/rules.

We exclude the screenshots (using debian/copyright Files-Excluded) in
our "orig" tarballs. The screenshots need to be stored online somewhere
and the upstream git repo was chosen. The screenshots are referenced in
the AppStream metadata and the project README but aren't needed by the
distro package itself. It doesn't feel worth using a repack suffix
version number just for this.

Debian Policy 4.7.1 was only released in February and we haven't updated
that metadata field in most of our packages yet.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2108942

Title:
  [MIR] ptyxis

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ptyxis/+bug/2108942/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 2108942] Re: [MIR] ptyxis

2025-04-24 Thread Jeremy Bícha
** Description changed:

  [Availability]
  The package ptyxis is already in Ubuntu universe.
  The package ptyxis build for the architectures it is designed to work on.
  It currently builds and works for all Ubuntu architectures except for i386 
where it is not needed.
  Link to package https://launchpad.net/ubuntu/+source/ptyxis
  
  [Rationale]
  - The package ptyxis is required in Ubuntu main for modernizing Ubuntu 
Desktop's terminal
  - The package ptyxis will generally be useful for a large part of our user 
base
  - Package ptyxis covers the same use case as gnome-terminal, but is better 
because [below], thereby we want to replace it.
  + Simpler preferences dialog but still full of features
  + Improved theming
  + Uses gtk4 (gnome-terminal will eventually switch to gtk4)
  + Part of the GNOME ecosystem. GNOME's default terminal is currently GNOME 
Console which isn't really suitable for us. I think GNOME will eventually 
switch to Ptyxis as the default terminal because both gnome-terminal and 
gnome-console aren't ideal for GNOME. Fedora Workstation switched from 
gnome-terminal to Ptyxis in 2024.
  
  - There is no other/better way to solve this that is already in main or
  should go universe->main instead of this.
  
  - The binary packages ptyxis needs to be in main to achieve Ubuntu Desktop's 
goal of modernizing the pre-installed terminal app
  - All binary packages built by ptyxis need to be in main (there is only one 
binary package)
  
  - The package ptyxis is required in Ubuntu main no later than August 14
  due to Ubuntu 25.10 Feature Freeze. We want early feedback in 25.10
  before 26.04 LTS.
  
  [Security]
  - No CVEs/security issues in this software in the past
  
  RULE: - Check for security relevant binaries, services and behavior.
  RULE:   If any are present, this requires a more in-depth security review.
  RULE:   Demonstrating that common isolation/risk-mitigation patterns are used
  RULE:   will help to raise confidence. For example a service running as root
  RULE:   open to the network will need to be considered very carefully. The 
same
  RULE:   service dropping the root permissions after initial initialization,
  RULE:   using various systemd isolation features and having a default active
  RULE:   apparmor profile is much less concerning and can speed up acceptance.
  RULE:   This helps Ubuntu, but you are encouraged to consider working with
  RULE:   Debian and upstream to get those security features used at wide scale.
  RULE: - It might be impossible for the submitting team to check this perfectly
  RULE:   (the security team will), but you should be aware that deprecated
  RULE:   security algorithms like 3DES or TLS/SSL 1.1 are not acceptable.
  RULE:   If you think a package might do that it would be great to provide a
  RULE:   hint for the security team like "Package may use deprecated crypto"
  RULE:   and provide the details you have about that.
  TODO: - no `suid` or `sgid` binaries
  TODO-A: - no executables in `/sbin` and `/usr/sbin`
  TODO-B: - Binary TBD in sbin is no problem because TBD
  TODO-A: - Package does not install services, timers or recurring jobs
  TODO-B: - Package does install services, timers or recurring jobs
  TODO-B:   TBD (list services, timers, jobs)
  TODO: - Security has been kept in mind and common isolation/risk-mitigation
  TODO:   patterns are in place utilizing the following features:
  TODO:   TBD (add details and links/examples about things like dropping
  TODO:   permissions, using temporary environments, restricted users/groups,
  TODO:   seccomp, systemd isolation features, apparmor, ...)
  TODO-A: - Packages does not open privileged ports (ports < 1024).
  TODO-B: - Packages open privileged ports (ports < 1024), but they have
  TODO-B:   a reason to do so (TBD)
  TODO-A: - Package does not expose any external endpoints
  TODO-B: - Package does expose an external endpoint, it is
  TODO-B:   TBD endpoint + TBD purpose
  TODO: - Packages does not contain extensions to security-sensitive software
  TODO:   (filters, scanners, plugins, UI skins, ...)
  
  RULE: The package should not use deprecated security algorithms like 3DES or
  RULE: TLS/SSL 1.1. The security team is the one responsible to check this,
  RULE: but if you happen to spot something it helps to provide a hint.
  RULE: Provide whatever made you suspicious as details along that statement.
  RULE: Or remove the following lines entirely if you did not spot anything.
  TODO: - I've spotted what I consider deprecated algorithms, the security team
  TODO:   should have a more careful look please, details are:
  
  [Quality assurance - function/usage]
  - The package works well right after install
  * There is a significant usability bug, LP: #2083705, that we expect to be 
able to fix with an upload of the bash package in May
  
  [Quality assurance - maintenance]
  - The package is maintained well in Debian/Ubuntu/Upstream and does not have 
too many, long-term &