Public bug reported:

[Availability]
- The source package rust-ntpd is published in Ubuntu (universe).
- Current Launchpad builds pass on: amd64, amd64v3, arm64, armhf, ppc64el, 
riscv64, s390x.
- Source package: https://launchpad.net/ubuntu/+source/rust-ntpd

[Rationale]
- The package src:rust-ntpd is required in Ubuntu main for providing users with
  an alternative, standards-compliant and memory-safe implementation of NTP
  client and server. alternative, memory safe implementation to the Network
  Time Procol.
- This is the first time src:rust-ntpd will be in main.
- The package src:rust-ntpd will generally be useful for a large part of our
  user base.
- It is meant to coexist with `chrony`.
- All binary packages built by src:rust-ntpd need to be in main.
- The package would be useful in main, but there is no definitive deadline.
- No prior MIR bug was found for this source or identified predecessor names.

[Security]
- Had 7 security issues in the past.
    - https://github.com/pendulum-project/ntpd-rs/security
    - Some have been assigned CVEs:
        - CVE-2026-26076
        - CVE-2025-58066
        - CVE-2024-38528
        - CVE-2023-33192
    - Upstream generally deals with security issues in a timely manner.
- No executables in /sbin and /usr/sbin.
- Installs services:
    - bin:ntpd-rs: ntpd-rs.service
    - bin:ntpd-rs-metrics: ntpd-rs-metrics.service
    - Services run using the ntpd-rs user (not root).
    - Service hardening is being worked on upstream: 
https://github.com/pendulum-project/ntpd-rs/issues/2414
- Installs AppArmor profile in /etc/apparmor.d/usr.bin.ntp-daemon.
- Deprecated algorithms are present in the vendored sources, but they are not
  used by the application.
- Package can open privileged ports (but not by default)
    - This only happens when ntpd-rs is configured to act as a NTP server.
    - Requires UDP 123.

[Quality assurance - function/usage]
- The package works with sane defaults, shipping a default configuration file
  and requiring no interactive debconf setup.
- By default, only configures a NTP client, using the Ubuntu NTP pool as 
sources.
- Can be configured to act as a server as well, but not by default.

[Quality assurance - maintenance]
- No critical Ubuntu or release-critical Debian bugs.
    - Ubuntu: https://bugs.launchpad.net/ubuntu/+source/rust-ntpd/+bug
    - Debian: https://bugs.debian.org/cgi-bin/pkgreport.cgi?src=rust-ntpd
    - Upstream: https://github.com/pendulum-project/ntpd-rs/issues
- Important open upstream bugs:
    - Dynamic sources: https://github.com/pendulum-project/ntpd-rs/issues/2412
    - Better configuration format: 
https://github.com/pendulum-project/ntpd-rs/issues/2394
- The package does not depend on exotic hardware we cannot support.

[Quality assurance - testing]
- Build-time test execution was observed.
    - 
http://launchpad.net/ubuntu/+source/rust-ntpd/1.9.0-0ubuntu2/+build/33560475/+files/buildlog_ubuntu-stonking-amd64.rust-ntpd_1.9.0-0ubuntu2_BUILDING.txt.gz
- Autopkgtests are present, not trivial, and pass on all architectures.
    - https://autopkgtest.ubuntu.com/packages/rust-ntpd

[Quality assurance - packaging]
- A debian/watch upstream-release mechanism is present.
- Lintian reported 0 errors and 1 warning.
    - W: rust-ntpd source: unknown-field Vendored-Sources-Rust
- debian/control defines a correct Maintainer field
- The packaging uses standard dh-cargo tooling with overrides for vendoring,
  copyright maintenance, and apparmor installation.
- This package does not rely on obsolete or about to be demoted packages.
- This package has no python2 or GTK2 dependencies.

[UI standards]
- Application is not end-user facing (does not need translation nor Desktop 
file).

[Dependencies]
- Used check-mir from ubuntu-dev-tools to validate all dependencies or 
recommends are in main.

[Standards compliance]
- This package correctly follows FHS and Debian policy.
- Based on a reasonable review of information available at the time of this
  report, no expiry, time-limited grants, or obvious legal encumbrances have
  been identified that would be expected to affect promotion.

[Maintenance/Owner]
- The owning team already subscribed to this package is confirmed and has
  explicitly acknowledged the long-term maintenance commitment.
- Package bug subscriber team(s): ubuntu-server.
- The team is aware of the implications by a static build and commits to test
  no-change-rebuilds and to fix any issues found for the lifetime of the
  release (including ESM).
- The team is aware of the implications of vendored code and commits to provide
  updates and backports to the security team for any affected vendored code for
  the lifetime of the release (including ESM).
- This package uses vendored rust code tracked in Cargo.lock as shipped. In the
  source package, refreshing that code is outlined in debian/README.source.
- This package uses vendored code, the debian/copyright has been updated to
  cover the vendored content.
- This package is rust based and vendors all non language-runtime dependencies.
- The package has been built within the last 3 months in the archive.
    - 
https://launchpadlibrarian.net/873183134/buildlog_ubuntu-stonking-amd64.rust-ntpd_1.9.0-0ubuntu1_BUILDING.txt.gz

[Background information]
- Upstream Name is ntpd-rs
- Link to upstream project: https://github.com/pendulum-project/ntpd-rs
- https://discourse.ubuntu.com/t/ntpd-rs-its-about-time/79154

** Affects: rust-ntpd (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166406

Title:
  [MIR] rust-ntpd

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/rust-ntpd/+bug/2166406/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to