** Description changed: - The team responsible is still not 100% clear to me. I filled out the - rest of the questions for the time being and will probably iterate over - it again. - [Availability] - The package libssc is already in Ubuntu universe. - - The package libssc build for the architectures it is designed to work on. - - It currently builds and works for architectures: arm64. It is building for - more architectures, but only relevant on ARM so far. Link to package - https://launchpad.net/ubuntu/+source/libssc + - It currently builds and works for architectures: amd64, arm64, armhf. Link to package + https://launchpad.net/ubuntu/+source/libssc + - Building has been restricted to these architectures by Debian. [Rationale] - The package libssc is required in Ubuntu main for depends fulfillment in - iio-sensor-proxy, to enable the SSC backend present since iio-sensor-proxy - 3.9 on Qualcomm ARM platforms. - - The package libssc will not generally be useful for a large part of our user - base, but is important/helpful still because it enables working with sensors - on Qualcomm boards and machines. While those are a minority, enabling these - should be in our focus. - - Additional reasons: We are working with Qualcomm boards and try to get Ubuntu - working on Qualcomm machines. + iio-sensor-proxy, to enable the SSC backend present since iio-sensor-proxy + 3.9 on Qualcomm ARM platforms. + - We are working with Qualcomm boards and try to get Ubuntu working on Qualcomm + machines. + - Enabling this on Qualcomm machines is relevant for enabling Ubuntu on ARM + machines in the coming years. - Package libssc covers the same use case as sensinghub, but is better because - it is already integrated within iio-sensor-proxy. + it is already integrated within iio-sensor-proxy and only a small targeted + library as opposed to sensorhub. - The package libssc is a new runtime dependency of package iio-sensor-proxy - that we already support. The SSC backend has been disabled for the time being - due to libssc not being present in main. - - There is no other/better way to solve this that is already in main or should - go universe->main instead of this. libssc is currently the only feasible way - to expose these sensors. + that we already support. The SSC backend has been disabled for the time being + due to libssc not being present in main. However this was a stopgap + measurement to avoid hasty decisions. - This is the first time package will be in main - The binary packages libssc2 need to be in main to achieve the - iio-sensor-proxy depends fulfillment and make these sensors accessible using - that way. + iio-sensor-proxy depends fulfillment and make these sensors accessible using + that way. - It would be great and useful to community/processes to have the package - libssc2 in Ubuntu main, but there is no definitive deadline. + libssc2 in Ubuntu main, but there is no definitive deadline. [Security] - - No CVEs/security issues in this software in the past. There are issues like - - https://codeberg.org/DylanVanAssche/libssc/issues/125 (use-after-free) - - https://codeberg.org/DylanVanAssche/libssc/issues/120 (crashing DSP) + - No CVEs/security issues in this software in the past - no executables in `/sbin` and `/usr/sbin` - Package does not install services, timers or recurring jobs - Security has been kept in mind and common isolation/risk-mitigation patterns - are in place utilizing the following features: - - Transport: libssc communicates with the SSC service over the kernel - AF_QIPCRTR socket family (via libqrtr-glib/libqmi-glib). There is no - default OS-level access control. iio-sensor-proxy, mitigates this only at - the via systemd RestrictAddressFamilies=...AF_QIPCRTR. - - Systemd unit restricts socket family - - Packages does not contain extensions to security-sensitive software - (filters, scanners, plugins, UI skins, ...) + are in place utilizing the following features: + - Transport: libssc communicates with the SSC service over the kernel + AF_QIPCRTR socket family (via libqrtr-glib/libqmi-glib). There is no + default OS-level access control. iio-sensor-proxy, mitigates this only at + the via systemd RestrictAddressFamilies=...AF_QIPCRTR. + - Systemd unit restricts socket family + - Packages does not contain extensions to security-sensitive software + (filters, scanners, plugins, UI skins, ...) [Quality assurance - function/usage] - - The package works well right after install. It is a library enhancing - functionality in iio-sensor-proxy. + - The package works well right after install. + - The MIR target is a library and a needs to be enabled in the iio-sensor-proxy + build process. [Quality assurance - maintenance] - The package has important open bugs, listing them: - - https://codeberg.org/DylanVanAssche/libssc/issues/125 - crashing - iio-sensor-proxy - - https://codeberg.org/DylanVanAssche/libssc/issues/120 - crashing DSPs - - https://codeberg.org/DylanVanAssche/libssc/issues/111 - device specific - - The package does deal with exotic hardware, such hardware is available to the - team for debugging, test, verification and development via: - - testflinger under the following queue(s): - https://certification.canonical.com/platforms/14801/ + - https://codeberg.org/DylanVanAssche/libssc/issues/125 - crashing + iio-sensor-proxy + - https://codeberg.org/DylanVanAssche/libssc/issues/120 - crashing DSPs + - https://codeberg.org/DylanVanAssche/libssc/issues/111 - device specific + - The package does deal with niche hardware for the moment, such as primarily + dev boards. Such hardware is available to the team for debugging, test, + verification and development via: + - testflinger under the following queue(s): + https://certification.canonical.com/platforms/14801/ [Quality assurance - testing] - - The package does not run a test at build time because - https://codeberg.org/DylanVanAssche/libssc/issues/117. This issue is fixed - and a version bump will address this. TODO: - The package runs an autopkgtest, - and is currently passing on this list of architectures, link to test logs TBD - - The package does have not failing autopkgtests right now. The build time - tests are currently disabled until a update to a version > 0.4.2 happens due - to https://codeberg.org/DylanVanAssche/libssc/issues/117 + - The package runs an autopkgtest, albeit superficial ones. + - The package does have not failing autopkgtests right now. + - The package has build time tests. [Quality assurance - packaging] - - A mechanism to detect and fetch new upstream versions is present and works, - debian/watch is set up. + - debian/watch is set up and works. - debian/control defines a correct Maintainer field - Lintian overrides are not present - This package has no python2 or GTK2 dependencies - The package will not be installed by default, if iio-sensor-proxy is pulled - in. The package itself does not use debconf. + in. The package itself does not use debconf. - Packaging and build is easy, link to debian/rules - https://salsa.debian.org/DebianOnMobile-team/libssc/-/blob/debian/latest/debian/rules + https://salsa.debian.org/DebianOnMobile-team/libssc/-/blob/debian/latest/debian/rules [UI standards] - Application is not end-user facing (does not need translation) [Dependencies] - Used check-mir from ubuntu-dev-tools to validate all dependencies (libc6, - libglib2.0-0t64, libprotobuf-c1, libqmi-glib5, libqmi-proxy, libqrtr-glib0) - or recommends are in main. + libglib2.0-0t64, libprotobuf-c1, libqmi-glib5, libqmi-proxy, libqrtr-glib0) + or recommends are in main. [Standards compliance] - This package correctly follows FHS and Debian Policy - Based on a reasonable review of information available at the time of this - report, no expiry, time-limited grants, or obvious legal encumbrances have - been identified that would be expected to affect promotion. The current - licenses in use are the GPLv3 for packaging related files and AGPLv3 for the - source code. + report, no expiry, time-limited grants, or obvious legal encumbrances have + been identified that would be expected to affect promotion. The current + licenses in use are the GPLv3 for packaging related files and AGPLv3 for the + source code. [Maintenance/Owner] - Maintenance can reasonably be inherited from Debian - - TBD: I Suggest the owning team to be Debcrafters + - I Suggest the owning team to be Debcrafters. This has been agreed upon with + @seb128 - This does not use static builds - This does not use vendored code - This package is not rust based - The package has been built within the last 3 months in the archive - - Build link on launchpad: - https://launchpad.net/ubuntu/+source/libssc/0.4.2-3ubuntu1 + - Build link on launchpad: + https://launchpad.net/ubuntu/+source/libssc/0.4.4-1 - This change will impact Debcrafters due to potentially crashing - iio-sensor-proxy + iio-sensor-proxy [Background information] - The Package description explains the package well - Upstream Name is libssc - Link to upstream project https://codeberg.org/DylanVanAssche/libssc - We are currently inheriting the package from Debian. - - The upstream repository seems to be a single person. + - The upstream repository seems to be a single person with occassional + contributions from other people. Considering that this package is fairly new + in Debian, this might be subject to change. - Upstream is responsive on the bugs as well as committing on a regular basis. + - The maintainer is actively working on this project since at least 3 + years.
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2159637 Title: [MIR] libssc To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/libssc/+bug/2159637/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
