[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Kernel Security Updates for Sarge



Hi Martin,

Steve Langasek asked me to get in contact with you in regards
to kernel security updates for sarge. I am happy to report
that I and other members of the kernel team have been keeping
the kernel-source for both 2.4.27 and 2.6.8 up to date in SVN.
And as of yesterday afternoon I have no outstanding security
bugs for either.

I think the best way forwards would be you, or someone
else on the security team to go through the changelogs provided,
and say yes an no to each item. There are some non-security
changes in there, mainly fixes for breakage, which IMHO should
go in, but I'm happy for you to say no. Its really up to
you and the other security people. Perhaps they are more
appropriate for rc1, perhaps not. I don't really mind.

Once we have a consensus on what can go in I can build
the kernel-source packages and upload them (somewhere).
I can also build the kernel-image-i386 and kernel-patch-powerpc
patches. Other architectures are built by other members of the
kernel team. And some architectures (e.g. ARM) aren't handled
by the kernel team at all.

For reference, these are the architectues that I believe
the kernel team handles, and the version of the kernel source
they are using in Sarge:

                Base kernel source version of package in Sarge
2.4.27: alpha      kernel-tree-2.4.27-9   (seems to be out of date in SVN)
        hppa       kernel-tree-2.4.27-8
        i386       kernel-tree-2.4.27-8
        ia64       kernel-tree-2.4.27-8
        mips       kernel-tree-2.4.27-8   (versioned dependancy needs to be
                                           changed to kernel-tree-2.4.27-8)
        s390       kernel-tree-2.4.27-8
        sparc      kernel-tree-2.4.27-9
        powerpc    kernel-tree-2.4.27-8   (versioned dependancy is missing)

                  Base kernel source version of package in Sarge
2.6.8: alpha               kernel-tree-2.6.8-15
       amd64 (arch i386)   kernel-tree-2.6.8-13
       hppa                kernel-tree-2.6.8-13
       i386                kernel-tree-2.6.8-13
       ia64                kernel-tree-2.6.8-13
       m68k                kernel-tree-2.6.8-13
       powerpc             kernel-tree-2.6.8-13
       s390                kernel-tree-2.6.8-13
       sparc               kernel-tree-2.6.8-15


The changelogs that I would like you to look at are as follows.
Almost all of the changes will be in kernel-source, and I believe 
that the log is accurate. There are also changelogs for each
architecture, but these are generally just packaging and kernel-config
changes:

The changelogs that I would like you to look at are as follows.
Almost all of the changes will be in kernel-source, and I believe 
that the log is accurate. There are also changelogs for each
architecture, but these are generally just packaging and kernel-config
changes:

The changelogs that I would like you to look at are as follows.
Almost all of the changes will be in kernel-source, and I believe 
that the log is accurate. There are also changelogs for each
architecture, but these are generally just packaging and kernel-config
changes:

The changelogs that I would like you to look at are as follows.
Almost all of the changes will be in kernel-source, and I believe 
that the log is accurate. There are also changelogs for each
architecture, but these are generally just packaging and kernel-config
changes:

The changelogs that I would like you to look at are as follows.
Almost all of the changes will be in kernel-source, and I believe 
that the log is accurate. There are also changelogs for each
architecture, but these are generally just packaging and kernel-config
changes:


2.4.27
  source: version in Sarge: 2.4.27-8
  http://svn.debian.org/wsvn/kernel/trunk/kernel-2.4/source/kernel-source-2.4.27-2.4.27/debian/changelog?op=file&rev=0&sc=0
  alpha: version in Sarge: 2.4.27-8
  http://svn.debian.org/wsvn/kernel/trunk/kernel-2.4/alpha/kernel-image-2.4.27-alpha-2.4.27/debian/changelog?op=file&rev=0&sc=0
  hppa: version in Sarge: 2.4.27-3
  http://svn.debian.org/wsvn/kernel/trunk/kernel-2.4/hppa/kernel-image-2.4.27-hppa-2.4.27/debian/changelog?op=file&rev=0&sc=0
  i386: version in Sarge: 2.4.27-8
  http://svn.debian.org/wsvn/kernel/trunk/kernel-2.4/i386/kernel-image-2.4.27-i386-2.4.27/debian/changelog?op=file&rev=0&sc=0
  ia64: version in Sarge: 2.4.27-7
  http://svn.debian.org/wsvn/kernel/trunk/kernel-2.4/ia64/kernel-image-2.4.27-ia64-2.4.27/debian/changelog?op=file&rev=0&sc=0
  mips: version in Sarge: 2.4.27-8.040815-1
  http://svn.debian.org/wsvn/kernel/trunk/kernel-2.4/mips/kernel-patch-2.4.27-mips-2.4.27/debian/changelog?op=file&rev=0&sc=0
  s380: version in Sarge: 2.4.27-2
  not in SVN?
  powerpc: version in Sarge: 2.4.27-4
  http://svn.debian.org/wsvn/kernel/trunk/kernel-2.4/powerpc/kernel-patch-powerpc-2.4.27/debian/changelog?op=file&rev=0&sc=0
  sparc: version in Sarge: 2.4.27-2
  http://svn.debian.org/wsvn/kernel/trunk/kernel-2.4/sparc/kernel-image-2.4.27-sparc-2.4.27/debian/changelog?op=file&rev=0&sc=0
  
  

2.6.8:
  source:  version in Sarge: 2.6.8-15 (but most are building off it 
                             patched down to 2.6.8-13)
  http://svn.debian.org/wsvn/kernel/trunk/kernel/source/kernel-source-2.6.8-2.6.8/debian/changelog?op=file&rev=0&sc=0
  alpha: version in Sarge: 2.6.8-9
  http://svn.debian.org/wsvn/kernel/trunk/kernel/alpha/kernel-image-2.6.8-alpha-2.6.8/debian/changelog?op=file&rev=0&sc=0
  amd64 (arch i386): version in Sarge: 2.6.8-13
  http://svn.debian.org/wsvn/kernel/trunk/kernel/amd64/kernel-image-2.6.8-amd64-2.6.8/debian/changelog?op=file&rev=0&sc=0
  hppa: version in Sarge: 2.6.8-6
  http://svn.debian.org/wsvn/kernel/trunk/kernel/hppa/kernel-image-2.6.8-hppa-2.6.8/debian/changelog?op=file&rev=0&sc=0
  i386: version in Sarge: 2.6.8-13
  http://svn.debian.org/wsvn/kernel/trunk/kernel/i386/kernel-image-2.6.8-i386-2.6.8/debian/changelog?op=file&rev=0&sc=0
  ia64: version in Sarge: 2.6.8-12
  http://svn.debian.org/wsvn/kernel/trunk/kernel/ia64/kernel-image-2.6.8-ia64-2.6.8/debian/changelog?op=file&rev=0&sc=0
  m68k: version in Sarge: 2.6.8-12
  http://svn.debian.org/wsvn/kernel/trunk/kernel/m68k/kernel-image-2.6.8-m68k-2.6.8/debian/changelog?op=file&rev=0&sc=0
  powerpc: version in Sarge: 2.6.8-12
  http://svn.debian.org/wsvn/kernel/trunk/kernel/powerpc/kernel-patch-powerpc-2.6.8-2.6.8/debian/changelog?op=file&rev=0&sc=0
  s390: version in Sarge: 2.6.8-5
  http://svn.debian.org/wsvn/kernel/trunk/kernel/s390/kernel-image-2.6.8-s390/debian/changelog?op=file&rev=0&sc=0
  sparc: version in Sarge: 2.6.8-6
  http://svn.debian.org/wsvn/kernel/trunk/kernel/sparc/kernel-image-2.6.8-sparc-2.6.8/debian/changelog?op=file&rev=0&sc=0





-- 
Horms

Attachment: signature.asc
Description: Digital signature


Reply to: