[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Meltdown fix for wheezy-backports



I found the chart I was thinking of.

https://www.freexian.com/en/services/debian-lts.html

"Traditionally, Debian manages security support of a given stable release until the next stable release plus one year. Roughly, this amounts to 3 years which is not enough for many organizations and does not allow to deploy version N+2 once N is no longer supported. The Debian LTS team wants to fix this by extending the security support of Debian releases to at least 5 years."




On 01/23/2018 10:35 AM, Thorsten Glaser wrote:
On Tue, 23 Jan 2018, Xan Charbonnet wrote:

I can't seem to find it now, but I believe somewhere official there is (or was
at one time?) a diagram showing how LTS would allow skipping stable versions:

No, that does not and cannot work.

LTS is “just” the extension of normal stable-security work, for a
subset of architectures and packages.

That being said…

I still believe it's particularly useful for the kernel: with a backported
Jessie kernel, new hardware like NVMe drives magically works on Wheezy.

… wheezy-backports{,-sloppy} ought to still be available for uploads
from people who DO care, even if those uploads will need to be
manually ACKed to ensure the rules (must be in jessie/stretch first)
are still followed, and perhaps only for packages already backported,
with few justified exceptions if needed.

On the other hand, it’s often possible to just run the next stable’s
kernel as-is once you’ve had the backported kernel (and the corre‐
sponding supporting packages) installed. It’s nowhere easy to achieve
though, APT pinning is still black magic, especially in versions as
antique as wheezy, so I’d still be in favour of allowing newer jessie
kernels into wheezy-backports right now IF someone’s willing to do
the work.

Given that wheezy currently gets the most amount of security fixes,
most quickly too, for several noticeable packages, it’s not unjusti‐
fied to want to continue running it, and quite a boon for LTS.

bye,
//mirabilos



Reply to: