[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Short Reminder: jessie-backport deprecation



On Fri, 8 Jun 2018, Thomas Arendsen Hein wrote:

> These two files are what I have in our local documentation for squeeze
> +(+lts backports), but I haven't tested it recently:
> 
> /etc/apt/sources.list:
> deb http://archive.debian.org/debian/            squeeze            main contrib non-free
> deb http://archive.debian.org/debian/            squeeze-lts        main contrib non-free
> deb http://archive.debian.org/debian-backports/  squeeze-backports  main contrib non-free

This will work (s!debian-backports!debian! for post-squeeze), but…

> /etc/apt/apt.conf.d/01local:
> Acquire::Check-Valid-Until false;

this will unfortunately not be enough in the long term,
as the PGP signatures will expire (rather, the keys).

I wish there were an APT option to say, per repository,
“this is archived, check the signature as if it were
the yyyy-mm-dd today, then pin it and error out if it
changes”.

The thing is, for the duration of LTS, the base system
will continue to get select updates (sometimes even
better ones than other releases get), but there’s no
way for uploaders who do care to update the backports,
i.e. they’ll be frozen. (I assume this also applies to
-sloppy, which is even more a PITA as testing is cur‐
rently still moving.) I do understand the manpower and
rules issue though… (@Alex: my offer from Hamburg is
still valid, if you wish.)

bye,
//mirabilos
-- 
tarent solutions GmbH
Rochusstraße 2-4, D-53123 Bonn • http://www.tarent.de/
Tel: +49 228 54881-393 • Fax: +49 228 54881-235
HRB 5168 (AG Bonn) • USt-ID (VAT): DE122264941
Geschäftsführer: Dr. Stefan Barth, Kai Ebenrett, Boris Esser, Alexander Steeg


Reply to: