[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: kernel abiname transition and security updates status



Joey Hess wrote:
> Before we can release d-i rc3 we need all the kernels updated with at
> least some security fixes, notably the ones that change the kernel
> module ABI, and we need to update things to reflect the new kernel
> "abiname". Here's my understanding of the current status of that:

Update for current status, 10 days after my first mail:

alpha
	Kernel updated, but not yet in testing (old binaries); udebs updated;
	rootskel/base-installer/debian-cd not yet updated.

amd64
	Updated, but I'm not tracking this arch.

arm
	No abiname; not updated. ?

	[At the moment this is one of the arches that I'd consider
	releasing d-i rc3 without it being updated for the kernel
	security fixes, since it has no abiname, and since the daily
	builds have been down since October.]

hppa
	2.4 lacks abiname, has not been updated, and we're in the process of
	dropping it.

	2.6 has abiname; not updated.

	[This is likely to block d-i rc3 until the new hppa 2.6 kernels
	with the new abiname are available.]

i386
	2.4 and 2.6 updated to -2 abiname; 2.4 debs in testing, 2.6
	not; udebs updated; rootskel/base-installer/debian-cd not yet
	updated.

ia64
	2.4 and 2.6 updated to -2 abiname; debs in testing; udebs
	updated; rootskel/base-installer/debian-cd not yet updated.
	No initrd builds for last 10 days, at least 2.4 udebs untested.

m68k
	No abiname; not updated. ?

	[This is another arch that I'd consider releasing d-i rc3 without
	it being updated for the kernel security fixes.]

mips
	No abiname. Kernel updated and in testing; udebs updated.
	No initrd daily builds since Dec 31 so new udebs untested.

mipsel
	No abiname. Kernel updated and in testing; udebs updated.

powerpc
 	No abiname. 2.4 not updated. 2.6 updated, debs in testing;
	udebs updated.

	[If powerpc 2.4 is not updated with the security fixes soon, I
	will probably not let it block a d-i rc3 release.]

s390
	Has abiname; not updated
	
	[This is likely to block d-i rc3 until the new kernels with the new
	abiname are available.]

sparc
	2.6 updated to -2 abiname; 2.4 not yet updated (except in svn); 
	2.6 debs not yet in testing (due to RC #288180); udebs updated;
	rootskel/base-installer/debian-cd not yet updated.

So s390 and hppa are the main potential rc3 blockers, while alpha and
sparc just need to get kernels into testing and arm, m68k, and powerpc
(2.4) need to get a move on if you want them updated for the rc3
release. We're fast approaching the point where the kernel updates are
the only significant thing blocking the rc3 release.

Note that besides the abiname changes, there are pending uploads for
both 2.4 and 2.6, for all arches, to fix numerous other security holes.
I'm not considering those above, since it should be much easier to roll
a fix for a "normal" kernel security hole into d-i than the it is for
these security fixes that involve ABI changes.

-- 
see shy jo

Attachment: signature.asc
Description: Digital signature


Reply to: