[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Debian i386 freeze



Previously Brian White wrote:
> >   24634  the 'Admin' profile includes 'raidtools' which cannot be in
> >   24569  bsdutils does not Pre-Depends on libc6.
> >   24236  emacs20, postrm is broken..
> >   22941  libreadline2 depends on libc6
> >   24595  FIXED: smail in frozen is an open relay
> 
> All these are fixed as of today.

Indeed. I also downgraded & retitled all of them.
> 
> 
> >   24557  netstd: netstd re-enables rlogin/rsh/rexec
> 
> This was at least partially fixed today.

I did a NMU for ssh which is already installed in nonus. Bug has already been
downgraded & retitled.
> 
> 
> >   24200  termcap: vulnerability
> Termcap isn't really used by Debian.  I'm still waiting to hear more from
> the maintainer.

dark did a NMU for this one. Waiting in incoming at the moment.

> >   24306  ssh: security patch[FIX] Wichert Akkerman uploaded NMU 1.2.25-1.1 on July 17, which fixes this
> >   24022  libssl: Upstream security fix available
> 
> Nonus isn't a wholly integrated part of the distribution yet and so isn't
> managed the same as the the rest.

(see above). Both have been installed, downgraded & retitled.

> >   24126  screen aborts with signal 11 in X
> I hadn't heard that yet.

Actually this is a ncurses3.4 bug. It has already been reassign & merged
with the correct ncurses3.4 report.

> > Package: dhcp
> > Maintainer: Rich Sahlender
> >   24443  [SECURITY] dhcp: potential buffer overflow problems
> > [STRATEGY] Eloy A. Paris promised to do a NMU to fix this.
> > 
> > Package: dhcp-beta
> > Maintainer: Rich Sahlender
> >   24442  /etc/init.d/dhcp-beta sources inexistent /etc/init.d/functi
> > [STRATEGY] Eloy A. Paris promised is making a NMU to fix this.
> >   24445  [SECURITY] dhcp-beta: potential buffer overflow problems
> > [STRATEGY] Eloy A. Paris promised to do a NMU to fix this.
> 
> These can also be removed without a large impact.

Hmm, Eloy promised he would make the NMU today. It would be a shame if he
is a couple of hours too late :(

> > Package: wu-ftpd-academ
> > Maintainer: Heiko Schlittermann
> >   24466  netstd: Upgrading netstd overrides wu-ftpd-academ entry in
> > [STRATEGY] "Will be fixed within the next two days or nights.", quote from
> >            Heiko Schlittermann.
 
> For those "necessary" packages, I can wait the weekend if absolutely
> necessary.

IMHO wu-ftpd-academ is as necessary as dhcp. dhcp is used in many sites and,
unlike wu-ftpd-academ, has no alternative. If you let wu-ftpd-academ through
at least let dhcp also in hamm.

> > Which would take us down to 18 bugs.  While they matter, archive bugs can't
> > be fixed by mere mortals and I am trying to convince wichert that since
> > non-us did not freeze with hamm and has essentially slink level software in
> > it now, there's no reason to count the bugs that aren't likely to be fixed
> > for non-us as hamm critical.

I'm biased on that. Since nonus is not a real part of hamm it should not
hold the release. On the other hand we want to offer a stable non-us
tree as well. I'll remove all nonus entries from the bug-list for hamm,
but I really think we should try to work somewhat on nonus. Ideally I would
like to be able to by a non-us CD in the shops here.


> > Package: binutils
> > Maintainer: Galen Hazelwood
> >   23153  strip: stripped binary(executable) dumping core.
> 
> It happens rarely and can be worked around if necessary.  I'm choosing to
> ignore this bug for Debian 2.0.

Which seems to be the consensus on debian-devel. It's actually a long-standing
bug which has been known upstream for quite while. We're the first to mark
it as important..

> > Package: kdebase              (i386 contrib)
> > Maintainer: Stephan Kulow
> >   24643  kdebase: We have no licence to distribute KDE binaries when
> 
> Removeable.

Uh.. if you remove kdebase you might as well remove the all kde* packages,
since they probably depend on kdebase.

> > Package: screen
> > Maintainer: Juan Cespedes
> >   23998  screen: can't handle the new xterm terminfo
> 
> (actually ncurses)  It only seems to affect screen which, while an
> important packages to have, is not (in my opinion) worth holding up
> the release.  I'm choosing to let this one pass for 2.0.

As mentioned above, already fixed.
 
> > Package: smail
> > Maintainer: Soenke Lange
> >   23717  smail: smtp entry in inetd.conf gone after smail upgrade
> 
> Fixed in latest upload.

Are you sure? I couldn't find any reference to that in the changelog.

> > Package: xbase
> > Maintainer: Branden Robinson
> >   24642  XF86Setup doesn't run: the file /usr/X11R6/lib/X11/xinit/xi
> 
> I'm still waiting to hear from Branden about this one.

Branden has built a new X which people on #debian are currently testing.
It's available at http://master.debian.org/~branden/xfree86 . For all
you apt-fans out there:
deb http://master.debian.org/%7Ebranden/ xfree86/

Wichert.

-- 
==============================================================================
This combination of bytes forms a message written to you by Wichert Akkerman.
E-Mail: wakkerma@wi.LeidenUniv.nl
WWW: http://www.wi.leidenuniv.nl/~wichert/

Attachment: pgp6JZ_QG53Nb.pgp
Description: PGP signature


Reply to: