[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#723641: pu: package xen/4.1.4-5



On Mon, Sep 30, 2013 at 04:38:24PM +0200, Thijs Kinkhorst wrote:
> Thanks. I've read them. My conclusion is that there are two problems:
> 1/ On a previous upload, someone from the security team added extra
> changes without coordination or reporting them back.
> 2/ It took long to process the upload and there was no feedback on problems.
> Agreed?

No.  This are symptoms, not problems.  The main problem is
_communication_.

> On the first point, although I don't know exactly what changes were added
> by whom, I fully agree that if such is the case that's not good and
> understanding that it's annoying to you. I'm sure that we can agree that
> this was a mistake and that this should not happen again.

I don't think this will work.  The current security process ignores
any communitation that is otherwise part of the NMU process.  As long as
the security team does not have some policy to cummunicate first and do
later, especially if the maintainer is already in the loop or, worse,
did it herself, I see not why this should work now.

> The second point is indeed unfortunate, reading back it seems related to
> two different problems with DAK.

My main problem are the missing mails on uploads.  If the ftp-masters
refuses to accept a patch---did they?---you have to do it by human
relay.

> Given the limitations of tools and manpower and the large number of issues
> that we need to deal with, the process will probably never be perfect.

If you lack manpower, why don't I remember any calls for help like the
ftp-team or ctte did?

All the cases in the last years actually made them _more_ work.
Preparing and _testing_ a package is way more work then sending a mail
"I don't like it, please …" or "I haven't seen an upload, I'll do it".

>                                     Do you think we could just try to
> start anew? In the end it benefits our users most if Xen updates would
> come through the security channel.

There where three points in my mail …

Bastian

-- 
Where there's no emotion, there's no motive for violence.
		-- Spock, "Dagger of the Mind", stardate 2715.1

Attachment: signature.asc
Description: Digital signature


Reply to: