[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#987329: marked as done (unblock: ceph/14.2.20-2)



Your message dated Mon, 26 Apr 2021 21:23:53 +0200
with message-id <8f09f98e-97c2-1c28-950c-2490a9a7c93b@debian.org>
and subject line Re: Bug#987329: unblock: ceph/14.2.20-2
has caused the Debian Bug report #987329,
regarding unblock: ceph/14.2.20-2
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
987329: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=987329
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: release.debian.org
Severity: normal
User: release.debian.org@packages.debian.org
Usertags: unblock
X-Debbugs-Cc: Bernd Zeimetz <bzed@debian.org>, Moritz Muehlenhoff <jmm@debian.org>, Adam Borowski <kilobyte@angband.pl>

Dear release team,

I've uploaded version 14.2.20-2 of Ceph. This is the last point release
from usptream, including the fixes for CVE-2021-20288 and CVE-2020-27839.

With such large software such as Ceph, the debdiff can be quite big.
This unfortunately is no exception. I understand that the rule is that
the release team insist reviewing all changes. That's clearly not
possible considering the debdiff size. However, I don't think it is
reasonable to not include point release fixes from upstream, just like
we do with other large software in Debian. I intend to keep Ceph 14.2.x
updated during the lifetime of Bullseye, following upstream updates,
hopefully you will agree that this is the sensitive thing to do.

I've uploaded the debdiff here:
http://shade.infomaniak.ch/ceph_14.2.20-2.debdiff

Note that I have setup and used version 14.2.20-2 in a production
OpenStack cluster: Ceph is used there for storing Glance images,
Cinder volumes, and Nova VM disks. I haven't seen any regression.

Please unblock package ceph/14.2.20-2

Cheers,

Thomas Goirand (zigo)

P.S: bzed, jmm and kilobyte as CC after discussing this update with bzed
who co-maintains the Ceph package. Also, this bug is instead of #985885
that I have closed.

--- End Message ---
--- Begin Message ---
Hi zigo,

On 23-04-2021 02:02, Thomas Goirand wrote:
> Thanks for your answer. I was kind of expecting an answer like this one,
> so I'm not surprised. Let me answer to your points one by one. I've
> tried to be precise, hopefully, this isn't a too long answer...

It helped, thanks.

> I'm sorry, but my MTA is configured to not accept anything that is
> bigger than 8MB, so I can't send such a large file by mail.

The size of the diff could have been a (tiny) bit smaller if the Debian
tree would not have been in there 4 times. A filtered diff without
/doc/, /qa/ and /src/test/ would also have been reasonable to provide
(and a significant bit smaller).

unblocked.

Paul

Attachment: OpenPGP_signature
Description: OpenPGP digital signature


--- End Message ---

Reply to: