Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.maint.java > #11220

Re: Debian distributions of stable OpenJDK updates

Path csiph.com!news.dns-netz.com!news.freedyn.net!aioe.org!bofh.it!news.nic.it!robomod
From Matthias Klose <doko@debian.org>
Newsgroups linux.debian.maint.java
Subject Re: Debian distributions of stable OpenJDK updates
Date Sun, 26 May 2019 21:50:02 +0200
Message-ID <y27jz-3XG-3@gated-at.bofh.it> (permalink)
References <xZNyG-7L7-5@gated-at.bofh.it> <xZNyG-7L7-3@gated-at.bofh.it> <xZPK9-xq-5@gated-at.bofh.it> <xZPK9-xq-3@gated-at.bofh.it> <xZQdc-WR-5@gated-at.bofh.it> <y0Yil-2bM-3@gated-at.bofh.it> <y0Zo6-34M-13@gated-at.bofh.it> <y13UJ-5GX-3@gated-at.bofh.it> <y1iK6-6EQ-9@gated-at.bofh.it> <y1n73-ZJ-3@gated-at.bofh.it>
X-Mailbox-Line From debian-java-request@lists.debian.org Sun May 26 19:47:32 2019
Old-Return-Path <doko@debian.org>
X-Amavis-Spam-Status No, score=-7.68 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, LDO_WHITELIST=-5, MURPHY_DRUGS_REL8=0.02, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham autolearn_force=no
X-Policyd-Weight using cached result; rate:hard: -3.5
Old-X-Envelope-From doko@debian.org
Openpgp preference=signencrypt
Autocrypt addr=doko@debian.org; prefer-encrypt=mutual; keydata= xsFNBFSG0WgBEADcWrLbnzkO07eqpkPsp0fRr2Tuhp+MABPwSS0msANqPiy9eWYGIXf2zHam Z77aKC+dykpnHn5ibvgOa70P5PBT+Ydk5EzI6Y98FvPQkuPFxkE29NK3Gn3DPHuAyfVpE0FM lMr9e10K+ZhY++nG4ZzHQUkg52iwlZ5twjpF0nwbtfHUMAPStCGC+orXnqcdmUq96r94+lZ2 Dsb2S67TM2umnqkzuIHlbhBXtnFiDtql+wW/Axqa6hGAVqks6OTX5NxGr+FTQ0UuptxhADZ2 S4cpftUROB7DgpDl3lGicvuOwW/UWJZMp0MwKJqu56Ajgu3IQM2oTTNmDLRP243gR5PxC1Yw VXhCG+juCO4Y1ous5fwCthiOE/3vOtF+GHRDVgikNKjv5MnsqbMJytAMIZS2uN07SPZKC4vX Vcw6KCBOBQhlrLTeffmPpnQzSUFwPJAySFFWjjpGLngglGM75zRa59PkVkPkeXKqz0O33xXm q6v3YNJNQgNVLAfn6rWmAckUly9mXmjAEvonrkR5impsyUGYPFHxb8TDhsGB6t9MHtMhr4pt wBMXv8aIWHfQndRvigfJC/xy7Su7qEaChuCjHEVVTuEEsnkKXOm7++VJsXG3wJBvqENu/9Lp uktBijnojbYrb0z+qgKt6jhBjUEy/iyfgQb4hwRX4jZ1T891dwARAQABzSBNYXR0aGlhcyBL bG9zZSA8ZG9rb0BkZWJpYW4ub3JnPsLBdwQTAQgAIQIbAwIeAQIXgAUCVIbUigULCQgHAwUV CgkICwUWAgMBAAAKCRC9fqpgd4+m9Rb7EADSQHuJpyADEuZxqlPMhJ/5WHM84Z+k4EQvnaqp czkKmZvtjCDn/8mhIAJ+oZdZer5VITkkUz/bX0ASV+2IDP6wWnZN5DGB9Ta1qFKfXRrVQVC1 bxtw5Rc+l7/dn9Jcz2v6uIzXUaybxRdEvsPrWYEM3WtRiiftm3J2HE7RzC4RplsSIUwSiT26 w5YbQo9im9rABkKdKw2+Y34YZv2QwCDcNqDfWqJQOu7DeN5PZ23V1nPRTcP907Y7OMkqzWOl Jl1Sj2q5g5fXha8c6+KQb52Yiki+7U9Z7pHiFCBEHWoDNMyNl4kUZM2Z5rwyFGAndtp+uHhY W9YIvuLxzvZPSWyEQIkG/k64rjx84SaQ04RuBBj3U1A1zMO/G4tI2rJ/+/TvV4Oa9iG37amI 7navLAtrXKkI1GFuNc/OUX6pezw7jypV3LB+6Z61tkYuwcNcz7NGAmHVuzVH5DI2udc1UogH 0yUO307IyhrmY1vM7Fohcg2fkwYba6PrqsyYhBowFmEk4j9kMuVIJplsEvKx0bIZY4xYgWQg UE1fvl3Fh4zWKzbopV0hMpcWvO0jxR4TG8vJkyZSyZtrRQiyYlIddJkk8HjD9MFSgO/cMQW6 x31A6eaQAhgNVChfv8KN8AZDbVoWvMz4RRwkl9Up8tinNWt2argz540M6DGz4JRHSScL0c7B TQRUhtFoARAAxRsii1f5GJEGnj2KR2Ct1zpIJCXta18v9/NhuVuSBygPYR2XCmVZTd3YivJN dnV5EFr8eQu+hgUxsq2OWAVFJSVb+WtLub0t3APSwTwo5Y+cZvupEwy31Btr9yRZlDns7MTW At1PFoG8iPwQwK6jbnPM+bap0t4o+/nd/7TWGBPgJNPVMxPoA+xCdMnZoiwDDsYsy8Mf6dZC ZfyKqrnDL9pe2hGBIvcY9HmuNP4wsgtPj9vCb01RK2Qd+wRDeePZ/k9sLwbfmeO9Ts8oCBoV Kd948zrQeIWnd2jiFpiROyUd0FeuNwO5CbSmV8HjBCZy8KSnBl/ruNlTIxnwTfpROCkchq8x 1mPQ1k+l+V/dzIGROAcgpNRKoPsciu0nXROgfgl7Fe2UPL7IfZ97UyoJicXlrhYF9jAc2pEQ apdTun88wIGDeLKE/pVl2XNq+PdN4AgFXIGuJZiP2BQdQ2/UU4NERSPzaf6kaDn3D8Q7sLqs cMa8cI7kHLr+fop5VYgubEi/Fv0W7F7YoeEARUMqAt37MpkJW7Mun4JxC/Rjju7JBD6U94Vi +Xqst2uTEp2gPc077CRUkQ2sN0oLzc6AyYCaD3NTFC0CcQA4vj7cMH5v61scpHu4gAMkTmZ/ 1Ys9LNT6lK51A/wJga9MMN3Uw3J48Oi9zv6woU19vlp7Z0EAEQEAAcLBXwQYAQgACQUCVIbR aAIbDAAKCRC9fqpgd4+m9Sj9D/0XNPuzW4p3qPZwwlA834fmMGTHlyxvmz5yCccJl20OM4qO dRtfSUCUfqjeQjUXePDYDfZb+Tys2A1Y0/kN+Y7nkv56WI5Ou1zkXwth3xcRtMar8DIpyfIf CZKy21ybD+GvJZOpRR/n3Gy1f4bnveEZHuitPIm1QPHEjJqHsUjZWhHKqe4J7yA50KYH9hNU N7FP5eE4WczpGrBmfX32zZkf5y0J4vX2YHyMJS4kV2h0fYbP7B3A4D0g7tTdXmmqCi7mgyVC J1iab+XeJ27VeNIOjmKByWiQllcjganhedN5Sh9hFoinjgjcfSmGv1zzgPM8A3hn9vVsOs/8 +ptDR8v7Zk/xIj/sX1SULWHA1m4Z0KvfgPVzFa5vEIYcPLNyhowm63ajrwaR+j/xSWjnKmST nNtaJnxEfFxjEFF6dhZ7cNaIZ2tQCjqMElhSe7JjmVHIxfGKbHJ4tyV9G6wSk++igbWWZNG9 3kZ/4mWpAlAzdStGACmErgfm+zlK3UgKzGWHsiwNB+OFdxmZVXnwCLdRkbvd4vT0PzBrjFOk c55kiQ/DTONVrsniWlttHvaYrlai6IbsUd2krqQcGJJeI4cnHX4pTDcZ2VLowJpDsfV05BV7 WthbUjKgI55iI3ZE5WATelv8dWV8zdLVlWjvYraTxtpSwdkle4wQNntkOdYAsw==
User-Agent Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.6.1
MIME-Version 1.0
Content-Type text/plain; charset=utf-8
Content-Language en-US
Content-Transfer-Encoding 8bit
X-Mailing-List <debian-java@lists.debian.org> archive/latest/21748
List-ID <debian-java.lists.debian.org>
List-URL <https://lists.debian.org/debian-java/>
List-Archive https://lists.debian.org/msgid-search/09c5b205-eb68-bd44-ee13-4b59f255ed2a@debian.org
Approved robomod@news.nic.it
Lines 76
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Cc debian-java@lists.debian.org
X-Original-Date Sun, 26 May 2019 21:47:13 +0200
X-Original-Message-ID <09c5b205-eb68-bd44-ee13-4b59f255ed2a@debian.org>
X-Original-References <4471343c-9b11-c218-2cc4-771170fe0e84@redhat.com> <d7bd9794-cfa3-a766-659b-f90fa8b279d8@apache.org> <4312b8ae-a1e9-7780-d7f5-37a2a7ec768a@redhat.com> <67ac780f-42e1-26cc-a8ed-f26ba091a9a0@apache.org> <a7b71570-a04c-2c48-c1dd-6a0a7a18ab4c@redhat.com> <9fce0f82-810f-a155-d9c2-2de8ddbafbbc@apache.org> <CAP7YuARgoeZs_TAtPwPKmjTCPH+kA2tcOaVdAD6naGJW1COxhg@mail.gmail.com> <110cbc62-6577-b6aa-c487-151a74560593@apache.org> <20190524133947.tfsboprzcs2eaf4m@lark> <CAP7YuARx11MgNC6Hfc_OoYa=ZKQC+1EhtQnYWQDXU9WGbDVxXw@mail.gmail.com>
Xref csiph.com linux.debian.maint.java:11220

Show key headers only | View raw


On 24.05.19 20:29, Martijn Verburg wrote:
> On Fri, 24 May 2019 at 15:40, tony mancill <tmancill@debian.org> wrote:
> 
>> On Thu, May 23, 2019 at 11:58:14PM +0200, Emmanuel Bourg wrote:
>>> Le 23/05/2019 à 19:04, Martijn Verburg a écrit :
>>>
>>>> What was the difficulty in grabbing the 11.0.3+7 tag directly?
>>>
>>> The difficulty is the policy that applies to backported packages. A
>>> package that is backported from the Debian release n+1 to the release n
>>> has to remain upgradable when the system is upgraded. For this to happen
>>> the version backported must rank lower than the version in the next
>>> release. That's why there are weird suffixes appended to the versions of
>>> the backported packages (1.2.3-1~bpo9+1 is lower than 1.2.3-1).
>>>
>>> Currently Debian Buster has openjdk-11/11.0.3+1-1, so it isn't possible
>>> to upload the version 11.0.3+7-1~bpo9+1 to stretch-backports. The only
>>> solutions is to either upgrade openjdk-11 in testing to a version higher
>>> than 11.0.3+7, or patch the existing version. Since testing is currently
>>> frozen and difficult to update until the release of Buster, it leaves
>>> only the patch solution.
>>
>> Emmanuel,
>>
>> It seems like we need to bring this up with the Release and Security
>> teams.  Releasing Buster with mulitple critical open CVEs in the JVM
>> isn't a good experience for our users.  My proposal is that we do what
>> we need to get 11.0.3-ga-1 into Buster.
>>
>> From a versioning standpoint, this should work.  Am I missing something?
>>
>> $ dpkg --compare-versions 11.0.3-ga-1 gt 11.0.3+7-1 && echo "11.0.3-ga-1
>> is newer"
>> 11.0.3-ga-1 is newer

I don't think that playing games with version numbers is a good thing to do.
Version numbers should match the upstream source release, and the binary
packages should not change that version.  Of course openjdk has a split
personality to give even another version when called with java --version

The final 11.0.3 release:
https://mail.openjdk.java.net/pipermail/jdk-updates-dev/2019-April/000951.html

does *not* contain the ea specifier.

> We (AdoptOpenJDK) would really be appreciative of that! We're aiming to get
> consistency amongst all of the OpenJDK providers that 'good known GA'
> versions are deployed to end users.  I can only apologise for not having
> reached out to the Debian community earlier to collaborate.  Appreciate the
> efforts being put in here!

I don't care what AdoptJdk is doing.  In the past, the only activity by AdoptJdk
was trying to promote their builds for inclusion in some Linux distros.
AdoptJdk only supports a subset of the Debian architectures, and we really don't
need yet another IcedTea.

> Is there anything we can do to help going forward?  OpenJDK upstream has a
> pretty good established policy around having the `-ga` suffix added to
> versions it would like downstream to take as a formal release. 

This is a recent addition. Last time I asked on an upstream mailing list,
everybody seemed fine with the versioning:
https://mail.openjdk.java.net/pipermail/jdk-updates-dev/2019-April/000969.html

> Is there
> anything else that OpenJDK can do to help Debian?  One thing that
> AdoptOpenJDK provides is a free test pipeline in it's build farm that could
> happily receive the Debian built binary and put it through 100,000+ tests
> and see if it matches what other OpenJDK providers are broadly producing,
> would that be of interest?

I'm moving that discussion to upstream, but in summary you shouldn't a dozen of
configure options to configure your build from source.  Just release a sane
upstream tarball.

Matthias

Back to linux.debian.maint.java | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: Debian distributions of stable OpenJDK updates Emmanuel Bourg <ebourg@apache.org> - 2019-05-20 12:20 +0200
  Re: Debian distributions of stable OpenJDK updates Emmanuel Bourg <ebourg@apache.org> - 2019-05-20 14:40 +0200
    Re: Debian distributions of stable OpenJDK updates Emmanuel Bourg <ebourg@apache.org> - 2019-05-20 15:10 +0200
      Re: Debian distributions of stable OpenJDK updates tony mancill <tmancill@debian.org> - 2019-05-22 06:20 +0200
        Re: Debian distributions of stable OpenJDK updates Emmanuel Bourg <ebourg@apache.org> - 2019-05-22 12:30 +0200
          Re: Debian distributions of stable OpenJDK updates tony mancill <tmancill@debian.org> - 2019-05-22 16:40 +0200
          Re: Debian distributions of stable OpenJDK updates Matthias Klose <doko@debian.org> - 2019-05-26 22:00 +0200
            Re: Debian distributions of stable OpenJDK updates Emmanuel Bourg <ebourg@apache.org> - 2019-05-27 00:00 +0200
              Re: Debian distributions of stable OpenJDK updates Matthias Klose <doko@debian.org> - 2019-05-27 16:00 +0200
            Re: Debian distributions of stable OpenJDK updates Thorsten Glaser <t.glaser@tarent.de> - 2019-05-27 18:50 +0200
    Re: Debian distributions of stable OpenJDK updates Emmanuel Bourg <ebourg@apache.org> - 2019-05-23 18:00 +0200
      Re: Debian distributions of stable OpenJDK updates Martijn Verburg <martijnverburg@gmail.com> - 2019-05-23 19:10 +0200
        Re: Debian distributions of stable OpenJDK updates Emmanuel Bourg <ebourg@apache.org> - 2019-05-24 00:00 +0200
          Re: Debian distributions of stable OpenJDK updates Thorsten Glaser <t.glaser@tarent.de> - 2019-05-24 00:50 +0200
            Re: Debian distributions of stable OpenJDK updates tony mancill <tmancill@debian.org> - 2019-05-25 18:10 +0200
              Re: Debian distributions of stable OpenJDK updates Emmanuel Bourg <ebourg@apache.org> - 2019-05-27 17:10 +0200
              Re: Debian distributions of stable OpenJDK updates Thorsten Glaser <t.glaser@tarent.de> - 2019-05-27 18:40 +0200
                Re: Debian distributions of stable OpenJDK updates Emmanuel Bourg <ebourg@apache.org> - 2019-05-28 10:40 +0200
                Re: Debian distributions of stable OpenJDK updates Thorsten Glaser <t.glaser@tarent.de> - 2019-05-29 14:20 +0200
                Re: Debian distributions of stable OpenJDK updates Emmanuel Bourg <ebourg@apache.org> - 2019-05-30 00:10 +0200
          Re: Debian distributions of stable OpenJDK updates tony mancill <tmancill@debian.org> - 2019-05-24 15:50 +0200
            Re: Debian distributions of stable OpenJDK updates Martijn Verburg <martijnverburg@gmail.com> - 2019-05-24 20:30 +0200
              Re: Debian distributions of stable OpenJDK updates Matthias Klose <doko@debian.org> - 2019-05-26 21:50 +0200
                Re: Debian distributions of stable OpenJDK updates tony mancill <tmancill@debian.org> - 2019-05-27 00:00 +0200
                Re: Debian distributions of stable OpenJDK updates Matthias Klose <doko@debian.org> - 2019-05-27 16:10 +0200
                Re: Debian distributions of stable OpenJDK updates Thorsten Glaser <t.glaser@tarent.de> - 2019-05-27 18:40 +0200
                debian/watch file for OpenJDK (was Re: Debian distributions of stable  OpenJDK updates) Emmanuel Bourg <ebourg@apache.org> - 2019-05-28 10:30 +0200
                Re: debian/watch file for OpenJDK (was Re: Debian distributions of  stable OpenJDK updates) Paul Wise <pabs@debian.org> - 2019-05-28 11:20 +0200
                Re: debian/watch file for OpenJDK (was Re: Debian distributions of  stable OpenJDK updates) Emmanuel Bourg <ebourg@apache.org> - 2019-05-28 11:30 +0200
                Re: debian/watch file for OpenJDK (was Re: Debian distributions of  stable OpenJDK updates) Tiago Daitx <tiago.daitx@canonical.com> - 2019-05-29 04:10 +0200
                Re: debian/watch file for OpenJDK (was Re: Debian distributions of  stable OpenJDK updates) Tiago Daitx <tiago.daitx@canonical.com> - 2019-05-29 04:20 +0200
                Re: debian/watch file for OpenJDK (was Re: Debian distributions of  stable OpenJDK updates) Thorsten Glaser <t.glaser@tarent.de> - 2019-05-29 14:20 +0200
                Re: debian/watch file for OpenJDK (was Re: Debian distributions of  stable OpenJDK updates) Dalibor Topic <dalibor.topic@oracle.com> - 2019-05-29 16:00 +0200
                Re: Debian distributions of stable OpenJDK updates Emmanuel Bourg <ebourg@apache.org> - 2019-05-30 00:00 +0200
                Re: Debian distributions of stable OpenJDK updates Thorsten Glaser <t.glaser@tarent.de> - 2019-05-30 00:30 +0200
                Re: Debian distributions of stable OpenJDK updates Matthias Klose <doko@debian.org> - 2019-06-10 11:40 +0200
                Re: Debian distributions of stable OpenJDK updates Martijn Verburg <martijnverburg@gmail.com> - 2019-05-27 12:30 +0200

csiph-web