Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #237614 > unrolled thread

kernel patch for "FULL FREEZE" branch /testing

Started byMarco Möller <talby@debianlists.mobilxpress.net>
First post2021-07-22 12:30 +0200
Last post2021-07-22 17:10 +0200
Articles 5 — 3 participants

Back to article view | Back to linux.debian.user


Contents

  kernel patch for "FULL FREEZE" branch /testing Marco Möller <talby@debianlists.mobilxpress.net> - 2021-07-22 12:30 +0200
    Re: kernel patch for "FULL FREEZE" branch /testing Tixy <tixy@yxit.co.uk> - 2021-07-22 13:50 +0200
      Re: kernel patch for "FULL FREEZE" branch /testing Marco Möller <talby@debianlists.mobilxpress.net> - 2021-07-22 16:10 +0200
        Re: kernel patch for "FULL FREEZE" branch /testing Tixy <tixy@yxit.co.uk> - 2021-07-22 17:10 +0200
        Re: kernel patch for "FULL FREEZE" branch /testing "Andrew M.A. Cater" <amacater@einval.com> - 2021-07-22 17:10 +0200

#237614 — kernel patch for "FULL FREEZE" branch /testing

FromMarco Möller <talby@debianlists.mobilxpress.net>
Date2021-07-22 12:30 +0200
Subjectkernel patch for "FULL FREEZE" branch /testing
Message-ID<CDE7L-183-5@gated-at.bofh.it>
Hello everyone! The Debian development branch "bullseye"(/testing) is in 
status "full freeze", if I am correctly informed, and packages from 
/unstable are for quite some time already no more automatically moved 
from /unstable to /testing.
Do you know how Debian handles situations like the current 
CVE-2021-33909 patched kernel being already in /unstable but for sure 
also /testing, the soon /stable, would benefit from receiving the patch 
as provided in 5.10.46-2 ?
The patched version I am speaking about is this:
linux-image-5.10.0-8-amd64/unstable 5.10.46-2 amd64
In my "bullseye" installation, which I update daily, I still have
linux-image-5.10.0-7-amd64/testing,now 5.10.40-1 amd64
Best wishes, Marco.

[toc] | [next] | [standalone]


#237617

FromTixy <tixy@yxit.co.uk>
Date2021-07-22 13:50 +0200
Message-ID<CDFnb-1UP-1@gated-at.bofh.it>
In reply to#237614
On Thu, 2021-07-22 at 12:23 +0200, Marco Möller wrote:
> Hello everyone! The Debian development branch "bullseye"(/testing) is in 
> status "full freeze", if I am correctly informed, and packages from 
> /unstable are for quite some time already no more automatically moved 
> from /unstable to /testing.
> Do you know how Debian handles situations like the current 
> CVE-2021-33909 patched kernel being already in /unstable but for sure 
> also /testing, the soon /stable, would benefit from receiving the patch 
> as provided in 5.10.46-2 ?
> The patched version I am speaking about is this:
> linux-image-5.10.0-8-amd64/unstable 5.10.46-2 amd64
> In my "bullseye" installation, which I update daily, I still have
> linux-image-5.10.0-7-amd64/testing,now 5.10.40-1 amd64

5.10.46-2 is now in testing, I've just updated to it.

Presumably the process is as described in full freeze announcement,
i.e. package developer makes unblock request to allow migration into
testing and release team grant it if they think it meets the criteria
for release.

-- 
Tixy

[toc] | [prev] | [next] | [standalone]


#237618

FromMarco Möller <talby@debianlists.mobilxpress.net>
Date2021-07-22 16:10 +0200
Message-ID<CDHyG-3qR-3@gated-at.bofh.it>
In reply to#237617
On 22.07.21 13:49, Tixy wrote:
> On Thu, 2021-07-22 at 12:23 +0200, Marco Möller wrote:
>> Hello everyone! The Debian development branch "bullseye"(/testing) is in
>> status "full freeze", if I am correctly informed, and packages from
>> /unstable are for quite some time already no more automatically moved
>> from /unstable to /testing.
>> Do you know how Debian handles situations like the current
>> CVE-2021-33909 patched kernel being already in /unstable but for sure
>> also /testing, the soon /stable, would benefit from receiving the patch
>> as provided in 5.10.46-2 ?
>> The patched version I am speaking about is this:
>> linux-image-5.10.0-8-amd64/unstable 5.10.46-2 amd64
>> In my "bullseye" installation, which I update daily, I still have
>> linux-image-5.10.0-7-amd64/testing,now 5.10.40-1 amd64
> 
> 5.10.46-2 is now in testing, I've just updated to it.
> 
> Presumably the process is as described in full freeze announcement,
> i.e. package developer makes unblock request to allow migration into
> testing and release team grant it if they think it meets the criteria
> for release.
> 

It meanwhile arrived also in the mirror which I am using. Nice.

So, although it is full freeze time, the former kernel with all its 
already known and tested functionality will not be specially patched, 
but the new kernel is taken although it besides containing the patch 
might also bring changed functionality?
Simply asking for curiosity, not that it would be of further importance 
for me.

[toc] | [prev] | [next] | [standalone]


#237619

FromTixy <tixy@yxit.co.uk>
Date2021-07-22 17:10 +0200
Message-ID<CDIl4-3GQ-1@gated-at.bofh.it>
In reply to#237618
On Thu, 2021-07-22 at 16:00 +0200, Marco Möller wrote:
> So, although it is full freeze time, the former kernel with all its 
> already known and tested functionality will not be specially patched, 
> but the new kernel is taken although it besides containing the patch 
> might also bring changed functionality?
> Simply asking for curiosity, not that it would be of further importance 
> for me.

I have no inside knowledge, but I would speculate that the release team
accept 'extra' package changes if they would normally be part of how
the security team issues fixes for that package in a stable release. 

For highly complex software like the Linux kernel, and web browsers
like Firefox, Debian security releases tend to stick with upstream long
-term-support releases that contain the security fix. It's completely
impractical to maintain a Debian specific fork and patch that.

-- 
Tixy

[toc] | [prev] | [next] | [standalone]


#237620

From"Andrew M.A. Cater" <amacater@einval.com>
Date2021-07-22 17:10 +0200
Message-ID<CDIuJ-3Zp-9@gated-at.bofh.it>
In reply to#237618
On Thu, Jul 22, 2021 at 04:00:26PM +0200, Marco Möller wrote:
> On 22.07.21 13:49, Tixy wrote:
> > On Thu, 2021-07-22 at 12:23 +0200, Marco Möller wrote:
> > > Hello everyone! The Debian development branch "bullseye"(/testing) is in
> > > status "full freeze", if I am correctly informed, and packages from
> > > /unstable are for quite some time already no more automatically moved
> > > from /unstable to /testing.
> > > Do you know how Debian handles situations like the current
> > > CVE-2021-33909 patched kernel being already in /unstable but for sure
> > > also /testing, the soon /stable, would benefit from receiving the patch
> > > as provided in 5.10.46-2 ?
> > > The patched version I am speaking about is this:
> > > linux-image-5.10.0-8-amd64/unstable 5.10.46-2 amd64
> > > In my "bullseye" installation, which I update daily, I still have
> > > linux-image-5.10.0-7-amd64/testing,now 5.10.40-1 amd64
> > 
> > 5.10.46-2 is now in testing, I've just updated to it.
> > 
> > Presumably the process is as described in full freeze announcement,
> > i.e. package developer makes unblock request to allow migration into
> > testing and release team grant it if they think it meets the criteria
> > for release.
> > 
> 
> It meanwhile arrived also in the mirror which I am using. Nice.
> 
> So, although it is full freeze time, the former kernel with all its already
> known and tested functionality will not be specially patched, but the new
> kernel is taken although it besides containing the patch might also bring
> changed functionality?
> Simply asking for curiosity, not that it would be of further importance for
> me.
> 

That's how it works. Normally, unstable -> testing would just migrate. Security fixes to stable would be made in the normal course of events. 

Bullseye / Debian 11 is now in really hard freeze - ready for release very shortly. So security fixes are more or less the only things going in.
Each of them is hand approved so as not to break everything else. The very latest kernel/systemd security update is a big deal - so it got
hand approved very quickly.

In general, any bug fixed package overrides all the files of the previous package: if there's a package foo-1.0.0 and foo1.0.1 is a security fix,
foo1.0.1 wll replace all the previous files from foo1.0.0. There are exceptions, especially where there are modified configuration files: in that
case, there will normally be a question asked sa to whether to update the files or not. In some cases, the new package will leave a sample config 
file (with a dpkg.new extension, I think) in the correct place to be looked at and edited as necessary.

All the very best, as ever,

Andy Cater 

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web