Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #210149 > unrolled thread

Please consider unblocking Chromium and linux packages for Buster

Started byLazar Tadić <lazar.tadic34@gmail.com>
First post2019-06-20 19:00 +0200
Last post2019-06-28 13:10 +0200
Articles 8 — 5 participants

Back to article view | Back to linux.debian.user


Contents

  Please consider unblocking Chromium and linux packages for Buster Lazar Tadić <lazar.tadic34@gmail.com> - 2019-06-20 19:00 +0200
    Re: Please consider unblocking Chromium and linux packages for Buster Étienne Mollier <etienne.mollier@mailoo.org> - 2019-06-20 20:50 +0200
      Re: Please consider unblocking Chromium and linux packages for Buster Greg Wooledge <wooledg@eeg.ccf.org> - 2019-06-20 20:50 +0200
        Re: Please consider unblocking Chromium and linux packages for Buster Étienne Mollier <etienne.mollier@mailoo.org> - 2019-06-20 21:00 +0200
        Re: Please consider unblocking Chromium and linux packages for Buster Sven Joachim <svenjoac@gmx.de> - 2019-06-20 21:40 +0200
    Re: Please consider unblocking Chromium and linux packages for  Buster Lazar Tadić <lazar.tadic34@gmail.com> - 2019-06-20 22:10 +0200
      Re: Please consider unblocking Chromium and linux packages for Buster Étienne Mollier <etienne.mollier@mailoo.org> - 2019-06-20 22:50 +0200
    Re: Please consider unblocking Chromium and linux packages for Buster Michael Fothergill <michael.fothergill@gmail.com> - 2019-06-28 13:10 +0200

#210149 — Please consider unblocking Chromium and linux packages for Buster

FromLazar Tadić <lazar.tadic34@gmail.com>
Date2019-06-20 19:00 +0200
SubjectPlease consider unblocking Chromium and linux packages for Buster
Message-ID<yb8zL-Xk-1@gated-at.bofh.it>
Chromium is currently 2 major and 3 minor versions behind upstream in
both Stretch and Buster. Please consider uploading a recent version to
address 34 open security issues, before the complete freeze on 25th of
June.

Likewise, linux package in Buster lack recent fixes for SACKs
Panic vulnerabilities. I hope it will also be uploaded soon.

Regards,
Lazar

[toc] | [next] | [standalone]


#210155

FromÉtienne Mollier <etienne.mollier@mailoo.org>
Date2019-06-20 20:50 +0200
Message-ID<ybaid-24z-1@gated-at.bofh.it>
In reply to#210149
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 6/20/19 6:40 PM, Lazar Tadić wrote:
> Likewise, linux package in Buster lack recent fixes for SACKs Panic vulnerabilities. I hope it will also be uploaded soon.

Good Day Lazar,

Thank you for your note.  I do /not/ speak for the Debian kernel
team, but an upgrade of Linux fixing these TCP SACK
vulnerabilities are in the pipeline in Debian Sid, in Linux
version 4.19.37-5.  There is an unconditional ten days delay for
introduction of upgrades from Sid to Testing, hence the missing
security upgrade into Debian Buster at t time.  Hopefully it
should land on time for July, the 6th.

Paradoxically, if security is a concern, Sid is preferable over
Testing.  Of course Debian Stable remains the best choice in
that situation, if applications or hardware allow it.

Kind Regards,
- -- 
Étienne Mollier <etienne.mollier@mailoo.org> 59DA 56FE FFF3 882D
-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEEWrFO32O7zP+LVC+pWdpW/v/ziC0FAl0L1FEACgkQWdpW/v/z
iC1lGQwAy1t8i7Tu1N+bgnsR+sLwgXYZ+NhRt7ldXpLGGrFUnBHwyl0SiJBADxli
aDX5dXXhFSMxWFE+Stx2kGXNMLmjs3mtPnYLwAVDfLwl6WWpU8ozbVpYqitROq8f
+7Ze7vSUu1tI8JEREYmx8kfDTNfBDyveM8UTaFQnUQuUZ/aZP7P4PBH8Jv2KKKih
Ihy6gAtYv8Ah2I1rwjO6UtFh+cWsfX0wrDMz6MPmvQCJT7scPW4F45BHHS6q5C5l
7/JMrrmAFBCD394TRzSN5ry1GacQu7ayaorDy7gW7bsJPeS7ZIqTgQUWwQBMy68m
yvauyGWm1lWKKoj5cEQwjFQb0WGasjIFm7J/+Dkd1at81fn3JgjvcgNf2o8zwx14
hCU5po0HlwIowC1SzoM5vQ2zf114voPqkbicxON8AVPaQoFL+vrSWOiKJNey3YAo
Nls/D1Cfzn8eoTznU2qb2IRCVPybGRJizCsQ734MTYhhtZoY/5FPuh9VUmK/6YRf
8/dXXItv
=H05u
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#210158

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2019-06-20 20:50 +0200
Message-ID<ybaie-24z-17@gated-at.bofh.it>
In reply to#210155
On Thu, Jun 20, 2019 at 08:45:51PM +0200, Étienne Mollier wrote:
> There is an unconditional ten days delay for
> introduction of upgrades from Sid to Testing, hence the missing
> security upgrade into Debian Buster at t time.  Hopefully it
> should land on time for July, the 6th.

The delay period is frequently shortened for packages with high urgency.
"Unconditional ten days" is quite false.

However, this is also complicated by the current freeze state of buster.
Packages are not flowing by the normal rules right now.  Expect everything
to be a lot more manual.

[toc] | [prev] | [next] | [standalone]


#210160

FromÉtienne Mollier <etienne.mollier@mailoo.org>
Date2019-06-20 21:00 +0200
Message-ID<ybarT-28p-3@gated-at.bofh.it>
In reply to#210158
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 6/20/19 8:48 PM, Greg Wooledge wrote:
> On Thu, Jun 20, 2019 at 08:45:51PM +0200, Étienne Mollier wrote:
>> There is an unconditional ten days delay for introduction of upgrades from Sid to Testing, hence the missing security upgrade into Debian Buster at t time.  Hopefully it should land on time for July, the 6th.
> The delay period is frequently shortened for packages with high urgency. "Unconditional ten days" is quite false.

I completely missed that...  Thank you Greg!  :)
- -- 
Étienne Mollier <etienne.mollier@mailoo.org> 59DA 56FE FFF3 882D
-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEEWrFO32O7zP+LVC+pWdpW/v/ziC0FAl0L1eAACgkQWdpW/v/z
iC3DFQwAi2xBm2jj1i7ukHuvco/xCqWuPnWoKVn9yU+D8k0Fm5ksvVItF603LtNS
2xLVfmFmjg5r6ATJXxFH3KnU+6niV89ArArFovLUd3fJcrqoYBcYeRmbgLmhl7b3
Hre7JlIgi+YRtDv8RxTIEiNnaNpcJt7/UrCpwwcHN9dmUXqLFF2MfDU9mhYVlgS1
ECwGQuMeA5Nh/msdWJ7E5chzKpgJtphZsLWV5zCrqGEgB5Xl9CtdUrypT+dALrJM
pSqnDP5Yp/NqOGqJWCtO8YHbwc1xWlxNijtxYlCUvc9siGSW6DHqyRFnOROXiEVY
Zpt/6MTgb9el6G6HM9HemDBZ+oo5phtflMb0NwM0KKO1r4WesoL36JnUR2+9ZOrF
NOOfGL/VIvBIJXrpapuc+WgWFPtdviA30unns7gZ6y9ZfHCAO5PQYTpqsAZ5Fjzn
wz49/EUoMD51u69Y+BS/mZdJrJnKWneqRybcVevtYp8HNQ6LnS5I4cM9nOX7GV7g
D6zCY8yM
=C0hr
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#210164

FromSven Joachim <svenjoac@gmx.de>
Date2019-06-20 21:40 +0200
Message-ID<ybb4B-2Bq-1@gated-at.bofh.it>
In reply to#210158
On 2019-06-20 14:48 -0400, Greg Wooledge wrote:

> On Thu, Jun 20, 2019 at 08:45:51PM +0200, Étienne Mollier wrote:
>> There is an unconditional ten days delay for
>> introduction of upgrades from Sid to Testing, hence the missing
>> security upgrade into Debian Buster at t time.  Hopefully it
>> should land on time for July, the 6th.
>
> The delay period is frequently shortened for packages with high urgency.

It is also frequently prolonged for packages which FTBFS on some
architecture or which are entangled in a library transition.

> "Unconditional ten days" is quite false.

For packages with high urgency it is usually two days if everything
works fine, but it can easily be two months or longer.  For security
critical packages like web browsers I would always recommend getting a
newer version from unstable or from stable-security ASAP.

Cheers,
       Sven

[toc] | [prev] | [next] | [standalone]


#210168 — Re: Please consider unblocking Chromium and linux packages for Buster

FromLazar Tadić <lazar.tadic34@gmail.com>
Date2019-06-20 22:10 +0200
SubjectRe: Please consider unblocking Chromium and linux packages for Buster
Message-ID<ybbxD-31o-1@gated-at.bofh.it>
In reply to#210149
> Thank you for your note.  I do /not/ speak for the Debian kernel
> team, but an upgrade of Linux fixing these TCP SACK
> vulnerabilities are in the pipeline in Debian Sid, in Linux
> version 4.19.37-5.  There is an unconditional ten days delay for
> introduction of upgrades from Sid to Testing,

> The delay period is frequently shortened for packages with high
> urgency.
> "Unconditional ten days" is quite false.
> 

Thank you both for your replies. Indeed, the delay for important
packages like linux is shorter, especially if the fix is urgent.
I know that the work devs do is voluntary and I'm certain they do their
best.
I'll wait for the fixes to arrive in Buster naturally. I just don't
want to use Chrome. It is enough that I'm using Google's services :)

Oh, and please excuse me for my poor use of these mailing lists, I'm
new here.

Regards,
Lazar

[toc] | [prev] | [next] | [standalone]


#210170

FromÉtienne Mollier <etienne.mollier@mailoo.org>
Date2019-06-20 22:50 +0200
Message-ID<ybcal-3eT-9@gated-at.bofh.it>
In reply to#210168

[Multipart message — attachments visible in raw view] — view raw

> Oh, and please excuse me for my poor use of these mailing
> lists, I'm new here.

I apologize myself if I've make you feel a bit uncomfortable.
I'm not a native English speaker, and sometimes my wording may
happen to be a little bit stronger than first intended, but I
try to watch my tongue.  Blame the language quality in English
movies!  :D

Security issues are enough of a concern to be welcome anyway,
perhaps you can have a look at the following page, should you
need to contact Debian Security team at some point:

	https://www.debian.org/security/faq

I should have read this myself earlier: I found the two days
mentioned by Greg in one of the entries relative to Testing.  :)

Kind Regards,
-- 
Étienne Mollier <etienne.mollier@mailoo.org> 59DA 56FE FFF3 882D


[toc] | [prev] | [next] | [standalone]


#210454

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2019-06-28 13:10 +0200
Message-ID<ydWVr-2YD-5@gated-at.bofh.it>
In reply to#210149

[Multipart message — attachments visible in raw view] — view raw

On Thu, 20 Jun 2019 at 17:57, Lazar Tadić <lazar.tadic34@gmail.com> wrote:

> Chromium is currently 2 major and 3 minor versions behind upstream in
> both Stretch and Buster. Please consider uploading a recent version to
> address 34 open security issues, before the complete freeze on 25th of
> June.
>

I have recently installed gentoo prefix within my debian buster OS  on my
kaveri box.

I installed chromium 76:

mikef@fart:~/gentoo/etc/portage$ equery l chromium
 * Searching for chromium ...
[IP-] [  ] www-client/chromium-76.0.3809.36:0
mikef@fart:~/gentoo/etc/portage$

It does take some effort install gentoo prefix on debian.  But I have
figured out how to do it with the help of the gentoo prefix dev team.
I am grateful to them.

Cheers

Michael Fothergill

>
> Likewise, linux package in Buster lack recent fixes for SACKs
> Panic vulnerabilities. I hope it will also be uploaded soon.
>
> Regards,
> Lazar
>
>

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web