- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Paul Gevers
- Date:
- 2023-04-04 21:21:03 UTC
- Severity:
- normal
- Tags:
Dear Ondřej, I just noticed that security bug 1031368 is fixed in unstable was fixed in php8.2 version 8.2.3-1. That didn't migrate to testing because we're in the freeze [1], you didn't request an unblock and (to be honest) I deferred when I looked a while back because it involves a new upstream release. New upstream versions are in principle against the freeze policy unless it's a targeted-fix-only release. From a quick look at the upstream NEWS file, that could very well be the case, can you confirm that? I'd like you to provide us the usual information we use in the unblock process so I have added the reportbug template below as an aid; the biggest question I have is: can you point us at the upstream policy that explains what goes into their stable releases? php8.2 is a key package. Paul [1] https://release.debian.org/testing/freeze_policy.html#hard Please unblock package php8.2 (Please provide enough (but not too much) information to help the release team to judge the request efficiently. E.g. by filling in the sections below.) [ Reason ] (Explain what the reason for the unblock request is.) [ Impact ] (What is the impact for the user if the unblock isn't granted?) [ Tests ] (What automated or manual tests cover the affected code?) [ Risks ] (Discussion of the risks involved. E.g. code is trivial or complex, key package vs leaf package, alternatives available.) [ Checklist ] [ ] all changes are documented in the d/changelog [ ] I reviewed all changes and I approve them [ ] attach debdiff against the package in testing [ Other info ] (Anything else the release team should know.) unblock php8.2/8.2.4-1
Paul, just a quick reply - PHP already has a security (and if I remember correctly release) team exception from the last time. So, we already had this talk about upstream policies. I’m happy to fill the template though when it’s not Sunday. Ondrej -- Ondřej Surý <ondrej@sury.org> (He/Him)
Hi Ondřej, I *suspect* the same, but because of the shear amount of work ongoing for the release team at the moment, I hope people can help point to the relevant information instead of us needing to find it. It can obviously wait a couple of days, we're not *that* close to releasing yet. Paul
Hi Paul, if this helps on the decision: We would, similarly as done for bullseye already, want to follow the upstream releases until supported by upstream and then switch to cherry-pick security fixes only on top. Ondrej can give a more detailed input, so please wait for his reply. Regards, Salvatore
Unblocked.
Hi Paul, Salvatore, I've finally got some time here. In all honesty, I thought that the pre-negotiated exception for PHP does apply to all future Debian releases, so it did come as surprise that I have to explain this again. The quality of PHP in Debian has increased since we started using upstream versions to fix security bugs. The basic release policy is described here: https://www.php.net/supported-versions.php Upstream makes a new release every four weeks (https://www.php.net/ChangeLog-8.php#8.2.4), but we generally only update to the releases that contain security fixes, and I don't use PU process to lighten the strain on the release team. Apart from the upstream release process, all the PHP releases are regularly tested via external repositories that I maintain, so even the intermediate releases are thoroughly tested by hundreds of thousands or more - the Debian repository has 5+ TB of traffic and 150M+ hits; I have no statistics from the deployment, but any breakages are very quickly reported. When the upstream security support ceases, I generally use Remi Collet's php-security repository to pull the security fixes for the last upstream release, as he's usually swift in preparing those. Unblocking the latest php8.2 (8.2.4-1 and 8.2.5-1 next week) would be appreciated so the next Debian stable releases with the current PHP version. Cheers, Ondrej On Tue, Mar 28, 2023, at 20:46, Salvatore Bonaccorso wrote: Hi Paul, if this helps on the decision: We would, similarly as done for bullseye already, want to follow the upstream releases until supported by upstream and then switch to cherry-pick security fixes only on top. Ondrej can give a more detailed input, so please wait for his reply. Regards, Salvatore
Am Tue, Apr 04, 2023 at 08:58:37AM +0200 schrieb Ondřej Surý:
If we would add the list of source packages which are following micro releases
in stable-security to a machine-parseable list (e.g. somewhere in the
Security Tracker repo), would that be useful to enhance release
management tooling (e.g. by automatically annotating unblock requests
or similar?)
Cheers,
Moritz
Hi Ondřej, Moritz, log, as there's not many things "pre-negotiated". My memory isn't great. If you would have pointed me at the earlier discussion, all would have been well I assume. Anyways, Sebastian already unblocked on 31 Mar when he closed this bug. On 04-04-2023 20:07, Moritz Mühlenhoff wrote: > If we would add the list of source packages which are following micro releases > in stable-security to a machine-parseable list (e.g. somewhere in the > Security Tracker repo), would that be useful to enhance release > management tooling (e.g. by automatically annotating unblock requests > or similar?) Do you have any idea how many packages are in that set. Yes if that were public that would help. In this case, I only created the unblock bug myself to have a place for this discussion, because I noticed RC bugs fixed in unstable in a key package (which was thus blocked). As the upload had much more than the RC bug fix, I was unsure what to due, hence the question. *I* normally use udd bug views [1,2] to do my regular checking, so if we can get this information in udd, at least in *my* workflow it could be included. Paul [1] https://udd.debian.org/dev/cgi-bin/rcblog7.cgi (top paragraph linking "blocked (freeze)" to [2]) [2] https://udd.debian.org/dev/bugs.cgi?merged=ign&rc=1&format=html&release=bookworm_not_sid&mig-ready=ign&mig-blocked=only&keypackages=only&cpopcon=1&chints=1&ckeypackage=1&ctags=1&cdeferred=1&caffected=1&cmissingbuilds=1&clastupload=1&crttags=1&cautormtime=1&cwhykey=1&cbritney=1&sortby=last_modified&sorto=ascresults
No need to apologise, we all do what we can. If there's anything I can do to help with the load, I am happy to do whatever I would have energy and time for. (I don't want to promise unicorns and rainbows :)). On my side it's src:bind9 for both buster and bookworm and src:php7.4 for buster and src:php8.2 for bookworm. Ondrej -- Ondřej Surý (He/Him) ondrej@sury.org
Am Tue, Apr 04, 2023 at 09:14:36PM +0200 schrieb Paul Gevers:
My gut feeling is "less than 20", I'll try to compile a list in the next days.
Cheers,
Moritz