#1033492 unblock: php8.2/8.2.4-1 ????

#1033492#5
Date:
2023-03-26 06:11:32 UTC
From:
To:
Dear Ondřej,

I just noticed that security bug 1031368 is fixed in unstable was fixed
in php8.2 version 8.2.3-1. That didn't migrate to testing because we're
in the freeze [1], you didn't request an unblock and (to be honest) I
deferred when I looked a while back because it involves a new upstream
release. New upstream versions are in principle against the freeze
policy unless it's a targeted-fix-only release. From a quick look at the
upstream NEWS file, that could very well be the case, can you confirm
that? I'd like you to provide us the usual information we use in the
unblock process so I have added the reportbug template below as an aid;
the biggest question I have is: can you point us at the upstream policy
that explains what goes into their stable releases?

php8.2 is a key package.

Paul

[1] https://release.debian.org/testing/freeze_policy.html#hard

Please unblock package php8.2

(Please provide enough (but not too much) information to help
the release team to judge the request efficiently. E.g. by
filling in the sections below.)

[ Reason ]
(Explain what the reason for the unblock request is.)

[ Impact ]
(What is the impact for the user if the unblock isn't granted?)

[ Tests ]
(What automated or manual tests cover the affected code?)

[ Risks ]
(Discussion of the risks involved. E.g. code is trivial or
complex, key package vs leaf package, alternatives available.)

[ Checklist ]
   [ ] all changes are documented in the d/changelog
   [ ] I reviewed all changes and I approve them
   [ ] attach debdiff against the package in testing

[ Other info ]
(Anything else the release team should know.)

unblock php8.2/8.2.4-1

#1033492#12
Date:
2023-03-26 06:36:26 UTC
From:
To:
Paul,

just a quick reply - PHP already has a security (and if I remember correctly release) team exception from the last time. So, we already had this talk about upstream policies.

I’m happy to fill the template though when it’s not Sunday.

Ondrej
--
Ondřej Surý <ondrej@sury.org> (He/Him)

#1033492#17
Date:
2023-03-26 11:40:10 UTC
From:
To:
Hi Ondřej,

I *suspect* the same, but because of the shear amount of work ongoing
for the release team at the moment, I hope people can help point to the
relevant information instead of us needing to find it.

It can obviously wait a couple of days, we're not *that* close to
releasing yet.

Paul

#1033492#22
Date:
2023-03-28 18:46:26 UTC
From:
To:
Hi Paul,

if this helps on the decision: We would, similarly as done for
bullseye already, want to follow the upstream releases until supported
by upstream and then switch to cherry-pick security fixes only on top.

Ondrej can give a more detailed input, so please wait for his reply.

Regards,
Salvatore

#1033492#27
Date:
2023-03-31 17:36:24 UTC
From:
To:
Unblocked.
#1033492#32
Date:
2023-04-04 06:58:37 UTC
From:
To:
Hi Paul, Salvatore,

I've finally got some time here.

In all honesty, I thought that the pre-negotiated exception for PHP
does apply to all future Debian releases, so it did come as surprise
that I have to explain this again.

The quality of PHP in Debian has increased since we started using
upstream versions to fix security bugs.

The basic release policy is described here:
https://www.php.net/supported-versions.php

Upstream makes a new release every four weeks (https://www.php.net/ChangeLog-8.php#8.2.4), but we generally only update to the releases that contain security fixes, and I don't use PU process to lighten the strain on the release team.

Apart from the upstream release process, all the PHP releases are regularly tested via external repositories that I maintain, so even the intermediate releases are thoroughly tested by hundreds of thousands or more - the Debian repository has 5+ TB of traffic and 150M+ hits; I have no statistics from the deployment, but any breakages are very quickly reported.

When the upstream security support ceases, I generally use Remi Collet's php-security repository to pull the security fixes for the last upstream release, as he's usually swift in preparing those.

Unblocking the latest php8.2 (8.2.4-1 and 8.2.5-1 next week) would be appreciated so the next Debian stable releases with the current PHP version.

Cheers,
Ondrej

On Tue, Mar 28, 2023, at 20:46, Salvatore Bonaccorso wrote:
Hi Paul,

if this helps on the decision: We would, similarly as done for
bullseye already, want to follow the upstream releases until supported
by upstream and then switch to cherry-pick security fixes only on top.

Ondrej can give a more detailed input, so please wait for his reply.

Regards,
Salvatore

#1033492#37
Date:
2023-04-04 18:07:54 UTC
From:
To:
Am Tue, Apr 04, 2023 at 08:58:37AM +0200 schrieb Ondřej Surý:
If we would add the list of source packages which are following micro releases
in stable-security to a machine-parseable list (e.g. somewhere in the
Security Tracker repo), would that be useful to enhance release
management tooling (e.g. by automatically annotating unblock requests
or similar?)

Cheers,
        Moritz

#1033492#42
Date:
2023-04-04 19:14:36 UTC
From:
To:
Hi Ondřej, Moritz,
log, as there's not many things "pre-negotiated". My memory isn't great.
If you would have pointed me at the earlier discussion, all would have
been well I assume.

Anyways, Sebastian already unblocked on 31 Mar when he closed this bug.

On 04-04-2023 20:07, Moritz Mühlenhoff wrote:
 > If we would add the list of source packages which are following micro
releases
 > in stable-security to a machine-parseable list (e.g. somewhere in the
 > Security Tracker repo), would that be useful to enhance release
 > management tooling (e.g. by automatically annotating unblock requests
 > or similar?)

Do you have any idea how many packages are in that set. Yes if that were
public that would help. In this case, I only created the unblock bug
myself to have a place for this discussion, because I noticed RC bugs
fixed in unstable in a key package (which was thus blocked). As the
upload had much more than the RC bug fix, I was unsure what to due,
hence the question. *I* normally use udd bug views [1,2] to do my
regular checking, so if we can get this information in udd, at least in
*my* workflow it could be included.

Paul

[1] https://udd.debian.org/dev/cgi-bin/rcblog7.cgi (top paragraph
linking "blocked (freeze)" to [2])
[2]
https://udd.debian.org/dev/bugs.cgi?merged=ign&rc=1&format=html&release=bookworm_not_sid&mig-ready=ign&mig-blocked=only&keypackages=only&cpopcon=1&chints=1&ckeypackage=1&ctags=1&cdeferred=1&caffected=1&cmissingbuilds=1&clastupload=1&crttags=1&cautormtime=1&cwhykey=1&cbritney=1&sortby=last_modified&sorto=asc&#results

#1033492#47
Date:
2023-04-04 19:44:08 UTC
From:
To:
No need to apologise, we all do what we can. If there's anything I can do to help with the load, I am happy to do whatever I would have energy and time for. (I don't want to promise unicorns and rainbows :)).

On my side it's src:bind9 for both buster and bookworm and src:php7.4 for buster and src:php8.2 for bookworm.

Ondrej
--
Ondřej Surý (He/Him)
ondrej@sury.org

#1033492#52
Date:
2023-04-04 21:19:49 UTC
From:
To:
Am Tue, Apr 04, 2023 at 09:14:36PM +0200 schrieb Paul Gevers:

My gut feeling is "less than 20", I'll try to compile a list in the next days.

Cheers,
        Moritz