- Package:
- ftp.debian.org
- Source:
- ftp.debian.org
- Submitter:
- Paul Wise
- Date:
- 2021-09-22 04:31:50 UTC
- Severity:
- normal
- Tags:
Please implement changelog/copyright export for the stable-security and oldstable-security suites. For now the PTS will link to the stable and oldstable suites when a package is in stable and stable-security but not in unstable (see #710323).
Hi ftp-masters, Should we extract changelog/copyright again on packages.d.o ? :) As a workaround for users: * view the changes introduced to the last security upload from http://packages.qa.debian.org/$package and search news for the last wheezy-security or squeeze-security upload. * follow vcs link and search for debian/changelog in the right branch
I'm unable to test this out (setting up dak is somewhat intimidating)
but I've taken a look at the source and I think I've found a candidate
solution.
Security uploads are added to the security archive with the
dak/new_securiy_install.py tool. After mirroring to the world the
script config/debian-security/export.sh is run to create the changelog
files and push them to a 'metasdo' server who I can't find any mention
of anywhere else. Presumably this is a counterpart to the metaftpdo
server at metadata.ftp-master.d.o. At any rate tools like aptitude are
looking for changelogs on metadata.ftp-master.d.o for all packages
regardless of the suite so it seems that the world doesn't know about
metasdo.
The code in config/debian-security/export.sh is a copy and paste from
the function changelogs() in config/debian/dinstall.functions. This
function pushes the normal archive changelogs out to the metadata server and I
assume that it works correctly given that changelogs are showing up just fine
there.
In commit 9384026b the changelog() function was changed to use the
static-update-component script instead of the runmirrors (part of
archvsync) script. config/debian-security/export.sh was *not* changed.
I suspect that the easy fix here is a patch like this:
rsync -aHW --delete --delete-after --ignore-errors ${exportdir}/changelogs/. .
- sudo -H -u archvsync /home/archvsync/runmirrors metasdo > ~dak/runmirrors-metadata.log 2>&1 &
+ sudo -H -u staticsync /usr/local/bin/static-update-component metadata.ftp-master.debian.org > ~
}
which updates config/debian-security/export.sh to use the same sync tool
*and server target* as the regular changelogs. I haven't tested it and
don't have the source for the command but if the static-update-component
is just doing an rsync or something like that it should merge the
directory trees and put the security changelogs side-by-side with the
normal ones. If the ftp-masters have a test version of the archive
there you can probably test this out and makes sure that it's not
clobbering the contents of stuff.
Hello,
[..]
I think there is even a problem earlier, as I can't find up to date metadata on
security-master itself.
/srv/security-master.debian.org/export/changelogs
/srv/security.debian.org/rsync/export/changelogs
Then assuming we got up to date metadata on security-master, how to share them ?
We cannot update the metadata.ftp-master.debian.org component as is, with the
local security-master contents, because it would overwrite
ftp-master.debian.org contents.
I see several solutions:
1/ using the same metadata.ftp-master.debian.org component :
* a 1st step rsync, copy metadata from security-master (chopin) to
ftp-master
* then adds them to metadata.ftp-master.debian.org
* then update the static component
2/ have a separate metadata.security-master.debian.org component and virtual
host
Hello, Good morning, We have gone through your samples from a partner and Here is our Order List. Please do bear in mind that we are very much in need of this order, quote your competitive prices. Kindly send the Order confirmation. Your early reply will be much appreciated. Best Regards, Maryanah Erwin. PT FINDORA INTERNUSA Jln Pahlawan 66 Kec. Arjawinangun 45162 CIREBON West-Java INDONESIA tel : +62 231 357334 fax: +62 231 357260 email: marketing@findora.com