/srv/irclogs.ubuntu.com/2016/12/01/#ubuntu-motu.txt

wxlhttps://ide.c9.io/wxl/sqawesomesauce XD00:01
tsimonq2wxl: LOL XD00:02
tsimonq2wxl: Pls gimme access00:03
wxltsimonq2: looks like it's too limited to handle lxd. gimme your infos00:12
tsimonq2wxl: Ok, sec00:20
tsimonq2wxl: ssh ubuntu@dev.kubuntu.co.uk -p 220200:29
wxl1s00:30
wxlgotta "go home" first00:30
tsimonq2k00:30
tsimonq2wxl: So how long?00:30
wxltsimonq2: is that a shared container?00:31
tsimonq2wxl: No it's "mine"00:32
tsimonq2Is there a better way to merging new Debian revisions while keeping the Ubuntu delta besides merging the diff from the two Debian revisions into the Ubuntu revision with the delta?01:46
=== alan_g is now known as alan_g|lunch
=== alan_g|lunch is now known as alan_g
=== Pici` is now known as Pici
=== jamespag` is now known as jamespage
YawningHello, how are security issues with Ubuntu universe packages handled?19:34
rbasakYawning: anyone can contribute a security fix, and the security team will review and upload it if it is good. But Canonical do not make any commitment for security updates to packages in universe. Some packages in universe are very well maintained security-wise; some aren't.20:02
YawningWho should I talk to about https://bugs.launchpad.net/ubuntu/+source/bubblewrap/+bug/164373420:09
ubottuLaunchpad bug 1643734 in bubblewrap (Ubuntu) "privilege escalation via ptrace (CVE-2016-8659)" [Undecided,Incomplete]20:09
Yawningthe security team told me "make a deb diff"20:10
Yawningbut I use neither debian, nor ubuntu20:10
YawningI write software the depends on bubblewrap, that I'd like my users to be able to run on ubuntu, but not enough to learn the intracasies of packaging, basically20:11
YawningZesty has a newer package that contains the security fix20:13
rbasakUnfortunately you need to know a little about packaging in order to prepare a security update.20:15
Yawningand I probably need to also use Ubuntu20:15
rbasakThat would be the easiest way, yes. It is possible to do it without Ubuntu but that is non-trivial. You can however easily create a VM or machine container running Ubuntu, so you don't need to reinstall your own machine or anything.20:16
Yawningyeah20:16
YawningIs this documented anywhere?20:16
rbasakThe "debdiff" command produces a debdiff given two source packages. So create a source package with the changes you want to ship to Ubuntu users, and then use "debdiff" to supply what you want changed to the security team.20:16
Yawningah20:17
rbasakCreating a container?20:17
rbasakhttps://www.ubuntu.com/cloud/lxd20:17
Yawningno, I have that, the debdiff part20:17
rbasakOr https://linuxcontainers.org/lxd/getting-started-cli/20:17
Yawningso I can diff the new package in zesty, vs the old vulnerable one in yakkety and be done?20:17
Yawningor is it slightly more involved than that20:18
rbasakSecurity updates should apply *only* the security fix required and no other changes.20:18
Yawningah20:18
Yawningso it's like the debian apprach20:18
Yawningok20:18
rbasakSee https://wiki.ubuntu.com/SecurityTeam/UpdatePreparation for some documentation20:18
YawningOk, thanks, I midht do that if I have time, but no promises20:20
YawningSorry for the dumb questions.20:23

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!