/srv/irclogs.ubuntu.com/2022/07/13/#ubuntu-security.txt

luis220413I am available now.05:08
luis220413Please review my updates.05:08
luis220413Please review the security update in bug 1970507.05:12
ubottuBug 1970507 in xen (Ubuntu) "No security updates since release in all Ubuntu releases" [Medium, Fix Committed] https://launchpad.net/bugs/197050705:12
luis220413Please review the SRUs in bug 1970779, bug 1978555 and bug 1978891.05:12
ubottuBug 1970779 in wpewebkit (Ubuntu) "Upgrade to 2.36.4 for Focal, Impish and Jammy" [Medium, New] https://launchpad.net/bugs/197077905:12
ubottuBug 1978555 in spip (Ubuntu) "New upstream maintenance and security releases for Focal and Jammy" [Medium, New] https://launchpad.net/bugs/197855505:12
ubottuBug 1978891 in xen (Debian) "Upgrade to 4.16.1+32-g2e82446cb2 for Jammy" [Unknown, Confirmed] https://launchpad.net/bugs/197889105:12
luis220413And bug 1980873 (not packaged by me)05:15
ubottuBug 1980873 in chromium-browser (Ubuntu) "New release 103.0.5060.53 for Bionic" [High, Fix Committed] https://launchpad.net/bugs/198087305:15
luis220413sbeattie: ^05:18
=== luis220413_ is now known as luis220413
luis220413I am unavailable until 11:00 UTC and may be so until 12:00 UTC.06:58
luis220413amurray: Please review my updates.12:01
luis220413I am available now.12:01
luis220413georgiag: Please review my updates.12:11
ebarrettoluis220413, I will be adding comments to your launchpad tickets today. Please note that SRUs are not the security team responsibility to review them or to notify the SRU team.12:52
luis220413ebarretto: Specifically, I want you to review bug 1970507, bug 1970779, bug 1978555, bug 1978891 and bug 1980873. The updated package in the last one was not made by me.13:12
ubottuBug 1970507 in xen (Ubuntu) "No security updates since release in all Ubuntu releases" [Medium, Fix Committed] https://launchpad.net/bugs/197050713:12
ubottuBug 1970779 in wpewebkit (Ubuntu) "Upgrade to 2.36.4 for Focal, Impish and Jammy" [Medium, New] https://launchpad.net/bugs/197077913:12
ubottuBug 1978555 in spip (Ubuntu) "New upstream maintenance and security releases for Focal and Jammy" [Medium, New] https://launchpad.net/bugs/197855513:12
ubottuBug 1978891 in xen (Debian) "Upgrade to 4.16.1+32-g2e82446cb2 for Jammy" [Unknown, Confirmed] https://launchpad.net/bugs/197889113:12
ubottuBug 1980873 in chromium-browser (Ubuntu) "New release 103.0.5060.53 for Bionic" [High, Fix Committed] https://launchpad.net/bugs/198087313:12
ebarrettoluis220413, spip for focal and jammy is an SRU 13:15
ebarrettoI think we already discussed about this one 13:15
luis220413I know. Ignore all but 1970779 (that should be a security update) and 198087313:15
luis220413And 197050713:15
ebarrettoagain, I will be adding comments, I won't be sponsoring those. I'm just reviewing everything so we assign people to it 13:16
luis220413I just converted 1970779 into a security update given comment #18 (by Marc Deslauriers)13:17
ebarrettoluis220413, regarding #1970507 I can't see a debdiff there 13:20
ebarrettonot sure if LP is misbehaving 13:21
ebarrettocould you please attach the debdiff(s)? 13:21
luis220413ebarretto: I will upload one now. It includes the fixes from the version in the unapproved queue.13:22
luis220413LP is not misbehaving.13:22
luis220413The debdiff has been attached 1 minute ago.13:23
ebarrettoluis220413, please add also information on how to test the package/cves 13:23
luis220413ebarretto: Done. I can perform the part of the testing that does not involve private exploits.13:26
luis220413The Ubuntu Security Team may have access to private exploits.13:26
ebarrettoluis220413, thanks! 13:30
ebarrettoluis220413, regarding https://bugs.launchpad.net/ubuntu/+source/wpewebkit/+bug/1970779  could you also upload a debdiff? I checked your ppa and I see build failures, are you currently working on fixing those? 13:39
ubottuLaunchpad bug 1970779 in wpewebkit (Ubuntu Jammy) "Upgrade to 2.36.4 for Focal, Impish and Jammy" [Undecided, New]13:39
luis220413ebarretto: Please download the source packages from https://launchpad.net/~luis220413/+archive/ubuntu/security-updates/+packages. I asked a question about Launchpad itself on Launchpad regarding the build failures because they do not have logs.13:40
luis220413I tried to upload the debdiffs but they were too large (around 200 MB).13:41
ebarrettoluis220413, 200mb debdiffs are really hard to sponsor and validate 13:43
luis220413When I completed the patched packages I tried to upload the debdiffs several times but encountered timeout errors due to the size of the debdiffs (around 100-200 MB), and filed a bug on Launchpad itself (that was marked as Won't Fix) as described in 1970779.13:43
luis220413ebarretto: A debdiff only with the security fixes would not fix compatibility issues with current websites. Many current websites only support the latest versions of browsers.13:43
ebarrettoluis220413, but still a large debdiff like that can introduce many regressions, ABI and API incompatiblity. Causing more issues than gains 13:45
luis220413ebarretto: See comment #18 in the bug. The wpewebkit 2.x series have stable ABI and API.13:47
ebarrettoluis220413, we still need to validate that in the debdiff has every piece of code needed, and nothing is missing. And that's not trivial in a 200mb debdiff 13:48
ebarrettoluis220413, your build should at least pass in all architectures before we continue this sponsoring13:48
ebarrettocould you please investigate it?13:48
luis220413I believe that should be investigated by the Launchpad team. I will upload a new version now. From the times of the previous builds of this package, the builds will take 1 to 10 hours.13:51
ebarrettoluis220413, if it fails again let me know and I can ask the launchpad team to take a look 13:52
luis220413ebarretto: I will skip Impish because it will reach end-of-life tomorrow.13:54
ebarrettoluis220413, yes, please skip it13:54
luis220413ebarretto: Regarding the debdiffs you can ignore the upstream changes and only consider the changes in the Debian packaging tarball.14:00
luis220413ebarretto: The new packages are building in my PPA14:03
luis220413ebarretto: Next is bug 198087314:09
ubottuBug 1980873 in chromium-browser (Ubuntu) "New release 103.0.5060.53 for Bionic" [High, Fix Committed] https://launchpad.net/bugs/198087314:09
ebarrettoluis220413, thanks, I will try to keep a look at it, but feel free to let me know if it fails again and there's no log, so I can ask launchpad team's help14:09
ebarrettoluis220413, 1980873 is already assigned to one of our colleagues, it will get done in the next days/weeks14:18
=== stoned is now known as Hash
=== wbrawner9 is now known as wbrawner
=== luis220413_ is now known as luis220413

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!