/srv/irclogs.ubuntu.com/2022/08/29/#ubuntu-security.txt

amurrayluis220413: if you happen to see this in channel logs etc - please there is no need to announce every time when you are going to go and come back - IRC is assumed to be asynchronous, Ubuntu developers are all over the globe in different time zones so it is assumed that in general no-one will reply immediately03:44
amurrayluis220413: therefore it is fine if you are not here at the time someone is trying to contact you - so please save some electrons and dispense with the 'I will return...' 'I returned' type messages03:45
Unit193...I just read that last bit in a Dragoon voice. >_>03:47
=== jbicha_ is now known as jbicha
=== ChanServ changed the topic of #ubuntu-security to: Twitter: @ubuntu_sec || https://usn.ubuntu.com || https://wiki.ubuntu.com/SecurityTeam || https://wiki.ubuntu.com/Security/Features || Community: sarnold
=== arif-ali_ is now known as arif-ali
=== arif-ali_ is now known as arif-ali
tewardoh good sarnold is on community duty this week heh16:46
teward[m]sarnold if/when you awake, do me a favor and ping me via PM18:54
teward[m]i have things to discuss ;P18:54
* sarnold hides behind flakey matrix bridges18:58
* teward hides the matrix bridges behind sarnold18:59
tewardoops :)18:59
tewardyou're hiding behind the bridge which is hiding behind you which is.... [KERNEL PANIC] oom tried to kill init.18:59
* sarnold falls over19:00
tomreynnow he's hiding *under* the bridge19:06
tewardhah19:08
sarnold:D19:19
luis220413https://bugs.launchpad.net/%7Eluis220413/+bugs?field.searchtext=&orderby=-importance&field.status%3Alist=NEW&field.status%3Alist=CONFIRMED&field.status%3Alist=TRIAGED&field.status%3Alist=INPROGRESS&field.status%3Alist=FIXCOMMITTED&field.status%3Alist=INCOMPLETE_WITH_RESPONSE&field.status%3Alist=INCOMPLETE_WITHOUT_RESPONSE&field.information_type%3Alist=PUBLICSECURITY&assignee_opti19:25
luis220413We will need to have a workaround for the toolchain requirements in bug 1970783.19:29
ubottuBug 1970783 in webkit2gtk (Ubuntu) "Multiple vulnerabilities in Bionic" [Wishlist, In Progress] https://launchpad.net/bugs/197078319:29
sarnoldhello luis220413, the upstream webkit2gtk folks move toolchains pretty quickly; we can't support it in older releases. see https://wiki.ubuntu.com/SecurityTeam/FAQ#WebKitGTK19:35
tewardluis220413: while you're at it, read the entirety of https://wiki.ubuntu.com/SecurityTeam/FAQ before you ping anyone in here again19:36
tewardsarnold knows all the reasoning behind this request, and likely will stand by the request even though I"m not on the SEcurity Team19:36
tewardEickmeyer: *cough*19:36
Eickmeyer[m]teward: ack19:37
luis220413sarnold: There are only 2 insufficient dependencies in Bionic, that can be backported with new source and binary package names.20:10
luis220413This is not a request, but a statement that I am available to get this fixed.20:12
tewardnew source and binary names are less likely to get included in an already released Ubuntu release as security updates20:13
tewardso for that reason alone I would assume the FAQ statement about the upstream moving too quickly stands20:13
tewardcc sarnold 20:13
tewardyes there are exceptions, and those exceptions are well documented20:14
tewardand i don't think this falls into those exception cases20:14
tewardluis220413: also, when the security team says 'no' and says 'we can't support this in older releases', just accept "no" as the answer20:16
tewardi'll let sarnold make a decision but those're my opinions anyways20:24
luis220413New source and binary names are needed in the security pocket because security updates only build with the release and security pockets enabled.20:31
sarnoldadding new packages is an undertaking; then those new packages must also be maintained, for whatever it is that people do with them. whatever built against the old version of webkit needs to be tested to make sure it works with new versions. Given that upstream has abandoned these old releases, they are perhaps not super-responsive to abi breaks.20:33
sarnoldboth firefox and chromium-browser are supported and exist20:33
luis220413I can maintain the CMake and ICU backports, except that the ICU backport will have to be in main.20:41
luis220413sarnold: What ABI breaks?20:41
luis220413There are security-sensitive uses of libwebkit2gtk-4.0-37 in Bionic:20:43
luis220413* libgoa-backend-1.0-1 uses it to access online account login pages20:43
luis220413* gnome-online-accounts same20:43
sarnoldluis220413: packages in ubuntu are typically maintained by teams: people come, people go, but teams are expected to continue20:44
luis220413* epiphany-browser is a web browser20:44
luis220413sarnold: I know, but I will not go before Bionic end-of-standard-support (April 2023)20:45
luis220413* surf is another web browser20:46
luis220413* libatrilview3 uses WebKit to execute JavaScript in PDFs20:46
luis220413* gthumb has a web album feature that appears to use WebKit20:48
luis220413I will prepare backports (if needed) and an updated webkit2gtk for Bionic soon.20:55
sarnoldI suggest you find a different way to spend your time21:02
sarnoldbringing in two new packages, who need an owner, is no small undertaking21:02
sarnoldthere's got to be something more important to work on21:02
luis220413They will be direct backports from Focal and this is affecting users right now. An alternative would be to state in the package description that support is only guaranteed during the first 3 years of the LTS period.21:10
luis220413Because they are direct backports from Focal, maintaining them would not take a lot of time.21:11
luis220413sarnold: What do you mean by "owner"?21:13
sarnoldluis220413: someone who would read all bug reports, triage them, respond to them, look for fixes, apply fixes, perform testing on all dependent packages, etc, for the next ten years21:14
luis220413These backports will only be needed until the next few months. Once Bionic enters ESM upstream will cease to support Focal.21:17
luis220413*in the next few months21:17
tewardupstream's support period doesn't matter21:17
tewardthe ESM period for Ubuntu does matter though to some extent21:17
tewardbecause it's not EOL until the end of ESM21:17
tewardhence 'eight years' and 'ten years' and such21:18
tewardincluding current LTS + its ESM period21:18
tewardthat's where Seth's values come into play21:19
sarnoldluis220413: heh, is that an argument *for* this work or against this work?21:20
tewardi would argue that your argument that upstream will cease to support Focal after Bionic enters ESM is support for *not* updating packages21:20
tewardjust, you know, my view on this.  (your statement to this effect is like shooting yourself in the foot and NOT in favor of doing the backporting)21:21
luis220413# My argument is for this work. Thomas Ward is right, but once upstream releases a version that requires new dependencies (most likely months after Bionic enters ESM) another backport will be needed.21:21
luis220413Remove the #21:21
luis220413* most likely a few months21:21
luis220413OK, I retire the "few months" statement.21:22
tewardsarnold: remind me, ESM for Bionic starts when?21:23
tewardApril?21:23
sarnoldteward: yeah, currently scheduled for april https://wiki.ubuntu.com/Releases21:24
tewardso about 8 months.  I don't see a justification to put this amount of effort into something that will ultimately become irrelevant in 8 months time.21:25
teward7 months*21:25
luis220413This will only become irrelevant when upstream releases a version with additional dependencies that are not satisfied in Bionic.21:25
luis220413nor by the backports21:25
luis220413OK21:27
luis220413Sorry. This will not become irrelevant because, when additional dependencies appear, additional backports can be made until the end of ESM.21:30
luis220413ESM for 16.04 covers the entirety of Ubuntu main, and I expect that that will also happen for 18.04.21:31
luis220413Source: https://wiki.ubuntu.com/SecurityTeam/ESM/16.0421:31
tewardi don't think you understand the scope for ESM21:31
tewardfrom the FAQ:21:31
tewardESM customers receive security updates for high and critical CVEs (common vulnerabilities and exposures) for the most commonly used server packages in the Ubuntu main archive. 21:31
teward*not* the entire Main archive21:31
tewardthe FAQ link in that link you have points to the FAQ I referenced21:32
tewardreread what https://wiki.ubuntu.com/SecurityTeam/FAQ#Standard_Support says21:32
tewardi'm going to literally quote Seth here:21:32
teward[We] suggest you find a different way to spend your time.  there's got to be something more important to work on.21:32
luis220413Sorry, but I have to say this part of the FAQ is a bit outdated. This is true for Precise and Trusty, but not Xenial.21:32
luis220413*That part of the FAQ is true for Precise and Trusty but not Xenial.21:33
luis220413teward: OK. I will prepare several security updates in the next weeks.21:33
tewardsarnold: my suggestion is ^^ you ignore any of their prods because all of their proddings have led to arguments and CoC violations21:34
tewardyou and the security team*21:34

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!