apt-get install debian-wizard

Insider infos, master your Debian/Ubuntu distribution

  • About
    • About this blog
    • About me
    • My free software history
  • Support my work
  • Get the newsletter
  • More stuff
    • Support Debian Contributors
    • Other sites
      • My company
      • French Blog about Free Software
      • Personal Website (French)
  • Mastering Debian
  • Contributing 101
  • Packaging Tutorials
You are here: Home / Archives for News

My Free Software Activities in June 2017

July 4, 2017 by Raphaël Hertzog

My monthly report covers a large part of what I have been doing in the free software world. I write it for my donors (thanks to them!) but also for the wider Debian community because it can give ideas to newcomers and it’s one of the best ways to find volunteers to work with me on projects that matter to me.

Debian LTS

I was allocated 12 hours to work on security updates for Debian 7 Wheezy. During this time I did the following:

  • Released DLA-983-1 and DLA-984-1 on tiff3/tiff to fix 4 CVE. I also updated our patch set to get back in sync with upstream since we had our own patches for a while and upstream ended up using a slightly different approach. I checked that the upstream fix did really fix the issues with the reproducer files that were available to us.
  • Handled CVE triage for a whole week.
  • Released DLA-1006-1 on libarchive (2 CVE fixed by Markus Koschany, one by me).

Debian packaging

Django. A last-minute update to Django in stretch before the release, I uploaded python-django 1:1.10.7-2 fixing two bugs (among which one was release critical) and filed the corresponding unblock request.

schroot. I tried to prepare another last-minute update, this time for schroot. The goal was to fix the bash completion (#855283) and a problem encountered by the Debian sysadmins (#835104). Those issues are fixed in unstable/testing but my unblock request got turned into a post-release stretch update because the release managers wanted to give the package some more testing time in unstable. Even now, they are wondering whether they should accept the new systemd service file.

live-build, live-config and live-boot. On live-build, I merged a patch to add a keyboard shortcut for the advanced option menu entry (#864386). For live-config, I uploaded version 5.20170623 to fix a broken boot sequence when you have multiple partitions (#827665). For live-boot, I uploaded version 1:20170623 to fix the path to udevadm (#852570) and avoiding a file duplication in the initrd (864385).

zim. I packaged a release candidate (0.67~rc2) in Debian Experimental and started to use it. I quickly discovered two annoying regressions that I reported upstream (here and here).

logidee-tools. This is a package I authored a long time ago and that I’m no longer actively using. It does still work but I sometimes wonder if it still has real users. Anyway I wanted to quickly replace the broken dependency on pgf but I ended up converting the Subversion repository to Git and I also added autopkgtests. At least those tests will inform me when the package no longer works… otherwise I would not notice since I’m no longer using it.

Bugs filed. I filed #865531 on lintian because the new check testsuite-autopkgtest-missing is giving some bad advice and probably does its check in a bad way. I also filed #865541 on sbuild because sbuild --apt-distupgrade can under some circumstances remove build-essential and break the build chroot. I filed an upstream ticket on publican to forward the request I received in #864648.

Sponsorship. I sponsored a jessie update for php-tcpdf (#814030) and dolibarr 5.0.4+dfsg3-1 for unstable. I sponsored many other packages, but all in the context of the pkg-security team.

pkg-security work

Now that the Stretch freeze is over, the team became more active again and I have been overwhelmed with the number of packages to review and sponsor:

  • knocker
  • recon-ng
  • dsniff
  • libnids
  • rfdump
  • snoopy
  • dirb
  • wcc
  • arpwatch
  • dhcpig
  • backdoor-factory

I also updated hashcat to a new upstream release (3.6.0) and had to discuss with upstream about its weird versioning change. Looks like we will have to introduce an epoch to be able to get back in sync with upstream. 🙁 To be able to get in sync with Kali, I introduced an hashcat-meta source package (in contrib) providing hashcat-nvidia to make it easy to install hashcat for owners of NVidia hardware.

Misc stuff

Distro Tracker. I merged a small CSS fix from Aurélien Couderc (#858101) and added a missing constraint on the data model (found through an unexpected traceback that I received by email). I also updated the list of repositories shortly after the stretch release (#865070).

Salt formulas. As part of my Kali work, I did setup a build daemon on Debian stretch host and I encountered a couple of issues with my Salt rules. I reported one against salt-formula (here) and I pushed updates for debootstrap-formula, apache-formula and schroot-formula.

Thanks

See you next month for a new summary of my activities.

Freexian’s report about Debian Long Term Support, May 2017

June 13, 2017 by Raphaël Hertzog

A Debian LTS logoLike each month, here comes a report about the work of paid contributors to Debian LTS.

Individual reports

In May, about 182 work hours have been dispatched among 11 paid contributors. Their reports are available:

  • Ben Hutchings did 13 hours (out of 15h allocated + 3 extra hours, thus keeping 5 extra hours for June).
  • Brian May did 10 hours.
  • Chris Lamb did 18 hours.
  • Emilio Pozuelo Monfort did 23 hours (out of 24 hours allocated + 2 hours remaining, thus keeping 3 hours for June).
  • Guido Günther did 8 hours.
  • Hugo Lefeuvre did 15 hours.
  • Jonas Meurer gave back his remaining hours from last month.
  • Markus Koschany did 27.25 hours.
  • Ola Lundqvist did 12 hours (out of 6h allocated + 6 remaining hours).
  • Raphaël Hertzog did 12 hours.
  • Roberto C. Sanchez did 22 hours (out of 20 hours allocated + 4.5 hour remaining, thus keeping 2.5 extra hours for June).
  • Thorsten Alteholz did 27.25 hours.

Evolution of the situation

The number of sponsored hours did not change and we are thus still a little behind our objective.

The security tracker currently lists 44 packages with a known CVE and the dla-needed.txt file 42. The number of open issues is close to last month.

Thanks to our sponsors

New sponsors are in bold (none this month unfortunately).

  • Platinum sponsors:
    • TOSHIBA (for 20 months)
    • GitHub (for 11 months)
  • Gold sponsors:
    • The Positive Internet (for 36 months)
    • Blablacar (for 35 months)
    • Linode (for 25 months)
    • Babiel GmbH (for 14 months)
    • Plat’Home (for 14 months)
  • Silver sponsors:
    • Domeneshop AS (for 35 months)
    • Université Lille 3 (for 35 months)
    • Trollweb Solutions (for 33 months)
    • Nantes Métropole (for 29 months)
    • Dalenys (for 26 months)
    • Univention GmbH (for 21 months)
    • Université Jean Monnet de St Etienne (for 21 months)
    • Sonus Networks (for 15 months)
    • UR Communications BV (for 9 months)
    • maxcluster GmbH (for 9 months)
    • Exonet B.V. (for 5 months)
  • Bronze sponsors:
    • David Ayers – IntarS Austria (for 36 months)
    • Evolix (for 36 months)
    • Offensive Security (for 36 months)
    • Seznam.cz, a.s. (for 36 months)
    • Freeside Internet Service (for 35 months)
    • MyTux (for 35 months)
    • Linuxhotel GmbH (for 33 months)
    • Intevation GmbH (for 32 months)
    • Daevel SARL (for 31 months)
    • Bitfolk LTD (for 30 months)
    • Megaspace Internet Services GmbH (for 30 months)
    • Greenbone Networks GmbH (for 29 months)
    • NUMLOG (for 29 months)
    • WinGo AG (for 28 months)
    • Ecole Centrale de Nantes – LHEEA (for 25 months)
    • Sig-I/O (for 22 months)
    • Entr’ouvert (for 20 months)
    • Adfinis SyGroup AG (for 17 months)
    • Laboratoire LEGI – UMR 5519 / CNRS (for 12 months)
    • Quarantainenet BV (for 12 months)
    • GNI MEDIA (for 11 months)
    • RHX Srl (for 9 months)
    • Bearstech (for 3 months)
    • LiHAS (for 3 months)

My Free Software Activities in May 2017

June 1, 2017 by Raphaël Hertzog

My monthly report covers a large part of what I have been doing in the free software world. I write it for my donors (thanks to them!) but also for the wider Debian community because it can give ideas to newcomers and it’s one of the best ways to find volunteers to work with me on projects that matter to me.

Debian LTS

I was allocated 12 hours to work on security updates for Debian 7 Wheezy. During this time I did the following:

  • Reviewed CVE against ntp (and mark them as no-dsa)
  • Prepared and released DLA-944-1 for openvpn 2.2.1-8+deb7u4 fixing CVE-2017-7479.
  • Prepared and released DLA-946-1 for nss 3.26-1+debu7u3 fixing two CVE.
  • Worked on bin/lts-cve-triage.py to no longer hide CVE on unsupported packages so that we actually add the proper status marker on each CVE.
  • Handled CVE triage for a whole week.

Misc Debian work

Debian Handbook. I started to work on the update of the Debian Administrator’s Handbook for Debian 9 Stretch. As part of this, I noticed a regression in dblatex and filed this issue both in the upstream tracker and in Debian and got that issue fixed in sid and stretch (sponsored the actual upload, filed the unblock request). I also stumbled on a regression in dia which was due to an incorrect Debian-specific patch that I reverted with a QA upload since the package is currently orphaned.

Django. On request of Scott Kitterman, I uploaded a new security release of Django 1.8 to jessie-backports but that upload got rejected because stretch no longer has Django 1.8 and I’m not allowed to maintain that branch in that repository. Ensued a long and heated discussion that has no clear resolution yet. It seems likely that some solution will be found for Django (the 1.8.18 that was rejected was accepted as a one-time update already, and our plans for the future make it clear that we would have like to have an LTS version in stretch in the first place) but the backports maintainers are not willing to change the policy to accomodate for other similar needs in the future.

The discussion has been complicated by the intervention of Neil Williams who brought up an upgrade problem of lava-server (#847277). Instead of fixing the root-problem in Django (#863267), or adding a work-around in lava-server’s code, he asserted that upgrading first to Django 1.8 from jessie-backports was the only upgrade path for lava-server.

Thanks

See you next month for a new summary of my activities.

Freexian’s report about Debian Long Term Support, April 2017

May 16, 2017 by Raphaël Hertzog

A Debian LTS logoLike each month, here comes a report about the work of paid contributors to Debian LTS.

Individual reports

In April, about 190 work hours have been dispatched among 13 paid contributors. Their reports are available:

  • Antoine Beaupré did 19.5 hours (out of 16h allocated + 5.5 remaining hours, thus keeping 2 extra hours for May).
  • Ben Hutchings did 12 hours (out of 15h allocated, thus keeping 3 extra hours for May).
  • Brian May did 10 hours.
  • Chris Lamb did 18 hours.
  • Emilio Pozuelo Monfort did 17.5 hours (out of 16 hours allocated + 3.5 hours remaining, thus keeping 2 hours for May).
  • Guido Günther did 12 hours (out of 8 hours allocated + 4 hours remaining).
  • Hugo Lefeuvre did 15.5 hours (out of 6 hours allocated + 9.5 hours remaining).
  • Jonas Meurer did nothing (out of 4 hours allocated + 3.5 hours remaining, thus keeping 7.5 hours for May).
  • Markus Koschany did 23.75 hours.
  • Ola Lundqvist did 14 hours (out of 20h allocated, thus keeping 6 extra hours for May).
  • Raphaël Hertzog did 11.25 hours (out of 10 hours allocated + 1.25 hours remaining).
  • Roberto C. Sanchez did 16.5 hours (out of 20 hours allocated + 1 hour remaining, thus keeping 4.5 extra hours for May).
  • Thorsten Alteholz did 23.75 hours.

Evolution of the situation

The number of sponsored hours decreased slightly and we’re now again a little behind our objective.

The security tracker currently lists 54 packages with a known CVE and the dla-needed.txt file 37. The number of open issues is comparable to last month.

Thanks to our sponsors

New sponsors are in bold.

  • Platinum sponsors:
    • TOSHIBA (for 19 months)
    • GitHub (for 10 months)
  • Gold sponsors:
    • The Positive Internet (for 35 months)
    • Blablacar (for 34 months)
    • Linode (for 24 months)
    • Babiel GmbH (for 13 months)
    • Plat’Home (for 13 months)
  • Silver sponsors:
    • Domeneshop AS (for 34 months)
    • Université Lille 3 (for 34 months)
    • Trollweb Solutions (for 32 months)
    • Nantes Métropole (for 28 months)
    • Dalenys (for 25 months)
    • Univention GmbH (for 20 months)
    • Université Jean Monnet de St Etienne (for 20 months)
    • Sonus Networks (for 14 months)
    • UR Communications BV (for 9 months)
    • maxcluster GmbH (for 8 months)
    • Exonet B.V. (for 4 months)
  • Bronze sponsors:
    • David Ayers – IntarS Austria (for 35 months)
    • Evolix (for 35 months)
    • Offensive Security (for 35 months)
    • Seznam.cz, a.s. (for 35 months)
    • Freeside Internet Service (for 34 months)
    • MyTux (for 34 months)
    • Linuxhotel GmbH (for 32 months)
    • Intevation GmbH (for 31 months)
    • Daevel SARL (for 30 months)
    • Bitfolk LTD (for 29 months)
    • Megaspace Internet Services GmbH (for 29 months)
    • Greenbone Networks GmbH (for 28 months)
    • NUMLOG (for 28 months)
    • WinGo AG (for 28 months)
    • Ecole Centrale de Nantes – LHEEA (for 24 months)
    • Sig-I/O (for 21 months)
    • Entr’ouvert (for 19 months)
    • Adfinis SyGroup AG (for 16 months)
    • GNI MEDIA (for 11 months)
    • Laboratoire LEGI – UMR 5519 / CNRS (for 11 months)
    • Quarantainenet BV (for 11 months)
    • RHX Srl (for 8 months)
    • Bearstech
    • LiHAS
  • « Previous Page
  • 1
  • …
  • 21
  • 22
  • 23
  • 24
  • 25
  • …
  • 70
  • Next Page »

Get the Debian Handbook

Available as paperback and as ebook.
Book cover

Email newsletter

Get updates and exclusive content by email, join the Debian Supporters Guild:

Follow me

  • Email
  • Facebook
  • GitHub
  • RSS
  • Twitter

Discover my French books

Planets

  • Planet Debian

Archives

I write software, books and documentation. I'm a Debian developer since 1998 and run my own company. I want to share my passion and knowledge of the Debian ecosystem. Read More…

Tags

3.0 (quilt) Activity summary APT aptitude Blog Book Cleanup conffile Contributing CUT d-i Debconf Debian Debian France Debian Handbook Debian Live Distro Tracker dpkg dpkg-source Flattr Flattr FOSS Freexian Funding Git GNOME GSOC HOWTO Interview LTS Me Multiarch nautilus-dropbox News Packaging pkg-security Programming PTS publican python-django Reference release rolling synaptic Ubuntu WordPress

Recent Posts

  • Freexian is looking to expand its team with more Debian contributors
  • Freexian’s report about Debian Long Term Support, July 2022
  • Freexian’s report about Debian Long Term Support, June 2022
  • Freexian’s report about Debian Long Term Support, May 2022
  • Freexian’s report about Debian Long Term Support, April 2022

Copyright © 2005-2021 Raphaël Hertzog