apt-get install debian-wizard

Insider infos, master your Debian/Ubuntu distribution

  • About
    • About this blog
    • About me
    • My free software history
  • Support my work
  • Get the newsletter
  • More stuff
    • Support Debian Contributors
    • Other sites
      • My company
      • French Blog about Free Software
      • Personal Website (French)
  • Mastering Debian
  • Contributing 101
  • Packaging Tutorials
You are here: Home / Archives for Debian

Freexian’s report about Debian Long Term Support, September 2015

October 16, 2015 by Raphaël Hertzog

A Debian LTS logoLike each month, here comes a report about the work of paid contributors to Debian LTS.

Individual reports

In September, 71.50 work hours have been dispatched among 7 paid contributors. Their reports are available:

  • Ben Hutchings did 9 hours (out of the 14.5 hours that he had allocated, he will catch up in October).
  • Guido Günther did 8 hours.
  • Mike Gabriel did 16 hours (8 assigned + 8 remaining from month before).
  • Raphaël Hertzog did 8 hours.
  • Santiago Ruano Rincón did 14.5 hours.
  • Scott Kitterman did nothing out of the 4 hours allocated. He will catch up in October.
  • Thorsten Alteholz did 14.50 hours.

Evolution of the situation

October is back to the highest level of funding with 85.5 hours funded. The late sponsors have all caught up now. And next month will again rise to a new record with multiple sponsors having joined up. So far we already have two new silver sponsors (Université Jean Monnet de Saint-Étienne and Univention GmbH) and a new bronze sponsor (Entr’ouvert). Many thanks to them!

With those sponsors we crossed the 50% mark that was our first objective. \o/ But we still need more support to reach our second goal of funding the equivalent of a full time position.

That said the increased level of support already allows us to do a better job in some areas that have been neglected : I asked the paid contributors to work towards providing mysql-5.5 in squeeze since version 5.1 is no longer supported by Oracle. We need beta testers to test the upgrade, see this message on the mailling list.

In terms of security updates waiting to be handled, the situation is close to last month: the dla-needed.txt file lists 15 packages awaiting an update (3 less than last month), the list of open vulnerabilities in Squeeze shows about 23 affected packages in total (7 less than last month).

Thanks to our sponsors

The new sponsors are in bold.

  • Gold sponsors:
    • The Positive Internet (for 16 months already)
    • Blablacar (for 15 months already)
    • Linode LLC (for 5 months already)
  • Silver sponsors:
    • David Ayers – IntarS Austria (for 16 months already)
    • Domeneshop AS (for 15 months already)
    • Université Lille 3 (for 15 months already)
    • Trollweb Solutions (for 13 months already)
    • Gandi SAS (for 10 months already)
    • University of Luxembourg (for 7 months already)
    • Rentabiliweb Group (for 5 months already)
    • Univention GmbH
    • Université Jean Monnet de St Etienne
  • Bronze sponsors:
    • Offensive Security (for 16 months already)
    • Seznam.cz, a.s. (for 16 months already)
    • Evolix (for 15 months already)
    • Freeside Internet Service (for 15 months already)
    • MyTux (for 15 months already)
    • Linuxhotel GmbH (for 13 months already)
    • Intevation GmbH (for 12 months already)
    • Daevel SARL (for 11 months already)
    • FOSSter (for 11 months already)
    • Bitfolk LTD (for 10 months already)
    • Megaspace Internet Services GmbH (for 10 months already)
    • Gree, Inc. (for 9 months already)
    • Greenbone Networks GmbH (for 9 months already)
    • NUMLOG (for 9 months already)
    • WinGo AG (for 8 months already)
    • Ecole Centrale de Nantes – LHEEA (for 5 months already)
    • Sig-I/O
    • Entr’ouvert

My Free Software Activities in September 2015

September 30, 2015 by Raphaël Hertzog

My monthly report covers a large part of what I have been doing in the free software world. I write it for my donators (thanks to them!) but also for the wider Debian community because it can give ideas to newcomers and it’s one of the best ways to find volunteers to work with me on projects that matter to me.

Debian LTS

This month I have been paid to work 8 hours on Debian LTS. In that time, I mostly did CVE triaging (in the last 3 days since I’m of LTS frontdesk duty this week). I pushed 14 commits to the security tracker. There were multiple CVE without any initial investigation so I checked the status of the CVE not only in squeeze but also in wheezy/jessie.

On unpaid time, I wrote and sent the summary of the work session held during DebConf. And I tried to initiate a discussion about offering mysql-5.5 in squeeze-lts. We also have setup lts-security@debian.org so that we can better handle embargoed security updates.

The Debian Administrator’s Handbook

Debian Handbook: cover of the jessie editionI spent a lot of time on my book, the content update has been done but now we’re reviewing it before preparing the paperback. I also started updating its French translation. You can help review it too.

While working on the book I noticed that snort got removed from jessie and the SE linux reference policy as well. I mailed their maintainers to recommend that they provide them in jessie-backports at least… those packages are relatively important/popular and it’s a pity that they are missing in jessie.

I hope to finish the book update in the next two weeks!

Distro Tracker

I spent a lot of time to revamp the mail part of Distro Tracker. But as it’s not finished yet, I don’t have anything to show yet. That said I pushed an important fix concerning the mail subscriptions (see #798555), basically all subscriptions of packages containing a dash were broken. It just shows that the new tracker is not yet widely used for mail subscription…

I also merged a patch from Andrew Starr-Bochicchio (#797633) to improve the description of the WNPP action items. And I reviewed another patch submitted by Orestis Ioannou to allow browsing of old news (see #756766).

And I filed #798011 against bugs.debian.org to request that a new X-Debian-PR-Severity header field be added to outgoing BTS mail so that Distro Tracker can filter mails by severity and offer people to subscribe to RC bugs only.

Misc Debian work

I filed many bugs this month and almost all of them are related to my Kali work:

  • 3 on debootstrap: #798560 (request for –suite-config option), #798562 (allow sharing bootstrap scripts), #7985604 (request to add kali related bootstrap scripts).
  • 3 requests of new upstream versions: for gpsd (#797899), for valgrind (#800013) and for puppet (#798636).
  • #797783: sbuild fails without any error message when /var/lib/sbuild is not writable in the chroot
  • #798181: gnuradio: Some files take way too long to compile (I had to request a give-back on another build daemon to ensure gnuradio migrated back to testing, and Julien Cristau suggested that it would be better to fix the package so that a single file doesn’t take more than 5 hours to build…)
  • #799550: libuhd003v5 lost its v5 suffix…

Thanks

See you next month for a new summary of my activities.

Freexian’s report about Debian Long Term Support, August 2015

September 17, 2015 by Raphaël Hertzog

A Debian LTS logoLike each month, here comes a report about the work of paid contributors to Debian LTS.

Individual reports

In August, 71.50 work hours have been dispatched among 7 paid contributors. Their reports are available:

  • Ben Hutchings did 15 hours.
  • Guido Günther did 4 hours.
  • Mike Gabriel was assigned 8 hours but did not do them. He will catch up in September.
  • Raphaël Hertzog did 6.5 hours.
  • Santiago Ruano Rincón did 17 hours.
  • Scott Kitterman did 4 hours.
  • Thorsten Alteholz did 17 hours.

Evolution of the situation

September is stable compared to August (71.50 hours per month) and has not caught up back to the level of July as I hoped. Again it’s because 2 sponsors were not able to pay their renewal invoice on time (one of last month paid, but another bigger sponsor failed this month). Those sponsors will continue to support us and I would like to be able to say that things will be back to normal next month, but I can’t say it since we have also been informed of the (hopefully temporary) defection of another bronze sponsor that will affect us next month.

Fortunately there are also good news, we have 3 new sponsors in the pipe (2 silver, 1 platinum) who shall join the project soon. And Blablacar increased their support from Silver to Gold (from 4h/month to 8h/month).

But we still need more support… in particular since we would like to commit to support virtualization related packages in Wheezy: that’s clearly an objective for us. I recently published the summary of the work session held during DebConf 15 in Heidelberg (video recording).

It would be really nice if we could get closer to the goal of funding a full-time position.

In terms of security updates waiting to be handled, the situation is close to last month: the dla-needed.txt file lists 18 packages awaiting an update (2 less than last month), the list of open vulnerabilities in Squeeze shows about 30 affected packages in total (8 more than last month).

Thanks to our sponsors

  • Gold sponsors:
    • The Positive Internet (for 15 months already)
    • Blablacar (for 14 months already)
    • Linode LLC (for 4 months already)
  • Silver sponsors:
    • David Ayers – IntarS Austria (for 15 months already)
    • Domeneshop AS (for 14 months already)
    • Université Lille 3 (for 14 months already)
    • Trollweb Solutions (for 12 months already)
    • Gandi SAS (for 9 months already)
    • University of Luxembourg (for 6 months already)
    • Rentabiliweb Group (for 4 months already)
  • Bronze sponsors:
    • Offensive Security (for 15 months already)
    • Seznam.cz, a.s. (for 15 months already)
    • Evolix (for 14 months already)
    • Freeside Internet Service (for 14 months already)
    • MyTux (for 14 months already)
    • Linuxhotel GmbH (for 12 months already)
    • Intevation GmbH (for 11 months already)
    • Daevel SARL (for 10 months already)
    • FOSSter (for 10 months already)
    • Bitfolk LTD (for 9 months already)
    • Megaspace Internet Services GmbH (for 9 months already)
    • Gree, Inc. (for 8 months already)
    • Greenbone Networks GmbH (for 8 months already)
    • NUMLOG (for 8 months already)
    • WinGo AG (for 7 months already)
    • Ecole Centrale de Nantes – LHEEA (for 4 months already)
    • Sig-I/O

My Free Software Activities in August 2015

September 1, 2015 by Raphaël Hertzog

My monthly report covers a large part of what I have been doing in the free software world. I write it for my donators (thanks to them!) but also for the wider Debian community because it can give ideas to newcomers and it’s one of the best ways to find volunteers to work with me on projects that matter to me.

Debian LTS

This month I have been paid to work 6.5 hours on Debian LTS. In that time I did the following:

  • Prepared and released DLA-301-1 fixing 2 CVE in python-django.
  • Did one week of “LTS Frontdesk” with CVE triaging. I pushed 11 commits to the security tracker.

Apart from that, I also gave a talk about Debian LTS at DebConf 15 in Heidelberg and also coordinated a work session to discuss our plans for Wheezy. Have a look at the video recordings:

  • Debian Long Term Support: Past Present and Future (slides)
  • Preparing for Wheezy LTS

DebConf 15

I attended DebConf 15 with great pleasure after having missed DebConf 14 last year. While I did not do lots of work there, I participated in many discussions and I certainly came back with a renewed motivation to work on Debian. That’s always good. 🙂

For the concrete work I did during DebConf, I can only claim two schroot uploads to fix the lack of support of the new “overlay” filesystem that replaces “aufs” in the official Debian kernel, and some Distro Tracker work (fixing an issue that some people had when they were logged in via Debian’s SSO).

While the numerous discussions I had during DebConf can’t be qualified as “work”, they certainly contribute to build up work plans for the future:

As a Kali developer, I attended multiple sessions related to derivatives (notably the Debian Derivatives Panel).

I was also interested by the “Debian in the corporate IT” BoF led by Michael Meskes (Credativ’s CEO). He pointed out a number of problems that corporate users might have when they first consider using Debian and we will try to do something about this. Expect further news and discussions on the topic.

Martin Kraff, Luca Filipozzi, and me had a discussion with the Debian Project Leader (Neil) about how to revive/transform the Debian’s Partner program. Nothing is fleshed out yet, but at least the process initiated by the former DPL (Lucas) is again moving forward.

Other Debian work

Sponsorship. I sponsored an NMU of pep8 by Daniel Stender as it was a requirement for prospector… which I also sponsored since all the required dependencies are now available in Debian. \o/

Packaging. I NMUed libxml2 2.9.2+really2.9.1+dfsg1-0.1 fixing 3 security issues and a RC bug that was breaking publican. Since there’s no upstream fix for more than 8 months, I went back to the former version 2.9.1. It’s in line with the new requirement of release managers… a package in unstable should migrate to testing reasonably quickly, it’s not acceptable to keep it unfixed for months. With this annoying bug fixed, I could again upload a new upstream release of publican… so I prepared and uploaded 4.3.2-1. It was my first source only upload. This release was more work than I expected and I filed no less than 3 bug to upstream (new bash-completion install path, request to provide sources of a minified javascript file, drop a .po file for an invalid language code).

GPG issues with smartcard. Back from DebConf, when I wanted to sign some key, I stumbled again upon the problem which makes it impossible for me to use my two smartcards one after the other without first deleting the stubs for the private key. It’s not a new issue but I decided that it was time to report it upstream, so I did it: #2079 on bugs.gnupg.org. Some research helped me to find a way to work-around the problem. Later in the month, after a dist-upgrade and a reboot, I was no longer able to use my smartcard as a SSH authentication key… again it was already reported but there was no clear analysis, so I tried to do my own one and added the results of my investigation in #795368. It looks like the culprit is pinentry-gnome3 not working when started by the gpg-agent which is started before the DBUS session. Simple fix is to restart the gpg-agent in the session… but I have no idea yet of what the proper fix should be (letting systemd manage the graphical user session and start gpg-agent would be my first answer, but that doesn’t solve the issue for users of other init systems so it’s not satisfying).

Distro Tracker. I merged two patches from Orestis Ioannou fixing some bugs tagged newcomer. There are more such bugs (I even filed two: #797096 and #797223), go grab them and do a first contribution to Distro Tracker like Orestis just did! I also merged a change from Christophe Siraut who presented Distro Tracker at DebConf.

I implemented in Distro Tracker the new authentication based on SSL client certificates that was recently announced by Enrico Zini. It’s working nice, and this authentication scheme is far easier to support. Good job, Enrico!

tracker.debian.org broke during DebConf, it stopped being updated with new data. I tracked this down to a problem in the archive (see #796892). Apparently Ansgar Burchardt changed the set of compression tools used on some jessie repositorie, replacing bz2 by xz. He dropped the old Packages.bz2 but missed some Sources.bz2 which were thus stale… and APT reported “Hashsum mismatch” on the uncompressed content.

Misc. I pushed some small improvement to my Salt formulas: schroot-formula and sbuild-formula. They will now auto-detect which overlay filesystem is available with the current kernel (previously “aufs” was hardcoded).

Thanks

See you next month for a new summary of my activities.

  • « Previous Page
  • 1
  • …
  • 31
  • 32
  • 33
  • 34
  • 35
  • …
  • 95
  • Next Page »

Get the Debian Handbook

Available as paperback and as ebook.
Book cover

Email newsletter

Get updates and exclusive content by email, join the Debian Supporters Guild:

Follow me

  • Email
  • Facebook
  • GitHub
  • RSS
  • Twitter

Discover my French books

Planets

  • Planet Debian

Archives

I write software, books and documentation. I'm a Debian developer since 1998 and run my own company. I want to share my passion and knowledge of the Debian ecosystem. Read More…

Tags

3.0 (quilt) Activity summary APT aptitude Blog Book Cleanup conffile Contributing CUT d-i Debconf Debian Debian France Debian Handbook Debian Live Distro Tracker dpkg dpkg-source Flattr Flattr FOSS Freexian Funding Git GNOME GSOC HOWTO Interview LTS Me Multiarch nautilus-dropbox News Packaging pkg-security Programming PTS publican python-django Reference release rolling synaptic Ubuntu WordPress

Recent Posts

  • Freexian is looking to expand its team with more Debian contributors
  • Freexian’s report about Debian Long Term Support, July 2022
  • Freexian’s report about Debian Long Term Support, June 2022
  • Freexian’s report about Debian Long Term Support, May 2022
  • Freexian’s report about Debian Long Term Support, April 2022

Copyright © 2005-2021 Raphaël Hertzog