apt-get install debian-wizard

Insider infos, master your Debian/Ubuntu distribution

  • About
    • About this blog
    • About me
    • My free software history
  • Support my work
  • Get the newsletter
  • More stuff
    • Support Debian Contributors
    • Other sites
      • My company
      • French Blog about Free Software
      • Personal Website (French)
  • Mastering Debian
  • Contributing 101
  • Packaging Tutorials
You are here: Home / Archives for LTS

My Free Software Activities in October 2015

November 4, 2015 by Raphaël Hertzog

My monthly report covers a large part of what I have been doing in the free software world. I write it for my donators (thanks to them!) but also for the wider Debian community because it can give ideas to newcomers and it’s one of the best ways to find volunteers to work with me on projects that matter to me.

Debian LTS

This month I have been paid to work 13.25 hours on Debian LTS. During this time I worked on the following things:

  • I prepared and released DLA 330-1 fixing two CVE on unzip.
  • I prepared a bouncycastle update fixing CVE-2015-7940 (after having requested that CVE assignment since nobody had done it yet) but I have not yet released the corresponding DLA yet since I’m waiting for a review by the upstream author. This is hairy cryptographic Java code that was non-trivial to backport and I’d rather make sure that I do not mess anything. The patches are available in the bug report #802671 that I opened.
  • I tested the update to MySQL 5.5 with multiple packages and sent back my findings to the debian-lts mailing list.

I also started a conversation about what paid contributors could work on if they have some spare cycle as the current funding level might allow us to invest some time on work outside of just plain security updates.

The Debian Administrator’s Handbook

I spent quite some time finalizing the Jessie book update, both for the content and for the layout of the printed book.

Debian Handbook: cover of the jessie edition

Misc Debian work

GNOME 3.18. I uploaded a new gnome-shell-timer working with GNOME Shell 3.18 and I filed bugs #800660 and #802480 about an annoying gnome-keyring regression… I did multiple test rounds with the Debian maintainers (Dmitry Shachnev, kudos to him!) and the upstream developers (see here and here). Apart from those regressions, I like GNOME 3.18!

Python-modules team migration to Git. After the Git migration, and since the team policy now imposes usage of git-dpm on all members, I made some tries with it on the python-django package while pushing version 1.8.5 to experimental. And the least I can say is that I’m not pleased with the result. I thus filed 3 bugs summarizing the problems I have with git-dpm: #801666 (no way to set the upstream branch names from within the repository), #801667 (no clean way to merge between packaging branches), #801668 (does not create upstream tag immediately on tarball import). That is on top of other randomly stupid bugs that were already reported like #801548 (does not work with perfectly valid pre-existing upstream tags).

Django packaging. I filed bugs on all packages build-depending on python-django that fail to build with Django 1.8 and informed them that I would upload Django 1.8 to unstable in early November (it’s done already). Then I fixed python-django-jsonfield myself since Distro Tracker relies on this package.

Following this small mass-bug filing, I filed a wishlist bug on devscripts to improve the “mass-bug” helper script (see #801926). And since I used “ratt” to rebuild the packages, I filed a wishlist issue on this new tool as well.

Tryton 3.6 upgrade. I upgraded my own Tryton installation to version 3.6 and filed bug #803066 because the SysV init script was not working properly. That also reminded me that the DD process of Matthias Behrle (the tryton package maintainer) was stalled due to a bug in the NM infrastructure so I pinged the NM team and we sorted out a way for me to advocate him and get his process going…

Distro Tracker. I continued my work to refactor the way we handle incoming mail processing (branch people/hertzog/mailprocessing). It’s now mostly finished and I need to deploy it in a test environment before being able to roll it out on tracker.debian.org.

Thanks

See you next month for a new summary of my activities.

Freexian’s report about Debian Long Term Support, September 2015

October 16, 2015 by Raphaël Hertzog

A Debian LTS logoLike each month, here comes a report about the work of paid contributors to Debian LTS.

Individual reports

In September, 71.50 work hours have been dispatched among 7 paid contributors. Their reports are available:

  • Ben Hutchings did 9 hours (out of the 14.5 hours that he had allocated, he will catch up in October).
  • Guido Günther did 8 hours.
  • Mike Gabriel did 16 hours (8 assigned + 8 remaining from month before).
  • Raphaël Hertzog did 8 hours.
  • Santiago Ruano Rincón did 14.5 hours.
  • Scott Kitterman did nothing out of the 4 hours allocated. He will catch up in October.
  • Thorsten Alteholz did 14.50 hours.

Evolution of the situation

October is back to the highest level of funding with 85.5 hours funded. The late sponsors have all caught up now. And next month will again rise to a new record with multiple sponsors having joined up. So far we already have two new silver sponsors (Université Jean Monnet de Saint-Étienne and Univention GmbH) and a new bronze sponsor (Entr’ouvert). Many thanks to them!

With those sponsors we crossed the 50% mark that was our first objective. \o/ But we still need more support to reach our second goal of funding the equivalent of a full time position.

That said the increased level of support already allows us to do a better job in some areas that have been neglected : I asked the paid contributors to work towards providing mysql-5.5 in squeeze since version 5.1 is no longer supported by Oracle. We need beta testers to test the upgrade, see this message on the mailling list.

In terms of security updates waiting to be handled, the situation is close to last month: the dla-needed.txt file lists 15 packages awaiting an update (3 less than last month), the list of open vulnerabilities in Squeeze shows about 23 affected packages in total (7 less than last month).

Thanks to our sponsors

The new sponsors are in bold.

  • Gold sponsors:
    • The Positive Internet (for 16 months already)
    • Blablacar (for 15 months already)
    • Linode LLC (for 5 months already)
  • Silver sponsors:
    • David Ayers – IntarS Austria (for 16 months already)
    • Domeneshop AS (for 15 months already)
    • Université Lille 3 (for 15 months already)
    • Trollweb Solutions (for 13 months already)
    • Gandi SAS (for 10 months already)
    • University of Luxembourg (for 7 months already)
    • Rentabiliweb Group (for 5 months already)
    • Univention GmbH
    • Université Jean Monnet de St Etienne
  • Bronze sponsors:
    • Offensive Security (for 16 months already)
    • Seznam.cz, a.s. (for 16 months already)
    • Evolix (for 15 months already)
    • Freeside Internet Service (for 15 months already)
    • MyTux (for 15 months already)
    • Linuxhotel GmbH (for 13 months already)
    • Intevation GmbH (for 12 months already)
    • Daevel SARL (for 11 months already)
    • FOSSter (for 11 months already)
    • Bitfolk LTD (for 10 months already)
    • Megaspace Internet Services GmbH (for 10 months already)
    • Gree, Inc. (for 9 months already)
    • Greenbone Networks GmbH (for 9 months already)
    • NUMLOG (for 9 months already)
    • WinGo AG (for 8 months already)
    • Ecole Centrale de Nantes – LHEEA (for 5 months already)
    • Sig-I/O
    • Entr’ouvert

My Free Software Activities in September 2015

September 30, 2015 by Raphaël Hertzog

My monthly report covers a large part of what I have been doing in the free software world. I write it for my donators (thanks to them!) but also for the wider Debian community because it can give ideas to newcomers and it’s one of the best ways to find volunteers to work with me on projects that matter to me.

Debian LTS

This month I have been paid to work 8 hours on Debian LTS. In that time, I mostly did CVE triaging (in the last 3 days since I’m of LTS frontdesk duty this week). I pushed 14 commits to the security tracker. There were multiple CVE without any initial investigation so I checked the status of the CVE not only in squeeze but also in wheezy/jessie.

On unpaid time, I wrote and sent the summary of the work session held during DebConf. And I tried to initiate a discussion about offering mysql-5.5 in squeeze-lts. We also have setup lts-security@debian.org so that we can better handle embargoed security updates.

The Debian Administrator’s Handbook

Debian Handbook: cover of the jessie editionI spent a lot of time on my book, the content update has been done but now we’re reviewing it before preparing the paperback. I also started updating its French translation. You can help review it too.

While working on the book I noticed that snort got removed from jessie and the SE linux reference policy as well. I mailed their maintainers to recommend that they provide them in jessie-backports at least… those packages are relatively important/popular and it’s a pity that they are missing in jessie.

I hope to finish the book update in the next two weeks!

Distro Tracker

I spent a lot of time to revamp the mail part of Distro Tracker. But as it’s not finished yet, I don’t have anything to show yet. That said I pushed an important fix concerning the mail subscriptions (see #798555), basically all subscriptions of packages containing a dash were broken. It just shows that the new tracker is not yet widely used for mail subscription…

I also merged a patch from Andrew Starr-Bochicchio (#797633) to improve the description of the WNPP action items. And I reviewed another patch submitted by Orestis Ioannou to allow browsing of old news (see #756766).

And I filed #798011 against bugs.debian.org to request that a new X-Debian-PR-Severity header field be added to outgoing BTS mail so that Distro Tracker can filter mails by severity and offer people to subscribe to RC bugs only.

Misc Debian work

I filed many bugs this month and almost all of them are related to my Kali work:

  • 3 on debootstrap: #798560 (request for –suite-config option), #798562 (allow sharing bootstrap scripts), #7985604 (request to add kali related bootstrap scripts).
  • 3 requests of new upstream versions: for gpsd (#797899), for valgrind (#800013) and for puppet (#798636).
  • #797783: sbuild fails without any error message when /var/lib/sbuild is not writable in the chroot
  • #798181: gnuradio: Some files take way too long to compile (I had to request a give-back on another build daemon to ensure gnuradio migrated back to testing, and Julien Cristau suggested that it would be better to fix the package so that a single file doesn’t take more than 5 hours to build…)
  • #799550: libuhd003v5 lost its v5 suffix…

Thanks

See you next month for a new summary of my activities.

Freexian’s report about Debian Long Term Support, August 2015

September 17, 2015 by Raphaël Hertzog

A Debian LTS logoLike each month, here comes a report about the work of paid contributors to Debian LTS.

Individual reports

In August, 71.50 work hours have been dispatched among 7 paid contributors. Their reports are available:

  • Ben Hutchings did 15 hours.
  • Guido Günther did 4 hours.
  • Mike Gabriel was assigned 8 hours but did not do them. He will catch up in September.
  • Raphaël Hertzog did 6.5 hours.
  • Santiago Ruano Rincón did 17 hours.
  • Scott Kitterman did 4 hours.
  • Thorsten Alteholz did 17 hours.

Evolution of the situation

September is stable compared to August (71.50 hours per month) and has not caught up back to the level of July as I hoped. Again it’s because 2 sponsors were not able to pay their renewal invoice on time (one of last month paid, but another bigger sponsor failed this month). Those sponsors will continue to support us and I would like to be able to say that things will be back to normal next month, but I can’t say it since we have also been informed of the (hopefully temporary) defection of another bronze sponsor that will affect us next month.

Fortunately there are also good news, we have 3 new sponsors in the pipe (2 silver, 1 platinum) who shall join the project soon. And Blablacar increased their support from Silver to Gold (from 4h/month to 8h/month).

But we still need more support… in particular since we would like to commit to support virtualization related packages in Wheezy: that’s clearly an objective for us. I recently published the summary of the work session held during DebConf 15 in Heidelberg (video recording).

It would be really nice if we could get closer to the goal of funding a full-time position.

In terms of security updates waiting to be handled, the situation is close to last month: the dla-needed.txt file lists 18 packages awaiting an update (2 less than last month), the list of open vulnerabilities in Squeeze shows about 30 affected packages in total (8 more than last month).

Thanks to our sponsors

  • Gold sponsors:
    • The Positive Internet (for 15 months already)
    • Blablacar (for 14 months already)
    • Linode LLC (for 4 months already)
  • Silver sponsors:
    • David Ayers – IntarS Austria (for 15 months already)
    • Domeneshop AS (for 14 months already)
    • Université Lille 3 (for 14 months already)
    • Trollweb Solutions (for 12 months already)
    • Gandi SAS (for 9 months already)
    • University of Luxembourg (for 6 months already)
    • Rentabiliweb Group (for 4 months already)
  • Bronze sponsors:
    • Offensive Security (for 15 months already)
    • Seznam.cz, a.s. (for 15 months already)
    • Evolix (for 14 months already)
    • Freeside Internet Service (for 14 months already)
    • MyTux (for 14 months already)
    • Linuxhotel GmbH (for 12 months already)
    • Intevation GmbH (for 11 months already)
    • Daevel SARL (for 10 months already)
    • FOSSter (for 10 months already)
    • Bitfolk LTD (for 9 months already)
    • Megaspace Internet Services GmbH (for 9 months already)
    • Gree, Inc. (for 8 months already)
    • Greenbone Networks GmbH (for 8 months already)
    • NUMLOG (for 8 months already)
    • WinGo AG (for 7 months already)
    • Ecole Centrale de Nantes – LHEEA (for 4 months already)
    • Sig-I/O
  • « Previous Page
  • 1
  • …
  • 26
  • 27
  • 28
  • 29
  • 30
  • …
  • 36
  • Next Page »

Get the Debian Handbook

Available as paperback and as ebook.
Book cover

Email newsletter

Get updates and exclusive content by email, join the Debian Supporters Guild:

Follow me

  • Email
  • Facebook
  • GitHub
  • RSS
  • Twitter

Discover my French books

Planets

  • Planet Debian

Archives

I write software, books and documentation. I'm a Debian developer since 1998 and run my own company. I want to share my passion and knowledge of the Debian ecosystem. Read More…

Tags

3.0 (quilt) Activity summary APT aptitude Blog Book Cleanup conffile Contributing CUT d-i Debconf Debian Debian France Debian Handbook Debian Live Distro Tracker dpkg dpkg-source Flattr Flattr FOSS Freexian Funding Git GNOME GSOC HOWTO Interview LTS Me Multiarch nautilus-dropbox News Packaging pkg-security Programming PTS publican python-django Reference release rolling synaptic Ubuntu WordPress

Recent Posts

  • Freexian is looking to expand its team with more Debian contributors
  • Freexian’s report about Debian Long Term Support, July 2022
  • Freexian’s report about Debian Long Term Support, June 2022
  • Freexian’s report about Debian Long Term Support, May 2022
  • Freexian’s report about Debian Long Term Support, April 2022

Copyright © 2005-2021 Raphaël Hertzog