[Secure-testing-team] Re: Moving forward with the 2.4.27 and 2.6.8 kernels

Horms horms at debian.org
Wed Aug 17 02:06:59 UTC 2005


On Tue, Aug 16, 2005 at 01:22:02PM -0600, dann frazier wrote:
> On Tue, 2005-08-16 at 15:31 +0900, Horms wrote:
> > Hi,
> > 
> > Here is my proposal for the immediate future of 2.4.27 and 2.6.8. 
> > I'm pretty comforatble with the shape of both of them in SVN,
> > and its probably a good time to think about some releases -
> > security bugs keep coming in all the time, but I really think
> > we have to draw a line in the sand and make a release.
> > 
> > To get this ball rolling I plan to release kernel-source-2.4.27
> > 2.4.27-11 and kernel-image-2.4.27-i386 2.4.27-11 into unstable tomorrow.
> > This is tagged in SVN, and I have made the packages available at
> > http://packages.vergenet.net/pending/ (i386 still building, will
> > be available soon). 
> 
> I see 2.6.8-16sarge1 there, but not 2.4.27.
> Are you wanting us to builds against 2.6.8-16sarge1?  And if so, should
> we be building in a pristine sarge environment and targeting
> stable-security (vs. unstable)?

Yes, I've done 2.6.8-16sarge1, but ran out of day before
I got to 2.4.27-10sarge1. I'll try and make that happen today
or tomorrow.

> Are you wanting us to builds against 2.6.8-16sarge1?  And if so,
> should
> we be building in a pristine sarge environment and targeting
> stable-security (vs. unstable)?

Yes, please.

Hopefully the security team will let us know the best way
to make these updates available to them - I susbequently
read up on queues and see that DDs are explicitily asked
not to upload to the security updates quese without the
ok from the security team. Hopefully they can give us an ok,
but In the mean time perhaps getting our packages up on 
people.debian.org would be a good idea. We could even start
passing URLs around for people who want to get their hands on
the packages.

> The rest of this message leads me to believe this is only a call for
> 2.4.27/unstable builds.

Sorry if this was a bit unclear. Basically I am calling for three builds.

1. 2.4.27-11 for unstable  
   - source packages now up on http://packages.vergenet.net/pending/
   - I will upload source and i386 today
   - If your arch should have 2.4.27 removed from unstable, make that so

2. 2.6.8-16sarge1 for stable-security  
   - source packages now up on http://packages.vergenet.net/pending/
   - need feedback from security team on how to coordinate this release
   - please make packages available and publish a URL in the mean time,
     perhaps on people.debian.org

3. 2.4.27-10sarge1 for stable-security  
   - source packages not prepared yet. I hope to do that today
   - need feedback from security team on how to coordinate this release

-- 
Horms




More information about the Secure-testing-team mailing list