summaryrefslogtreecommitdiffstats
path: root/zarb-ml/mageia-dev/2011-September/007734.html
blob: b778f426a94073ab8a7eb93fd4f2e3adc782ee96 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
 <HEAD>
   <TITLE> [Mageia-dev] Status report for Mageia 1 updates,	and call for help from you packagers
   </TITLE>
   <LINK REL="Index" HREF="index.html" >
   <LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Status%20report%20for%20Mageia%201%20updates%2C%0A%09and%20call%20for%20help%20from%20you%20packagers&In-Reply-To=%3C201109011216.19806.stormi%40laposte.net%3E">
   <META NAME="robots" CONTENT="index,nofollow">
   <META http-equiv="Content-Type" content="text/html; charset=us-ascii">
   <LINK REL="Previous"  HREF="007801.html">
   <LINK REL="Next"  HREF="007738.html">
 </HEAD>
 <BODY BGCOLOR="#ffffff">
   <H1>[Mageia-dev] Status report for Mageia 1 updates,	and call for help from you packagers</H1>
    <B>Samuel Verschelde</B> 
    <A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Status%20report%20for%20Mageia%201%20updates%2C%0A%09and%20call%20for%20help%20from%20you%20packagers&In-Reply-To=%3C201109011216.19806.stormi%40laposte.net%3E"
       TITLE="[Mageia-dev] Status report for Mageia 1 updates,	and call for help from you packagers">stormi at laposte.net
       </A><BR>
    <I>Thu Sep  1 12:16:19 CEST 2011</I>
    <P><UL>
        <LI>Previous message: <A HREF="007801.html">[Mageia-dev] Copying dependencies to Updates (Testing),	or changing mgaapplet to use urpmi --auto-update instead of urpmi	--update.
</A></li>
        <LI>Next message: <A HREF="007738.html">[Mageia-dev] [RPM] cauldron core/release	bluedevil-1.2-0.rc2.1.mga2
</A></li>
         <LI> <B>Messages sorted by:</B> 
              <a href="date.html#7734">[ date ]</a>
              <a href="thread.html#7734">[ thread ]</a>
              <a href="subject.html#7734">[ subject ]</a>
              <a href="author.html#7734">[ author ]</a>
         </LI>
       </UL>
    <HR>  
<!--beginarticle-->
<PRE>Le jeudi 25 ao&#251;t 2011 23:48:19, Stew Benedict a &#233;crit :
&gt;<i> On 08/25/2011 01:12 PM, Samuel Verschelde wrote:
</I>&gt;<i> &gt; Le jeudi 25 ao&#251;t 2011 14:09:26, Stew Benedict a &#233;crit :
</I>&gt;<i> &gt;&gt; On 08/24/2011 08:50 PM, Samuel Verschelde wrote:
</I>&gt;<i> &gt;&gt;&gt; Hi,
</I>&gt;<i> &gt;&gt;&gt; 
</I>&gt;<i> &gt;&gt;&gt; I was told that QA Team's work's visibility needs to be improved, so as
</I>&gt;<i> &gt;&gt;&gt; a team member I'll try to give you some sort of status report.
</I>&gt;<i> &gt;&gt;&gt; 
</I>&gt;<i> &gt;&gt;&gt; - 1 has been validated by QA one month ago, but was assigned to
</I>&gt;<i> &gt;&gt;&gt; security team following updates policy for security fixes, and got not
</I>&gt;<i> &gt;&gt;&gt; answer. We have to improve either the policy or the security team here
</I>&gt;<i> &gt;&gt;&gt; (or both).
</I>&gt;<i> &gt;&gt; 
</I>&gt;<i> &gt;&gt; Do you have a pointer to this bug? I'm not finding it in bugzilla. I'm
</I>&gt;<i> &gt;&gt; not sure what I can do with it once assigned back to secteam, aside from
</I>&gt;<i> &gt;&gt; write an advisory text. I don't have admin rights to release it, etc.
</I>&gt;<i> &gt;&gt; (afaik). It was basically my understanding that the secteam role is to
</I>&gt;<i> &gt;&gt; initiate the bug, provide patches, POC, and advisory text and the
</I>&gt;<i> &gt;&gt; maintainer do the update and pass it on to QA. I've stopped even
</I>&gt;<i> &gt;&gt; intiating because they are just sitting there in the new/unassigned
</I>&gt;<i> &gt;&gt; state. some for 2 months or more now. While a shiny new KDE is nice, not
</I>&gt;<i> &gt;&gt; pushing updates for published vulnerabilities makes us look bad, imho.
</I>&gt;<i> &gt; 
</I>&gt;<i> &gt; It's <A HREF="https://bugs.mageia.org/show_bug.cgi?id=2239">https://bugs.mageia.org/show_bug.cgi?id=2239</A>
</I>&gt;<i> &gt; 
</I>&gt;<i> &gt; I think the initial idea in the updates policy is that security fixes
</I>&gt;<i> &gt; have to be tested by secteam to ensure that the security problem is not
</I>&gt;<i> &gt; there anymore, because sometimes the upstream or the packager fixes it
</I>&gt;<i> &gt; in a wrong way or does a mistake, so we need to ensure the security
</I>&gt;<i> &gt; problems are really fixed. Otherwise we risk saying that a security
</I>&gt;<i> &gt; issue is fixed when it's not. Obviously, this can't happen if the
</I>&gt;<i> &gt; security team doesn't grow. Maybe some kind of joint effort from
</I>&gt;<i> &gt; security and QA could help ?
</I>&gt;<i> &gt; 
</I>&gt;<i> &gt; I already know updates that have been pushed without the security fixes
</I>&gt;<i> &gt; being tested.
</I>&gt;<i> &gt; 
</I>&gt;<i> &gt; Also, the security bugs being open in bugzilla and not adressed by the
</I>&gt;<i> &gt; packagers is a really big issue, that we have to find a way to fix as
</I>&gt;<i> &gt; soon as possible. Can you give us a link to the list of pending security
</I>&gt;<i> &gt; issues ?
</I>&gt;<i> 
</I>&gt;<i> While I don't disagree with the theory, it's not workable with the
</I>&gt;<i> current state, as I don't have enough free cycles to think about
</I>&gt;<i> actually updating any packages an/or doing the testing. One has to keep
</I>&gt;<i> in mind that in the past life this was nearly a full time job for 2
</I>&gt;<i> people to identify, fix build, test, release updates for the supported
</I>&gt;<i> releases. The people that have inquired about helping with security
</I>&gt;<i> issues quickly go away when they find out how inglorious(sic) it is.
</I>&gt;<i> 
</I>
What has been decided during latest packager meeting is that it's the QA team 
who will try to check that the security bugs are really fixed during QA testing 
(when it's possible), so that the security team doesn't need to do it and can 
concentrate on monitoring and finding about existing issues.

So the procedure is :
- security team identifies issues and creates bug reports
- packagers fix bugs
- QA team validates

This way I hope the security team work becomes doable with our current 
ressources. It means also that we need a real commitment from packagers. QA 
team is already ready and testing.

Best regards

Samuel Verschelde
</PRE>










<!--endarticle-->
    <HR>
    <P><UL>
        <!--threads-->
	<LI>Previous message: <A HREF="007801.html">[Mageia-dev] Copying dependencies to Updates (Testing),	or changing mgaapplet to use urpmi --auto-update instead of urpmi	--update.
</A></li>
	<LI>Next message: <A HREF="007738.html">[Mageia-dev] [RPM] cauldron core/release	bluedevil-1.2-0.rc2.1.mga2
</A></li>
         <LI> <B>Messages sorted by:</B> 
              <a href="date.html#7734">[ date ]</a>
              <a href="thread.html#7734">[ thread ]</a>
              <a href="subject.html#7734">[ subject ]</a>
              <a href="author.html#7734">[ author ]</a>
         </LI>
       </UL>

<hr>
<a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev
mailing list</a><br>
</body></html>