[Pkg-samba-maint] Debian->Ubuntu flow for samba packages?

Steve Langasek vorlon at debian.org
Fri Jan 9 21:50:43 UTC 2009


On Wed, Jan 07, 2009 at 06:45:58AM +0100, Christian Perrier wrote:
> Quoting Steve Langasek (vorlon at debian.org):

> > 8.04 (== hardy) has 3.0.28a, so is not affected by this bug.
> > 8.10 (== intrepid) has 3.2.3, so is affected.  The USN for this issue has
> > already been published: http://www.ubuntu.com/usn

> I suppose this is handled by the Ubuntu Security Team in a similar way
> than we handle security updates in Debian, right?

It's handled by the Ubuntu Security Team, yes.  Since there are no
individual package maintainers in Ubuntu, other Ubuntu developers are
generally not in the loop on embargoed security updates.

> If I understand well the concept of LTS versions, once jaunty is out,
> no more security support will be provided for intrepid...or will it
> remains for some time ("some" being shorter than the delay for LTS
> versions)?

Security support for each non-LTS Ubuntu version is provided for 18 months
after release - so at any given time there are at least 3 Ubuntu releases
with security support for the "main" component.

> > jaunty will eventually be Ubuntu 9.04, and contains version
> > 2:3.2.5-3ubuntu1.  So getting the security fix into jaunty will require an

> How does *this* work? Is this automatic because 2:3.2.5-3 hit Debian
> unstable? Being subscribed to the PTS, I should then get a mail from
> samba_derivatives at packages.qa.debian.org, which I didn't get....

No, merges are always done manually.  Syncs are done automatically, up until
the "Debian Import Freeze" each cycle; after which they're done only in
response to specific acknowledgement by an Ubuntu developer.

Considering the reliability of code merge algorithms in general, I don't
think we would ever have automatic merges even in theory. :)

-- 
Steve Langasek                   Give me a lever long enough and a Free OS
Debian Developer                   to set it on, and I can move the world.
Ubuntu Developer                                    http://www.debian.org/
slangasek at ubuntu.com                                     vorlon at debian.org



More information about the Pkg-samba-maint mailing list