Bug#449497: foo2zjs: getweb script depends on non-free firmware

2008-10-31 Thread Michael Gilbert
i'll go ahead and start the discussion since no one else is running
with it.  this matter is rather urgent since the problem is now being
considered release-critical for lenny.  i see three possible courses
of action:

1.  ignore the problem:  mark the bug wontfix
rationalle:  the firmware fetching stuff is a small component of the
package and the debian policy is not explicitly clear on the matter
cons: leaves vector for possible security attacks and script can
become non-functional (e.g. getweb has been non-functional in over a
year in etch)

2.  fix the problem now:  either remove getweb completely or make a
separate foo2zjs-contrib package with just getweb, and have this ready
for the lenny release
rationalle: since getweb is a security risk and could break, it should
be eliminated
cons: less functionality for user.  some work for the maintainer.

3.  fix the problem later: same as above, but tag lenny-ignore
rationalle:  same as above, but with limited time, this is the least
path of resistance
cons: same as above, but leaves users vulnerable during the lenny time frame.

there is also the matter of whether the policy should be clarified for
this type of situation -- and whether all other cases of fetching
scripts should be tagged release-critical.  i will leave this for
further discussion since it isn't so urgent.

let me again stress that action is URGENT since this is
release-critical for lenny.

regards,
mike



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#503814: [Foo2zjs-maintainer] Bug#449497: foo2zjs: getweb script depends on non-free firmware

2008-10-31 Thread Luca Capello
Hi Michael!

Adding the d-release mailing list to cc:.

On Fri, 31 Oct 2008 13:41:25 +0100, Michael Gilbert wrote:
 i'll go ahead and start the discussion since no one else is running
 with it.  this matter is rather urgent since the problem is now being
 considered release-critical for lenny.
[...]
 let me again stress that action is URGENT since this is
 release-critical for lenny.

Can you please stop dealing with this bug and let the tech-ctte [1] do
their work?

About the urgency and lenny: the bug is marked as serious, which means
that if the tech-ctte does not fix it before lenny (something which I do
not think is going to happen), the Release Team must deal with it.

FYI, other people have already started to work on it, check the thread
on the d-ctte mailing list [2].

Thx, bye,
Gismo / Luca

Footnotes: 
[1] http://www.debian.org/devel/tech-ctte
[2] http://lists.debian.org/debian-ctte/2008/10/msg0.html


pgpldEY8q46y5.pgp
Description: PGP signature