Bug#859122: 31 DLAs missing from the website
Holger Levsen writes: > the script disagrees on DLA 607-1 and 377-1 and indeed > https://www.debian.org/lts/security/2016/dla-607 does not exist. > while https://www.debian.org/lts/security/2016/dla-377 does (which > matches debian-www.git) > > do you know what's up with DLA-607? Oops. I looked at it, then forgot to finish. See https://salsa.debian.org/webmaster-team/webwml/merge_requests/222 Not sure why you referenced dla-377 - is there something wrong with this one? -- Brian May
Bug#859122: 31 DLAs missing from the website
On Thu, Aug 22, 2019 at 05:38:18PM +1000, Brian May wrote: > I believe all of these have now been resolved. and YAY! (& sorry I forgot that in my previous mail!) signature.asc Description: PGP signature
Bug#859122: 31 DLAs missing from the website
control: retitle -1 1 DLA missing from the website (or not) thanks Hi Brian, On Thu, Aug 22, 2019 at 05:38:18PM +1000, Brian May wrote: > On Wed, Aug 14, 2019 at 11:16:50AM +, Holger Levsen wrote: > > ~/Projects/debian-www/webwml$ ../cron/parts/10-check-advisories --mode DLA > > 2>&1 > > ERROR: .data or .wml file missing for DLA 1885-1 > > ERROR: .data or .wml file missing for DLA 1884-1 > > ERROR: .data or .wml file missing for DLA 1879-1 > > ERROR: .data or .wml file missing for DLA 1877-1 > > ERROR: .data or .wml file missing for DLA 1871-1 > > ERROR: .data or .wml file missing for DLA 1846-2 > > ERROR: .data or .wml file missing for DLA 1833-2 > > ERROR: .data or .wml file missing for DLA 1784-1 > > ERROR: .data or .wml file missing for DLA 607-1 > > ERROR: .data or .wml file missing for DLA 567-1 > > ERROR: .data or .wml file missing for DLA 377-1 > > ERROR: .data or .wml file missing for DLA 267-1 > > ERROR: .data or .wml file missing for DLA 115-2 > > ERROR: .data or .wml file missing for DLA 145-2 > > I believe all of these have now been resolved. the script disagrees on DLA 607-1 and 377-1 and indeed https://www.debian.org/lts/security/2016/dla-607 does not exist. while https://www.debian.org/lts/security/2016/dla-377 does (which matches debian-www.git) do you know what's up with DLA-607? -- cheers, Holger --- holger@(debian|reproducible-builds|layer-acht).org PGP fingerprint: B8BF 5413 7B09 D35C F026 FE9D 091A B856 069A AA1C signature.asc Description: PGP signature
Bug#859122: 31 DLAs missing from the website
On Wed, Aug 14, 2019 at 11:16:50AM +, Holger Levsen wrote: > ~/Projects/debian-www/webwml$ ../cron/parts/10-check-advisories --mode DLA > 2>&1 > ERROR: .data or .wml file missing for DLA 1885-1 > ERROR: .data or .wml file missing for DLA 1884-1 > ERROR: .data or .wml file missing for DLA 1879-1 > ERROR: .data or .wml file missing for DLA 1877-1 > ERROR: .data or .wml file missing for DLA 1871-1 > ERROR: .data or .wml file missing for DLA 1846-2 > ERROR: .data or .wml file missing for DLA 1833-2 > ERROR: .data or .wml file missing for DLA 1784-1 > ERROR: .data or .wml file missing for DLA 607-1 > ERROR: .data or .wml file missing for DLA 567-1 > ERROR: .data or .wml file missing for DLA 377-1 > ERROR: .data or .wml file missing for DLA 267-1 > ERROR: .data or .wml file missing for DLA 115-2 > ERROR: .data or .wml file missing for DLA 145-2 I believe all of these have now been resolved. -- Brian May
Bug#859122: 31 DLAs missing from the website
Hi Brian, thanks for caring about this old information! On Thu, Aug 15, 2019 at 05:31:51PM +1000, Brian May wrote: > Where to from here? Should I invent an appropriate DLA-145-2 based on > the information above? yes, that seems very reasonable. -- tschau, cheers, Holger --- holger@(debian|reproducible-builds|layer-acht).org PGP fingerprint: B8BF 5413 7B09 D35C F026 FE9D 091A B856 069A AA1C signature.asc Description: PGP signature
Bug#859122: 31 DLAs missing from the website
Holger Levsen writes: > ERROR: .data or .wml file missing for DLA 145-2 Hmm. Looks like that really should exist, and point to next version 5.3.3-7+squeeze25 (DLA-145-1 points to 5.3.3-7+squeeze24) Here is the relevant information I can find: commit f225a141ff91e4790ef74f00893cf29c2521eff6 Author: Thorsten Alteholz Date: Mon Feb 2 16:30:14 2015 + DLA-145-1 php5 regression update git-svn-id: svn+ssh://svn.debian.org/svn/secure-testing@31913 e39458fd-73e7-0310-bf30-c45bca0a0e42 diff --git a/data/DLA/list b/data/DLA/list index efe2117968..abf5a895cd 100644 --- a/data/DLA/list +++ b/data/DLA/list @@ -1,3 +1,5 @@ +[02 Feb 2015] DLA-145-2 php5 - regression update + [squeeze] - php5 5.3.3-7+squeeze25 [31 Jan 2015] DLA-145-1 php5 - security update {CVE-2014-0237 CVE-2014-0238 CVE-2014-2270 CVE-2014-8117} [squeeze] - php5 5.3.3-7+squeeze24 php5 (5.3.3-7+squeeze25) squeeze-lts; urgency=high * Non-maintainer upload by the Squeeze LTS Team. * as the patch for PHP bug 68739 seems to break cURL cookie handling it is removed again in this version, CVE-2015-TEMP-1.patch is affected (bug report can be found in: https://lists.debian.org/debian-lts/2015/02/msg7.html) -- Thorsten Alteholz Mon, 02 Feb 2015 14:17:00 +0100 * https://bugs.php.net/bug.php?id=68739: upstream bug. * https://lists.debian.org/debian-lts/2015/02/msg7.html contains technical information on the regression. So it looks like the fix was reverted, which means in turn means that CVE-2015-TEMP-1 was not fixed despite DLA 145-1 declaring otherwise, however no point worrying about that now :-) Where to from here? Should I invent an appropriate DLA-145-2 based on the information above? -- Brian May
Bug#859122: 31 DLAs missing from the website
Hi Brian, On Wed, Aug 14, 2019 at 05:16:46PM +1000, Brian May wrote: > On Mon, Apr 15, 2019 at 12:06:35PM +, Holger Levsen wrote: > > many thanks for all your fixes on this bug! > Can you please rerun the command: > ~/Projects/debian-www/webwml$ ../cron/parts/10-check-advisories --mode DLA ~/Projects/debian-www/webwml$ ../cron/parts/10-check-advisories --mode DLA 2>&1 ERROR: .data or .wml file missing for DLA 1885-1 ERROR: .data or .wml file missing for DLA 1884-1 ERROR: .data or .wml file missing for DLA 1879-1 ERROR: .data or .wml file missing for DLA 1877-1 ERROR: .data or .wml file missing for DLA 1871-1 ERROR: .data or .wml file missing for DLA 1846-2 ERROR: .data or .wml file missing for DLA 1833-2 ERROR: .data or .wml file missing for DLA 1784-1 ERROR: .data or .wml file missing for DLA 607-1 ERROR: .data or .wml file missing for DLA 567-1 ERROR: .data or .wml file missing for DLA 377-1 ERROR: .data or .wml file missing for DLA 267-1 ERROR: .data or .wml file missing for DLA 115-2 ERROR: .data or .wml file missing for DLA 145-2 > I am loosing track of which DLAs are still missing, and it looks like > I can't run that command myself. it's not merged into master but it's only in MR#1 for the cron.git repo of debian-www... Thanks for looking into this again! -- cheers, Holger --- holger@(debian|reproducible-builds|layer-acht).org PGP fingerprint: B8BF 5413 7B09 D35C F026 FE9D 091A B856 069A AA1C signature.asc Description: PGP signature
Bug#859122: 31 DLAs missing from the website
On Mon, Apr 15, 2019 at 12:06:35PM +, Holger Levsen wrote: > many thanks for all your fixes on this bug! Can you please rerun the command: ~/Projects/debian-www/webwml$ ../cron/parts/10-check-advisories --mode DLA I am loosing track of which DLAs are still missing, and it looks like I can't run that command myself. Thanks -- Brian May
Bug#859122: 31 DLAs missing from the website
control: retitle -1 7 DLAs missing from the website (or not) thanks Hi Brian, many thanks for all your fixes on this bug! On Fri, Apr 12, 2019 at 04:03:25PM +1000, Brian May wrote: > > ERROR: .data or .wml file missing for DLA 1130-1 > > ERROR: .data or .wml file missing for DLA 719-1 > > ERROR: .data or .wml file missing for DLA 706-1 > > ERROR: .data or .wml file missing for DLA 659-1 > Looks like these are all mine, I have copies of the outgoing emails, but > from my private mail archives, not in the public web archive. So I guess > that means I am the only one who can fix these :-) and you did. Many thanks for that! > > ERROR: .data or .wml file missing for DLA 772-1 this one has been dealt with > > ERROR: .data or .wml file missing for DLA 607-1 > > ERROR: .data or .wml file missing for DLA 567-1 > > ERROR: .data or .wml file missing for DLA 377-1 > > ERROR: .data or .wml file missing for DLA 267-1 > > ERROR: .data or .wml file missing for DLA 115-2 > > ERROR: .data or .wml file missing for DLA 145-2 > I can't actually find these - or anything like them - in the mailing > list archives or on my computer. I believe those DLAs were allocated but never used. We will need to double check and then probably provide dummy/empty DLAs documenting this. > * I can find DLA-567-2 but not a DLA-567-1; I suspect DLA-567-2 was sent > instead of DLA-567-1. fun ;) > > ERROR: .data or .wml file missing for DLA 580-1 > > I suspect that might be this email: > > Date: Mon, 1 Aug 2016 12:05:55 +0200 > From: Balint Reczey > Subject: [SECURITY] [REGRESSION] [DLA -] graphite2 regression update > To: debian-lts-annou...@lists.debian.org > Mail-Followup-To: debian-...@lists.debian.org > > Source: https://lists.debian.org/debian-lts-announce/2016/08/msg0.html > > Impossible to mark a positive identication, however the email was sent > after DLA-578-1, before DLA-582-1, and the package name matches, and the > security tracker has similar title. seems like DLA 580 indeed. -- tschau, Holger --- holger@(debian|reproducible-builds|layer-acht).org PGP fingerprint: B8BF 5413 7B09 D35C F026 FE9D 091A B856 069A AA1C signature.asc Description: PGP signature
Bug#859122: 31 DLAs missing from the website
Holger Levsen writes: > ~/Projects/debian-www/webwml$ ../cron/parts/10-check-advisories --mode DLA > ERROR: .data or .wml file missing for DLA 1685-1 > ERROR: .data or .wml file missing for DLA 1684-1 > ERROR: .data or .wml file missing for DLA 1683-1 > ERROR: .data or .wml file missing for DLA 1682-1 I haven't look at these. > ERROR: .data or .wml file missing for DLA 1130-1 > ERROR: .data or .wml file missing for DLA 719-1 > ERROR: .data or .wml file missing for DLA 706-1 > ERROR: .data or .wml file missing for DLA 659-1 Looks like these are all mine, I have copies of the outgoing emails, but from my private mail archives, not in the public web archive. So I guess that means I am the only one who can fix these :-) > ERROR: .data or .wml file missing for DLA 772-1 > ERROR: .data or .wml file missing for DLA 607-1 > ERROR: .data or .wml file missing for DLA 567-1 > ERROR: .data or .wml file missing for DLA 377-1 > ERROR: .data or .wml file missing for DLA 267-1 > ERROR: .data or .wml file missing for DLA 115-2 > ERROR: .data or .wml file missing for DLA 145-2 I can't actually find these - or anything like them - in the mailing list archives or on my computer. * I can find DLA-567-2 but not a DLA-567-1; I suspect DLA-567-2 was sent instead of DLA-567-1. > ERROR: .data or .wml file missing for DLA 580-1 I suspect that might be this email: Date: Mon, 1 Aug 2016 12:05:55 +0200 From: Balint Reczey Subject: [SECURITY] [REGRESSION] [DLA -] graphite2 regression update To: debian-lts-annou...@lists.debian.org Mail-Followup-To: debian-...@lists.debian.org Source: https://lists.debian.org/debian-lts-announce/2016/08/msg0.html Impossible to mark a positive identication, however the email was sent after DLA-578-1, before DLA-582-1, and the package name matches, and the security tracker has similar title. I can't find the original DLA that caused the breakage however. I also noticed this other email without a DLA: https://lists.debian.org/debian-lts-announce/2016/08/msg00010.html As far as I can tell, this one may not actually have a DLA. > ERROR: .data or .wml file missing for DLA 0015-1 > ERROR: .data or .wml file missing for DLA 0014-1 > ERROR: .data or .wml file missing for DLA 0013-1 > ERROR: .data or .wml file missing for DLA 0012-1 > ERROR: .data or .wml file missing for DLA 0011-1 > ERROR: .data or .wml file missing for DLA 0010-1 > ERROR: .data or .wml file missing for DLA 0009-1 > ERROR: .data or .wml file missing for DLA 0008-1 > ERROR: .data or .wml file missing for DLA 0007-1 > ERROR: .data or .wml file missing for DLA 0006-1 > ERROR: .data or .wml file missing for DLA 0005-1 > ERROR: .data or .wml file missing for DLA 0004-1 > ERROR: .data or .wml file missing for DLA 0003-1 > ERROR: .data or .wml file missing for DLA 0002-1 > ERROR: .data or .wml file missing for DLA 0001-1 These are fixed. -- Brian May
Bug#859122: 31 DLAs missing from the website
control: tags -1 - patch control: retitle -1 31 DLAs missing from the website thanks Hi, due to the work of mostly Antoine and Laura, over 1600 DLAs are now visible on www.debian.org/lts - this is pretty awesome IMO! A few are still missing however: ~/Projects/debian-www/webwml$ ../cron/parts/10-check-advisories --mode DLA ERROR: .data or .wml file missing for DLA 1685-1 ERROR: .data or .wml file missing for DLA 1684-1 ERROR: .data or .wml file missing for DLA 1683-1 ERROR: .data or .wml file missing for DLA 1682-1 ERROR: .data or .wml file missing for DLA 1130-1 ERROR: .data or .wml file missing for DLA 772-1 ERROR: .data or .wml file missing for DLA 719-1 ERROR: .data or .wml file missing for DLA 706-1 ERROR: .data or .wml file missing for DLA 659-1 ERROR: .data or .wml file missing for DLA 607-1 ERROR: .data or .wml file missing for DLA 580-1 ERROR: .data or .wml file missing for DLA 567-1 ERROR: .data or .wml file missing for DLA 377-1 ERROR: .data or .wml file missing for DLA 267-1 ERROR: .data or .wml file missing for DLA 115-2 ERROR: .data or .wml file missing for DLA 145-2 ERROR: .data or .wml file missing for DLA 0015-1 ERROR: .data or .wml file missing for DLA 0014-1 ERROR: .data or .wml file missing for DLA 0013-1 ERROR: .data or .wml file missing for DLA 0012-1 ERROR: .data or .wml file missing for DLA 0011-1 ERROR: .data or .wml file missing for DLA 0010-1 ERROR: .data or .wml file missing for DLA 0009-1 ERROR: .data or .wml file missing for DLA 0008-1 ERROR: .data or .wml file missing for DLA 0007-1 ERROR: .data or .wml file missing for DLA 0006-1 ERROR: .data or .wml file missing for DLA 0005-1 ERROR: .data or .wml file missing for DLA 0004-1 ERROR: .data or .wml file missing for DLA 0003-1 ERROR: .data or .wml file missing for DLA 0002-1 ERROR: .data or .wml file missing for DLA 0001-1 I suppose we should be able to fix those as well ;) -- tschau, Holger --- holger@(debian|reproducible-builds|layer-acht).org PGP fingerprint: B8BF 5413 7B09 D35C F026 FE9D 091A B856 069A AA1C In Europe there are people prosecuted by courts because they saved other people from drowning in the Mediterranean Sea. That is almost as absurd as if there were people being prosecuted because they save humans from drowning in the sea. signature.asc Description: PGP signature