[Bug 1947174] Re: Add final-checks to check certificates

2021-11-15 Thread Dimitri John Ledkov
** Changed in: linux (Ubuntu) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1947174 Title: Add final-checks to check certificates To manage

[Bug 1921518] Re: OpenSSL "double free" error

2021-11-12 Thread Dimitri John Ledkov
> How will you test that the change does not regress any wget behavior? In default Ubuntu configuration, either no openssl configuration is provided, or it contains no settings that affect wget. This code path changes how/when openssl configuration is loaded and used by openssl. One should

[Bug 1940528] Re: curl 7.68 does not init OpenSSL correctly

2021-11-12 Thread Dimitri John Ledkov
Not only patch was missing, it was partially missing. reuploading again. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1940528 Title: curl 7.68 does not init OpenSSL correctly To manage

[Bug 1940528] Re: curl 7.68 does not init OpenSSL correctly

2021-11-12 Thread Dimitri John Ledkov
Reuploaded curl into focal proposed, with series fix & on top of security upload that has happened since. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1940528 Title: curl 7.68 does not init

[Bug 1940656] Re: Potential use after free bugs in 1.1.1

2021-11-12 Thread Dimitri John Ledkov
** Tags removed: verification-needed verification-needed-focal ** Tags added: verification-done verification-done-focal -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1940656 Title: Potential use

[Bug 1940656] Re: Potential use after free bugs in 1.1.1

2021-11-12 Thread Dimitri John Ledkov
I currently do not have a more regular smartcard setup to test out a hardware pk11 engine with openssl, which is typically the most common one. But I can use software gost engine to test out that algos provided by the engine operate correctly. Installed openssl from proposed, and gost engine. $

[Bug 1949603] Re: iptables-save -c shows incorrect counters with iptables-nft

2021-11-12 Thread Dimitri John Ledkov
In addition to the changelog versions it seems to me that the debdiff is potentially a bit missleading: 1) the shell testcases are not executed neither during build, nor during autopkgtest. As they seem to need root, it would be nice to add autopkgtest that would do: cd iptables/tests/shell;

[Bug 1949603] Re: iptables-save -c shows incorrect counters with iptables-nft

2021-11-12 Thread Dimitri John Ledkov
The proposed patch looks ok. The version numbers are interesting. Impish release is at 1.8.7-1ubuntu2, and impish upload 1.8.7-1ubuntu3 got only published into Jammy. So the correct version numbers to use will be ubuntu4 for jammy and 2.1 for impish, I will correct that for SRU. -- You

[Bug 1928244] Re: pahole: FAILED unresolved symbol cubictcp_state with linux 5.13

2021-11-11 Thread Dimitri John Ledkov
Verified in https://bugs.launchpad.net/ubuntu/+source/dwarves- dfsg/+bug/1912811 this bug was referenced in the backport changelog. ** Tags removed: verification-needed verification-needed-bionic ** Tags added: verification-done verification-done-bionic -- You received this bug notification

[Bug 1940656] Re: Potential use after free bugs in 1.1.1

2021-11-11 Thread Dimitri John Ledkov
There is now only a transient ADT regression in Regression in linux- hwe-5.13 (armhf), which is not a valid ADT because armhf ADT runs in lxd containers and does not boot the requested kernel. Please release this package. -- You received this bug notification because you are a member of Ubuntu

[Bug 1950283] Re: r-base: gfortran and gcc disagree on double complex

2021-11-09 Thread Dimitri John Ledkov
https://launchpad.net/ubuntu/+source/r-base/4.1.2-1ubuntu1 ** Changed in: r-base (Ubuntu) Status: New => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1950283 Title: r-base:

[Bug 1912811] Re: Update dwarves-dfsg in focal to version 1.21 from impish

2021-11-06 Thread Dimitri John Ledkov
Built linux-hwe-5.4 in bionic with BTF enabled and proposed enabled: Build used dwarves (= 1.21-0ubuntu1~18.04) $ zgrep BTF buildlog_ubuntu-bionic-amd64.linux-hwe-5.4_5.4.0-90.101~18.04.1_BUILDING.txt.gz BTF .btf.vmlinux.bin.o BTF .btf.vmlinux.bin.o BTF turned on correctly. See

[Bug 1934424] Re: kernel NULL pointer dereference during xen hibernation

2021-11-05 Thread Dimitri John Ledkov
We already ship lib/systemd/system-sleep/hibinit-agent that does post things in hibinit-resume to workaround things. Including stuff about networking, due to previous issues with xen-netfront. Given we already restart systemd-networkd, I wonder if we should do better and not keep xen-netfront

[Bug 1943963] Re: patchelf creates unloadable non-PIE riscv64 executables

2021-11-05 Thread Dimitri John Ledkov
I think this is now fixed in snapcraft. ** Changed in: snapcraft Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1943963 Title: patchelf creates unloadable

[Bug 1903288] Re: Power guest secure boot with static keys: kernel portion

2021-11-05 Thread Dimitri John Ledkov
Added my own review https://lore.kernel.org/linux- integrity/8d7e1609-f77e-834e-cf40-05e19bbc3...@canonical.com/ A few optional comments; and one required change needed to add one more ifdef. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 1926330] Re: HWE kernels should support eBPF CO-RE

2021-11-04 Thread Dimitri John Ledkov
Note that dwarves-dfsg portion of this request was done a while back in https://bugs.launchpad.net/ubuntu/+source/dwarves-dfsg/+bug/1912811 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1926330

[Bug 1949286] Re: [MIR]: Include dwarves-dfsg-hwe package into Bionic and Focal

2021-11-04 Thread Dimitri John Ledkov
NAK we have backported dwarves-dfsg to bionic and up with support for pahole which is now in use by kernel builds to enable CONFIG_DEBUG_INFO_BTF in them. The backports were done in https://bugs.launchpad.net/ubuntu/+source/dwarves-dfsg/+bug/1912811 Why do we need pahole-btf? Given that

[Bug 1942319] Re: When booting with UEFI, mokvar table and %:.platform keyring must be available

2021-11-03 Thread Dimitri John Ledkov
Booted impish lxd vm; enabled proposed and upgraded to the new kvm abi: # uname -a Linux leading-fly 5.13.0-1005-kvm #5-Ubuntu SMP Tue Oct 26 23:55:45 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux # ls /sys/firmware/efi/mok-variables/ MokListRT MokListXRT SbatLevelRT # keyctl list %:.blacklist |

[Bug 1942319] Re: When booting with UEFI, mokvar table and %:.platform keyring must be available

2021-11-02 Thread Dimitri John Ledkov
failing to get lxd to work to verify this. will try again tomorrow. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1942319 Title: When booting with UEFI, mokvar table and %:.platform keyring must be

[Bug 1945757] Re: sysdig-dkms fails to build on arm64 - kernel 5.13

2021-11-02 Thread Dimitri John Ledkov
sysdig (0.27.1-0.2ubuntu1) impish; urgency=medium * Fix syscall table base ID on arm64 (LP: #1945757) -- Andrea Righi Fri, 01 Oct 2021 11:20:07 +0200 ** Package changed: linux-oem-5.6 (Ubuntu) => sysdig (Ubuntu) ** Changed in: sysdig (Ubuntu Impish) Status: Fix Committed => Fix

[Bug 1948040] [NEW] modprobe.d is not honored on uc20

2021-10-21 Thread Dimitri John Ledkov
Public bug reported: Ubuntu kernels by default ship modprobe.d that excludes many modules from loading: # Kernel supplied blacklist for linux 5.4.0-89-generic amd64 # modprobe.d/common.conf # LP:1434842 -- disable OSS drivers by default to allow pulseaudio to emulate blacklist snd-mixer-oss

[Bug 1946965] Re: python3-defaults: py3versions -i does not list python3.10 when it is installed

2021-10-20 Thread Dimitri John Ledkov
Is this needed in focal too? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1946965 Title: python3-defaults: py3versions -i does not list python3.10 when it is installed To manage notifications

[Bug 1942260] Re: compress firmware in /lib/firmware

2021-10-19 Thread Dimitri John Ledkov
** Also affects: linux-firmware-raspi2 (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1942260 Title: compress firmware in /lib/firmware To

[Bug 1947721] [NEW] shellcheck has regressions

2021-10-19 Thread Dimitri John Ledkov
Public bug reported: https://github.com/koalaman/shellcheck/commit/fbc8d2cb2f8070f820c9337851bb97478e40e710 is a fix for a regression in 0.7.2 release Imho either we should stick with current shellcheck or package a newer snapshot / cherry-picks of fixes? ** Affects: shellcheck (Ubuntu)

[Bug 1932329] Re: Benchmark if we can compress kernel modules

2021-10-19 Thread Dimitri John Ledkov
** Also affects: initramfs-tools (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1932329 Title: Benchmark if we can compress kernel modules To

[Bug 1942260] Re: compress firmware in /lib/firmware

2021-10-19 Thread Dimitri John Ledkov
** Also affects: initramfs-tools (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1942260 Title: compress firmware in /lib/firmware To manage

[Bug 1947581] [NEW] Download times for 1Mbit DSL connection and 56k modem are meaningless

2021-10-18 Thread Dimitri John Ledkov
Public bug reported: """ You have to download a total of 5276 M. This download will take about 11 hours with a 1Mbit DSL connection and about 8 days 12 hours with a 56k modem. """ Are meaningless. On 4G connectivity one can get stable 4-6 Mbit, developing world speeds are 8-10 Mbit range, and

[Bug 1671536] Re: Default initrd is LZMA compressed, yet rebuilt initramfs are gzip?

2021-10-18 Thread Dimitri John Ledkov
I believe livecd-rootfs and live-build have been fixed for this. ** Changed in: cloud-images Status: New => Fix Released ** Changed in: initramfs-tools (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1944082] Re: initramfs-tools: zstd uses too much memory in mkinitramfs

2021-10-18 Thread Dimitri John Ledkov
In general we optimize for bootspeed, at the expense of generation time. It is often the case that we can complete the boot on systems smaller than required to recreate files for such boot. I.e. impossible to install/upgrade packages. Are you experiencing failure to create initrd, where

[Bug 1941649] Re: switch to zstd by default breaks booting focal LTS kernel

2021-10-18 Thread Dimitri John Ledkov
partial upgrades are not supported, and during upgrades we generally do not recreate initrds for old kernels. Meaning one should have at least .old kernel+initrd pair bootable. It is more of linux bug maybe that v5.4 does not support zstd compressed initrd? -- You received this bug

[Bug 1947043] Re: nvidia drivers do not update initramfs properly

2021-10-14 Thread Dimitri John Ledkov
Why are you using dkms modules, instead of signed lrm modules? ** Also affects: linux-restricted-modules (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1947174] [NEW] Add final-checks to check certificates

2021-10-14 Thread Dimitri John Ledkov
Public bug reported: [Impact] * As part of landing builtin revocation certificates work https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1932029 it has been identified that many kernels do not correct enforce newly enfoced keys in the derivative flavours. I.e. due to annotations not

[Bug 1840122] Re: System fails to reboot from live session or ubiquity-dm - squashfs_read_data failed to read block

2021-10-13 Thread Dimitri John Ledkov
I wonder if we need before= or after= umount.target -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1840122 Title: System fails to reboot from live session or ubiquity-dm - squashfs_read_data

[Bug 1840122] Re: System fails to reboot from live session or ubiquity-dm - squashfs_read_data failed to read block

2021-10-13 Thread Dimitri John Ledkov
Our installer could stop finalrd before issuing shutdown too, as a workaround. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1840122 Title: System fails to reboot from live session or ubiquity-dm -

[Bug 1840122] Re: System fails to reboot from live session or ubiquity-dm - squashfs_read_data failed to read block

2021-10-13 Thread Dimitri John Ledkov
we should check ordering of services for stop in a booted live session (desktop / server / next-installer) and then figure out if we can add additional dependencies to finalr.service (after) such that its stop is ordered before everything else is stopped. ** Also affects: finalrd (Ubuntu)

[Bug 1946642] Re: nvidia-graphics-drivers-390 ftbfs on armhf

2021-10-13 Thread Dimitri John Ledkov
https://objectstorage.prodstack4-5.canonical.com/v1/AUTH_39a8dbb93caf4ec889f8a1b7f69885db/bileto-4684/2021-10-12_16:41:27/impish_nvidia- graphics-drivers-390_content.diff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1946808] Re: zfs fails reverting to a previous snapshot on reboot when selected on grub

2021-10-13 Thread Dimitri John Ledkov
** Description changed: [Impact] - * zfs fails reverting to a previous snapshot on reboot when selected on +  * zfs fails reverting to a previous snapshot on reboot when selected on grub - * A miss-merge dropped initramfs hook changes, which result in failing +  * A miss-merge dropped

[Bug 1946808] Re: zfs fails reverting to a previous snapshot on reboot when selected on grub

2021-10-13 Thread Dimitri John Ledkov
Also I wonder if: grep -a -m10 -E "\*" /dev/urandom 2>/dev/null | tr -dc 'a-z0-9' | cut -c-6 can be implemented as: cut -c-6 /proc/sys/kernel/random/uuid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1946808] Re: zfs fails reverting to a previous snapshot on reboot when selected on grub

2021-10-13 Thread Dimitri John Ledkov
** Description changed: + [Impact] + + * zfs fails reverting to a previous snapshot on reboot when selected on + grub + + * A miss-merge dropped initramfs hook changes, which result in failing + to generate and use a new zfs uid. + + [Test Plan] + + * Create snapshot with $ zsysctl save

[Bug 1946808] Re: zfs fails reverting to a previous snapshot on reboot when selected on grub

2021-10-13 Thread Dimitri John Ledkov
** Also affects: zfs-linux (Ubuntu Impish) Importance: Critical Assignee: Dimitri John Ledkov (xnox) Status: Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1946808 Title: zfs

[Bug 1933826] Re: default file permissions on bootloader configuration

2021-10-12 Thread Dimitri John Ledkov
I am still confused how 400 permission for grub.cfg can work at all. Depending on the upstream grub version, it either cats things to it, or moves a new file to it. In both cases, either permissions reset to 600 or write is not allowed at all. Or one has custom/distro/downstream patched grub that

[Bug 1939287] Re: dbgsym package is missing for ubuntu focal hwe kernel 5.11 & 5.13

2021-10-12 Thread Dimitri John Ledkov
To fix this on hwe-5.11 all of https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1930713 needs to be backported. Given that hwe-5.11 will be rolled over to hwe-5.13 soon, I am not sure if it is worth the effort. ** Changed in: linux-hwe-5.11 (Ubuntu Focal) Status: Confirmed => Won't Fix

[Bug 1939287] Re: dbgsym package is missing for ubuntu focal hwe kernel 5.11

2021-10-12 Thread Dimitri John Ledkov
The bug was committed for the linux-hwe-5.13 kernel in proposed: linux-image-5.13.0-17-generic-dbgsym_5.13.0-17.17~20.04.1_armhf.ddeb (937.5 MiB) linux-image-5.13.0-17-generic-lpae-dbgsym_5.13.0-17.17~20.04.1_armhf.ddeb (923.4 MiB)

[Bug 1946642] Re: nvidia-graphics-drivers-390 ftbfs on armhf

2021-10-12 Thread Dimitri John Ledkov
That also does not work, due to: /var/lib/dkms/nvidia/390.144/build/nvidia-modeset/nvidia-modeset-linux.c:72:5: note: in expansion of macro ‘do_div’ 72 | do_div(result, 100); ./include/asm-generic/div64.h:245:36: error: passing argument 1 of ‘__div64_32’ from incompatible pointer

[Bug 1946642] Re: nvidia-graphics-drivers-390 ftbfs on armhf

2021-10-11 Thread Dimitri John Ledkov
** Patch added: "lp1946642.patch" https://bugs.launchpad.net/ubuntu/+source/nvidia-graphics-drivers-390/+bug/1946642/+attachment/5531917/+files/lp1946642.patch -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1946642] Re: nvidia-graphics-drivers-390 ftbfs on armhf

2021-10-11 Thread Dimitri John Ledkov
Testing in https://bileto.ubuntu.com/#/ticket/4681 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1946642 Title: nvidia-graphics-drivers-390 ftbfs on armhf To manage notifications about this bug go

[Bug 1946642] Re: nvidia-graphics-drivers-390 ftbfs on armhf

2021-10-11 Thread Dimitri John Ledkov
That failed, missed one more place. Retesting. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1946642 Title: nvidia-graphics-drivers-390 ftbfs on armhf To manage notifications about this bug go to:

[Bug 1946642] Re: nvidia-graphics-drivers-390 ftbfs on armhf

2021-10-11 Thread Dimitri John Ledkov
Testing patch in https://launchpad.net/~ci-train-ppa- service/+archive/ubuntu/4680 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1946642 Title: nvidia-graphics-drivers-390 ftbfs on armhf To manage

[Bug 1946642] Re: nvidia-graphics-drivers-390 ftbfs on armhf

2021-10-11 Thread Dimitri John Ledkov
** Patch added: "lp1946642.patch" https://bugs.launchpad.net/ubuntu/+source/nvidia-graphics-drivers-390/+bug/1946642/+attachment/5531904/+files/lp1946642.patch -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1946642] [NEW] nvidia-graphics-drivers-390 ftbfs on armhf

2021-10-11 Thread Dimitri John Ledkov
Public bug reported: nvidia-graphics-drivers-390 ftbfs on armhf In file included from /var/lib/dkms/nvidia/390.144/build/nvidia/os-interface.c:16: /var/lib/dkms/nvidia/390.144/build/nvidia/os-interface.c: In function ‘os_flush_cpu_write_combine_buffer’:

[Bug 1946343] Re: Stale os-release file after possible upgrade from 20.04.2 to 20.04.3

2021-10-08 Thread Dimitri John Ledkov
It looks like it is this platform: http://oem.archive.canonical.com/dists/focal-somerville-bulbasaur/ But I don't see any packages called oem-release or where they came from. Dear reporter, what's the output of: $ apt-cache policy oem-release ? ** Also affects: dell Importance: Undecided

[Bug 1946343] Re: Stale os-release file after possible upgrade from 20.04.2 to 20.04.3

2021-10-08 Thread Dimitri John Ledkov
** Also affects: oem-priority Importance: Undecided Status: New ** Changed in: oem-priority Importance: Undecided => Critical -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1946343

[Bug 1946001] Re: impish:linux-aws 5.13 panic during systemd autotest

2021-10-07 Thread Dimitri John Ledkov
** Also affects: ubuntu-release-notes Importance: Undecided Status: New ** Changed in: linux-aws (Ubuntu Impish) Milestone: None => ubuntu-21.10 ** Tags added: rls-ff-incoming -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 1945757] Re: sysdig-dkms fails to build on arm64 - kernel 5.13

2021-10-05 Thread Dimitri John Ledkov
** Changed in: linux-oem-5.6 (Ubuntu Impish) Status: New => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1945757 Title: sysdig-dkms fails to build on arm64 - kernel 5.13 To

[Bug 1941720] Re: openafs dkms: FTBFS for linux-hwe-5.13

2021-10-05 Thread Dimitri John Ledkov
** Changed in: openafs (Ubuntu) Status: New => Fix Released ** Changed in: openafs (Ubuntu Focal) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1941720

[Bug 1941616] Re: rtl8821ce dkms: FTBFS for linux-hwe-5.13

2021-10-05 Thread Dimitri John Ledkov
Whitespace change is redundant, but it was made in the upstream commit, meaning any future cherrypicks will continue to be clean. ** Changed in: rtl8821ce (Ubuntu) Status: New => Fix Released ** Changed in: rtl8821ce (Ubuntu Focal) Status: New => In Progress -- You received this

[Bug 1941187] Re: gost-crypto dkms: FTBFS for linux-hwe-5.13

2021-10-05 Thread Dimitri John Ledkov
** Changed in: gost-crypto (Ubuntu Focal) Status: New => In Progress ** Changed in: gost-crypto (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1941071] Re: dm-writeboost dkms: FTBFS for linux-hwe-5.13

2021-10-05 Thread Dimitri John Ledkov
** Changed in: dm-writeboost (Ubuntu Focal) Status: New => In Progress ** Changed in: dm-writeboost (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1945784] Re: tp-smapi build failure on arm64 with the latest impish kernel

2021-10-05 Thread Dimitri John Ledkov
** Changed in: tp-smapi (Ubuntu Impish) Status: New => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1945784 Title: tp-smapi build failure on arm64 with the latest impish

[Bug 1942319] Re: When booting with UEFI, mokvar table and %:.platform keyring must be available

2021-10-05 Thread Dimitri John Ledkov
** Description changed: - When booting with UEFI, mokvar table and %:.platform keyring must be - available + [Impact] + + * When booting with UEFI, mokvar table and %:.platform keyring must be + available. These are required for builtin revocation certificates to be + present, shim builtin

[Bug 1912811] Re: Update dwarves-dfsg in focal to version 1.21 from impish

2021-10-04 Thread Dimitri John Ledkov
** Also affects: dwarves-dfsg (Ubuntu Bionic) Importance: Undecided Status: New ** Also affects: libbpf (Ubuntu Bionic) Importance: Undecided Status: New ** Changed in: dwarves-dfsg (Ubuntu Bionic) Status: New => In Progress -- You received this bug notification

[Bug 1912811] Re: Update dwarves-dfsg in focal to version 1.21 from impish

2021-10-04 Thread Dimitri John Ledkov
Using 1.21-0ubuntu1~20.04 and 1.21-0ubuntu1~21.04 it was possible to create BTF enabled kernels on all architectures. ** Tags removed: verification-needed verification-needed-focal verification-needed-hirsute ** Tags added: verification-done verification-done-focal verification-done-hirsute --

[Bug 1928648] Re: expiring trust anchor compatibility issue

2021-10-01 Thread Dimitri John Ledkov
** Changed in: gnutls28 (Ubuntu Trusty) Status: Confirmed => Won't Fix ** Also affects: gnutls28 (Ubuntu Focal) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1928679] Re: Support importing mokx keys into revocation list from the mok table

2021-10-01 Thread Dimitri John Ledkov
** Merge proposal linked: https://code.launchpad.net/~xnox/ubuntu/+source/linux/+git/focal/+merge/409374 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928679 Title: Support importing mokx keys

[Bug 1932029] Re: Support builtin revoked certificates

2021-10-01 Thread Dimitri John Ledkov
** Description changed: [Impact] Upstream linux kernel now supports configuring built-in revoked certificates for the .blacklist keyring. Add support in our kernel configuration to have built-in revoked certificates. Revoke UEFI amd64 & arm64 2012 signing certificate.

[Bug 1413664] Re: 15.04: consider enabling CONFIG_DEBUG_INFO_SPLIT and package the .dwo files

2021-09-30 Thread Dimitri John Ledkov
Should we look into this? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1413664 Title: 15.04: consider enabling CONFIG_DEBUG_INFO_SPLIT and package the .dwo files To manage notifications about

[Bug 1945632] [NEW] Re-enable DEBUG_INFO_BTF where it was dissabled

2021-09-30 Thread Dimitri John Ledkov
Public bug reported: [Impact] * pahole used to segfault on 32-bit platforms, which has now been fixed * pahole used to be too old in focal, which is now being SRUed * renable DEBUG_INFO_BTF in all the kernels/arches that had it disabled, as otherwise one cannot compile/use advanced BTF

[Bug 1932029] Re: Support builtin revoked certificates

2021-09-27 Thread Dimitri John Ledkov
** Description changed: [Impact] Upstream linux kernel now supports configuring built-in revoked certificates for the .blacklist keyring. Add support in our kernel configuration to have built-in revoked certificates. Revoke UEFI amd64 & arm64 2012 signing certificate.

[Bug 1928679] Re: Support importing mokx keys into revocation list from the mok table

2021-09-27 Thread Dimitri John Ledkov
** Also affects: linux-azure-5.8 (Ubuntu) Importance: Undecided Status: New ** Changed in: linux-azure-5.8 (Ubuntu Hirsute) Status: New => Invalid ** Changed in: linux-azure-5.8 (Ubuntu) Status: New => Invalid ** Changed in: linux-azure-5.8 (Ubuntu Bionic) Status:

[Bug 1928679] Re: Support importing mokx keys into revocation list from the mok table

2021-09-27 Thread Dimitri John Ledkov
** Description changed: [Impact] - * Ubuntu's 15.4 based shim ships a very large vendor-dbx (aka mokx) +  * Ubuntu's 15.4 based shim ships a very large vendor-dbx (aka mokx) which revokes many Ubuntu kernel hashes and 2012 signing key. - * Kernel should import those into it's

[Bug 1932029] Re: Support builtin revoked certificates

2021-09-27 Thread Dimitri John Ledkov
** Description changed: [Impact] Upstream linux kernel now supports configuring built-in revoked certificates for the .blacklist keyring. Add support in our kernel configuration to have built-in revoked certificates. Revoke UEFI amd64 & arm64 2012 signing certificate.

[Bug 1932029] Re: Support builtin revoked certificates

2021-09-27 Thread Dimitri John Ledkov
** Description changed: [Impact] Upstream linux kernel now supports configuring built-in revoked certificates for the .blacklist keyring. Add support in our kernel configuration to have built-in revoked certificates. Revoke UEFI amd64 & arm64 2012 signing certificate.

[Bug 1932029] Re: Support builtin revoked certificates

2021-09-27 Thread Dimitri John Ledkov
** Description changed: [Impact] Upstream linux kernel now supports configuring built-in revoked certificates for the .blacklist keyring. Add support in our kernel configuration to have built-in revoked certificates. Revoke UEFI amd64 & arm64 2012 signing certificate.

[Bug 1932029] Re: Support builtin revoked certificates

2021-09-27 Thread Dimitri John Ledkov
** Also affects: linux-azure-5.8 (Ubuntu) Importance: Undecided Status: New ** Changed in: linux-azure-5.8 (Ubuntu Hirsute) Status: New => Invalid ** Changed in: linux-azure-5.8 (Ubuntu Bionic) Status: New => Invalid ** Changed in: linux-azure-5.8 (Ubuntu Xenial)

[Bug 1944744] Re: vboxsf missing in focal

2021-09-23 Thread Dimitri John Ledkov
** Description changed: virtualbox got SRUed into focal that drops virtualbox-guest-dkms virtualbox-guest-dkms (among other modules) used to provide vboxsf which src:linux used as source to build & sign vboxsf. - vboxsf is also available in upstream vanilla kernels from v5.6+ + vboxsf

[Bug 1944744] [NEW] vboxsf missing in focal

2021-09-23 Thread Dimitri John Ledkov
Public bug reported: virtualbox got SRUed into focal that drops virtualbox-guest-dkms virtualbox-guest-dkms (among other modules) used to provide vboxsf which src:linux used as source to build & sign vboxsf. vboxsf is also available in upstream vanilla kernels from v5.6+ to continue building

[Bug 1933248] Re: please drop virtualbox-guest-dkms virtualbox-guest-source

2021-09-23 Thread Dimitri John Ledkov
https://lists.ubuntu.com/archives/kernel-team/2021-September/124249.html https://lists.ubuntu.com/archives/kernel-team/2021-September/124250.html ** Changed in: linux (Ubuntu Focal) Status: Fix Committed => Triaged -- You received this bug notification because you are a member of Ubuntu

[Bug 1933248] Re: please drop virtualbox-guest-dkms virtualbox-guest-source

2021-09-23 Thread Dimitri John Ledkov
$ git describe 0fd1695766 v5.5-rc6-150-g0fd1695766 0fd1695766 fs: Add VirtualBox guest shared folder (vboxsf) support ** Tags added: block-proposed-focal -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1933248] Re: please drop virtualbox-guest-dkms virtualbox-guest-source

2021-09-23 Thread Dimitri John Ledkov
reading old modules... MISS: vboxguest (ignored) MISS: vboxsf (ignored) In the current kerenl. So it appears that building with a dkms module got dropped, and yet the guest modules from upstream code have not been built either. And i am able to reproduce

[Bug 1933248] Re: please drop virtualbox-guest-dkms virtualbox-guest-source

2021-09-23 Thread Dimitri John Ledkov
./fs/vboxsf is not available in v5.4 kernel. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1933248 Title: please drop virtualbox-guest-dkms virtualbox-guest-source To manage notifications about

[Bug 1933248] Re: please drop virtualbox-guest-dkms virtualbox-guest-source

2021-09-23 Thread Dimitri John Ledkov
linux (5.4.0-87.98) focal; urgency=medium * please drop virtualbox-guest-dkms virtualbox-guest-source (LP: #1933248) - [Config] Disable virtualbox dkms build Disabled do_dkms_vbox, because src:virtualbox got srued into Focal which no longer provides virtualbox-guest-dkms I fear/wonder

[Bug 1933248] Re: please drop virtualbox-guest-dkms virtualbox-guest-source

2021-09-23 Thread Dimitri John Ledkov
I was not expecting for focal/linux to change. This change was expected to be done in impish/linux only. How can I figure out why this was done in focal/linux? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1942357] Re: Regression in openssl 1.0.1f for trusty/esm after last update

2021-09-21 Thread Dimitri John Ledkov
** Changed in: openssl (Ubuntu) Status: In Progress => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1942357 Title: Regression in openssl 1.0.1f for trusty/esm after last update To

[Bug 1944403] Re: FIPS cannot be enabled on non usrmerged 20.04 systems

2021-09-21 Thread Dimitri John Ledkov
if we can't fix fips version of libgcrypt in focal, we must add a maintainer script somewhere else to copy the hmac from /lib to /usr/lib. I.e. a fixup in ua tool or ubuntu-fips package. ** Also affects: libgcrypt (Ubuntu) Importance: Undecided Status: New ** Changed in: libgcrypt

[Bug 1944403] Re: FIPS cannot be enabled on non usrmerged 20.04 systems

2021-09-21 Thread Dimitri John Ledkov
an .hmac for a matching soname, should be shipped in the same location as recorded for a given deb in the dpkg database. In bionic, # dpkg -L libgcrypt20 | grep so.20.2.1 /lib/x86_64-linux-gnu/libgcrypt.so.20.2.1 Thus bionic gcrypt hmac file should be under /lib In focal, # dpkg -L libgcrypt20

[Bug 1912811] Re: Update dwarves-dfsg in focal to version 1.21 from impish

2021-09-20 Thread Dimitri John Ledkov
Uploaded new dwarves-dfsg SRUs that use embeded libbpf (which in turn is updated to the same source as used in impish). This makes dwarves-dfsg SRU stand-alone, without introducing or upgrading the system-wide libbpf. ** Changed in: libbpf (Ubuntu Focal) Status: Confirmed => Won't Fix **

[Bug 1939287] Re: dbgsym package is missing for ubuntu focal hwe kernel 5.11

2021-09-20 Thread Dimitri John Ledkov
** Changed in: linux-hwe-5.13 (Ubuntu Focal) Status: Confirmed => In Progress ** Changed in: linux-hwe-5.13 (Ubuntu Focal) Assignee: (unassigned) => Dimitri John Ledkov (xnox) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subs

[Bug 1939287] Re: dbgsym package is missing for ubuntu focal hwe kernel 5.11

2021-09-20 Thread Dimitri John Ledkov
** Description changed: + [Impact] + + * Due to disk space constraints previously hwe-5.11 disabled building + dbgsyms packages + + * This has been resolved in hwe-5.13, thus builds with debug symbols + can be re-enabled + + [Test Plan] + + * Build new kernel, check that dbgsyms packages

[Bug 1912811] Re: Update dwarves-dfsg in focal to version 1.21 from impish

2021-09-20 Thread Dimitri John Ledkov
** Summary changed: - Update dwarves-dfsg in focal to version 1.21 from hirsute + Update dwarves-dfsg in focal to version 1.21 from impish -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1912811

[Bug 1939287] Re: dbgsym package is missing for ubuntu focal hwe kernel 5.11

2021-09-20 Thread Dimitri John Ledkov
** Also affects: linux-hwe-5.13 (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1939287 Title: dbgsym package is missing for ubuntu focal hwe

[Bug 1928648] Re: expiring trust anchor compatibility issue

2021-09-20 Thread Dimitri John Ledkov
xenial autopkgtest regressions explained in https://bugs.launchpad.net/ubuntu/+source/gnutls28/+bug/1928648/comments/13 https://bugs.launchpad.net/ubuntu/+source/gnutls28/+bug/1928648/comments/14 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed

[Bug 1941904] Re: Check if letsencrypt clients support configuring shorter chains

2021-09-16 Thread Dimitri John Ledkov
** Tags added: letsencryptexpiry -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1941904 Title: Check if letsencrypt clients support configuring shorter chains To manage notifications about this bug

[Bug 1928648] Re: expiring trust anchor compatibility issue

2021-09-15 Thread Dimitri John Ledkov
bionic autopkgtests are all clean -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928648 Title: expiring trust anchor compatibility issue To manage notifications about this bug go to:

[Bug 1928648] Re: expiring trust anchor compatibility issue

2021-09-15 Thread Dimitri John Ledkov
In xenial systemd autopkgtest only fails with boot-smoke FAIL: expected: '' actual: ' 1 graphical.target start waiting 92 rng-tools.servicestart running 101 systemd-update-utmp-runlevel.service start waiting 2 multi-user.targetstart

[Bug 1928648] Re: expiring trust anchor compatibility issue

2021-09-15 Thread Dimitri John Ledkov
On xenial lxc autopkgtest fails with "ERROR: Unable to fetch GPG key from keyserver." due to using keyserver that is no longer available on the internet. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1928648] Re: expiring trust anchor compatibility issue

2021-09-15 Thread Dimitri John Ledkov
# dpkg-query -W gnutls-bin libgnutls30 gnutls-bin 3.5.18-1ubuntu1.4 libgnutls30:amd64 3.5.18-1ubuntu1.4 # gnutls-cli --x509cafile=ca.pem expired-root-ca-test.germancoding.com Processed 2 CA certificate(s). Resolving 'expired-root-ca-test.germancoding.com:443'... Connecting to

[Bug 1928648] Re: expiring trust anchor compatibility issue

2021-09-15 Thread Dimitri John Ledkov
# gnutls-cli --x509cafile=ca.pem expired-root-ca-test.germancoding.com Processed 2 CA certificate(s). Resolving 'expired-root-ca-test.germancoding.com'... Connecting to '2a01:4f8:151:506c::2:443'... ... - Status: The certificate is NOT trusted. The certificate chain uses expired certificate. ***

[Bug 1940528] Re: curl 7.68 does not init OpenSSL correctly

2021-09-14 Thread Dimitri John Ledkov
** Changed in: curl (Ubuntu Focal) Assignee: (unassigned) => Dimitri John Ledkov (xnox) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1940528 Title: curl 7.68 does not init OpenSSL correc

[Bug 1940656] Re: Potential use after free bugs in 1.1.1

2021-09-14 Thread Dimitri John Ledkov
** Changed in: openssl (Ubuntu Focal) Status: Incomplete => In Progress ** Changed in: openssl (Ubuntu Focal) Assignee: (unassigned) => Robie Basak (racb) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1940656] Re: Potential use after free bugs in 1.1.1

2021-09-14 Thread Dimitri John Ledkov
I would agree that any hypothetical use-after-free / double-free errors are usually also security vulnerabilities. But these ones were discovered with static analysis and/or affecting engine use, in error conditions only. Thus connectivity must already be failing / denied, before one can trip

<    1   2   3   4   5   6   7   8   9   10   >