** Description changed:

- openssl 4.0.1-1ubuntu2 in stonking proposed requires a MIR for
- jitterentropy-library
+ [Availability]
+ - The source package jitterentropy-library is published in Ubuntu (universe).
+ - Current Launchpad builds pass on: amd64, amd64v3, arm64, armhf, i386, 
ppc64el, riscv64, s390x.
+ - Source package: https://launchpad.net/ubuntu/+source/jitterentropy-library
+ 
+ [Rationale]
+ - The package src:jitterentropy-library is required in Ubuntu main for
+ 
+   The package libssl-dev in Ubuntu main ships a static library libcrypto.a. 
The static library comes with a pkg-config configuration that declares a 
dependency on libjitterentropy.a which is packaged in the libjitterentropy3-dev.
+   See more details 
https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/2158026.
+ 
+ - The package src:jitterentropy-library serves a narrower but important 
Ubuntu use case.
+ - The narrower use case is important because There is not better supported 
alternative. Each package static linking with libcrypto.a will have to declare 
delcare dependency on libjitterentropy3-dev package which is not ideal.
+ - The Ubuntu user benefit and enabled use cases are Developers static linking 
with libcrypto.a will be able to build their applications.
+ - There is no other/better way already in main; alternatives considered: I 
considered explicitly asking users to declare dependency on 
libjitterentropy3-dev in their builds. I rejected it becasue it is reasonalbe 
to expect the static library dependency to be being present on the system.
+ - Specific binary packages built by src:jitterentropy-library, listed below, 
need to be in main.
+   The specific binary packages needing promotion are libjitterentropy3-dev
+ - The package src:jitterentropy-library is required in Ubuntu main by no 
later than 18 August, 2026
+ 
+ [Security]
+ - No package-associated CVEs were found in the queried trackers.
+ - No setuid/setgid files, sbin executables, systemd units, or cron jobs were 
found.
+ - No AppArmor profiles, desktop files, translations, or plugin candidates 
were found.
+ - Security exposure and proportional mitigation assessment: Assess 
security-sensitive behavior, exposed endpoints, privileged operation, 
cryptography, and whether mitigations are proportional.
+ - Deprecated cryptographic algorithm concerns: No
+ 
+ [Quality assurance - function/usage]
+ - Package function after installation and required configuration: The package 
works after installation.
+ 
+ [Quality assurance - maintenance]
+ - No critical Ubuntu or release-critical Debian bugs were found.
+ - The package does not depend on exotic hardware we cannot support.
+ - The package maintenance health is: The package maintenance health is: Good. 
The package is new, one version behind the latest upstream. There are no open 
old bugs in Debian or Ubuntu.
+ 
+ [Quality assurance - testing]
+ - The package does not run a test at build time.
+   #TODO
+ - No autopkgtest results were found for this source package.
+   #TODO
+ - Testing gaps and the owning team test plan are: There are no build time 
tests or autopkgtest.
+ - Overall automated and end-to-end test adequacy: Low
+ 
+ [Quality assurance - packaging]
+ - A debian/watch upstream-release mechanism is present.
+ - Lintian reported 0 error(s) and 0 warning(s).
+ - Maintainer: Eric Berry <[email protected]>; source format: 3.0 
(quilt); debconf templates: 0; debian/rules overrides: dh_auto_install.
+ - Packaging complexity and maintainability assessment: Packaging complexity 
and maintainability assessment: Simple
+ 
+   Maintainer field needs an update. Somebody from
+ https://launchpad.net/~canonical-security-certification
+ 
+ - No Python 2, GTK 2, or other catalogued obsolete runtime dependency
+ was found.
+ 
+ [UI standards]
+ - Evidence-based UI applicability assessment: There are not desktop files.
+ 
+ [Dependencies]
+ - No in-scope runtime dependencies outside main require a separate MIR.
+ 
+ [Standards compliance]
+ - This package correctly follows FHS and Debian Policy.
+ - No license expiry, time-bound terms, entity/contract coupling, withdrawable 
branches, patents, or other encumbrances were identified; the license is 
expected to remain compatible with Ubuntu main throughout the full support 
lifetime.
+ 
+ [Maintenance/Owner]
+ - A different owning team will subscribe to this package, named below.
+ - The new owning team will be 
https://launchpad.net/~canonical-security-certification and has acknowledged 
the commitment.
+ - No owning-team package bug subscription was found.
+   (A team must subscribe before promotion.)
+ - No shipped vendored directories were detected.
+ - No Launchpad build within the last three months was confirmed.
+   #TODO
+ - This change affects other Ubuntu teams and the required coordination is 
still in progress.
+ 
+ [Background information]
+ - The package description and additional background explain the package: 
Jitter Entropy library enables fips based containers to run on non-fips host 
Ubuntu systems. the library has been compiled into OpenSSL.
+ - Upstream project: https://github.com/smuellerDD/jitterentropy-library
+ 
+ 
+ Original report is below
+ 
================================================================================
+ openssl 4.0.1-1ubuntu2 in stonking proposed requires a MIR for 
jitterentropy-library
  
  As a result of 4.0.1-1ubuntu2 lp: #2158026
  
  update_excuses shows:
  
  libssl-dev/amd64 in main cannot depend on libjitterentropy3-dev in universe
  libssl-dev/amd64v3 in main cannot depend on libjitterentropy3-dev in universe
  libssl-dev/arm64 in main cannot depend on libjitterentropy3-dev in universe
  libssl-dev/armhf in main cannot depend on libjitterentropy3-dev in universe
  libssl-dev/i386 in main cannot depend on libjitterentropy3-dev in universe
  libssl-dev/ppc64el in main cannot depend on libjitterentropy3-dev in universe
  libssl-dev/riscv64 in main cannot depend on libjitterentropy3-dev in universe
  libssl-dev/s390x in main cannot depend on libjitterentropy3-dev in universe
  
  confirmed in component mismatches:
  
  https://ubuntu-archive-team.ubuntu.com/component-mismatches-proposed.svg

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2162943

Title:
  [MIR] jitterentropy-library

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/jitterentropy-library/+bug/2162943/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to