Public bug reported:
[Availability]
- The source package rust-ntpd is published in Ubuntu (universe).
- Current Launchpad builds pass on: amd64, amd64v3, arm64, armhf, ppc64el,
riscv64, s390x.
- Source package: https://launchpad.net/ubuntu/+source/rust-ntpd
[Rationale]
- The package src:rust-ntpd is required in Ubuntu main for providing users with
an alternative, standards-compliant and memory-safe implementation of NTP
client and server. alternative, memory safe implementation to the Network
Time Procol.
- This is the first time src:rust-ntpd will be in main.
- The package src:rust-ntpd will generally be useful for a large part of our
user base.
- It is meant to coexist with `chrony`.
- All binary packages built by src:rust-ntpd need to be in main.
- The package would be useful in main, but there is no definitive deadline.
- No prior MIR bug was found for this source or identified predecessor names.
[Security]
- Had 7 security issues in the past.
- https://github.com/pendulum-project/ntpd-rs/security
- Some have been assigned CVEs:
- CVE-2026-26076
- CVE-2025-58066
- CVE-2024-38528
- CVE-2023-33192
- Upstream generally deals with security issues in a timely manner.
- No executables in /sbin and /usr/sbin.
- Installs services:
- bin:ntpd-rs: ntpd-rs.service
- bin:ntpd-rs-metrics: ntpd-rs-metrics.service
- Services run using the ntpd-rs user (not root).
- Service hardening is being worked on upstream:
https://github.com/pendulum-project/ntpd-rs/issues/2414
- Installs AppArmor profile in /etc/apparmor.d/usr.bin.ntp-daemon.
- Deprecated algorithms are present in the vendored sources, but they are not
used by the application.
- Package can open privileged ports (but not by default)
- This only happens when ntpd-rs is configured to act as a NTP server.
- Requires UDP 123.
[Quality assurance - function/usage]
- The package works with sane defaults, shipping a default configuration file
and requiring no interactive debconf setup.
- By default, only configures a NTP client, using the Ubuntu NTP pool as
sources.
- Can be configured to act as a server as well, but not by default.
[Quality assurance - maintenance]
- No critical Ubuntu or release-critical Debian bugs.
- Ubuntu: https://bugs.launchpad.net/ubuntu/+source/rust-ntpd/+bug
- Debian: https://bugs.debian.org/cgi-bin/pkgreport.cgi?src=rust-ntpd
- Upstream: https://github.com/pendulum-project/ntpd-rs/issues
- Important open upstream bugs:
- Dynamic sources: https://github.com/pendulum-project/ntpd-rs/issues/2412
- Better configuration format:
https://github.com/pendulum-project/ntpd-rs/issues/2394
- The package does not depend on exotic hardware we cannot support.
[Quality assurance - testing]
- Build-time test execution was observed.
-
http://launchpad.net/ubuntu/+source/rust-ntpd/1.9.0-0ubuntu2/+build/33560475/+files/buildlog_ubuntu-stonking-amd64.rust-ntpd_1.9.0-0ubuntu2_BUILDING.txt.gz
- Autopkgtests are present, not trivial, and pass on all architectures.
- https://autopkgtest.ubuntu.com/packages/rust-ntpd
[Quality assurance - packaging]
- A debian/watch upstream-release mechanism is present.
- Lintian reported 0 errors and 1 warning.
- W: rust-ntpd source: unknown-field Vendored-Sources-Rust
- debian/control defines a correct Maintainer field
- The packaging uses standard dh-cargo tooling with overrides for vendoring,
copyright maintenance, and apparmor installation.
- This package does not rely on obsolete or about to be demoted packages.
- This package has no python2 or GTK2 dependencies.
[UI standards]
- Application is not end-user facing (does not need translation nor Desktop
file).
[Dependencies]
- Used check-mir from ubuntu-dev-tools to validate all dependencies or
recommends are in main.
[Standards compliance]
- This package correctly follows FHS and Debian policy.
- Based on a reasonable review of information available at the time of this
report, no expiry, time-limited grants, or obvious legal encumbrances have
been identified that would be expected to affect promotion.
[Maintenance/Owner]
- The owning team already subscribed to this package is confirmed and has
explicitly acknowledged the long-term maintenance commitment.
- Package bug subscriber team(s): ubuntu-server.
- The team is aware of the implications by a static build and commits to test
no-change-rebuilds and to fix any issues found for the lifetime of the
release (including ESM).
- The team is aware of the implications of vendored code and commits to provide
updates and backports to the security team for any affected vendored code for
the lifetime of the release (including ESM).
- This package uses vendored rust code tracked in Cargo.lock as shipped. In the
source package, refreshing that code is outlined in debian/README.source.
- This package uses vendored code, the debian/copyright has been updated to
cover the vendored content.
- This package is rust based and vendors all non language-runtime dependencies.
- The package has been built within the last 3 months in the archive.
-
https://launchpadlibrarian.net/873183134/buildlog_ubuntu-stonking-amd64.rust-ntpd_1.9.0-0ubuntu1_BUILDING.txt.gz
[Background information]
- Upstream Name is ntpd-rs
- Link to upstream project: https://github.com/pendulum-project/ntpd-rs
- https://discourse.ubuntu.com/t/ntpd-rs-its-about-time/79154
** Affects: rust-ntpd (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166406
Title:
[MIR] rust-ntpd
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/rust-ntpd/+bug/2166406/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs