** Description changed:

  This is a MIR request for src:openssh-gssapi. It's a split from
  src:openssh, which is already in main, triggered by debian[1]. The main
  reasoning is to reduce the security exposure of src:openssh by removing
  the kerberos/gssapi feature in src:openssh and moving it to src:openssh-
  gssapi. It's basically a different set of build options of the same
  source.
  
  I'm invoking the Renamed or reorganized sources[6] part of the MIR
  process.
  
- The one thing Ubuntu is adding on top is the ccache patch[2].
+ The one thing Ubuntu is adding on top is the ccache patch[2], from
+ Fedora.
  
- That patch has been requested for ubuntu since 2020, and has been
+ That patch has been requested for ubuntu since 2020[2], and has been
  provided in a Server Team maintained PPA[3] for jammy, noble, and more
  recently resolute. The PPA work is detailed in a Canonical-internal
  SPEC[4]. The security team was made aware[7] (Canonical-only internal
  link) of this PPA back then and agreed to help support it if needed, but
  that was never necessary as the patch always applied cleanly and
  introduced no regressions in all these years. Still, it's of course
  feasible that a security vulnerability could only affect src:openssh-
  gssapi due to this patch.
  
  Differently from the PPA, the approach here is a plain patch-and-build
  one. The PPA for jammy, noble, resolute, still uses the alternatives
  mechanism and two builds from the same source.
  
  The package includes a new autopkgtest[5] which covers the patch
  behavior, and runs the normal upstream regression test at both build-
  time and as an autopkgtest. And still has the normal openssh
  autopkgtests, like socket-activation, xinetd, and general
  gssapi/kerberos login.
  
  The canonical-server team will subscribe to this package.
  
  1. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141274
  2. https://bugs.launchpad.net/ubuntu/+source/openssh-gssapi/+bug/1889548
  3. 
https://launchpad.net/~canonical-server/+archive/ubuntu/openssh-server-default-ccache
  4. 
https://docs.google.com/document/d/1UJDtDNCbDxfaq10inp5nVlisbMh-zwxzpPR0Hp_UrnI/edit
  5. 
https://git.launchpad.net/ubuntu/+source/openssh-gssapi/tree/debian/tests/ssh-gssapi-default-ccache
  6. 
https://ubuntu.com/project/docs/MIR/mir-rereview/#renamed-or-reorganized-sources
  7. 
https://docs.google.com/document/d/1-qadf8qTJyOF5CKVR5iFFYlKF5-XLB_qShDw5Ykp5pw/edit?tab=t.0

** Description changed:

  This is a MIR request for src:openssh-gssapi. It's a split from
  src:openssh, which is already in main, triggered by debian[1]. The main
  reasoning is to reduce the security exposure of src:openssh by removing
  the kerberos/gssapi feature in src:openssh and moving it to src:openssh-
  gssapi. It's basically a different set of build options of the same
  source.
  
  I'm invoking the Renamed or reorganized sources[6] part of the MIR
  process.
  
  The one thing Ubuntu is adding on top is the ccache patch[2], from
  Fedora.
  
  That patch has been requested for ubuntu since 2020[2], and has been
  provided in a Server Team maintained PPA[3] for jammy, noble, and more
  recently resolute. The PPA work is detailed in a Canonical-internal
  SPEC[4]. The security team was made aware[7] (Canonical-only internal
  link) of this PPA back then and agreed to help support it if needed, but
  that was never necessary as the patch always applied cleanly and
  introduced no regressions in all these years. Still, it's of course
  feasible that a security vulnerability could only affect src:openssh-
  gssapi due to this patch.
  
+ The other consequence of this new source package is that a non-
+ kerberos/gssapi vulnerability on openssh will likely need to be fixed in
+ both source packages.
+ 
  Differently from the PPA, the approach here is a plain patch-and-build
  one. The PPA for jammy, noble, resolute, still uses the alternatives
  mechanism and two builds from the same source.
  
  The package includes a new autopkgtest[5] which covers the patch
  behavior, and runs the normal upstream regression test at both build-
  time and as an autopkgtest. And still has the normal openssh
  autopkgtests, like socket-activation, xinetd, and general
  gssapi/kerberos login.
  
  The canonical-server team will subscribe to this package.
  
  1. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141274
  2. https://bugs.launchpad.net/ubuntu/+source/openssh-gssapi/+bug/1889548
  3. 
https://launchpad.net/~canonical-server/+archive/ubuntu/openssh-server-default-ccache
  4. 
https://docs.google.com/document/d/1UJDtDNCbDxfaq10inp5nVlisbMh-zwxzpPR0Hp_UrnI/edit
  5. 
https://git.launchpad.net/ubuntu/+source/openssh-gssapi/tree/debian/tests/ssh-gssapi-default-ccache
  6. 
https://ubuntu.com/project/docs/MIR/mir-rereview/#renamed-or-reorganized-sources
  7. 
https://docs.google.com/document/d/1-qadf8qTJyOF5CKVR5iFFYlKF5-XLB_qShDw5Ykp5pw/edit?tab=t.0

** Description changed:

  This is a MIR request for src:openssh-gssapi. It's a split from
  src:openssh, which is already in main, triggered by debian[1]. The main
  reasoning is to reduce the security exposure of src:openssh by removing
  the kerberos/gssapi feature in src:openssh and moving it to src:openssh-
  gssapi. It's basically a different set of build options of the same
  source.
  
  I'm invoking the Renamed or reorganized sources[6] part of the MIR
  process.
  
  The one thing Ubuntu is adding on top is the ccache patch[2], from
  Fedora.
  
  That patch has been requested for ubuntu since 2020[2], and has been
  provided in a Server Team maintained PPA[3] for jammy, noble, and more
  recently resolute. The PPA work is detailed in a Canonical-internal
  SPEC[4]. The security team was made aware[7] (Canonical-only internal
  link) of this PPA back then and agreed to help support it if needed, but
  that was never necessary as the patch always applied cleanly and
  introduced no regressions in all these years. Still, it's of course
  feasible that a security vulnerability could only affect src:openssh-
  gssapi due to this patch.
  
  The other consequence of this new source package is that a non-
  kerberos/gssapi vulnerability on openssh will likely need to be fixed in
- both source packages.
+ both source packages. Likewise for regular bugs.
  
  Differently from the PPA, the approach here is a plain patch-and-build
  one. The PPA for jammy, noble, resolute, still uses the alternatives
  mechanism and two builds from the same source.
  
  The package includes a new autopkgtest[5] which covers the patch
  behavior, and runs the normal upstream regression test at both build-
  time and as an autopkgtest. And still has the normal openssh
  autopkgtests, like socket-activation, xinetd, and general
  gssapi/kerberos login.
  
  The canonical-server team will subscribe to this package.
  
  1. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141274
  2. https://bugs.launchpad.net/ubuntu/+source/openssh-gssapi/+bug/1889548
  3. 
https://launchpad.net/~canonical-server/+archive/ubuntu/openssh-server-default-ccache
  4. 
https://docs.google.com/document/d/1UJDtDNCbDxfaq10inp5nVlisbMh-zwxzpPR0Hp_UrnI/edit
  5. 
https://git.launchpad.net/ubuntu/+source/openssh-gssapi/tree/debian/tests/ssh-gssapi-default-ccache
  6. 
https://ubuntu.com/project/docs/MIR/mir-rereview/#renamed-or-reorganized-sources
  7. 
https://docs.google.com/document/d/1-qadf8qTJyOF5CKVR5iFFYlKF5-XLB_qShDw5Ykp5pw/edit?tab=t.0

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167624

Title:
  MIR (source fork): openssh-gssapi + ccache patch (the new thing)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssh-gssapi/+bug/2167624/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to