dwarves-dfsg from updates is required to build security updates of kernels please release dwarves-dfsg to security

Bug #1981574 reported by Dimitri John Ledkov
262
This bug affects 1 person
Affects Status Importance Assigned to Milestone
dwarves-dfsg (Ubuntu)
Triaged
High
Unassigned
Bionic
Triaged
High
Unassigned
Focal
Triaged
High
Unassigned

Bug Description

dwarves-dfsg from updates is required to build security updates of kernels please release dwarves-dfsg to security

Please publish dwarves-dfsg focal-updates 1.21-0ubuntu1~20.04 to focal-security

Please publish dwarves-dfsg bionic-updates 1.21-0ubuntu1~18.04 to bionic-security

Changed in dwarves-dfsg (Ubuntu Bionic):
status: New → Triaged
importance: Undecided → High
Changed in dwarves-dfsg (Ubuntu Focal):
status: New → Triaged
importance: Undecided → High
Revision history for this message
Seth Arnold (seth-arnold) wrote :

Given the conversations in:

- https://bugs.launchpad.net/ubuntu/+source/dwarves-dfsg/+bug/1951438
- https://bugs.launchpad.net/ubuntu/+source/dwarves-dfsg/+bug/1912811

I think it'd be nice to have a better idea of what has changed, why it is necessary now, how these have been tested in -updates in the last nine-ish months, etc.

(perhaps you've already had this conversation and I'm unaware of it, in which case sorry for the trouble; I'm throwing in questions I think I'd ask if I were the one to do the lever-pulling, in an attempt to reduce conversation round-trips.)

Thanks

Revision history for this message
Dimitri John Ledkov (xnox) wrote :

As you have seen in the above conversations, libbpf was not updated in the SRUs. Instead dwarves-dfsg was SRUed with a vendored copy of libbpf statically linked, such that only it uses updated libbpf as it expects latest one.

The package from -updates was binary copied into build-depends PPA used to build all kernels since forever, and all kernels that we have build for -security pocket have been using dwarves-dfsg from -updates effectively.

However, it means locally users cannot rebuild src:linux package in a local chroot with release & -security suites alone.

The tooling is end-developer targeted one, and the only/primary users of it are people working with kernel bpf. And most likely they are using the up to date version from -updates already.

Please binary copy / release dwarves-dfsg from -updates to -security to allow users to rebuild kernels locally against the -security pocket only.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.