[MIR] protobuf-c
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OEM Priority Project |
In Progress
|
High
|
Unassigned | ||
protobuf-c (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Focal |
Fix Committed
|
Undecided
|
Unassigned | ||
Jammy |
Fix Released
|
Undecided
|
Unassigned | ||
Kinetic |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
[Availability]
The package protobuf-c is already in Ubuntu universe, and was in main some years ago.
The package protobuf-c builds for the architectures it is designed to work on.
It currently builds and works for architectures: amd64 arm64 armhf i386 ppc64el riscv64 s390x
Link to package https:/
[Rationale]
- The package protobuf-c is required in Ubuntu main for fwupd 1.7.x to handle firmware updates for Logitech devices that use logitech_
- The feature is only going to be useful to users owning such hardware but it is important for those users.
[Security]
- No CVEs/security issues in this software in the past
- no `suid` or `sgid` binaries
- no executables in `/sbin` and `/usr/sbin`
- Package does not install services, timers or recurring jobs
- Packages does not open privileged ports (ports < 1024)
- Packages does not contain extensions to security-sensitive software
[Quality assurance - function/usage]
- The package works well right after install
[Quality assurance - maintenance]
- The package is maintained well in Debian/Ubuntu and has no bugs open in Debian or Ubuntu
- Ubuntu https:/
- Debian https:/
- The package does not deal with exotic hardware we cannot support
[Quality assurance - testing]
- The package runs a test suite on build time, if it fails
it makes the build fail, link to build log https:/
- The package does not run an autopkgtest but there is no reason they shouldn't be added.
[Quality assurance - packaging]
- debian/watch is not present, no reason it shouldn't have one though
- This package has some minor lintian warnings
# lintian --pedantic
running with root privileges is not recommended!
W: protobuf-
W: protobuf-
P: protobuf-c source: package-
P: protobuf-c source: silent-
P: protobuf-c source: update-
and some warnings about long lines in upstream sources
- Lintian overrides are not present
- This package does not rely on obsolete or about to be demoted packages.
- This package has no python2 or GTK2 dependencies
- The package will be installed by default, but does not ask debconf questions
- Packaging and build is easy, link to d/rules https:/
[UI standards]
- Application is not end-user facing (does not need translation)
[Dependencies]
- No further depends or recommends dependencies that are not yet in main
[Standards compliance]
- This package correctly follows FHS and Debian Policy
[Maintenance/Owner]
- Owning Team should be foundations since they own fwupd
- Team is not yet, but will subscribe to the package before promotion
- This does not use static builds
- This does not use vendored code
[Background information]
The Package description explains the package well
Upstream Name is protobuf-c
Link to upstream project https:/
CVE References
tags: | added: rls-jj-incoming |
Changed in protobuf-c (Ubuntu): | |
assignee: | nobody → Christian Ehrhardt (paelzer) |
tags: | added: sec-754 |
Changed in protobuf-c (Ubuntu): | |
status: | New → In Progress |
Changed in protobuf-c (Ubuntu): | |
status: | Fix Committed → In Progress |
Changed in protobuf-c (Ubuntu Kinetic): | |
status: | In Progress → Fix Released |
Changed in protobuf-c (Ubuntu Focal): | |
status: | In Progress → Fix Committed |
Changed in protobuf-c (Ubuntu Jammy): | |
status: | In Progress → Fix Committed |
status: | Fix Committed → In Progress |
Changed in protobuf-c (Ubuntu Focal): | |
status: | Fix Committed → In Progress |
Changed in oem-priority: | |
importance: | Undecided → High |
status: | New → Confirmed |
status: | Confirmed → In Progress |
tags: | added: fwupd |
tags: | added: oem-priority |
tags: | removed: fr-1990 |
The original MIR request was bug #801735