Comment 12 for bug 1951834

Revision history for this message
Andreas Hasenack (ahasenack) wrote :

Archive Admin, please promote src:frr and these binary packages to main:
frr
frr-pythontools (pulled in by frr via Recommends)

Note libyang2 will be pulled in as well, and its MIR (#1958293) was completed and ACKed.

Leave in universe:
frr-snmp
frr-rpki-rtrlib (uses a library that is still in universe)
frr-doc (or not, whatever happens automatically)

frr-snmp I decided to not promote:
- there are quite a large number of bugs filed in the upstream tracker with "snmp" in them that are still open (https://github.com/FRRouting/frr/issues?page=2&q=is%3Aissue+is%3Aopen+snmp)
- the upstream documentation warns that it can be a firehose and lead to crashes and hangs[1] if abused
- snmp is usually hard to troubleshoot, and can be a security nightmare
- it's easier to promote it to main later if deemed necessary, than to demote it after it has been in main in a release

frr was given a special consideration by the security team (see comment #10) and didn't go through the usual security review process. This plus all the above made me decide to keep frr-snmp in universe for now.

1. http://docs.frrouting.org/en/latest/snmp.html