glibc: drop libnss-nis and libnss-nisplus from libc6 Recommends?

Bug #2045241 reported by Simon Chopin
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
glibc (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

Asked by vorlon:

Should libc6 still Recommends: libnss-nis + libnss-nisplus?

Dropping this would let us shed various i386 packages from the package pool on install images, as well as reducing the size of the base system.

CVE References

Simon Chopin (schopin)
tags: added: foundations-todo
Changed in glibc (Ubuntu):
status: New → Triaged
Revision history for this message
Simon Chopin (schopin) wrote :

After reading up on NIS and NIS+, I think we should drop our delta on this. The fact we diverged from Debian on this particular point is actually just an accident due to our different release schedules and us having basically stopped merging their changes for several years right after the demotion from Depends to Recommends.

However, we should definitely mention this in the release notes.

Some further reading on NIS support in our stack:

https://lists.debian.org/debian-devel/2022/04/msg00216.html
https://lwn.net/Articles/874174/
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=975077

Revision history for this message
Simon Chopin (schopin) wrote :

I'll be testing this change in our upcoming test rebuild.

Simon Chopin (schopin)
Changed in glibc (Ubuntu):
status: Triaged → In Progress
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package glibc - 2.39-0ubuntu1

---------------
glibc (2.39-0ubuntu1) noble; urgency=medium

  * New upstream release
    Contains fixes for the following CVEs:
    - CVE-2023-6246: Heap buffer overflow in __vsyslog_internal()
    - CVE-2023-6779: Heap buffer overflow in __vsyslog_internal()
    - CVE-2023-6780: Integer overflow in __vsyslog_internal()
    Patches:
    - Several patches refreshed
    - d/p/localedata/lv_LV-current.patch: dropped, applied upstream
    - d/p/lp{2031495,2032624}: dropped, applied upstream
    - d/p/any/git-c-utf-8-language.diff: dropped, applied upstream
  * d/p/ubuntu/submitted-tests-gracefully-handle-AppArmor-userns-containment.patch:
    Fix the tests in recent apparmor environments (LP: #2048375)
  * Drop libnss-nis and libnss-nisplus to Suggests (LP: #2045241)
  * Fix Replaces version for libsotruss.so file move (LP: #2042665)
  * Remove libc6-dev dependency on libtirpc-dev (LP: #2045763)
  * Dropped a lot of Ubuntu-specific xfails that are now passing.
  * Drop the -prof variant to instead use frame pointers on all 64-bit
    architectures by default to match the rest of the distro (LP: #2042790)

 -- Simon Chopin <email address hidden> Thu, 01 Feb 2024 09:44:24 +0100

Changed in glibc (Ubuntu):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.