Activity log for bug #1973031

Date Who What changed Old value New value Message
2022-05-11 14:17:12 Sebastien Bacher bug added bug
2022-05-11 14:19:16 Sebastien Bacher bug added subscriber MIR approval team
2022-05-11 14:25:49 Sebastien Bacher libwpe (Ubuntu): importance Undecided High
2022-05-11 20:38:20 Sebastien Bacher description [Availability] The package libwpe is already in Ubuntu universe. The package libwpe build for the architectures it is designed to work on. It currently builds and works for architectures: amd64 arm64 armhf i386 ppc64el riscv64 s390x Link to package https://launchpad.net/ubuntu/+source/libwpe [Rationale] The package libwpe is required in Ubuntu main as a dependency of webkit2gtk. The dependency is optional but the default upstream and in other distributions and the only one upstream is really testing (turned out some of the issues we had previous cycle are because we aren't using the default backend, which also made a lower priority for upstream to work on fixes). Upstream is also planning to deprecate the nonwpe codepath. - The package wpebackend-fdo is required in Ubuntu main no later than aug 25 due to feature freeze [Security] - No CVEs/security issues in this software in the past - no executables in `/sbin` and `/usr/sbin` - Package does not install services, timers or recurring jobs - Packages does not open privileged ports (ports < 1024) - Packages does not contain extensions to security-sensitive software [Quality assurance - function/usage] - The package works well right after install [Quality assurance - maintenance] - The package is maintained well in Ubuntu and Debian and has currently no reports - Ubuntu https://bugs.launchpad.net/ubuntu/+source/libwpe/+bug - Debian https://bugs.debian.org/cgi-bin/pkgreport.cgi?src=libwpe [Quality assurance - testing] - The package does not run a test at build time because upstream doesn't have one. That's something we need to work on. BLOCKER ^ - The package does not run an autopkgtest because upstream has no test and Debian didn't have some either. That's something we need to work on. BLOCKER ^ We need to work on the testing story, backup plan is to write some manual test plans. It's likely that the test plan for wpebackend-fdo will cover the library. [Quality assurance - packaging] - debian/watch is present and works -- There is only one lintian warning # lintian --pedantic P: libwpe source: package-uses-old-debhelper-compat-version 12 12 isn't that old but we will work on updating to 13 - Lintian overrides are not present - This package does not rely on obsolete or about to be demoted packages. - This package has no python2 or GTK2 dependencies - The package will be installed by default, but does not ask debconf question - Packaging and build is easy, link to d/rules https://salsa.debian.org/webkit-team/libwpe/-/blob/master/debian/rules [UI standards] - Application is not end-user facing (does not need translation) [Dependencies] - No further depends or recommends dependencies that are not yet in main [Standards compliance] - This package correctly follows FHS and Debian Policy [Maintenance/Owner] - Owning Team will be desktop-packages - Team is not yet, but will subscribe to the package before promotion - This does not use static builds - This does not use vendored code - The package successfully built during the most recent test rebuild [Background information] The Package description explains the package well Upstream Name is libwpe Link to upstream project https://github.com/WebPlatformForEmbedded/libwpe [Availability] The package libwpe is already in Ubuntu universe. The package libwpe build for the architectures it is designed to work on. It currently builds and works for architectures: amd64 arm64 armhf i386 ppc64el riscv64 s390x Link to package https://launchpad.net/ubuntu/+source/libwpe [Rationale] The package libwpe is required in Ubuntu main as a dependency of webkit2gtk. The dependency is optional but the default upstream and in other distributions and the only one upstream is really testing (turned out some of the issues we had previous cycle are because we aren't using the default backend, which also made a lower priority for upstream to work on fixes). Upstream is also planning to deprecate the nonwpe codepath. - The package wpebackend-fdo is required in Ubuntu main no later than aug 25 due to feature freeze [Security] - No CVEs/security issues in this software in the past - no executables in `/sbin` and `/usr/sbin` - Package does not install services, timers or recurring jobs - Packages does not open privileged ports (ports < 1024) - Packages does not contain extensions to security-sensitive software [Quality assurance - function/usage] - The package works well right after install [Quality assurance - maintenance] - The package is maintained well in Ubuntu and Debian and has currently no reports   - Ubuntu https://bugs.launchpad.net/ubuntu/+source/libwpe/+bug   - Debian https://bugs.debian.org/cgi-bin/pkgreport.cgi?src=libwpe [Quality assurance - testing] - The package does not run a test at build time because upstream doesn't have one. That's something we need to work on. BLOCKER ^ If webkit2gtk is built with it as it default backend then the webkitgtk autopkgtests are going to exercise wpe, is that enough? BLOCKER? ^ We need to work on the testing story, backup plan is to write some manual test plans. It's likely that the test plan for wpebackend-fdo will cover the library. [Quality assurance - packaging] - debian/watch is present and works -- There is only one lintian warning # lintian --pedantic P: libwpe source: package-uses-old-debhelper-compat-version 12 12 isn't that old but we will work on updating to 13 - Lintian overrides are not present - This package does not rely on obsolete or about to be demoted packages. - This package has no python2 or GTK2 dependencies - The package will be installed by default, but does not ask debconf question - Packaging and build is easy, link to d/rules https://salsa.debian.org/webkit-team/libwpe/-/blob/master/debian/rules [UI standards] - Application is not end-user facing (does not need translation) [Dependencies] - No further depends or recommends dependencies that are not yet in main [Standards compliance] - This package correctly follows FHS and Debian Policy [Maintenance/Owner] - Owning Team will be desktop-packages - Team is not yet, but will subscribe to the package before promotion - This does not use static builds - This does not use vendored code - The package successfully built during the most recent test rebuild [Background information] The Package description explains the package well Upstream Name is libwpe Link to upstream project https://github.com/WebPlatformForEmbedded/libwpe
2022-05-17 14:46:12 Christian Ehrhardt  libwpe (Ubuntu): assignee Christian Ehrhardt  (paelzer)
2022-05-18 09:03:56 Christian Ehrhardt  libwpe (Ubuntu): assignee Christian Ehrhardt  (paelzer) Ubuntu Security Team (ubuntu-security)
2022-05-18 21:08:00 Seth Arnold tags sec-1003
2022-06-07 14:24:46 Sebastien Bacher bug watch added https://github.com/WebPlatformForEmbedded/libwpe/issues/110
2022-07-27 08:52:16 Spyros Seimenis bug added subscriber Spyros Seimenis
2022-07-27 08:52:40 Spyros Seimenis libwpe (Ubuntu): assignee Ubuntu Security Team (ubuntu-security)
2022-08-02 14:40:49 Seth Arnold libwpe (Ubuntu): status New In Progress
2022-08-02 14:44:03 Christian Ehrhardt  libwpe (Ubuntu): assignee Sebastien Bacher (seb128)
2022-08-04 09:23:01 Sebastien Bacher libwpe (Ubuntu): status In Progress Fix Committed
2022-08-09 07:40:26 Didier Roche-Tolomelli libwpe (Ubuntu): status Fix Committed Fix Released
2022-12-01 14:31:39 Sebastien Bacher nominated for series Ubuntu Jammy
2022-12-01 14:31:39 Sebastien Bacher bug task added libwpe (Ubuntu Jammy)
2022-12-06 15:53:47 Lukas Märdian libwpe (Ubuntu Jammy): assignee Ioanna Alifieraki (joalif)
2023-03-30 19:42:02 Mark Esler bug added subscriber Mark Esler
2023-04-11 13:40:53 Ioanna Alifieraki bug added subscriber Ioanna Alifieraki
2023-04-11 14:49:28 Ioanna Alifieraki libwpe (Ubuntu Jammy): assignee Ioanna Alifieraki (joalif) Ubuntu Security Team (ubuntu-security)
2023-04-12 19:23:34 Seth Arnold bug added subscriber Seth Arnold
2023-04-12 19:23:37 Seth Arnold libwpe (Ubuntu Jammy): assignee Ubuntu Security Team (ubuntu-security)
2023-06-16 14:12:05 Sebastien Bacher libwpe (Ubuntu Jammy): importance Undecided High
2023-06-16 14:12:05 Sebastien Bacher libwpe (Ubuntu Jammy): status New Fix Released
2023-06-16 14:12:34 Sebastien Bacher libwpe (Ubuntu Jammy): status Fix Released In Progress
2023-06-16 14:36:58 Sebastien Bacher libwpe (Ubuntu Jammy): status In Progress Fix Released