Activity log for bug #1630073

Date Who What changed Old value New value Message
2016-10-04 00:42:36 Steve Langasek bug added bug
2016-10-04 00:44:22 Steve Langasek python-pyelftools (Ubuntu): assignee Christian Ehrhardt (der-schoenne)
2016-10-04 00:45:12 Steve Langasek bug added subscriber Canonical Server Team
2016-10-04 04:05:38 Steve Langasek python-pyelftools (Ubuntu): status New Incomplete
2016-10-04 04:44:39 Steve Langasek python-pyelftools (Ubuntu): assignee Christian Ehrhardt (der-schoenne) ChristianEhrhardt (paelzer)
2016-10-04 05:25:31 Steve Langasek bug added subscriber MIR approval team
2016-10-04 06:51:30 Christian Ehrhardt  bug task added dpdk (Ubuntu)
2016-10-04 06:51:40 Christian Ehrhardt  dpdk (Ubuntu): status New Triaged
2016-10-04 06:51:42 Christian Ehrhardt  dpdk (Ubuntu): importance Undecided High
2016-10-04 06:51:44 Christian Ehrhardt  dpdk (Ubuntu): assignee ChristianEhrhardt (paelzer)
2016-10-04 12:59:05 Launchpad Janitor dpdk (Ubuntu): status Triaged Fix Released
2016-10-05 11:09:23 Christian Ehrhardt  description The latest upload of dpdk introduces a dependency on python-pyelftools. MIR, or dropping of the dependency, needed. [MIR] Listing MIR requirements that are fulfilled IMHO: 0. First of all - this is for the Z* release, no rush into Yakkety, but starting to do it right for Z* now instead of late in the next cycle. 1. Availability: Is already in Ubuntu universe and builds for the architectures it is designed to work on. 2. Rationale: having this python extension available would allow us to ship a dpdk helper tool that can help debugging it in case uncommon network cards are used. DPDK is in main, so this would be a runtime dependency. 3. Security: There were no open CVEs reported against it in the past. No Binaries, services or anything like it - just py files to include and a readme. 4. Quality assurance: Being a python extension there is no config needed that would make usability complex. The code is well myintained upstream. Currently there is no Ubuntu Delta to Debian and so far there are zero bugs against the package at https://bugs.launchpad.net/ubuntu/+source/python-pyelftools Neither are there in Debian: https://bugs.debian.org/cgi-bin/pkgreport.cgi?pkg=python-pyelftools It has a set of integrated tests ran on build in override_dh_auto_test. 5. UI Standards: No UI 6. Dependencies: Runtime dependencies are on python2/3 only which already is in main. Build dependencies are on python, dh-python and debhelper. Again a small list and all already in main. 7. Standards compliance: Packaging is small and easy to understand as it is almost "just" calling dh with pybuild. It has a watch file and also FHS/Debian compliance is given. Lintian reports no open issues. 8. Maintenance: As said so far no open bugs and no delta. Since it doesn't expose anything to the network the risk of security issues is medium. It is medium and not low as it is used to process elf data on e.g. shared libraries - that means reading arbitrary data. Since it is in python a lot of the protection e.g. for buffer overflows comes from the runtime environment. There is no owning Team yet as it falls in the MIR prerequisites quote of "Simple packages (e.g. language bindings, simple Perl modules, small command-line programs, etc.) might not need very much maintenance effort, and if they are maintained well in Debian we can just keep them synced" ---- The latest upload of dpdk introduces a dependency on python-pyelftools. MIR, or dropping of the dependency, needed.
2016-10-05 11:10:25 Christian Ehrhardt  bug added subscriber ChristianEhrhardt
2016-10-05 11:10:42 Christian Ehrhardt  bug added subscriber Ubuntu Security Team
2016-10-31 18:42:55 Michael Terry python-pyelftools (Ubuntu): assignee ChristianEhrhardt (paelzer) Ubuntu Security Team (ubuntu-security)
2016-11-25 08:42:13 Christian Ehrhardt  python-pyelftools (Ubuntu): status Incomplete Confirmed
2016-11-25 11:31:15 Matthias Klose python-pyelftools (Ubuntu): status Confirmed Incomplete
2016-11-28 14:37:00 Scott Moser python-pyelftools (Ubuntu): status Incomplete Confirmed
2017-01-24 16:46:50 Jon Grimm bug added subscriber Jon Grimm
2017-06-01 15:47:48 Christian Ehrhardt  python-pyelftools (Ubuntu): importance Undecided Low
2017-09-23 02:23:23 Seth Arnold bug added subscriber Seth Arnold
2017-09-23 02:23:27 Seth Arnold python-pyelftools (Ubuntu): assignee Ubuntu Security Team (ubuntu-security)
2018-01-30 06:00:10 Matthias Klose python-pyelftools (Ubuntu): status Confirmed Fix Released
2023-05-25 10:41:26 Christian Ehrhardt  bug task deleted dpdk (Ubuntu)