sru request for sun-java5

Bug #255011 reported by Matthias Klose
14
Affects Status Importance Assigned to Milestone
sun-java5 (Ubuntu)
Invalid
Undecided
Matthias Klose
Dapper
Fix Released
Undecided
Unassigned
Hardy
Fix Released
Undecided
Unassigned
Intrepid
Won't Fix
Undecided
Matthias Klose

Bug Description

sun-java5 (1.5.0-16-1ubuntu2) hardy-proposed; urgency=low

Revision history for this message
Matthias Klose (doko) wrote :

  * New upstream bug fix release. LP: #255011.
    - Including security related changes.
      CVE-2008-3115, CVE-2008-3114, CVE-2008-3113, CVE-2008-3112,
      CVE-2008-3111, CVE-2008-3110, CVE-2008-3109, CVE-2008-3108,
      CVE-2008-3107, CVE-2008-3106, CVE-2008-3105, CVE-2008-3104,
      CVE-2008-3103, CVE-2008-3102.
    - Fix locking assertion failure. LP: #86103.

Revision history for this message
Matthias Klose (doko) wrote :

for dapper-proposed:

sun-java5 (1.5.0-16-0ubuntu0.6.06) dapper-proposed; urgency=low

  * CVE's addressed in this upstream release:
      CVE-2008-3115, CVE-2008-3114, CVE-2008-3113, CVE-2008-3112,
      CVE-2008-3111, CVE-2008-3110, CVE-2008-3109, CVE-2008-3108,
      CVE-2008-3107, CVE-2008-3106, CVE-2008-3105, CVE-2008-3104,
      CVE-2008-3103, CVE-2008-3102.
  * Fix locking assertion failure. Closes: #402165.
  * Update sv translation for debconf template (Martin Bagge). Closes: #488183.
  * JB-bin.postinst.in: Call java -client -Xshare:dump with -Xmx1m, if the
    memory is available. Closes: #390296.
  * Ignore errors during activation of class data sharing. Closes: #402067.

  [ Following changes based on sun-java6 patch by Philipp Hahn]
  * Don't remove alternatives on upgrade. Closes: #465970.
  * debian/control: Add Pre-Depends: debconf for bin-package.
    convert to UTF-8.
  * debian/JB-doc.postinst.in: /chown/s/./:/.
  * debian/*.menu.in: s/Apps/Applications/.

Revision history for this message
Martin Pitt (pitti) wrote :

Accepted into -proposed, please test and give feedback here. Please see https://wiki.ubuntu.com/Testing/EnableProposed for documentation how to enable and use -proposed. Thank you in advance!

Changed in sun-java5:
status: New → Fix Committed
Revision history for this message
Martin Pitt (pitti) wrote :

Accepted into dapper-proposed as well.

Changed in sun-java5:
status: New → Fix Committed
Revision history for this message
Martin Pitt (pitti) wrote :

For the intrepid task, do we actually need to keep sun-java5, and thus should update it here as well, or just drop the package entirely?

Changed in sun-java5:
assignee: nobody → doko
status: New → Triaged
Revision history for this message
Alex Mayorga (alex-mayorga) wrote :

Matthias,

I believe that's entirely up to you as the maintainer. Java 5 would reach "End of Service Life" (EOSL) on October 30, 2009 and Sun already encourages to "Migrate to the latest Java SE release" http://java.sun.com/javase/downloads/index_jdk5.jsp so in theory this should make it into Intrepid too.

IMHO if the package is readily available for Dapper and Hardy, there's no reason for not making it available on Intrepid that by definition, in my mind at least, should have the "latest and greatest" packages.

Revision history for this message
Max Bowsher (maxb) wrote :

Java developers usually have to use the earliest JDK version with which they want their product to remain compatible with, to verify that compatibility. As such, there's certainly a large group of people who would find it very useful for Java 5 to remain in Intrepid and beyond, who will need to pursue manual installs if it is dropped. If the maintenance burden isn't prohibitive, it would certainly be very useful to retain as long as possible.

Revision history for this message
Max Bowsher (maxb) wrote :

I've just realized an additional point. Owing to evolution of interfaces that are included in the JDK, such as JDBC, there are projects such as Hibernate which *cannot* be compiled with JDK 6, and must use JDK 5 (because JDK 6 added methods to interfaces). So, yes, there's significant benefit in retaining Java 5 until its End of Service Life.

Revision history for this message
Matthias Klose (doko) wrote :

keep it for intrepid; then remove it in jaunty. End of Service life means we won't get any updates anymore, and leave our users without fixes for the time they run the release.

Revision history for this message
Colin Watson (cjwatson) wrote :

Should this bug still be open against Intrepid? sun-java5 1.5.0-16-3 seems to fix this, although it doesn't refer to this bug report.

Revision history for this message
Matthias Klose (doko) wrote :

keeping it open, so I know I have to revisit it / remove the package from jaunty after the next (1.5.0-17) release.

Revision history for this message
Steve Langasek (vorlon) wrote :

this bug was targeted to intrepid, though - if you want to track this bug for jaunty, this should be 'wontfix' now for intrepid.

Changed in sun-java5:
status: Triaged → Won't Fix
Steve Langasek (vorlon)
Changed in sun-java5:
status: Won't Fix → Fix Released
status: Fix Released → Won't Fix
Revision history for this message
Martin Pitt (pitti) wrote :

Intrepid has 1.5.0-16, so does Jaunty. Should this package be removed from Jaunty?

Revision history for this message
Martin Pitt (pitti) wrote :

Also, anyone who could give the dapper/hardy-proposed versions a quick test to check that they still by and large work?

Revision history for this message
Andreas Wenning (andreas-wenning) wrote :

hardy-proposed package confirmed. The following has been tested:
- stand-alone application
- applet in firefox3
- applet in firefox2
- applet in konqueror

Revision history for this message
Andreas Wenning (andreas-wenning) wrote :

dapper-proposed packages looks good as well. Tested:
- stand-alone applications
- applets in firefox

Revision history for this message
Andreas Wenning (andreas-wenning) wrote :

@pitti
Do you want me to perform any more validation-testing on this?

Revision history for this message
Andreas Wenning (andreas-wenning) wrote :

Could this be marked as verification-done; or should more tests be performed?

Revision history for this message
Martin Pitt (pitti) wrote :

Copied to hardy-updates.

Changed in sun-java5:
status: Fix Committed → Fix Released
Revision history for this message
Martin Pitt (pitti) wrote :

As for the dapper update, I removed it since it was sitting in dapper-proposed for half a year without a bug # reference, thus it fell victim to my SRU cleanup. I'll upload a no-change upload to -updates.

Revision history for this message
Martin Pitt (pitti) wrote :

sun-java5 (1.5.0-16-0ubuntu0.6.06.1) dapper-updates; urgency=low

  * No-change upload to -updates, after passed verification. (LP: #255011)

 -- Martin Pitt <email address hidden> Wed, 28 Jan 2009 12:17:41 +0000

sun-java5 (1.5.0-16-0ubuntu0.6.06) dapper-proposed; urgency=low

  * CVE's addressed in this upstream release:
      CVE-2008-3115, CVE-2008-3114, CVE-2008-3113, CVE-2008-3112,
      CVE-2008-3111, CVE-2008-3110, CVE-2008-3109, CVE-2008-3108,
      CVE-2008-3107, CVE-2008-3106, CVE-2008-3105, CVE-2008-3104,
      CVE-2008-3103, CVE-2008-3102.
  * Fix locking assertion failure. Closes: #402165.
  * Update sv translation for debconf template (Martin Bagge). Closes: #488183.
  * JB-bin.postinst.in: Call java -client -Xshare:dump with -Xmx1m, if the
    memory is available. Closes: #390296.
  * Ignore errors during activation of class data sharing. Closes: #402067.

  [ Following changes based on sun-java6 patch by Philipp Hahn]
  * Don't remove alternatives on upgrade. Closes: #465970.
  * debian/control: Add Pre-Depends: debconf for bin-package.
    convert to UTF-8.
  * debian/JB-doc.postinst.in: /chown/s/./:/.
  * debian/*.menu.in: s/Apps/Applications/.

 -- Matthias Klose <email address hidden> Tue, 5 Aug 2008 16:51:38 +0000

Changed in sun-java5:
status: Fix Committed → Fix Released
status: Triaged → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers