Thursday, August 3, 2017

[USN-3377-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-3377-1
August 03, 2017

linux, linux-raspi2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 17.04

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-raspi2: Linux kernel for Raspberry Pi 2

Details:

Fan Wu and Shixiong Zhao discovered a race condition between inotify events
and vfs rename operations in the Linux kernel. An unprivileged local
attacker could use this to cause a denial of service (system crash) or
execute arbitrary code. (CVE-2017-7533)

It was discovered that the Linux kernel did not properly restrict
RLIMIT_STACK size. A local attacker could use this in conjunction with
another vulnerability to possibly execute arbitrary code.
(CVE-2017-1000365)

李强 discovered that the Virtio GPU driver in the Linux kernel did not
properly free memory in some situations. A local attacker could use this to
cause a denial of service (memory consumption). (CVE-2017-10810)

石磊 discovered that the RxRPC Kerberos 5 ticket handling code in the
Linux kernel did not properly verify metadata. A remote attacker could use
this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2017-7482)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 17.04:
linux-image-4.10.0-1013-raspi2 4.10.0-1013.16
linux-image-4.10.0-30-generic 4.10.0-30.34
linux-image-4.10.0-30-generic-lpae 4.10.0-30.34
linux-image-4.10.0-30-lowlatency 4.10.0-30.34
linux-image-generic 4.10.0.30.31
linux-image-generic-lpae 4.10.0.30.31
linux-image-lowlatency 4.10.0.30.31
linux-image-raspi2 4.10.0.1013.15

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://www.ubuntu.com/usn/usn-3377-1
CVE-2017-1000365, CVE-2017-10810, CVE-2017-7482, CVE-2017-7533

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.10.0-30.34
https://launchpad.net/ubuntu/+source/linux-raspi2/4.10.0-1013.16

OpenBSD Errata: August 3rd, 2017 (kernel)

Errata patches for a number of kernel issues have been released for
OpenBSD 6.1 and 6.0.

A SIGIO-related use-after-free can occur in two drivers.

A missing length check in sendsyslog() may result in a kernel panic.

An out-of-bound read in vfs_getcwd_scandir() (mainly used for FUSE)
may result in a kernel panic or info leak.

An alignment issue in recv() may result in an info leak via ktrace().

With an invalid address family, tcp_usrreq() may take an unintended code
path.

Missing socket address validation from userland may result in an info leak.

An uninitialized variable in ptrace() may result in an info leak.

An uninitialized variable in fcntl() may result in an info leak.

An integer overflow in wsdisplay_cfg_ioctl() may result in an out-of-bound
read.

A race condition in sosplice() may result in a kernel memory leak.

An out-of-bound read could occur during processing of EAPOL frames in
the wireless stack. Information from kernel memory could be leaked to
root in userland via an ieee80211(9) ioctl.

Binary updates for the amd64 and i386 platforms are available via the
syspatch utility. Source code patches can be found on the respective
errata pages:

https://www.openbsd.org/errata60.html
https://www.openbsd.org/errata61.html

As these affect the kernel, a reboot will be needed after patching.

Ubuntu 16.04.3 LTS released

The Ubuntu team is pleased to announce the release of Ubuntu 16.04.3 LTS
(Long-Term Support) for its Desktop, Server, and Cloud products, as well
as other flavours of Ubuntu with long-term support.

Like previous LTS series', 16.04.3 includes hardware enablement stacks
for use on newer hardware. This support is offered on all architectures
except for 32-bit powerpc, and is installed by default when using one of
the desktop images. Ubuntu Server defaults to installing the GA kernel,
however you may select the HWE kernel from the installer bootloader.

As usual, this point release includes many updates, and updated
installation media has been provided so that fewer updates will need to
be downloaded after installation. These include security updates and
corrections for other high-impact bugs, with a focus on maintaining
stability and compatibility with Ubuntu 16.04 LTS.

Kubuntu 16.04.3 LTS, Xubuntu 16.04.3 LTS, Mythbuntu 16.04.3 LTS,
Ubuntu GNOME 16.04.3 LTS, Lubuntu 16.04.3 LTS, Ubuntu Kylin 16.04.3 LTS,
Ubuntu MATE 16.04.3 LTS and Ubuntu Studio 16.04.3 LTS are also now
available. More details can be found in their individual release notes:

https://wiki.ubuntu.com/XenialXerus/ReleaseNotes#Official_flavours

Maintenance updates will be provided for 5 years for Ubuntu Desktop,
Ubuntu Server, Ubuntu Cloud, Ubuntu Base, and Ubuntu Kylin. All the
remaining flavours will be supported for 3 years.

To get Ubuntu 16.04.3
---------------------

In order to download Ubuntu 16.04.3, visit:

http://www.ubuntu.com/download

Users of Ubuntu 14.04 will be offered an automatic upgrade to
16.04.3 via Update Manager. For further information about upgrading,
see:

https://help.ubuntu.com/community/XenialUpgrades

As always, upgrades to the latest version of Ubuntu are entirely free of
charge.

We recommend that all users read the 16.04.3 release notes, which
document caveats and workarounds for known issues, as well as more
in-depth notes on the release itself. They are available at:

https://wiki.ubuntu.com/XenialXerus/ReleaseNotes

If you have a question, or if you think you may have found a bug but
aren't sure, you can try asking in any of the following places:

#ubuntu on irc.freenode.net
http://lists.ubuntu.com/mailman/listinfo/ubuntu-users
http://www.ubuntuforums.org
http://askubuntu.com


Help Shape Ubuntu
-----------------

If you would like to help shape Ubuntu, take a look at the list of ways
you can participate at:

http://www.ubuntu.com/community/get-involved


About Ubuntu
------------

Ubuntu is a full-featured Linux distribution for desktops, laptops,
clouds and servers, with a fast and easy installation and regular
releases. A tightly-integrated selection of excellent applications is
included, and an incredible variety of add-on software is just a few
clicks away.

Professional services including support are available from Canonical and
hundreds of other companies around the world. For more information
about support, visit:

http://www.ubuntu.com/support


More Information
----------------

You can learn more about Ubuntu and about this release on our website
listed below:

http://www.ubuntu.com/

To sign up for future Ubuntu announcements, please subscribe to Ubuntu's
very low volume announcement list at:

http://lists.ubuntu.com/mailman/listinfo/ubuntu-announce

On behalf of the Ubuntu Release Team,

... Adam Conrad

--
ubuntu-announce mailing list
ubuntu-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-announce

Pagure over dist-git: what changes?

Good morning everyone,

We're now in the final sprint before Pagure over dist-git is a real thing. This
is a great time and we're very excited to see it happen.
However this change brings other changes with it which are detailed below.


Point of contact in bugzilla
----------------------------
Pkgdb used to be the place where package points of contact were set and then
synced to bugzilla.
With Pagure over dist-git, the main admin of the Pagure project is now the point
of contact.
However, this is not always valid. For example, there are cases where the main
admin in Pagure does not want to be the point of contact for EPEL branches, or
the point of contact is a group.
For these cases, we have set up a procedure using a separate Pagure project
which allows you to override the default point of contact and set it to a
different Bugzilla account.
To change the default point of contact, simply open a pull-request (we will
build some automation around merging these requests so they do not depend on
human interventions).

More information at: https://pagure.io/dist-git-requests/

On this note, Pagure does not support having a group as the main admin.
We are of course using a script to sync data from pkgdb to pagure for packages
and set admin access.
When this script runs on a package with a group as main admin, it will set
the new main admin to the first account it encounters with commit access that is
not a group. So if you are suddenly the main admin of a project where you used
to only be co-maintainer before, this is likely why. Feel free to correct the
situation with your fellow co-maintainers.


CC in Bugzilla
--------------

Pagure over dist-git does not offer issue tracking. Issues for packages will
continue to be tracked in Bugzilla.
However, if you look at the watch options in a project in Pagure over dist-git,
you will see there is an option to watch issues on the project. This mechanism
will be used to retrieve the list of packagers to be CC'd on Bugzilla tickets.

Note: there is a ticket open against Pagure to have the list of people watching
the project available in the UI (it is currently only present in the API).


New package and new branch request process
------------------------------------------

PkgDB used to be the place where packagers could request a new branch or a new
package to be added.
The new package and branch processes will now rely on a project
hosted on pagure.io where people can open a ticket to request additions.
There is a CLI tool for packagers to use: fedrepo-req (already present
in updates-testing) that opens the ticket for you in
such a way that these requests can be automatically handled by release
engineering.

More information about this tool at: https://pagure.io/fedrepo_req


Koschei integration
-------------------

Packager used to activate koschei monitoring in pkgdb. Since pagure
does not offer this possibility, koschei has activated its own UI to allow that.
If you want to tweak koschei monitoring, the koschei web UI is now the place to
do it.


Anitya integration
------------------

Packagers used to be able to activate anitya integration in pkgdb. Since pagure
does not offer this, the integration with anitya and the new hotness will now be
achieved using the same pagure project as the bugzilla overrides.
This is targeted to be adjusted after pagure is deployed. mprahl and threebean
have volunteered to port the current integration status to the new mechanism
without requiring any action from you.

Efforts on this can be tracked at:
https://github.com/fedora-infra/the-new-hotness/issues/183


Pkgdb is still there!
---------------------

That is true, pkgdb is still available at its usual location. However, it has now
been made read-only. So the data can still be accessed, but as Pagure becomes
more integrated into our packaging workflow, the data in pkgdb will slowly grow
out of sync -- especially around the different ACLs and packages, modules,
containers available.
This gives us a little more time to adjust all the tooling that relies on
pkgdb. However, be aware the data is no longer current and you cannot rely on it.


It takes a while to fork!
-------------------------

This is also true. We have optimized pagure to only update parts of gitolite's
configuration file when there is a change. However, just re-compiling that
configuration file takes around a minute. So when you fork a repo, you may have
to wait for your task to be started and that task will take a little more than
a minute. Just be patient and it should work. If you wait and the task doesn't
complete as expected, please let us know, either on IRC on #fedora-admin
on irc.freenode.net or via a ticket on:
https://pagure.io/fedora-infrastructure/new_issue

One reason we wait for the gitolite configuration to be recompiled
is so that once the UI shows the task is done, you can directly commit to
your fork. Otherwise, the UI would show you your fork, but if you pushed to it
immediately after, you would receive a "permission denied" error.


Additional information
----------------------

These are only some of the changes that are coming with pagure over dist-git and
more of them are described here:

https://fedoraproject.org/wiki/Infrastructure/WhatHappenedToPkgdb

Some of them are still a little bit unclear, so please bear with us. Better
yet, come help us figure out the best solution for them.


Thank you for your attention,
Pierre

Wednesday, August 2, 2017

[USN-3376-1] WebKitGTK+ vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJZgc2ZAAoJEGVp2FWnRL6TL4oP/1ASW0QQnGIM+g+Vki/4vy7/
yLSBNWMNkopWS/MIN8XdZPUnst95ycxLUN3FakI5G82O/6icWBH4tANNnilb2h0a
2jfHkLQFtrqBMYLFtHagdIsD3X7EqocbIniKSx2S169z6w1T+inwCKFOREZkPrbv
+eYYg2VDZduyzU+nAYu6gXAwasm+85yT3JAXCqcINLVJifTu9sITDfm51cvIJQ2H
ukCWQoPHv90HE/QcKARpCoyMCN7A5nkyA4I4ZkwjDZsIZsu/hq53uWsCq0mSBo0q
FWOx/qC44rpgMB74ii4zyHNsALIL74Gw78+I7n+oRMkR6SbUd0X954z6b/gnpaPI
wluf8RVTj3sPBwYl/YA03A6+IzjwrcA9KRcwEZ3h7+a4dSr5qk9zl5IVdMxiSx5s
jnMFiFBe+QtnGwtiEinNukcYkQ5HAfZkG6DyKA/M1fW8QGQLquX3112Tfd8fwWyz
QBpMCb5daqJ2aIpMUDNmDnb0LaXgqiP36j4rO34wv36Xvk5DXF0HzuOmrfemXB0U
E35/Hr8P8ootLRvReR5CslQz3Y8QNKhi8CM1laPgJbY38kVTo1eIg0Lik+4yS7hl
8ZxZ2jvFC7+O4H/aA763v+7+wxcgCq3yDF9iHxhU92dejLN3pX6+Ydy3Mu0iO4ec
gTLwbBuytpzuZX0K6l8t
=+bsE
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3376-1
August 02, 2017

webkit2gtk vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 17.04
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in WebKitGTK+.

Software Description:
- webkit2gtk: Web content engine library for GTK+

Details:

A large number of security issues were discovered in the WebKitGTK+ Web and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of service
attacks, and arbitrary code execution.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 17.04:
libjavascriptcoregtk-4.0-18 2.16.6-0ubuntu0.17.04.1
libwebkit2gtk-4.0-37 2.16.6-0ubuntu0.17.04.1

Ubuntu 16.04 LTS:
libjavascriptcoregtk-4.0-18 2.16.6-0ubuntu0.16.04.1
libwebkit2gtk-4.0-37 2.16.6-0ubuntu0.16.04.1

This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK+, such as Epiphany, to make all the necessary changes.

References:
https://www.ubuntu.com/usn/usn-3376-1
CVE-2017-2538, CVE-2017-7018, CVE-2017-7030, CVE-2017-7034,
CVE-2017-7037, CVE-2017-7039, CVE-2017-7046, CVE-2017-7048,
CVE-2017-7052, CVE-2017-7055, CVE-2017-7056, CVE-2017-7061,
CVE-2017-7064

Package Information:
https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.17.04.1
https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1

[USN-3375-1] LXC vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJZgc2FAAoJEGVp2FWnRL6ToFAQAJgn7vMy2pPnOMyPBV88YS9v
kDqOXeB3iTi9y0NrMAkzAFRXaL02spqS2NH2uYcJU2MBNkHoEtDycjlzRthYUYKg
I1aywLxWW6PLqrK4p3tGeQdUqpBQD1NAm4NROpooOmddBHSEY9kxFV8SJWd41nSA
e77iUZDiLWB7vBN/RyskbKjtnP3INL81McvbIdEsuBeKaB/mq+Ij9LZBMHvzjCgH
XJUkiyReIkn75/lMMTVVAPQCrhdIaPxjdeADk2xt0fZLt1Blt6bA+friXUeOgkMJ
vIlMoCYylhO79oyA9WaRMV5IHzboXSaIs8E2hCShHxHZ9aVnXBYL8oQkGNtgd+2k
rLq04thoAB5gPZfK9tLdVFVGwDiep9Kp8oM1ZRXO6smU6a4SNaYH/q/a2EYaZEjX
yaAAZel1vJKin9eJ1E26R3mEJVg2Bu07BW95aai9neekYMrbkpacjR+UooV1PUwp
B8IeIGADIzdgOaDlbbF0WFki2k18/fondCLgQ2VWhNtCPdoO109648njlAxjwQDF
LGVJbBeZHSxaGmkrebcN10gVse8OZFamB3KzGursxmhW9w8n4NGb+xkEdv+Iapij
HD3m0343389ShyNgYnuN5t4bAIiz9qQZGhmNDI9pPP1BuLtCIWirDA6QYq+QZmkk
h1fuH/26LvWbPRGf6dPm
=UQMj
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3375-1
August 02, 2017

lxc vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

LXC would allow unintended access.

Software Description:
- lxc: Linux Containers userspace tools

Details:

It was discovered that LXC incorrectly handled the TIOCSTI ioctl. An
attacker could possibly use this issue to escape LXC containers.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
lxc 1.0.10-0ubuntu1.1

After a standard system update you need to restart LXC containers to make
all the necessary changes.

References:
https://www.ubuntu.com/usn/usn-3375-1
CVE-2016-10124

Package Information:
https://launchpad.net/ubuntu/+source/lxc/1.0.10-0ubuntu1.1

Tuesday, August 1, 2017

[USN-3370-2] Apache HTTP Server vulnerability

==========================================================================
Ubuntu Security Notice USN-3370-2
August 01, 2017

apache2 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

Apache HTTP Server could be made to crash or leak sensitive information
if it received specially crafted network traffic.

Software Description:
- apache2: Apache HTTP server

Details:

USN-3370-1 fixed a vulnerability in Apache HTTP Server.
This update provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 Robert Święcki discovered that the Apache HTTP Server mod_auth_digest
 module incorrectly cleared values when processing certain requests. A
 remote attacker could use this issue to cause the server to crash,
 resulting in a denial or service, or possibly obtain sensitive
 information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  apache2.2-bin                   2.2.22-1ubuntu1.13

In general, a standard system update will make all the necessary
changes.

References:
  https://www.ubuntu.com/usn/usn-3370-2
  https://www.ubuntu.com/usn/usn-3370-1
  CVE-2017-9788

Planned Outage: koji database server - 2017-08-01 21:00:00 UTC

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEESz7rprBJHpbnMnrQSzew2A/7u14FAlmAorIACgkQSzew2A/7
u164TRAAlXXyJAuSF676n9ffLGYHBdyh+lWP8gT/exOEvSCn/uLy41FYW8X4gJ4V
dMUIcsegLV24VIqzI/1yO188fnEdF5U3MONzm3Gp8uyBoiKMonh0o/Wpmqp/uCS9
9KwiqfYk930//OAmTQsdNgadkr3ndmssCSyke37VsgLgyesVuBPYs8frEp/LC/oq
jkBCcwh1iTq0uVhjfgA1fcpxVsvNlGWLt9rm1pMfMN9VymLd7JHG1pOsqq5Xe8qJ
OWDq3HPDrZulrLfGYUQRvClWXSFHxOs4sqCW5VT8loM+cUaowe4CTdNSCSom++m4
gw0nrV15MQyjoZgCM78iPyT3G1lKo38Qlvh/Cfe8IQlupfCyLOB6kQqQ41QvQ4xy
C5WJZmug0AY7tqrP5fyBlwqqb5JZ4spA1qqLAriACkLegtAplxEWLSDs446HJCCq
LBjLc/eubkUb5VVCHk8hWN6d5PXjMivIx19Wt0sVy0uUFfVVR3QAQCJ/p7zH62Is
CUrLv3kg/ThB2DRh86xp9wfWvGg5QahuSxvo3eTBWvbAd6RZ0nG6gLjPYH4AlKxV
uGBrqnDF6mQxbPxgybsHv6RWeJjSQ7P0MKcNy8z2llRX2TdZriDuQfO6tCGFweIG
5u3uwTUWgcyQGRupSXcGlOioSmTr+JzWVSUmcYU2HA2/sD10pf0=
=fouL
-----END PGP SIGNATURE-----
Planned Outage: koji database server - 2017-08-01 21:00:00 UTC

There will be an outage starting at 2017-08-01 21:00:00 UTC,
which will last approximately 1 hour.

To convert UTC to your local time, take a look at
http://fedoraproject.org/wiki/Infrastructure/UTCHowto
or run:

date -d '2017-08-01 21:00:00 UTC'

Reason for outage:

We are updating koji to its latest version which requires a
small database schema update.
During this outage we will take it off line.

Affected Services:

koji.fedoraproject.org
koschei.fedoraproject.org
bodhi.fedoraproject.org

Contact Information:

Ticket Link: https://fedorahosted.org/fedora-infrastructure/ticket/6186

Please join #fedora-admin or #fedora-noc on irc.freenode.net or
add comments to the ticket for this outage above.

[USN-3294-2] Bash vulnerability

==========================================================================
Ubuntu Security Notice USN-3294-2
August 01, 2017

bash vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

A security issues were fixed in Bash.

Software Description:
- bash: GNU Bourne Again SHell

Details:

USN-3294-1 fixed a vulnerability in Bash. This update provides the
corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 It was discovered that Bash incorrectly handled the SHELLOPTS and PS4
 environment variables. A local attacker could use this issue to
 execute arbitrary code with root privileges. (CVE-2016-7543)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  bash                            4.2-2ubuntu2.7

In general, a standard system update will make all the necessary
changes.

References:
  https://www.ubuntu.com/usn/usn-3294-2
  https://www.ubuntu.com/usn/usn-3294-1
  CVE-2016-7543

lists.linuxfromscratch.org mailing list memberships reminder

This is a reminder, sent out once a month, about your
lists.linuxfromscratch.org mailing list memberships. It includes your
subscription info and how to use it to change it or unsubscribe from a
list.

You can visit the URLs to change your membership status or
configuration, including unsubscribing, setting digest-style delivery
or disabling delivery altogether (e.g., for a vacation), and so on.

In addition to the URL interfaces, you can also use email to make such
changes. For more info, send a message to the '-request' address of
the list (for example, mailman-request@lists.linuxfromscratch.org)
containing just the word 'help' in the message body, and an email
message will be sent to you with instructions.

If you have questions, problems, comments, etc, send them to
mailman-owner@lists.linuxfromscratch.org. Thanks!

Passwords for reallost1.fbsd2233449@blogger.com:

List Password // URL
---- --------
lfs-announce@lists.linuxfromscratch.org vaozebru
http://lists.linuxfromscratch.org/options/lfs-announce/reallost1.fbsd2233449%40blogger.com

[opensuse-announce] Refresh of Linux Distribution Continues Leveraging Community, Enterprise Benefits

Hi all,
The release team and openSUSE community are proud to have released openSUSE Leap 42.3. I would encourage you to read the release at https://news.opensuse.org/2017/07/26/refresh-of-linux-distribution-continues-leveraging-community-enterprise-benefits/ and check out the features at https://en.opensuse.org/Features. Most importantly, I would encourage you download it at your earliest convenience at https://software.opensuse.org.
Respectfully,
Doug

Fedora 27 Change Checkpoint: Completion deadline (testable)

Greetings!

Today, on 2017-Aug-01, we have reached Fedora 27 Change
Checkpoint:Completion deadline (testable) [1].

At this point, all accepted changes [2] should be substantially
complete, and testable. Additionally, if a change is to be enabled by
default, it must be enabled at Change Completion deadline as well.

Change tracking bug should be set to the MODIFIED state to indicate it
achieved completeness.

Incomplete and non testable Changes [3] will be reported to FESCo on
2017-Aug-04 meeting. Contingency plan for System Wide Changes in case
of serious doubts regarding Change completion, will be activated.

Side note: Currently we still have several Changes waiting for FESco
approval [4]. I am going to ask FESCo to consider postponing of this
Checkpoint for these Changes, in case these are approved.

[1] https://fedoraproject.org/wiki/Releases/27/Schedule
[2] https://fedoraproject.org/wiki/Releases/27/ChangeSet
[3] http://red.ht/2vijerN
[4] https://pagure.io/fesco/issues

--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org