Tuesday, January 7, 2020

[announce] Next NYC*BUG: Tomorrow *Please note new location*

Next NYC*BUG: Tomorrow 

*Please note new location*

What is notqmail?

by Amitai Schleier

2020-01-08 @ 18:45 - close of meeting


*Chartbeat 826 Broadway, 6th Floor New York, NY 10003*


Monday, January 6, 2020

[USN-4228-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-4228-1
January 07, 2020

linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon
vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-kvm: Linux kernel for cloud environments
- linux-raspi2: Linux kernel for Raspberry Pi 2
- linux-snapdragon: Linux kernel for Snapdragon processors

Details:

It was discovered that a heap-based buffer overflow existed in the Marvell
WiFi-Ex Driver for the Linux kernel. A physically proximate attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2019-14895, CVE-2019-14901)

It was discovered that a heap-based buffer overflow existed in the Marvell
Libertas WLAN Driver for the Linux kernel. A physically proximate attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2019-14896, CVE-2019-14897)

Anthony Steinhauser discovered that the Linux kernel did not properly
perform Spectre_RSB mitigations to all processors for PowerPC architecture
systems in some situations. A local attacker could use this to expose
sensitive information. (CVE-2019-18660)

It was discovered that Geschwister Schneider USB CAN interface driver in
the Linux kernel did not properly deallocate memory in certain failure
conditions. A physically proximate attacker could use this to cause a
denial of service (kernel memory exhaustion). (CVE-2019-19052)

It was discovered that the driver for memoryless force-feedback input
devices in the Linux kernel contained a use-after-free vulnerability. A
physically proximate attacker could possibly use this to cause a denial of
service (system crash) or execute arbitrary code. (CVE-2019-19524)

It was discovered that the PEAK-System Technik USB driver in the Linux
kernel did not properly sanitize memory before sending it to the device. A
physically proximate attacker could use this to expose sensitive
information (kernel memory). (CVE-2019-19534)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
linux-image-4.4.0-1064-kvm 4.4.0-1064.71
linux-image-4.4.0-1100-aws 4.4.0-1100.111
linux-image-4.4.0-1127-raspi2 4.4.0-1127.136
linux-image-4.4.0-1131-snapdragon 4.4.0-1131.139
linux-image-4.4.0-171-generic 4.4.0-171.200
linux-image-4.4.0-171-generic-lpae 4.4.0-171.200
linux-image-4.4.0-171-lowlatency 4.4.0-171.200
linux-image-4.4.0-171-powerpc-e500mc 4.4.0-171.200
linux-image-4.4.0-171-powerpc-smp 4.4.0-171.200
linux-image-4.4.0-171-powerpc64-emb 4.4.0-171.200
linux-image-4.4.0-171-powerpc64-smp 4.4.0-171.200
linux-image-aws 4.4.0.1100.104
linux-image-generic 4.4.0.171.179
linux-image-generic-lpae 4.4.0.171.179
linux-image-kvm 4.4.0.1064.64
linux-image-lowlatency 4.4.0.171.179
linux-image-powerpc-e500mc 4.4.0.171.179
linux-image-powerpc-smp 4.4.0.171.179
linux-image-powerpc64-emb 4.4.0.171.179
linux-image-powerpc64-smp 4.4.0.171.179
linux-image-raspi2 4.4.0.1127.127
linux-image-snapdragon 4.4.0.1131.123
linux-image-virtual 4.4.0.171.179

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4228-1
CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901,
CVE-2019-18660, CVE-2019-19052, CVE-2019-19524, CVE-2019-19534

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.4.0-171.200
https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1100.111
https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1064.71
https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1127.136
https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1131.139

[USN-4227-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-4227-1
January 07, 2020

linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15,
linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2,
linux-snapdragon vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-gke-4.15: Linux kernel for Google Container Engine (GKE) systems
- linux-kvm: Linux kernel for cloud environments
- linux-oem: Linux kernel for OEM processors
- linux-oracle: Linux kernel for Oracle Cloud systems
- linux-raspi2: Linux kernel for Raspberry Pi 2
- linux-snapdragon: Linux kernel for Snapdragon processors
- linux-aws-hwe: Linux kernel for Amazon Web Services (AWS-HWE) systems
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-hwe: Linux hardware enablement (HWE) kernel

Details:

It was discovered that a heap-based buffer overflow existed in the Marvell
WiFi-Ex Driver for the Linux kernel. A physically proximate attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2019-14895, CVE-2019-14901)

It was discovered that a heap-based buffer overflow existed in the Marvell
Libertas WLAN Driver for the Linux kernel. A physically proximate attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2019-14896, CVE-2019-14897)

It was discovered that the Fujitsu ES network device driver for the Linux
kernel did not properly check for errors in some situations, leading to a
NULL pointer dereference. A local attacker could use this to cause a denial
of service. (CVE-2019-16231)

It was discovered that the QLogic Fibre Channel driver in the Linux kernel
did not properly check for error, leading to a NULL pointer dereference. A
local attacker could possibly use this to cause a denial of service (system
crash). (CVE-2019-16233)

Anthony Steinhauser discovered that the Linux kernel did not properly
perform Spectre_RSB mitigations to all processors for PowerPC architecture
systems in some situations. A local attacker could use this to expose
sensitive information. (CVE-2019-18660)

It was discovered that the Mellanox Technologies Innova driver in the Linux
kernel did not properly deallocate memory in certain failure conditions. A
local attacker could use this to cause a denial of service (kernel memory
exhaustion). (CVE-2019-19045)

It was discovered that Geschwister Schneider USB CAN interface driver in
the Linux kernel did not properly deallocate memory in certain failure
conditions. A physically proximate attacker could use this to cause a
denial of service (kernel memory exhaustion). (CVE-2019-19052)

It was discovered that the AMD Display Engine Driver in the Linux kernel
did not properly deallocate memory in certain error conditions. A local
attack could use this to cause a denial of service (memory exhaustion).
(CVE-2019-19083)

It was discovered that the driver for memoryless force-feedback input
devices in the Linux kernel contained a use-after-free vulnerability. A
physically proximate attacker could possibly use this to cause a denial of
service (system crash) or execute arbitrary code. (CVE-2019-19524)

It was discovered that the Microchip CAN BUS Analyzer driver in the Linux
kernel contained a use-after-free vulnerability on device disconnect. A
physically proximate attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-19529)

It was discovered that the PEAK-System Technik USB driver in the Linux
kernel did not properly sanitize memory before sending it to the device. A
physically proximate attacker could use this to expose sensitive
information (kernel memory). (CVE-2019-19534)

Tristan Madani discovered that the ALSA timer implementation in the Linux
kernel contained a use-after-free vulnerability. A local attacker could use
this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2019-19807)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
linux-image-4.15.0-1031-oracle 4.15.0-1031.34
linux-image-4.15.0-1050-gke 4.15.0-1050.53
linux-image-4.15.0-1052-kvm 4.15.0-1052.52
linux-image-4.15.0-1053-raspi2 4.15.0-1053.57
linux-image-4.15.0-1057-aws 4.15.0-1057.59
linux-image-4.15.0-1066-oem 4.15.0-1066.76
linux-image-4.15.0-1070-snapdragon 4.15.0-1070.77
linux-image-4.15.0-74-generic 4.15.0-74.84
linux-image-4.15.0-74-generic-lpae 4.15.0-74.84
linux-image-4.15.0-74-lowlatency 4.15.0-74.84
linux-image-aws 4.15.0.1057.58
linux-image-aws-lts-18.04 4.15.0.1057.58
linux-image-generic 4.15.0.74.76
linux-image-generic-lpae 4.15.0.74.76
linux-image-gke 4.15.0.1050.53
linux-image-gke-4.15 4.15.0.1050.53
linux-image-kvm 4.15.0.1052.52
linux-image-lowlatency 4.15.0.74.76
linux-image-oem 4.15.0.1066.70
linux-image-oracle 4.15.0.1031.36
linux-image-oracle-lts-18.04 4.15.0.1031.36
linux-image-powerpc-e500mc 4.15.0.74.76
linux-image-powerpc-smp 4.15.0.74.76
linux-image-powerpc64-emb 4.15.0.74.76
linux-image-powerpc64-smp 4.15.0.74.76
linux-image-raspi2 4.15.0.1053.51
linux-image-snapdragon 4.15.0.1070.73
linux-image-virtual 4.15.0.74.76

Ubuntu 16.04 LTS:
linux-image-4.15.0-1031-oracle 4.15.0-1031.34~16.04.1
linux-image-4.15.0-1052-gcp 4.15.0-1052.56
linux-image-4.15.0-1057-aws 4.15.0-1057.59~16.04.1
linux-image-4.15.0-1066-azure 4.15.0-1066.71
linux-image-4.15.0-74-generic 4.15.0-74.83~16.04.1
linux-image-4.15.0-74-generic-lpae 4.15.0-74.83~16.04.1
linux-image-4.15.0-74-lowlatency 4.15.0-74.83~16.04.1
linux-image-aws-hwe 4.15.0.1057.57
linux-image-azure 4.15.0.1066.69
linux-image-azure-edge 4.15.0.1066.69
linux-image-gcp 4.15.0.1052.66
linux-image-generic-hwe-16.04 4.15.0.74.94
linux-image-generic-lpae-hwe-16.04 4.15.0.74.94
linux-image-gke 4.15.0.1052.66
linux-image-lowlatency-hwe-16.04 4.15.0.74.94
linux-image-oem 4.15.0.74.94
linux-image-oracle 4.15.0.1031.24
linux-image-virtual-hwe-16.04 4.15.0.74.94

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4227-1
CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901,
CVE-2019-16231, CVE-2019-16233, CVE-2019-18660, CVE-2019-19045,
CVE-2019-19052, CVE-2019-19083, CVE-2019-19524, CVE-2019-19529,
CVE-2019-19534, CVE-2019-19807

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.15.0-74.84
https://launchpad.net/ubuntu/+source/linux-aws/4.15.0-1057.59
https://launchpad.net/ubuntu/+source/linux-gke-4.15/4.15.0-1050.53
https://launchpad.net/ubuntu/+source/linux-kvm/4.15.0-1052.52
https://launchpad.net/ubuntu/+source/linux-oem/4.15.0-1066.76
https://launchpad.net/ubuntu/+source/linux-oracle/4.15.0-1031.34
https://launchpad.net/ubuntu/+source/linux-raspi2/4.15.0-1053.57
https://launchpad.net/ubuntu/+source/linux-snapdragon/4.15.0-1070.77
https://launchpad.net/ubuntu/+source/linux-aws-hwe/4.15.0-1057.59~16.04.1
https://launchpad.net/ubuntu/+source/linux-azure/4.15.0-1066.71
https://launchpad.net/ubuntu/+source/linux-gcp/4.15.0-1052.56
https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-74.83~16.04.1
https://launchpad.net/ubuntu/+source/linux-oracle/4.15.0-1031.34~16.04.1

[USN-4226-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-4226-1
January 07, 2020

linux, linux-aws, linux-aws-5.0, linux-azure, linux-gcp, linux-gke-5.0,
linux-kvm, linux-oem-osp1, linux-oracle, linux-oracle-5.0, linux-raspi2
vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 19.04
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-kvm: Linux kernel for cloud environments
- linux-oracle: Linux kernel for Oracle Cloud systems
- linux-raspi2: Linux kernel for Raspberry Pi 2
- linux-aws-5.0: Linux kernel for Amazon Web Services (AWS) systems
- linux-gke-5.0: Linux kernel for Google Container Engine (GKE) systems
- linux-oem-osp1: Linux kernel for OEM processors
- linux-oracle-5.0: Linux kernel for Oracle Cloud systems

Details:

Michael Hanselmann discovered that the CIFS implementation in the Linux
kernel did not sanitize paths returned by an SMB server. An attacker
controlling an SMB server could use this to overwrite arbitrary files.
(CVE-2019-10220)

It was discovered that a heap-based buffer overflow existed in the Marvell
WiFi-Ex Driver for the Linux kernel. A physically proximate attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2019-14895, CVE-2019-14901)

It was discovered that a heap-based buffer overflow existed in the Marvell
Libertas WLAN Driver for the Linux kernel. A physically proximate attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2019-14896, CVE-2019-14897)

It was discovered that the Fujitsu ES network device driver for the Linux
kernel did not properly check for errors in some situations, leading to a
NULL pointer dereference. A local attacker could use this to cause a denial
of service. (CVE-2019-16231)

It was discovered that the QLogic Fibre Channel driver in the Linux kernel
did not properly check for error, leading to a NULL pointer dereference. A
local attacker could possibly use this to cause a denial of service (system
crash). (CVE-2019-16233)

Nicolas Waisman discovered that the WiFi driver stack in the Linux kernel
did not properly validate SSID lengths. A physically proximate attacker
could use this to cause a denial of service (system crash).
(CVE-2019-17133)

Anthony Steinhauser discovered that the Linux kernel did not properly
perform Spectre_RSB mitigations to all processors for PowerPC architecture
systems in some situations. A local attacker could use this to expose
sensitive information. (CVE-2019-18660)

It was discovered that the Mellanox Technologies Innova driver in the Linux
kernel did not properly deallocate memory in certain failure conditions. A
local attacker could use this to cause a denial of service (kernel memory
exhaustion). (CVE-2019-19045)

It was discovered that the VirtualBox guest driver implementation in the
Linux kernel did not properly deallocate memory in certain error
conditions. A local attacker could use this to cause a denial of service
(memory exhaustion). (CVE-2019-19048)

It was discovered that Geschwister Schneider USB CAN interface driver in
the Linux kernel did not properly deallocate memory in certain failure
conditions. A physically proximate attacker could use this to cause a
denial of service (kernel memory exhaustion). (CVE-2019-19052)

It was discovered that the netlink-based 802.11 configuration interface in
the Linux kernel did not deallocate memory in certain error conditions. A
local attacker could possibly use this to cause a denial of service (kernel
memory exhaustion). (CVE-2019-19055)

It was discovered that the ADIS16400 IIO IMU Driver for the Linux kernel
did not properly deallocate memory in certain error conditions. A local
attacker could use this to cause a denial of service (memory exhaustion).
(CVE-2019-19060)

It was discovered that the Intel OPA Gen1 Infiniband Driver for the Linux
kernel did not properly deallocate memory in certain error conditions. A
local attacker could use this to cause a denial of service (memory
exhaustion). (CVE-2019-19065)

It was discovered that the AMD Audio CoProcessor Driver for the Linux
kernel did not properly deallocate memory in certain error conditions. A
local attacker with the ability to load modules could use this to cause a
denial of service (memory exhaustion). (CVE-2019-19067)

It was discovered that the event tracing subsystem of the Linux kernel did
not properly deallocate memory in certain error conditions. A local
attacker could use this to cause a denial of service (kernel memory
exhaustion). (CVE-2019-19072)

It was discovered that the Cascoda CA8210 SPI 802.15.4 wireless controller
driver for the Linux kernel did not properly deallocate memory in certain
error conditions. A local attacker could use this to cause a denial of
service (memory exhaustion). (CVE-2019-19075)

It was discovered that the AMD Display Engine Driver in the Linux kernel
did not properly deallocate memory in certain error conditions. A local
attack could use this to cause a denial of service (memory exhaustion).
(CVE-2019-19083)

It was discovered that the driver for memoryless force-feedback input
devices in the Linux kernel contained a use-after-free vulnerability. A
physically proximate attacker could possibly use this to cause a denial of
service (system crash) or execute arbitrary code. (CVE-2019-19524)

It was discovered that the NXP PN533 NFC USB driver in the Linux kernel did
not properly free resources after a late probe error, leading to a use-
after-free vulnerability. A physically proximate attacker could use this to
cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2019-19526)

It was discovered that the Microchip CAN BUS Analyzer driver in the Linux
kernel contained a use-after-free vulnerability on device disconnect. A
physically proximate attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-19529)

It was discovered that multiple USB HID device drivers in the Linux kernel
did not properly validate device metadata on attachment, leading to out-of-
bounds writes. A physically proximate attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2019-19532)

It was discovered that the PEAK-System Technik USB driver in the Linux
kernel did not properly sanitize memory before sending it to the device. A
physically proximate attacker could use this to expose sensitive
information (kernel memory). (CVE-2019-19534)

It was discovered that in some situations the fair scheduler in the Linux
kernel did not permit a process to use its full quota time slice. A local
attacker could use this to cause a denial of service. (CVE-2019-19922)

It was discovered that the binder IPC implementation in the Linux kernel
did not properly perform bounds checking in some situations, leading to an
out-of-bounds write. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2019-2214)

Nicolas Waisman discovered that the Chelsio T4/T5 RDMA Driver for the Linux
kernel performed DMA from a kernel stack. A local attacker could use this
to cause a denial of service (system crash). (CVE-2019-17075)

It was discovered that the DesignWare USB3 controller driver in the Linux
kernel did not properly deallocate memory in some error conditions. A local
attacker could possibly use this to cause a denial of service (memory
exhaustion). (CVE-2019-18813)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
linux-image-5.0.0-1009-oracle 5.0.0-1009.14
linux-image-5.0.0-1023-aws 5.0.0-1023.26
linux-image-5.0.0-1024-kvm 5.0.0-1024.26
linux-image-5.0.0-1024-raspi2 5.0.0-1024.25
linux-image-5.0.0-1028-azure 5.0.0-1028.30
linux-image-5.0.0-1028-gcp 5.0.0-1028.29
linux-image-5.0.0-38-generic 5.0.0-38.41
linux-image-5.0.0-38-generic-lpae 5.0.0-38.41
linux-image-5.0.0-38-lowlatency 5.0.0-38.41
linux-image-aws 5.0.0.1023.25
linux-image-azure 5.0.0.1028.28
linux-image-gcp 5.0.0.1028.53
linux-image-generic 5.0.0.38.40
linux-image-generic-lpae 5.0.0.38.40
linux-image-gke 5.0.0.1028.53
linux-image-kvm 5.0.0.1024.25
linux-image-lowlatency 5.0.0.38.40
linux-image-oracle 5.0.0.1009.35
linux-image-raspi2 5.0.0.1024.22
linux-image-virtual 5.0.0.38.40

Ubuntu 18.04 LTS:
linux-image-5.0.0-1009-oracle 5.0.0-1009.14~18.04.1
linux-image-5.0.0-1023-aws 5.0.0-1023.26~18.04.1
linux-image-5.0.0-1027-gke 5.0.0-1027.28~18.04.1
linux-image-5.0.0-1028-azure 5.0.0-1028.30~18.04.1
linux-image-5.0.0-1033-oem-osp1 5.0.0-1033.38
linux-image-aws-edge 5.0.0.1023.37
linux-image-azure 5.0.0.1028.39
linux-image-gke-5.0 5.0.0.1027.16
linux-image-oem-osp1 5.0.0.1033.37
linux-image-oracle-edge 5.0.0.1009.8

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4226-1
CVE-2019-10220, CVE-2019-14895, CVE-2019-14896, CVE-2019-14897,
CVE-2019-14901, CVE-2019-16231, CVE-2019-16233, CVE-2019-17075,
CVE-2019-17133, CVE-2019-18660, CVE-2019-18813, CVE-2019-19045,
CVE-2019-19048, CVE-2019-19052, CVE-2019-19055, CVE-2019-19060,
CVE-2019-19065, CVE-2019-19067, CVE-2019-19072, CVE-2019-19075,
CVE-2019-19083, CVE-2019-19524, CVE-2019-19526, CVE-2019-19529,
CVE-2019-19532, CVE-2019-19534, CVE-2019-19922, CVE-2019-2214

Package Information:
https://launchpad.net/ubuntu/+source/linux/5.0.0-38.41
https://launchpad.net/ubuntu/+source/linux-aws/5.0.0-1023.26
https://launchpad.net/ubuntu/+source/linux-azure/5.0.0-1028.30
https://launchpad.net/ubuntu/+source/linux-gcp/5.0.0-1028.29
https://launchpad.net/ubuntu/+source/linux-kvm/5.0.0-1024.26
https://launchpad.net/ubuntu/+source/linux-oracle/5.0.0-1009.14
https://launchpad.net/ubuntu/+source/linux-raspi2/5.0.0-1024.25
https://launchpad.net/ubuntu/+source/linux-aws-5.0/5.0.0-1023.26~18.04.1
https://launchpad.net/ubuntu/+source/linux-azure/5.0.0-1028.30~18.04.1
https://launchpad.net/ubuntu/+source/linux-gke-5.0/5.0.0-1027.28~18.04.1
https://launchpad.net/ubuntu/+source/linux-oem-osp1/5.0.0-1033.38
https://launchpad.net/ubuntu/+source/linux-oracle-5.0/5.0.0-1009.14~18.04.1

[USN-4225-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-4225-1
January 07, 2020

linux, linux-aws, linux-azure, linux-azure-5.3, linux-gcp, linux-gcp-5.3,
linux-kvm, linux-oracle, linux-raspi2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 19.10
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-kvm: Linux kernel for cloud environments
- linux-oracle: Linux kernel for Oracle Cloud systems
- linux-raspi2: Linux kernel for Raspberry Pi 2
- linux-azure-5.3: Linux kernel for Microsoft Azure Cloud systems
- linux-gcp-5.3: Linux kernel for Google Cloud Platform (GCP) systems

Details:

It was discovered that a heap-based buffer overflow existed in the Marvell
WiFi-Ex Driver for the Linux kernel. A physically proximate attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2019-14895, CVE-2019-14901)

It was discovered that a heap-based buffer overflow existed in the Marvell
Libertas WLAN Driver for the Linux kernel. A physically proximate attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2019-14896, CVE-2019-14897)

It was discovered that the Fujitsu ES network device driver for the Linux
kernel did not properly check for errors in some situations, leading to a
NULL pointer dereference. A local attacker could use this to cause a denial
of service. (CVE-2019-16231)

Anthony Steinhauser discovered that the Linux kernel did not properly
perform Spectre_RSB mitigations to all processors for PowerPC architecture
systems in some situations. A local attacker could use this to expose
sensitive information. (CVE-2019-18660)

It was discovered that the Broadcom V3D DRI driver in the Linux kernel did
not properly deallocate memory in certain error conditions. A local
attacker could possibly use this to cause a denial of service (kernel
memory exhaustion). (CVE-2019-19044)

It was discovered that the Mellanox Technologies Innova driver in the Linux
kernel did not properly deallocate memory in certain failure conditions. A
local attacker could use this to cause a denial of service (kernel memory
exhaustion). (CVE-2019-19045)

It was discovered that the Mellanox Technologies ConnectX driver in the
Linux kernel did not properly deallocate memory in certain failure
conditions. A local attacker could use this to cause a denial of service
(kernel memory exhaustion). (CVE-2019-19047)

It was discovered that the Intel WiMAX 2400 driver in the Linux kernel did
not properly deallocate memory in certain situations. A local attacker
could use this to cause a denial of service (kernel memory exhaustion).
(CVE-2019-19051)

It was discovered that Geschwister Schneider USB CAN interface driver in
the Linux kernel did not properly deallocate memory in certain failure
conditions. A physically proximate attacker could use this to cause a
denial of service (kernel memory exhaustion). (CVE-2019-19052)

It was discovered that the netlink-based 802.11 configuration interface in
the Linux kernel did not deallocate memory in certain error conditions. A
local attacker could possibly use this to cause a denial of service (kernel
memory exhaustion). (CVE-2019-19055)

It was discovered that the event tracing subsystem of the Linux kernel did
not properly deallocate memory in certain error conditions. A local
attacker could use this to cause a denial of service (kernel memory
exhaustion). (CVE-2019-19072)

It was discovered that the driver for memoryless force-feedback input
devices in the Linux kernel contained a use-after-free vulnerability. A
physically proximate attacker could possibly use this to cause a denial of
service (system crash) or execute arbitrary code. (CVE-2019-19524)

It was discovered that the Microchip CAN BUS Analyzer driver in the Linux
kernel contained a use-after-free vulnerability on device disconnect. A
physically proximate attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-19529)

It was discovered that the PEAK-System Technik USB driver in the Linux
kernel did not properly sanitize memory before sending it to the device. A
physically proximate attacker could use this to expose sensitive
information (kernel memory). (CVE-2019-19534)

Tristan Madani discovered that the ALSA timer implementation in the Linux
kernel contained a use-after-free vulnerability. A local attacker could use
this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2019-19807)

It was discovered that the DesignWare USB3 controller driver in the Linux
kernel did not properly deallocate memory in some error conditions. A local
attacker could possibly use this to cause a denial of service (memory
exhaustion). (CVE-2019-18813)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.10:
linux-image-5.3.0-1008-oracle 5.3.0-1008.9
linux-image-5.3.0-1009-aws 5.3.0-1009.10
linux-image-5.3.0-1009-azure 5.3.0-1009.10
linux-image-5.3.0-1009-kvm 5.3.0-1009.10
linux-image-5.3.0-1011-gcp 5.3.0-1011.12
linux-image-5.3.0-1015-raspi2 5.3.0-1015.17
linux-image-5.3.0-26-generic 5.3.0-26.28
linux-image-5.3.0-26-generic-lpae 5.3.0-26.28
linux-image-5.3.0-26-lowlatency 5.3.0-26.28
linux-image-5.3.0-26-snapdragon 5.3.0-26.28
linux-image-aws 5.3.0.1009.11
linux-image-azure 5.3.0.1009.27
linux-image-gcp 5.3.0.1011.12
linux-image-generic 5.3.0.26.30
linux-image-generic-lpae 5.3.0.26.30
linux-image-gke 5.3.0.1011.12
linux-image-kvm 5.3.0.1009.11
linux-image-lowlatency 5.3.0.26.30
linux-image-oracle 5.3.0.1008.9
linux-image-raspi2 5.3.0.1015.12
linux-image-snapdragon 5.3.0.26.30
linux-image-virtual 5.3.0.26.30

Ubuntu 18.04 LTS:
linux-image-5.3.0-1009-azure 5.3.0-1009.10~18.04.1
linux-image-5.3.0-1010-gcp 5.3.0-1010.11~18.04.1
linux-image-azure-edge 5.3.0.1009.9
linux-image-gcp-edge 5.3.0.1010.10

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4225-1
CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901,
CVE-2019-16231, CVE-2019-18660, CVE-2019-18813, CVE-2019-19044,
CVE-2019-19045, CVE-2019-19047, CVE-2019-19051, CVE-2019-19052,
CVE-2019-19055, CVE-2019-19072, CVE-2019-19524, CVE-2019-19529,
CVE-2019-19534, CVE-2019-19807

Package Information:
https://launchpad.net/ubuntu/+source/linux/5.3.0-26.28
https://launchpad.net/ubuntu/+source/linux-aws/5.3.0-1009.10
https://launchpad.net/ubuntu/+source/linux-azure/5.3.0-1009.10
https://launchpad.net/ubuntu/+source/linux-gcp/5.3.0-1011.12
https://launchpad.net/ubuntu/+source/linux-kvm/5.3.0-1009.10
https://launchpad.net/ubuntu/+source/linux-oracle/5.3.0-1008.9
https://launchpad.net/ubuntu/+source/linux-raspi2/5.3.0-1015.17
https://launchpad.net/ubuntu/+source/linux-azure-5.3/5.3.0-1009.10~18.04.1
https://launchpad.net/ubuntu/+source/linux-gcp-5.3/5.3.0-1010.11~18.04.1

Fedora 33 Self-Contained Change proposal: retire python34

https://fedoraproject.org/wiki/Changes/RetirePython34

== Summary ==
The {{package|python34}} package will be retired without replacement
from [[Releases/33|Fedora 33]]. Python 3.4 has been End of Life since
March 2019 and was kept around only to test software targeting EPEL 6
and Debian 8 "Jessie". The removal is aligned with EPEL 6 EOL and
happens after the EOL of Debian 8.

== Owner ==
* Name: [[User:Churchyard|Miro Hrončok]]
* Email: mhroncok@redhat.com

== Detailed Description ==
The {{package|python34}} package with the Python interpreter in
version 3.4 is kept in Fedora only to make it possible for Fedora
users to test their software against the Python version shipped in
EPEL 6 and EPEL 7. RHEL 7 now contains Python 3.6.

[https://wiki.debian.org/LTS Debian 8 "Jessie" is End of Life in
2020-06]. [[EPEL|The EPEL 6 End of Life is planned for 2020-11]]. This
roughly corresponds with the
[https://fedorapeople.org/groups/schedule/f-33/f-33-key-tasks.html
Fedora 33 release date]. Hence, we decided to retire (completely
remove) {{package|python34}} from Fedora 33, before it gets released.

== Benefit to Fedora ==
The maintenance of Python 3.4 was getting harder and harder every
year. The support for Python 3.4 has disappeared from pip and an older
version of pip has to be bundled in {{package|python34}}, while pip
bundles even more old libraries. Support from tox and virtualenv will
eventually disappear as well.

There is no direct benefit here, except that we don't want to maintain
it anymore and we don't think it's a good idea either.

Consider this change proposal a louder orphaning, except that we will
continue to maintain the package in older released and supported
Fedoras (31 and 32). If you wish to continue maintaining Python 3.4 in
Fedora, please [[SIGs/Python|speak to us]] first.

== Scope ==
* Proposal owners: Retire {{package|python34}}. Obsolete it from
{{package|fedora-obsolete-packages}} if it causes troubles on
upgrades. Make sure no Fedora package depends on it in any way (incl.
weak dependencies).

* Other developers: N/A (not a System Wide Change)
* Release engineering: N/A (not a System Wide Change)
* Policies and guidelines: N/A (not a System Wide Change)
* Trademark approval: N/A (not needed for this Change)


== Upgrade/compatibility impact ==
The package will no longer be available from the repositories, but it
may remain on existing installations. If it causes troubles on
upgrade, it needs to be obsoleted.

== How To Test ==
N/A (not a System Wide Change)

== User Experience ==
No more Python 3.4 to test user software on.

== Dependencies ==
N/A (not a System Wide Change)

== Contingency Plan ==
* Contingency mechanism: (What to do? Who will do it?) N/A (not a
System Wide Change)
* Contingency deadline: N/A (not a System Wide Change)
* Blocks release? N/A (not a System Wide Change)

== Documentation ==
N/A (not a System Wide Change)

--
Ben Cotton
He / Him / His
Fedora Program Manager
Red Hat
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org

Fedora 33 Self-Contained Change proposal: retire python26

https://fedoraproject.org/wiki/Changes/RetirePython26

== Summary ==
The {{package|python26}} package will be retired without replacement
from [[Releases/33|Fedora 33]]. Python 2.6 has been End of Life since
October 2013 and was kept around only to test software targeting
RHEL/EPEL 6. The removal is aligned with EPEL 6 EOL.

== Owner ==
* Name: [[User:Churchyard|Miro Hrončok]]
* Email: mhroncok@redhat.com


== Detailed Description ==
The {{package|python26}} package with the Python interpreter in
version 2.6 is kept in Fedora only to make it possible for Fedora
users to test their software against the Python version shipped in
RHEL 6.

[[EPEL|The EPEL 6 End of Life is planned for 2020-11]]. This roughly
corresponds with the
[https://fedorapeople.org/groups/schedule/f-33/f-33-key-tasks.html
Fedora 33 release date]. Hence, we decided to retire (completely
remove) {{package|python26}} from Fedora 33, before it gets released.

== Benefit to Fedora ==
The maintenance of Python 2.6 was getting harder and harder every
year. The support for Python 2.6 has disappeared from virtualenv, tox.
{{package|python26}} cannot be built against the new OpenSSL versions,
etc.

There is no direct benefit here, except that we don't want to maintain
it anymore and we don't think it's a good idea either.

Consider this change proposal a louder orphaning, except that we will
continue to maintain the package in older released and supported
Fedoras (31 and 32). If you wish to continue maintaining Python 2.6 in
Fedora, please [[SIGs/Python|speak to us]] first.

== Scope ==
* Proposal owners: Retire {{package|python26}}. Obsolete it from
{{package|fedora-obsolete-packages}} if it causes troubles on
upgrades. Make sure no Fedora package depends on it in any way (incl.
weak dependencies).

* Other developers: N/A (not a System Wide Change)
* Release engineering: N/A (not a System Wide Change)
* Policies and guidelines: N/A (not a System Wide Change)
* Trademark approval: N/A (not needed for this Change)


== Upgrade/compatibility impact ==
The package will no longer be available from the repositories, but it
may remain on existing installations. If it causes troubles on
upgrade, it needs to be obsoleted.

== How To Test ==
N/A (not a System Wide Change)

== User Experience ==
No more Python 2.6 to test user software on.

== Dependencies ==
N/A (not a System Wide Change)

== Contingency Plan ==
* Contingency mechanism: (What to do? Who will do it?) N/A (not a
System Wide Change)
* Contingency deadline: N/A (not a System Wide Change)
* Blocks release? N/A (not a System Wide Change)

== Documentation ==
N/A


--
Ben Cotton
He / Him / His
Fedora Program Manager
Red Hat
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org

Orphaned packages looking for new maintainers

The following packages are orphaned and will be retired when they
are orphaned for six weeks, unless someone adopts them. If you know for sure
that the package should be retired, please do so now with a proper reason:
https://fedoraproject.org/wiki/How_to_remove_a_package_at_end_of_life

Note: If you received this mail directly you (co)maintain one of the affected
packages or a package that depends on one. Please adopt the affected package or
retire your depending package to avoid broken dependencies, otherwise your
package will be retired when the affected package gets retired.

Request package ownership via the *Take* button in he left column on
https://src.fedoraproject.org/rpms/<pkgname>

Full report available at:
https://churchyard.fedorapeople.org/orphans-2020-01-06.txt
grep it for your FAS username and follow the dependency chain.

Package (co)maintainers Status Change
================================================================================
MochiKit orphan 3 weeks ago
dzen2 bstinson, dcantrel, fale, 5 weeks ago
lupinix, orphan
golang-github-codahale- go-sig, orphan 2 weeks ago
aesnicheck
i3-ipc cicku, fale, gchamoul, 5 weeks ago
lupinix, mpreisle, orphan
ike-scan orphan, pwouters 3 weeks ago
infinispan gil, orphan 6 weeks ago
maven-ant-plugin mizdebsk, orphan 4 weeks ago
maven-docck-plugin mizdebsk, orphan 4 weeks ago
maven-ear-plugin orphan 4 weeks ago
mcollective-qpid-plugin orphan, tdawson 3 weeks ago
multithreadedtc orphan 4 weeks ago
nbtscan orphan 3 weeks ago
nesc cicku, orphan 4 weeks ago
ninvaders orphan 3 weeks ago
oyranos orphan 3 weeks ago
pscan orphan 3 weeks ago
pykka orphan 0 weeks ago
python-dockerpty lsm5, orphan, ttomecek 3 weeks ago
python-flask-classy orphan 5 weeks ago
python-flask-debugtoolbar orphan 5 weeks ago
python-fsmonitor orphan 5 weeks ago
python-mongoengine bowlofeggs, echevemaster, 5 weeks ago
orphan
python-virtkey orphan 3 weeks ago
qpid-proton orphan 2 weeks ago
rubygem-awesome_spawn jstribny, orphan 4 weeks ago
rubygem-bootstrap-sass orphan 4 weeks ago
rubygem-charlock_holmes orphan 4 weeks ago
rubygem-faker orphan 1 weeks ago
rubygem-omniauth orphan 3 weeks ago
rubygem-orm_adapter orphan 4 weeks ago
saxon dbhole, dchen, jjohnstn, 5 weeks ago
mbooth, orphan
shed orphan 3 weeks ago
sound-theme-acoustic orphan 1 weeks ago
swingx orphan 0 weeks ago
tmuxinator orphan 3 weeks ago
tudu orphan 1 weeks ago
vttest cicku, orphan 3 weeks ago
xml-stylebook mizdebsk, orphan 5 weeks ago

The following packages require above mentioned packages:
See https://churchyard.fedorapeople.org/orphans-2020-01-06.txt
Grep it for your username and follow the dependency chain.

Affected (co)maintainers
abompard: qpid-proton
arobinso: multithreadedtc
ausil: qpid-proton
bkabrda: qpid-proton
bowlofeggs: python-mongoengine, qpid-proton
bstinson: dzen2
cicku: i3-ipc, nesc, vttest
cqi: qpid-proton
cverna: qpid-proton
dbhole: saxon
dcantrel: dzen2
dchen: saxon
dgoodwin: qpid-proton
dmach: qpid-proton
dodji: qpid-proton
dridi: vttest
echevemaster: python-mongoengine
ellert: maven-docck-plugin
error: python-dockerpty
fab: vttest
fale: i3-ipc, dzen2
frixxon: qpid-proton
frostyx: qpid-proton
fujiwara: qpid-proton
gchamoul: i3-ipc
gil: infinispan
go-sig: golang-github-codahale-aesnicheck
halfie: qpid-proton
infra-sig: qpid-proton
ingvar: vttest
irina: qpid-proton
jamesturner246: saxon
jcline: qpid-proton
jjohnstn: saxon
jlieskov: qpid-proton
jortel: qpid-proton
jplesnik: qpid-proton
jsteffan: vttest
jstribny: rubygem-awesome_spawn
jvymazal: qpid-proton
kellin: qpid-proton
kevin: qpid-proton, vttest
kgiusti: qpid-proton
leamas: qpid-proton
lef: multithreadedtc
lkundrak: qpid-proton
lsedlar: qpid-proton
lsm5: python-dockerpty
luhliarik: vttest
lupinix: i3-ipc, dzen2
maxamillion: qpid-proton
mbooth: saxon
mdarade: qpid-proton
mhlavink: vttest
mikem: qpid-proton
mildew: qpid-proton
mizdebsk: xml-stylebook, maven-docck-plugin, maven-ant-plugin
mohanboddu: qpid-proton
mpreisle: i3-ipc
ngompa: qpid-proton
nim: qpid-proton
onosek: qpid-proton
orion: qpid-proton
pingou: qpid-proton
ppisar: qpid-proton
puiterwijk: qpid-proton
pwouters: ike-scan
qwan: qpid-proton
ralph: qpid-proton
romanofski: qpid-proton
rsroka: qpid-proton
ruben: vttest
santiago: qpid-proton
sinnykumari: qpid-proton
sochotni: qpid-proton
tagoh: qpid-proton
tdawson: qpid-proton, mcollective-qpid-plugin
tosykora: qpid-proton
tross: qpid-proton
ttomecek: python-dockerpty, qpid-proton
twaugh: qpid-proton
vrutkovs: qpid-proton
wwoods: qpid-proton
xaeth: vttest
xiubli: qpid-proton

--
The script creating this output is run and developed by Fedora
Release Engineering. Please report issues at its pagure instance:
https://pagure.io/releng/
The sources of this script can be found at:
https://pagure.io/releng/blob/master/f/scripts/find_unblocked_orphans.py
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org

List of long term FTBFS packages to be retired in February

Dear maintainers.

Based on the latest fail to build from source policy, the following packages
will be retired from Fedora 32 approximately one week before branching (February
2020).

Policy:
https://docs.fedoraproject.org/en-US/fesco/Fails_to_build_from_source_Fails_to_install/

The packages in rawhide were not successfully built at least since Fedora 30.

This report is based on dist tags.

Packages collected via:
https://github.com/hroncok/fedora-report-ftbfs-retirements/blob/master/ftbfs-retirements.ipynb

If you see a package that was built, please let me know.
If you see a package that should be exempted from the process, please let me
know and we can work together to get a FESCo approval for that.

If you see a package that can be rebuilt, please do so.

Package (co)maintainers Latest build
================================================================================
elasticsearch hubbitus, jvanek, lbazan, Fedora 24
zbyszek
expresso jamielinux, nodejs-sig, Fedora 28
patches
libocrdma ocrdma Fedora 27
nuvola-app-google-calendar martinkg Fedora 29
nuvola-app-groove martinkg Fedora 28
nuvola-app-logitech-media- martinkg Fedora 29
server
nuvola-app-plex martinkg Fedora 29
nuvola-app-soundcloud martinkg Fedora 29
nuvola-app-yandex-music martinkg Fedora 29
shim-unsigned-aarch64 pjones Fedora 28
shim-unsigned-x64 pjones Fedora 28

The following packages require above mentioned packages:
Depending on: expresso (1)
nodejs-chrono (maintained by: jamielinux, nodejs-sig, tomh)
nodejs-chrono-1.0.5-10.fc31.src requires npm(expresso) = 0.9.2

Affected (co)maintainers
hubbitus: elasticsearch
jamielinux: expresso
jvanek: elasticsearch
lbazan: elasticsearch
martinkg: nuvola-app-soundcloud, nuvola-app-logitech-media-server,
nuvola-app-yandex-music, nuvola-app-groove, nuvola-app-google-calendar,
nuvola-app-plex
nodejs-sig: expresso
ocrdma: libocrdma
patches: expresso
pjones: shim-unsigned-aarch64, shim-unsigned-x64
tomh: expresso
zbyszek: elasticsearch


--
Miro Hrončok
--
Phone: +420777974800
IRC: mhroncok
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org

Sunday, January 5, 2020

Re: koji / bodhi issues status update

On Sun, Jan 05, 2020 at 05:27:19PM +0100, Clement Verna wrote:
> On Fri, 3 Jan 2020 at 22:41, Kevin Fenzi <kevin@scrye.com> wrote:
>
> > As some of you may know, we have been having issues with koji and bodhi
> > over the holidays. :( koji would sometimes not tag builds or error them
> > with odd error messages and bodhi wasn't pushing updates.
> >
> > I'm happy to report that the underlying issue seems to be fixed now.
> > We hopefully will have a more detailed root cause next week.
> >
> > However, due to the koji issues builds were in a state where bodhi
> > ejected many of them from updates pushes. We are working on cleaning
> > up the state of those updates and there's no need for maintainers to do
> > anything with those updates at this time.
> >
> > Once we get the ejected builds cleaned up we should be able to resume
> > normal bodhi updates pushes.
> >
>
> Hi all,
>
> I think that we now have dealt with most of the ejected updates. It seems
> that there are still a few rawhide updates stuck in pending so I ll be
> looking at unblocking these.
>
> Please let us know if you believed that we have missed something.

Additionally there were a number of builds in koji in "BUILDING" state,
even though they had failed/had no active tasks building them.

I went ahead and canceled them all, so now maintainers should be able to
resubmit or just do a new build. List of those by maintainer is:

cabal-rpm-1.0.3-1.fc32 petersen BUILDING
cobbler-2.8.5-1.el7 orion BUILDING
desktopfolder-1.1.2-1.fc31 atim BUILDING
efl-1.23.1-1.fc32 spot BUILDING
fleet-commander-admin-0.15.0-1.fc30 ogutierrez BUILDING
gstreamer1-plugins-bad-free-1.16.2-1.fc32 wtaymans BUILDING
gstreamer1-plugins-base-1.16.2-2.fc31 wtaymans BUILDING
heimdal-7.7.0-2.epel8.playground abo BUILDING
im-chooser-1.7.3-1.epel8.playground tagoh BUILDING
imsettings-1.8.2-1.fc32 tagoh BUILDING
js8call-2.1.1-1.fc32 hobbes1069 BUILDING
libbpf-0.0.6-1.fc32 jolsa BUILDING
libwacom-1.2-2.fc32 whot BUILDING
mellowplayer-3.5.8-1.20191227git9fd6cee.fc32 martinkg BUILDING
module-build-macros-0.1-1.module_f32+7264+508b1e07 mbs/mbs.fedoraproject.org BUILDING
module-build-macros-0.1-1.module_f32+7272+cab9d0cd mbs/mbs.fedoraproject.org BUILDING
musique-1.7-1.fc32 lbazan BUILDING
mypaint-2.0.0-0.4.beta.0.fc32 avsej BUILDING
osc-source_validator-0.19-2.fc31 ngompa BUILDING
pdf-stapler-1.0.0-1.fc32 aarem BUILDING
perl-Config-Model-2.138-1.fc32 eseyman BUILDING
python-avocado-74.0-1.module_f31+7253+5196ffdf mbs/mbs.fedoraproject.org BUILDING
python-chaospy-3.0.17-1.fc30 lbazan BUILDING
python-django-threadedcomments-1.2-8.fc30 lbazan BUILDING
python-lz4-3.0.2-1.fc30 jgu BUILDING
python-lz4-3.0.2-1.fc31 jgu BUILDING
python-lz4-3.0.2-1.fc32 jgu BUILDING
python-mypy_extensions-0.4.1-5.fc32 ignatenkobrain BUILDING
python-paho-mqtt-1.5.0-2.fc31 fab BUILDING
python-pycares-3.1.0-fix3.1.fc31 fantom BUILDING
python-pyelectro-0.1.10-1.fc32 major BUILDING
python-versioneer-0.18-2.fc32 nonamedotc BUILDING
rubygem-pg-1.2.0-1.fc32 jaruga BUILDING
ucblogo-6.1-1.fc31 jrincayc BUILDING
vertica-python-0.10.1-1.el7 kubo BUILDING

I don't want to blindly resubmit in case folks already bumped release
and make newer builds. If thats the case, you have nothing to do here.

kevin

Re: koji / bodhi issues status update



On Fri, 3 Jan 2020 at 22:41, Kevin Fenzi <kevin@scrye.com> wrote:
As some of you may know, we have been having issues with koji and bodhi
over the holidays. :( koji would sometimes not tag builds or error them
with odd error messages and bodhi wasn't pushing updates.

I'm happy to report that the underlying issue seems to be fixed now.
We hopefully will have a more detailed root cause next week.

However, due to the koji issues builds were in a state where bodhi
ejected many of them from updates pushes. We are working on cleaning
up the state of those updates and there's no need for maintainers to do
anything with those updates at this time.

Once we get the ejected builds cleaned up we should be able to resume
normal bodhi updates pushes.

Hi all,

I think that we now have dealt with most of the ejected updates. It seems that there are still a few rawhide updates stuck in pending so I ll be looking at unblocking these.

Please let us know if you believed that we have missed something.

Thanks
 

Thanks everyone for your patience on this issue!

kevin
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org

Saturday, January 4, 2020

[arch-announce] Now using Zstandard instead of xz for package compression

As announced on the [mailing list](https://lists.archlinux.org/pipermail/arch-dev-public/2019-December/029752.html), on Friday, Dec 27 2019, our package compression scheme has changed from xz (.pkg.tar.xz) to [zstd (.pkg.tar.zst)](https://lists.archlinux.org/pipermail/arch-dev-public/2019-December/029778.html).

zstd and xz trade blows in their compression ratio. Recompressing all packages to zstd with our options yields a total ~0.8% increase in package size on all of our packages combined, but the decompression time for all packages saw a ~1300% speedup.

We already have more than 545 zstd-compressed packages in our repositories, and as packages get updated more will keep rolling in. We have not found any user-facing issues as of yet, so things appear to be working.

As a packager, you will automatically start building .pkg.tar.zst packages if you are using the latest version of devtools (&gt;= 20191227).
As an end-user no manual intervention is required, assuming that you have read and followed the news post [from late last year](https://www.archlinux.org/news/required-update-to-recent-libarchive/).

If you nevertheless haven&#39;t updated libarchive since 2018, all hope is not lost! Binary builds of pacman-static are available from Eli Schwartz&#39; [personal repository](https://wiki.archlinux.org/index.php/Unofficial_user_repositories#eschwartz), signed with their Trusted User keys, with which you can perform the update.

URL: https://www.archlinux.org/news/now-using-zstandard-instead-of-xz-for-package-compression/
_______________________________________________
arch-announce mailing list
arch-announce@archlinux.org
https://lists.archlinux.org/listinfo/arch-announce