==========================================================================
Ubuntu Security Notice USN-6657-2
April 24, 2024
dnsmasq vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
Summary:
Several security issues were fixed in Dnsmasq.
Software Description:
- dnsmasq: Small caching DNS proxy and DHCP/TFTP server
Details:
USN-6657-1 fixed several vulnerabilities in Dnsmasq. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Dnsmasq icorrectly handled validating DNSSEC messages. A remote
attacker could possibly use this issue to cause Dnsmasq to consume
resources, leading to a denial of service. (CVE-2023-50387)
It was discovered that Dnsmasq incorrectly handled preparing an NSEC3
closest encloser proof. A remote attacker could possibly use this issue to
cause Dnsmasq to consume resources, leading to a denial of service.
(CVE-2023-50868)
It was discovered that Dnsmasq incorrectly set the maximum EDNS.0 UDP
packet size as required by DNS Flag Day 2020. This issue only affected
Ubuntu 23.10. (CVE-2023-28450)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS (Available with Ubuntu Pro):
dnsmasq-base 2.90-0ubuntu0.18.04.1+esm1
Ubuntu 16.04 LTS (Available with Ubuntu Pro):
dnsmasq-base 2.90-0ubuntu0.16.04.1+esm1
This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to reboot your computer to
make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6657-2
https://ubuntu.com/security/notices/USN-6657-1
CVE-2023-28450, CVE-2023-50387, CVE-2023-50868
Wednesday, April 24, 2024
[USN-6749-1] FreeRDP vulnerabilities
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmYpTIAACgkQZWnYVadE
vpPAbBAAoj4MpECGQM9gR6PfIccurfhlaw21h78r1vQ5ADfguRWpGkDvq0OBc1At
QMJ45shgb1DG1081bSMi9PwctOVQly5hOr4UndyLS9z5fb+pe8cZoRyPwf6XymkO
U4BDTUynqoFMIhrejKpGXm0VFaBpkTZLBxiJAb113fHZqaf/ykPwdkulwupLRVZ+
9oSTUqPVnD6i8D3Q6nn09skBfGVZr7PWIflKa1jqVwQa3OtNtbgFpX6XmWHSJ84B
YJHJS0NsngEdkEXR96ub2UpflLM53vj8wk4dHpks5U2wXF6K3jLOcoC6NNX9Yrhi
EaMfg+Gvb+SBexMmRRQixaYAnexmnf0C6aB7Dq+NXmxJfbJoevok6D3MNpVlJzj2
Lr5Nylmoasfo+fpRMpCmmPhliYm9Ks05qI39hYx90340gsi9UVpwJ2SQ8wlGPNM/
sv1Cl1cIHIs2KbL/lxHhlXD1ePDW36Hu8NFWQZEa7JXwPVRfmUpSD3+7aQNxUn4D
BxCY0H5rw/e+0Hkk7p+dl+FUGYGntmWQMX5fly6JNxHc3AAafKSbi1UKJxxDAFcW
oGVkWLxOb1jgP5bi2M+SWtaH/VAKtCx0w97chkI1tKq9+OtvulIqBTszXHusz+up
jruNyjGpl6RY8YYf5fJS0lW97DpV/mD5aUUOcWs1fACNtdKZWZY=
=cZ3s
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6749-1
April 24, 2024
freerdp2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in FreeRDP.
Software Description:
- freerdp2: RDP client for Windows Terminal Services
Details:
It was discovered that FreeRDP incorrectly handled certain context resets.
If a user were tricked into connecting to a malicious server, a remote
attacker could use this issue to cause FreeRDP to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2024-22211)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could use this issue to cause FreeRDP to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2024-32039, CVE-2024-32040)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could possibly use this issue to cause FreeRDP to crash,
resulting in a denial of service. (CVE-2024-32041, CVE-2024-32458,
CVE-2024-32460)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. A remote attacker could possibly use this issue to cause
FreeRDP clients and servers to crash, resulting in a denial of service.
(CVE-2024-32459)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
libfreerdp2-2 2.10.0+dfsg1-1.1ubuntu1.2
Ubuntu 22.04 LTS:
libfreerdp2-2 2.6.1+dfsg1-3ubuntu2.6
Ubuntu 20.04 LTS:
libfreerdp2-2 2.6.1+dfsg1-0ubuntu0.20.04.1
After a standard system update you need to restart your session to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6749-1
CVE-2024-22211, CVE-2024-32039, CVE-2024-32040, CVE-2024-32041,
CVE-2024-32458, CVE-2024-32459, CVE-2024-32460
Package Information:
https://launchpad.net/ubuntu/+source/freerdp2/2.10.0+dfsg1-1.1ubuntu1.2
https://launchpad.net/ubuntu/+source/freerdp2/2.6.1+dfsg1-3ubuntu2.6
https://launchpad.net/ubuntu/+source/freerdp2/2.6.1+dfsg1-0ubuntu0.20.04.1
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmYpTIAACgkQZWnYVadE
vpPAbBAAoj4MpECGQM9gR6PfIccurfhlaw21h78r1vQ5ADfguRWpGkDvq0OBc1At
QMJ45shgb1DG1081bSMi9PwctOVQly5hOr4UndyLS9z5fb+pe8cZoRyPwf6XymkO
U4BDTUynqoFMIhrejKpGXm0VFaBpkTZLBxiJAb113fHZqaf/ykPwdkulwupLRVZ+
9oSTUqPVnD6i8D3Q6nn09skBfGVZr7PWIflKa1jqVwQa3OtNtbgFpX6XmWHSJ84B
YJHJS0NsngEdkEXR96ub2UpflLM53vj8wk4dHpks5U2wXF6K3jLOcoC6NNX9Yrhi
EaMfg+Gvb+SBexMmRRQixaYAnexmnf0C6aB7Dq+NXmxJfbJoevok6D3MNpVlJzj2
Lr5Nylmoasfo+fpRMpCmmPhliYm9Ks05qI39hYx90340gsi9UVpwJ2SQ8wlGPNM/
sv1Cl1cIHIs2KbL/lxHhlXD1ePDW36Hu8NFWQZEa7JXwPVRfmUpSD3+7aQNxUn4D
BxCY0H5rw/e+0Hkk7p+dl+FUGYGntmWQMX5fly6JNxHc3AAafKSbi1UKJxxDAFcW
oGVkWLxOb1jgP5bi2M+SWtaH/VAKtCx0w97chkI1tKq9+OtvulIqBTszXHusz+up
jruNyjGpl6RY8YYf5fJS0lW97DpV/mD5aUUOcWs1fACNtdKZWZY=
=cZ3s
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6749-1
April 24, 2024
freerdp2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in FreeRDP.
Software Description:
- freerdp2: RDP client for Windows Terminal Services
Details:
It was discovered that FreeRDP incorrectly handled certain context resets.
If a user were tricked into connecting to a malicious server, a remote
attacker could use this issue to cause FreeRDP to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2024-22211)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could use this issue to cause FreeRDP to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2024-32039, CVE-2024-32040)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. If a user were tricked into connecting to a malicious server, a
remote attacker could possibly use this issue to cause FreeRDP to crash,
resulting in a denial of service. (CVE-2024-32041, CVE-2024-32458,
CVE-2024-32460)
Evgeny Legerov discovered that FreeRDP incorrectly handled certain memory
operations. A remote attacker could possibly use this issue to cause
FreeRDP clients and servers to crash, resulting in a denial of service.
(CVE-2024-32459)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
libfreerdp2-2 2.10.0+dfsg1-1.1ubuntu1.2
Ubuntu 22.04 LTS:
libfreerdp2-2 2.6.1+dfsg1-3ubuntu2.6
Ubuntu 20.04 LTS:
libfreerdp2-2 2.6.1+dfsg1-0ubuntu0.20.04.1
After a standard system update you need to restart your session to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6749-1
CVE-2024-22211, CVE-2024-32039, CVE-2024-32040, CVE-2024-32041,
CVE-2024-32458, CVE-2024-32459, CVE-2024-32460
Package Information:
https://launchpad.net/ubuntu/+source/freerdp2/2.10.0+dfsg1-1.1ubuntu1.2
https://launchpad.net/ubuntu/+source/freerdp2/2.6.1+dfsg1-3ubuntu2.6
https://launchpad.net/ubuntu/+source/freerdp2/2.6.1+dfsg1-0ubuntu0.20.04.1
F41 Change Proposal: Drop Mandatory Requires on JRE (system-wide)
Wiki - https://fedoraproject.org/wiki/Changes/Drop_Mandatory_Requires_on_JRE
Announced - https://discussion.fedoraproject.org/t/f41-change-proposal-drop-mandatory-requires-on-jre-system-wide/114186
This is a proposed Change for Fedora Linux.
This document represents a proposed Change. As part of the Changes
process, proposals are publicly announced in order to receive
community feedback. This proposal will only be implemented if approved
by the Fedora Engineering Steering Committee.
== Summary ==
Drop the requirement of Java libraries to have Requires on JREs.
== Owner ==
* Name: [[User:mkoncek| Marián Konček]]
* Email: mkoncek@redhat.com
== Detailed Description ==
Current [https://docs.fedoraproject.org/en-US/packaging-guidelines/Java/#_buildrequires_and_requires
guidelines] require all Java packages to `Require: java-headless or
java-headless >= 1:minimal_required_version`.
Our aim is to drop this explicit requirement on Java library packages.
The requirement should stay for Java applications.
=== Context ===
Java packages are compiled using `javac` into `.class` files and
composed into `.jar` archives. Jar archives can be used as compile or
runtime dependencies for other packages or can be directly executed
with the java command provided by a JRE.
Jar archives can be executed using the command: `java -jar ${FILE}`.
This command executes the `main` method either specified via CLI or
specified within the Jar manifest file.
Java packages, which serve as libraries only, lack the `main` method
and are not executable. Therefore, there is no requirement on any
specific JRE imposed by the library implicitly.
=== Different JDKs ===
This proposal is also related to the topic of different JDKs.
Developers may want to use or build packages which use a JDK different
than the one provided by the `java-<N>-openjdk` package. After this
proposal was implemented, they would be able to depend on Java library
packages with no introduction of the OpenJDK package.
=== Rationale ===
Java libraries are more similar to native libraries than to libraries
written in dynamic scripting languages. They are compiled to a
bytecode and are not executable. Java libraries can be used as
dependencies for any Java application and there is no implicit
dependency on the system default JDK.
Java applications, on the other hand, are expected to be tested and to
work with the system JDK and from the user's perspective: after
installing an application they must be able to simply run the binary.
Therefore the `Requires` on the system JDK is kept for Java
applications.
== Feedback ==
== Benefit to Fedora ==
* Very little user-visible benefit.
* Reduced dependencies of Java packages.
* Simplified maintenance of Java packages.
** Smaller impact of JDK major updates (e.g. `1.8.0 -> 11 -> 17 ->
21`). Introducing a new system version of JDK requires the rebuild of
each Java package in order to have updated `Requires` to contain the
newest version.
== Scope ==
* Proposal owners:
** Find all Java applications in Fedora, i.e. packages which
`BuildRequire` `java-devel / maven-local / ant` and at the same time
install files into `/bin` or `/sbin` or `/usr/bin` or `/usr/sbin`.
** Open pull requests adding `Requires: java-headless` into their `.spec` file.
** Remove `Requires` generator from
[https://src.fedoraproject.org/rpms/javapackages-tools/blob/8714cc1d03d3f31251539c3fca53383b822834bc/f/javapackages-config.json#_5
javapackages-tools]
** Wait for a mass rebuild.
* Other developers:
** Maintainers of Java applications will need to add an explicit
`Requires: java-headless` field into their `.spec` file or a specific
version of thereof (such as `java-17-openjdk-headless`).
* Release engineering: [https://pagure.io/releng/issue/12069 #12069]
** Mass rebuild is not required, this change can propagate via natural rebuilds.
* Policies and guidelines:
** Guidelines need to be modified
([https://pagure.io/packaging-committee/pull-request/1360 open Pull
Request]).
* Trademark approval: N/A (not needed for this Change)
* Alignment with Community Initiatives: N/A
== Upgrade/compatibility impact ==
* For Java libraries:
** This change is removing `Requires` and therefore users manually
installing a Java library will not additionally install the JVM.
* For Java applications:
** After fully implemented, applications will no longer be installable
along with any JVM but rather only the system one (unless the package
maintainer decides otherwise)
== How To Test ==
* Installing a Java library should not typically install JVM (but can
if the library depends on a Java application)
* Installing a Java application MUST cause the installation of the
system-wide JVM (or a different version thereof)
* Executing a binary installed in typical locations (such as
`/usr/bin`) MUST NOT cause an error related to the JVM not being
installed.
== User Experience ==
Users with no Java application installed, but some Java libraries
installed: the JVM may be automatically uninstalled as it is possibly
not required by anything.
It is possible that there are users with only some older JVM
installed. The following depends on the decision of each Java
application package maintainer, but the general expectation is that
the system-wide JVM will be installed and the older JVM will no longer
be required by other packages.
Users who explicitly installed JVMs of various versions: no change.
== Dependencies ==
* `javapackages-tools`
** This change allows the removal of the `Requires` generator.
== Contingency Plan ==
* Contingency mechanism:
** In case of unexpected problems, the `Requires` generators can be
reintroduced into `javapackages-tools` and packages can be rebuilt.
* Contingency deadline: Branch Fedora Linux 41 from Rawhide Tue 2024-08-06
* Blocks release? No
== Documentation ==
No documentation outside of this document.
== Release Notes ==
--
Aoife Moloney
Fedora Operations Architect
Fedora Project
Matrix: @amoloney:fedora.im
IRC: amoloney
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Announced - https://discussion.fedoraproject.org/t/f41-change-proposal-drop-mandatory-requires-on-jre-system-wide/114186
This is a proposed Change for Fedora Linux.
This document represents a proposed Change. As part of the Changes
process, proposals are publicly announced in order to receive
community feedback. This proposal will only be implemented if approved
by the Fedora Engineering Steering Committee.
== Summary ==
Drop the requirement of Java libraries to have Requires on JREs.
== Owner ==
* Name: [[User:mkoncek| Marián Konček]]
* Email: mkoncek@redhat.com
== Detailed Description ==
Current [https://docs.fedoraproject.org/en-US/packaging-guidelines/Java/#_buildrequires_and_requires
guidelines] require all Java packages to `Require: java-headless or
java-headless >= 1:minimal_required_version`.
Our aim is to drop this explicit requirement on Java library packages.
The requirement should stay for Java applications.
=== Context ===
Java packages are compiled using `javac` into `.class` files and
composed into `.jar` archives. Jar archives can be used as compile or
runtime dependencies for other packages or can be directly executed
with the java command provided by a JRE.
Jar archives can be executed using the command: `java -jar ${FILE}`.
This command executes the `main` method either specified via CLI or
specified within the Jar manifest file.
Java packages, which serve as libraries only, lack the `main` method
and are not executable. Therefore, there is no requirement on any
specific JRE imposed by the library implicitly.
=== Different JDKs ===
This proposal is also related to the topic of different JDKs.
Developers may want to use or build packages which use a JDK different
than the one provided by the `java-<N>-openjdk` package. After this
proposal was implemented, they would be able to depend on Java library
packages with no introduction of the OpenJDK package.
=== Rationale ===
Java libraries are more similar to native libraries than to libraries
written in dynamic scripting languages. They are compiled to a
bytecode and are not executable. Java libraries can be used as
dependencies for any Java application and there is no implicit
dependency on the system default JDK.
Java applications, on the other hand, are expected to be tested and to
work with the system JDK and from the user's perspective: after
installing an application they must be able to simply run the binary.
Therefore the `Requires` on the system JDK is kept for Java
applications.
== Feedback ==
== Benefit to Fedora ==
* Very little user-visible benefit.
* Reduced dependencies of Java packages.
* Simplified maintenance of Java packages.
** Smaller impact of JDK major updates (e.g. `1.8.0 -> 11 -> 17 ->
21`). Introducing a new system version of JDK requires the rebuild of
each Java package in order to have updated `Requires` to contain the
newest version.
== Scope ==
* Proposal owners:
** Find all Java applications in Fedora, i.e. packages which
`BuildRequire` `java-devel / maven-local / ant` and at the same time
install files into `/bin` or `/sbin` or `/usr/bin` or `/usr/sbin`.
** Open pull requests adding `Requires: java-headless` into their `.spec` file.
** Remove `Requires` generator from
[https://src.fedoraproject.org/rpms/javapackages-tools/blob/8714cc1d03d3f31251539c3fca53383b822834bc/f/javapackages-config.json#_5
javapackages-tools]
** Wait for a mass rebuild.
* Other developers:
** Maintainers of Java applications will need to add an explicit
`Requires: java-headless` field into their `.spec` file or a specific
version of thereof (such as `java-17-openjdk-headless`).
* Release engineering: [https://pagure.io/releng/issue/12069 #12069]
** Mass rebuild is not required, this change can propagate via natural rebuilds.
* Policies and guidelines:
** Guidelines need to be modified
([https://pagure.io/packaging-committee/pull-request/1360 open Pull
Request]).
* Trademark approval: N/A (not needed for this Change)
* Alignment with Community Initiatives: N/A
== Upgrade/compatibility impact ==
* For Java libraries:
** This change is removing `Requires` and therefore users manually
installing a Java library will not additionally install the JVM.
* For Java applications:
** After fully implemented, applications will no longer be installable
along with any JVM but rather only the system one (unless the package
maintainer decides otherwise)
== How To Test ==
* Installing a Java library should not typically install JVM (but can
if the library depends on a Java application)
* Installing a Java application MUST cause the installation of the
system-wide JVM (or a different version thereof)
* Executing a binary installed in typical locations (such as
`/usr/bin`) MUST NOT cause an error related to the JVM not being
installed.
== User Experience ==
Users with no Java application installed, but some Java libraries
installed: the JVM may be automatically uninstalled as it is possibly
not required by anything.
It is possible that there are users with only some older JVM
installed. The following depends on the decision of each Java
application package maintainer, but the general expectation is that
the system-wide JVM will be installed and the older JVM will no longer
be required by other packages.
Users who explicitly installed JVMs of various versions: no change.
== Dependencies ==
* `javapackages-tools`
** This change allows the removal of the `Requires` generator.
== Contingency Plan ==
* Contingency mechanism:
** In case of unexpected problems, the `Requires` generators can be
reintroduced into `javapackages-tools` and packages can be rebuilt.
* Contingency deadline: Branch Fedora Linux 41 from Rawhide Tue 2024-08-06
* Blocks release? No
== Documentation ==
No documentation outside of this document.
== Release Notes ==
--
Aoife Moloney
Fedora Operations Architect
Fedora Project
Matrix: @amoloney:fedora.im
IRC: amoloney
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
F41 Change Proposal: Fedora Miracle Spin (self-contained)
Wiki - https://fedoraproject.org/wiki/Changes/FedoraMiracle
Discussion Thread -
https://discussion.fedoraproject.org/t/f41-change-proposal-fedora-miracle-spin-self-contained/114182
This is a proposed Change for Fedora Linux.
This document represents a proposed Change. As part of the Changes
process, proposals are publicly announced in order to receive
community feedback. This proposal will only be implemented if approved
by the Fedora Engineering Steering Committee.
== Summary ==
Create an official Fedora Spin shipping the up-and-coming Miracle Window Manager
== Owner ==
* Name: [[User:mattkae| Matthew Kosarek]], [[User:tsimonq2| Simon
Quigley]], [[User:ngompa| Neal Gompa]]
* Email: matthew@matthewkosarek.xyz, simon@tsimonq2.net, ngompa13@gmail.com
== Detailed Description ==
The Miracle Window Manager is a tiling window manager based on the Mir
compositor library. While it is a newer project, it contains many
useful features such as a manual tiling algorithm, floating window
manager support, support for many Wayland protocols, proprietary
Nvidia driver support, and much more. Users are increasingly
interested in using miracle in various systems.
The goal of the miracle spin is to build a complete and elegant tiling
window experience within the Fedora ecosystem.
== Feedback ==
== Benefit to Fedora ==
Miracle will provide Fedora with a high-quality Wayland experience
built with support for all kinds of platforms, including low-end ARM
and x86 devices. On top of this, Fedora will be the first distribution
to provide a Miracle based spin, ensuring that it will become the de
facto distribution for running Miracle.
== Scope ==
* Proposal owners:
** SIG request: [https://pagure.io/fedora-infrastructure/issue/11856 #11856]
** comps: TODO
** fedora-release-miracle: TODO
** kickstart: TODO
** livesys-scripts: TODO
* Other developers: N/A
* Release engineering: [https://pagure.io/releng/issue/12077 #12077]
* Policies and guidelines: N/A (not needed for this Change)
* Trademark approval: [https://pagure.io/Fedora-Council/tickets/issue/491 #491]
* Alignment with Community Initiatives: N/A
== Upgrade/compatibility impact ==
This is a new spin, so there is nothing.
== How To Test ==
{{package|miracle-wm}} is available in Fedora Linux 40, so it can be
installed on top of something like the existing Sway spin and
configured to reuse much of the tools used there.
For Fedora Linux 41, once the spin is produced, people can download
and try the experience intended to be released.
== User Experience ==
The experience will be similar to the Sway spin, though with more
features there may be some different choices on defaults.
== Dependencies ==
N/A
== Contingency Plan ==
* Contingency mechanism: Push off to the next Fedora release.
* Contingency deadline: Beta freeze
* Blocks release? No
== Documentation ==
N/A (not a System Wide Change)
== Release Notes ==
This release introduces the Fedora Miracle Spin. The Fedora Miracle
Spin aims to provide the premiere Miracle window manager experience on
top of Fedora Linux, the leading edge platform for developers and
users alike.
--
Aoife Moloney
Fedora Operations Architect
Fedora Project
Matrix: @amoloney:fedora.im
IRC: amoloney
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Discussion Thread -
https://discussion.fedoraproject.org/t/f41-change-proposal-fedora-miracle-spin-self-contained/114182
This is a proposed Change for Fedora Linux.
This document represents a proposed Change. As part of the Changes
process, proposals are publicly announced in order to receive
community feedback. This proposal will only be implemented if approved
by the Fedora Engineering Steering Committee.
== Summary ==
Create an official Fedora Spin shipping the up-and-coming Miracle Window Manager
== Owner ==
* Name: [[User:mattkae| Matthew Kosarek]], [[User:tsimonq2| Simon
Quigley]], [[User:ngompa| Neal Gompa]]
* Email: matthew@matthewkosarek.xyz, simon@tsimonq2.net, ngompa13@gmail.com
== Detailed Description ==
The Miracle Window Manager is a tiling window manager based on the Mir
compositor library. While it is a newer project, it contains many
useful features such as a manual tiling algorithm, floating window
manager support, support for many Wayland protocols, proprietary
Nvidia driver support, and much more. Users are increasingly
interested in using miracle in various systems.
The goal of the miracle spin is to build a complete and elegant tiling
window experience within the Fedora ecosystem.
== Feedback ==
== Benefit to Fedora ==
Miracle will provide Fedora with a high-quality Wayland experience
built with support for all kinds of platforms, including low-end ARM
and x86 devices. On top of this, Fedora will be the first distribution
to provide a Miracle based spin, ensuring that it will become the de
facto distribution for running Miracle.
== Scope ==
* Proposal owners:
** SIG request: [https://pagure.io/fedora-infrastructure/issue/11856 #11856]
** comps: TODO
** fedora-release-miracle: TODO
** kickstart: TODO
** livesys-scripts: TODO
* Other developers: N/A
* Release engineering: [https://pagure.io/releng/issue/12077 #12077]
* Policies and guidelines: N/A (not needed for this Change)
* Trademark approval: [https://pagure.io/Fedora-Council/tickets/issue/491 #491]
* Alignment with Community Initiatives: N/A
== Upgrade/compatibility impact ==
This is a new spin, so there is nothing.
== How To Test ==
{{package|miracle-wm}} is available in Fedora Linux 40, so it can be
installed on top of something like the existing Sway spin and
configured to reuse much of the tools used there.
For Fedora Linux 41, once the spin is produced, people can download
and try the experience intended to be released.
== User Experience ==
The experience will be similar to the Sway spin, though with more
features there may be some different choices on defaults.
== Dependencies ==
N/A
== Contingency Plan ==
* Contingency mechanism: Push off to the next Fedora release.
* Contingency deadline: Beta freeze
* Blocks release? No
== Documentation ==
N/A (not a System Wide Change)
== Release Notes ==
This release introduces the Fedora Miracle Spin. The Fedora Miracle
Spin aims to provide the premiere Miracle window manager experience on
top of Fedora Linux, the leading edge platform for developers and
users alike.
--
Aoife Moloney
Fedora Operations Architect
Fedora Project
Matrix: @amoloney:fedora.im
IRC: amoloney
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Fedora 40 Elections are now open!
Hello everyone,
I hope you all are enjoying Fedora 40, and this release also marks the start of a new election cycle[1]. As of now, the nomination period for positions on Fedora Council, Fedora Mindshare, FESCo and EPEL Steering Committee is now open! 🎉
We have some slight changes to some elections this cycle, with more detail available to read on the Elections blog post coming tomorrow as part of the Fedora Council hackfest mini-series, but for now the main things you need to know are the following:
- We are welcoming the EPEL Steering Committee to our elections cycle! There are currently four seats available for the EPEL Steering Committee, so if you or someone you know would like to serve for a term of 12 months on this committee, you can nominate yourself or someone else on their candidate nominations page[2].
- The Fedora Council is moving to a once-per-year election, and we will be electing two new members for this cycle for a 12-month term. If you would like to serve on the council, or know someone who would be a great fit, you can nominate yourself or other(s) on the council nominations page[3].
- The Fedora Engineering Steering Committee (FESCo) will have four seats open this cycle, and will remain on the current twice per year elections cadence. If you would like to nominate yourself, or someone you know who would be a great addition to FESCo, you can nominate yourself or others on their nominations page[4].
- The Fedora Mindshare Committee has one seat open for this election term, and their election schedule will also stay on the twice-per-year cadence. If you would like to get involved, or know someone who would be a great person to be considered for the Mindshare committee activities like budget management with the FCA, ambassador work, outreachy work, etc, you can nominate yourself and/or them now on the nominations page[5].
Very Important: Please do not nominate someone for a seat on any of the above governance bodies without their explicit consent.
The nominations period will be open until Wednesday, May 8th and events during the F40 elections period can be found on the schedule[6].
[USN-6748-1] Sanitize vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEAPYWTpwtIbr7xH4OWNrRIKaTkWcFAmYoqncFAwAAAAAACgkQWNrRIKaTkWcP
dBAAmrZmoWmOq4kXshsbijkIH0TuT5OwfKgCTtbis90LJvMPqsoYATC/jPBlifry2HjSUwHXGm3W
i8C3QLKnp0vwEWpHkJmRvT+Qi9ViIBvscAGUhqaXkGtzcK8TGxDM6u+JLMYZykM0zXb0jNEYlc2Y
B1WPW4nhs0UshcSHR5aKaWlRzeFuXPZILI0vR70GsWH+FAyoZ6xs/Te1+BzuvttIUTiwcixG8I2i
xFeZ806LGgk1CIf068bs9rjsl6CdOublyACOHILzyVcqV+d7jxuiiCAE2jSQN9VHzlaK1BjGMcuD
RAVqEF3jpcWGaE9J//pMTe/B9Aqf9uonRZCnhtwaKXX9tEalWZmz44yZLatGp8DjhqTExGXC3QU5
OWp/rnv7s8dvZem9IKAOl8zEX309fUvqKFK1BVyQfR+6fj7snEdvl/8kc+9f7mwJCkgMEjV1++sl
dae7VNMqezzf2QhZtl5TaME1bwrkNl6ax4/73wERyZDY43MxfEF5GfegDS2CT5EkprMjM/+VeyN/
kdObwaRIL/IAZ4fZf2bY+i5p8Np0IRyLDqNKd6dq3dYogVfB4ggshEGXIO8XkLKPHlqrvlKA//Pd
S1fRWLqqAOc+TpciVeKP+IdYH7MphYMs+TPDMEVMrDCir+xwQW2iIrab8D/sGxK6/vayzKRH7+6S
Ce4=
=30UQ
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6748-1
April 24, 2024
ruby-sanitize vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Sanitize.
Software Description:
- ruby-sanitize: Allowlist-based HTML and CSS sanitizer
Details:
It was discovered that Sanitize incorrectly handled noscript elements
under certain circumstances. An attacker could possibly use this issue to
execute a cross-site scripting (XSS) attack. This issue only affected
Ubuntu 22.04 LTS. (CVE-2023-23627)
It was discovered that Sanitize incorrectly handled style elements under
certain circumstances. An attacker could possibly use this issue to
execute a cross-site scripting (XSS) attack. (CVE-2023-36823)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
ruby-sanitize 6.0.0-1.1ubuntu0.23.10.1
Ubuntu 22.04 LTS:
ruby-sanitize 6.0.0-1ubuntu0.1
Ubuntu 20.04 LTS:
ruby-sanitize 4.6.6-2.1~0.20.04.2
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6748-1
CVE-2023-23627, CVE-2023-36823
Package Information:
https://launchpad.net/ubuntu/+source/ruby-sanitize/6.0.0-1.1ubuntu0.23.10.1
https://launchpad.net/ubuntu/+source/ruby-sanitize/6.0.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/ruby-sanitize/4.6.6-2.1~0.20.04.2
wsF5BAABCAAjFiEEAPYWTpwtIbr7xH4OWNrRIKaTkWcFAmYoqncFAwAAAAAACgkQWNrRIKaTkWcP
dBAAmrZmoWmOq4kXshsbijkIH0TuT5OwfKgCTtbis90LJvMPqsoYATC/jPBlifry2HjSUwHXGm3W
i8C3QLKnp0vwEWpHkJmRvT+Qi9ViIBvscAGUhqaXkGtzcK8TGxDM6u+JLMYZykM0zXb0jNEYlc2Y
B1WPW4nhs0UshcSHR5aKaWlRzeFuXPZILI0vR70GsWH+FAyoZ6xs/Te1+BzuvttIUTiwcixG8I2i
xFeZ806LGgk1CIf068bs9rjsl6CdOublyACOHILzyVcqV+d7jxuiiCAE2jSQN9VHzlaK1BjGMcuD
RAVqEF3jpcWGaE9J//pMTe/B9Aqf9uonRZCnhtwaKXX9tEalWZmz44yZLatGp8DjhqTExGXC3QU5
OWp/rnv7s8dvZem9IKAOl8zEX309fUvqKFK1BVyQfR+6fj7snEdvl/8kc+9f7mwJCkgMEjV1++sl
dae7VNMqezzf2QhZtl5TaME1bwrkNl6ax4/73wERyZDY43MxfEF5GfegDS2CT5EkprMjM/+VeyN/
kdObwaRIL/IAZ4fZf2bY+i5p8Np0IRyLDqNKd6dq3dYogVfB4ggshEGXIO8XkLKPHlqrvlKA//Pd
S1fRWLqqAOc+TpciVeKP+IdYH7MphYMs+TPDMEVMrDCir+xwQW2iIrab8D/sGxK6/vayzKRH7+6S
Ce4=
=30UQ
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6748-1
April 24, 2024
ruby-sanitize vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Sanitize.
Software Description:
- ruby-sanitize: Allowlist-based HTML and CSS sanitizer
Details:
It was discovered that Sanitize incorrectly handled noscript elements
under certain circumstances. An attacker could possibly use this issue to
execute a cross-site scripting (XSS) attack. This issue only affected
Ubuntu 22.04 LTS. (CVE-2023-23627)
It was discovered that Sanitize incorrectly handled style elements under
certain circumstances. An attacker could possibly use this issue to
execute a cross-site scripting (XSS) attack. (CVE-2023-36823)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
ruby-sanitize 6.0.0-1.1ubuntu0.23.10.1
Ubuntu 22.04 LTS:
ruby-sanitize 6.0.0-1ubuntu0.1
Ubuntu 20.04 LTS:
ruby-sanitize 4.6.6-2.1~0.20.04.2
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6748-1
CVE-2023-23627, CVE-2023-36823
Package Information:
https://launchpad.net/ubuntu/+source/ruby-sanitize/6.0.0-1.1ubuntu0.23.10.1
https://launchpad.net/ubuntu/+source/ruby-sanitize/6.0.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/ruby-sanitize/4.6.6-2.1~0.20.04.2
[USN-6747-1] Firefox vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEAPYWTpwtIbr7xH4OWNrRIKaTkWcFAmYoqhkFAwAAAAAACgkQWNrRIKaTkWc/
7A/8Djx1NmjTcdZVmZBxDhnascjz+uri/x9TnEJd2H6GQzlJQtKu2F09DMKr4Rs6pnZg18M7j+EC
FFFFa5BkhmsGwP5H991bqZSCghuqjcyG9i2QihrPGmRaPTvnAaP7LM/SUvUAJXI4mfDgMKo4UZB4
0Q4+JOBL1erRfm5Zj+KxzlnlBxKkgSRlrciBGr4ihpkw1EtftcWFvguMa07w4sxZskXn2rTPaFUL
At3AA9Yw3bAOQL+J5kE14nMS3rShHgAmRIA/2Q4Yk8UPn6w/paudggyUsnjLCFuTW4XbQTz0kQF1
hI+bOdk3Sbf4m2qcKkdPqc20D6dHR1p4qGQKX6StLC+9JQqoNcPlZHZoXso3TB3vq4OL0dN6SnU0
ZWNiSGqWLuzEhym+Fkv8Amd9wpw6E3pqP+Cl1rUy8+OGYGwpEKiTVJMnY658abJVmxivovQ/4BpE
oD8/G3i1y2ux1pA+oFnNwzZo751mDU5ctTm4m+bt9sFfHZ49cfsVhOgm3RHvnvfpdSe/CB+s3Bpn
PVO7kXKCOhN9lFbfZiT/B0sS3ttFMFABoRQDSSaWpLo316x8TQ1i3m+ANLbmGy1kBePol+HqQaSi
UPU7FmExiWSxpSa+39RSWpOnHSpeSvK7r/67AnSB33Owvzsmq5gL36+lgnKgPwhRnuuPZDW8l3VB
zps=
=kmDf
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6747-1
April 24, 2024
firefox vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Firefox.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-3852,
CVE-2024-3864, CVE-2024-3865)
Bartek Nowotarski discovered that Firefox did not properly limit HTTP/2
CONTINUATION frames. An attacker could potentially exploit this issue to
cause a denial of service. (CVE-2024-3302)
Gary Kwong discovered that Firefox did not properly manage memory when
running garbage collection during realm initialization. An attacker could
potentially exploit this issue to cause a denial of service, or execute
arbitrary code. (CVE-2024-3853)
Lukas Bernhard discovered that Firefox did not properly manage memory
during JIT optimisations, leading to an out-of-bounds read vulnerability.
An attacker could possibly use this issue to cause a denial of service or
expose sensitive information. (CVE-2024-3854, CVE-2024-3855)
Nan Wang discovered that Firefox did not properly manage memory during
WASM garbage collection. An attacker could potentially exploit this issue
to cause a denial of service, or execute arbitrary code. (CVE-2024-3856)
Lukas Bernhard discovered that Firefox did not properly manage memory
when handling JIT created code during garbage collection. An attacker
could potentially exploit this issue to cause a denial of service, or
execute arbitrary code. (CVE-2024-3857)
Lukas Bernhard discovered that Firefox did not properly manage memory when
tracing in JIT. An attacker could potentially exploit this issue to cause
a denial of service. (CVE-2024-3858)
Ronald Crane discovered that Firefox did not properly manage memory in the
OpenType sanitizer on 32-bit devices, leading to an out-of-bounds read
vulnerability. An attacker could possibly use this issue to cause a denial
of service or expose sensitive information. (CVE-2024-3859)
Garry Kwong discovered that Firefox did not properly manage memory when
tracing empty shape lists in JIT. An attacker could potentially exploit
this issue to cause a denial of service. (CVE-2024-3860)
Ronald Crane discovered that Firefox did not properly manage memory when
handling an AlignedBuffer. An attacker could potentially exploit this
issue to cause denial of service, or execute arbitrary code.
(CVE-2024-3861)
Ronald Crane discovered that Firefox did not properly manage memory when
handling code in MarkStack. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2024-3862)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS:
firefox 125.0.2+build1-0ubuntu0.20.04.2
After a standard system update you need to restart Firefox to make all the
necessary changes.
References:
https://ubuntu.com/security/notices/USN-6747-1
CVE-2024-3302, CVE-2024-3852, CVE-2024-3853, CVE-2024-3854,
CVE-2024-3855, CVE-2024-3856, CVE-2024-3857, CVE-2024-3858,
CVE-2024-3859, CVE-2024-3860, CVE-2024-3861, CVE-2024-3862,
CVE-2024-3864, CVE-2024-3865
Package Information:
https://launchpad.net/ubuntu/+source/firefox/125.0.2+build1-0ubuntu0.20.04.2
wsF5BAABCAAjFiEEAPYWTpwtIbr7xH4OWNrRIKaTkWcFAmYoqhkFAwAAAAAACgkQWNrRIKaTkWc/
7A/8Djx1NmjTcdZVmZBxDhnascjz+uri/x9TnEJd2H6GQzlJQtKu2F09DMKr4Rs6pnZg18M7j+EC
FFFFa5BkhmsGwP5H991bqZSCghuqjcyG9i2QihrPGmRaPTvnAaP7LM/SUvUAJXI4mfDgMKo4UZB4
0Q4+JOBL1erRfm5Zj+KxzlnlBxKkgSRlrciBGr4ihpkw1EtftcWFvguMa07w4sxZskXn2rTPaFUL
At3AA9Yw3bAOQL+J5kE14nMS3rShHgAmRIA/2Q4Yk8UPn6w/paudggyUsnjLCFuTW4XbQTz0kQF1
hI+bOdk3Sbf4m2qcKkdPqc20D6dHR1p4qGQKX6StLC+9JQqoNcPlZHZoXso3TB3vq4OL0dN6SnU0
ZWNiSGqWLuzEhym+Fkv8Amd9wpw6E3pqP+Cl1rUy8+OGYGwpEKiTVJMnY658abJVmxivovQ/4BpE
oD8/G3i1y2ux1pA+oFnNwzZo751mDU5ctTm4m+bt9sFfHZ49cfsVhOgm3RHvnvfpdSe/CB+s3Bpn
PVO7kXKCOhN9lFbfZiT/B0sS3ttFMFABoRQDSSaWpLo316x8TQ1i3m+ANLbmGy1kBePol+HqQaSi
UPU7FmExiWSxpSa+39RSWpOnHSpeSvK7r/67AnSB33Owvzsmq5gL36+lgnKgPwhRnuuPZDW8l3VB
zps=
=kmDf
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6747-1
April 24, 2024
firefox vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Firefox.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-3852,
CVE-2024-3864, CVE-2024-3865)
Bartek Nowotarski discovered that Firefox did not properly limit HTTP/2
CONTINUATION frames. An attacker could potentially exploit this issue to
cause a denial of service. (CVE-2024-3302)
Gary Kwong discovered that Firefox did not properly manage memory when
running garbage collection during realm initialization. An attacker could
potentially exploit this issue to cause a denial of service, or execute
arbitrary code. (CVE-2024-3853)
Lukas Bernhard discovered that Firefox did not properly manage memory
during JIT optimisations, leading to an out-of-bounds read vulnerability.
An attacker could possibly use this issue to cause a denial of service or
expose sensitive information. (CVE-2024-3854, CVE-2024-3855)
Nan Wang discovered that Firefox did not properly manage memory during
WASM garbage collection. An attacker could potentially exploit this issue
to cause a denial of service, or execute arbitrary code. (CVE-2024-3856)
Lukas Bernhard discovered that Firefox did not properly manage memory
when handling JIT created code during garbage collection. An attacker
could potentially exploit this issue to cause a denial of service, or
execute arbitrary code. (CVE-2024-3857)
Lukas Bernhard discovered that Firefox did not properly manage memory when
tracing in JIT. An attacker could potentially exploit this issue to cause
a denial of service. (CVE-2024-3858)
Ronald Crane discovered that Firefox did not properly manage memory in the
OpenType sanitizer on 32-bit devices, leading to an out-of-bounds read
vulnerability. An attacker could possibly use this issue to cause a denial
of service or expose sensitive information. (CVE-2024-3859)
Garry Kwong discovered that Firefox did not properly manage memory when
tracing empty shape lists in JIT. An attacker could potentially exploit
this issue to cause a denial of service. (CVE-2024-3860)
Ronald Crane discovered that Firefox did not properly manage memory when
handling an AlignedBuffer. An attacker could potentially exploit this
issue to cause denial of service, or execute arbitrary code.
(CVE-2024-3861)
Ronald Crane discovered that Firefox did not properly manage memory when
handling code in MarkStack. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2024-3862)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS:
firefox 125.0.2+build1-0ubuntu0.20.04.2
After a standard system update you need to restart Firefox to make all the
necessary changes.
References:
https://ubuntu.com/security/notices/USN-6747-1
CVE-2024-3302, CVE-2024-3852, CVE-2024-3853, CVE-2024-3854,
CVE-2024-3855, CVE-2024-3856, CVE-2024-3857, CVE-2024-3858,
CVE-2024-3859, CVE-2024-3860, CVE-2024-3861, CVE-2024-3862,
CVE-2024-3864, CVE-2024-3865
Package Information:
https://launchpad.net/ubuntu/+source/firefox/125.0.2+build1-0ubuntu0.20.04.2
Tuesday, April 23, 2024
[USN-6742-2] Linux kernel vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmYn8uQFAwAAAAAACgkQZ0GeRcM5nt2L
2Af+Jp0rlyU/rqL4eKsXF2iVpDLJW5Ae4JEur8W0daRuFaCUU5vsE+kGvlTQM1S92bJi5JozaAMD
45l8XAgbyEJKIdW/Yy7KlxWCM2y0VW/UeEuv2Jgmo4fHWlI+WZenSfPRu+/I/L/SB2Bqx9KIdOqU
8915wkWkzCzj1JJNWRVjFpF0pWQ4pusu9iyuXsVbqey5u2IvQHqEWpjLyeobmJmQY4Qsms96uhe+
c2OpADaXNAIMUuA+JW6iceEXEeYl4Y7g7hw3ylqGnLp/cb7HmcdntjjKWO/NYBvpnBUkDH33EB7B
q+Dzr2esx/bHQEqbBPFv43Z0778/uEGWOtBWZwrqcA==
=VEEq
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6742-2
April 23, 2024
linux-azure, linux-lowlatency, linux-nvidia vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-lowlatency: Linux low latency kernel
- linux-nvidia: Linux kernel for NVIDIA systems
Details:
Daniele Antonioli discovered that the Secure Simple Pairing and Secure
Connections pairing in the Bluetooth protocol could allow an
unauthenticated user to complete authentication without pairing
credentials. A physically proximate attacker placed between two Bluetooth
devices could use this to subsequently impersonate one of the paired
devices. (CVE-2023-24023)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- JFS file system;
- Netfilter;
(CVE-2024-26581, CVE-2023-52600, CVE-2023-52603)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS:
linux-image-5.15.0-105-lowlatency 5.15.0-105.115
linux-image-5.15.0-105-lowlatency-64k 5.15.0-105.115
linux-image-5.15.0-1053-nvidia 5.15.0-1053.54
linux-image-5.15.0-1053-nvidia-lowlatency 5.15.0-1053.54
linux-image-5.15.0-1061-azure 5.15.0-1061.70
linux-image-azure-lts-22.04 5.15.0.1061.59
linux-image-lowlatency 5.15.0.105.100
linux-image-lowlatency-64k 5.15.0.105.100
linux-image-nvidia 5.15.0.1053.53
linux-image-nvidia-lowlatency 5.15.0.1053.53
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-6742-2
https://ubuntu.com/security/notices/USN-6742-1
CVE-2023-24023, CVE-2023-52600, CVE-2023-52603, CVE-2024-26581
Package Information:
https://launchpad.net/ubuntu/+source/linux-azure/5.15.0-1061.70
https://launchpad.net/ubuntu/+source/linux-lowlatency/5.15.0-105.115
https://launchpad.net/ubuntu/+source/linux-nvidia/5.15.0-1053.54
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmYn8uQFAwAAAAAACgkQZ0GeRcM5nt2L
2Af+Jp0rlyU/rqL4eKsXF2iVpDLJW5Ae4JEur8W0daRuFaCUU5vsE+kGvlTQM1S92bJi5JozaAMD
45l8XAgbyEJKIdW/Yy7KlxWCM2y0VW/UeEuv2Jgmo4fHWlI+WZenSfPRu+/I/L/SB2Bqx9KIdOqU
8915wkWkzCzj1JJNWRVjFpF0pWQ4pusu9iyuXsVbqey5u2IvQHqEWpjLyeobmJmQY4Qsms96uhe+
c2OpADaXNAIMUuA+JW6iceEXEeYl4Y7g7hw3ylqGnLp/cb7HmcdntjjKWO/NYBvpnBUkDH33EB7B
q+Dzr2esx/bHQEqbBPFv43Z0778/uEGWOtBWZwrqcA==
=VEEq
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6742-2
April 23, 2024
linux-azure, linux-lowlatency, linux-nvidia vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-lowlatency: Linux low latency kernel
- linux-nvidia: Linux kernel for NVIDIA systems
Details:
Daniele Antonioli discovered that the Secure Simple Pairing and Secure
Connections pairing in the Bluetooth protocol could allow an
unauthenticated user to complete authentication without pairing
credentials. A physically proximate attacker placed between two Bluetooth
devices could use this to subsequently impersonate one of the paired
devices. (CVE-2023-24023)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- JFS file system;
- Netfilter;
(CVE-2024-26581, CVE-2023-52600, CVE-2023-52603)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS:
linux-image-5.15.0-105-lowlatency 5.15.0-105.115
linux-image-5.15.0-105-lowlatency-64k 5.15.0-105.115
linux-image-5.15.0-1053-nvidia 5.15.0-1053.54
linux-image-5.15.0-1053-nvidia-lowlatency 5.15.0-1053.54
linux-image-5.15.0-1061-azure 5.15.0-1061.70
linux-image-azure-lts-22.04 5.15.0.1061.59
linux-image-lowlatency 5.15.0.105.100
linux-image-lowlatency-64k 5.15.0.105.100
linux-image-nvidia 5.15.0.1053.53
linux-image-nvidia-lowlatency 5.15.0.1053.53
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-6742-2
https://ubuntu.com/security/notices/USN-6742-1
CVE-2023-24023, CVE-2023-52600, CVE-2023-52603, CVE-2024-26581
Package Information:
https://launchpad.net/ubuntu/+source/linux-azure/5.15.0-1061.70
https://launchpad.net/ubuntu/+source/linux-lowlatency/5.15.0-105.115
https://launchpad.net/ubuntu/+source/linux-nvidia/5.15.0-1053.54
Announcing Fedora Linux 40
Fedora Linux 40 is now officially available.
Read the details in our Fedora Magazine article at:
* https://fedoramagazine.org/announcing-fedora-linux-40
or download installer images from:
* https://fedoraproject.org/
or, of course, simply upgrade your already-installed systems, which
shouldn't take much longer than ordering and consuming your favorite
hot and possibly caffeinated beverage. If you run into any trouble, or
just have questions, you can find help at
* https://ask.fedoraproject.org/
There are several important release-day bugfix and security updates
available today as well. If you upgrade from an earlier Fedora Linux
release, you'll get them as part of that. For new systems, please
make sure to check for and apply updates as soon as possible.
--
Matthew Miller
<mattdm@fedoraproject.org>
Fedora Project Leader
--
_______________________________________________
announce mailing list -- announce@lists.fedoraproject.org
To unsubscribe send an email to announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Read the details in our Fedora Magazine article at:
* https://fedoramagazine.org/announcing-fedora-linux-40
or download installer images from:
* https://fedoraproject.org/
or, of course, simply upgrade your already-installed systems, which
shouldn't take much longer than ordering and consuming your favorite
hot and possibly caffeinated beverage. If you run into any trouble, or
just have questions, you can find help at
* https://ask.fedoraproject.org/
There are several important release-day bugfix and security updates
available today as well. If you upgrade from an earlier Fedora Linux
release, you'll get them as part of that. For new systems, please
make sure to check for and apply updates as soon as possible.
--
Matthew Miller
<mattdm@fedoraproject.org>
Fedora Project Leader
--
_______________________________________________
announce mailing list -- announce@lists.fedoraproject.org
To unsubscribe send an email to announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
[USN-6746-1] Google Guest Agent and Google OS Config Agent vulnerability
==========================================================================
Ubuntu Security Notice USN-6746-1
April 23, 2024
google-guest-agent, google-osconfig-agent vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 22.04 LTS
Summary:
Google Guest Agent and OS Config Agent could be made to crash
if it open a specially crafted JSON.
Software Description:
- google-guest-agent: Google Compute Engine Guest Agent
- google-osconfig-agent: Google OS Config Agent
Details:
It was discovered that Google Guest Agent and Google OS Config Agent incorrectly
handled certain JSON files. An attacker could possibly use this issue to
cause a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
google-guest-agent 20231004.02-0ubuntu1~23.10.3
google-osconfig-agent 20230504.00-0ubuntu2.2
Ubuntu 22.04 LTS:
google-guest-agent 20231004.02-0ubuntu1~22.04.4
google-osconfig-agent 20230504.00-0ubuntu1~22.04.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6746-1
CVE-2024-24786
Package Information:
https://launchpad.net/ubuntu/+source/google-guest-agent/20231004.02-0ubuntu1~23.10.3
https://launchpad.net/ubuntu/+source/google-osconfig-agent/20230504.00-0ubuntu2.2
https://launchpad.net/ubuntu/+source/google-guest-agent/20231004.02-0ubuntu1~22.04.4
https://launchpad.net/ubuntu/+source/google-osconfig-agent/20230504.00-0ubuntu1~22.04.1
Ubuntu Security Notice USN-6746-1
April 23, 2024
google-guest-agent, google-osconfig-agent vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 22.04 LTS
Summary:
Google Guest Agent and OS Config Agent could be made to crash
if it open a specially crafted JSON.
Software Description:
- google-guest-agent: Google Compute Engine Guest Agent
- google-osconfig-agent: Google OS Config Agent
Details:
It was discovered that Google Guest Agent and Google OS Config Agent incorrectly
handled certain JSON files. An attacker could possibly use this issue to
cause a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
google-guest-agent 20231004.02-0ubuntu1~23.10.3
google-osconfig-agent 20230504.00-0ubuntu2.2
Ubuntu 22.04 LTS:
google-guest-agent 20231004.02-0ubuntu1~22.04.4
google-osconfig-agent 20230504.00-0ubuntu1~22.04.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6746-1
CVE-2024-24786
Package Information:
https://launchpad.net/ubuntu/+source/google-guest-agent/20231004.02-0ubuntu1~23.10.3
https://launchpad.net/ubuntu/+source/google-osconfig-agent/20230504.00-0ubuntu2.2
https://launchpad.net/ubuntu/+source/google-guest-agent/20231004.02-0ubuntu1~22.04.4
https://launchpad.net/ubuntu/+source/google-osconfig-agent/20230504.00-0ubuntu1~22.04.1
[USN-6728-3] Squid vulnerability
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmYnoXgACgkQZWnYVadE
vpOfjRAAtaSxKXT3Tyxk67aVXjWAUyGWFvLNm9OG642aXaWKjj1Qyei91WL/4bmD
ZW9SsHDM/gTGSMfP71aWF4hiIOb8rj8vSCy9gyJIkptzV3cKSZK1Q/1YlpVle2dw
eSfqr6ePGSFuV9pgii+TX045VuZ7WhF+gn7bUKvQquQrCLA44rMH7C7fhN84Mx2q
OrqSlzcnkElX2zDkaeTxCSzumPt9MAdDiPRp59jfWSGhIUzaKoHhClv9OUVr3sYn
7jCE8B7aFGGquiXPvJesUiJsjrdNteBsmNwiH/0VjszXnemczKoOG/mY/7pw1+Gb
nYMzgu8WezJYmhCzP600nS2JEnMMf6rzGNislacZrPuf068M4QBj2n866ZloaJCy
vWOCM5TIgksj/tJng8e5Nh+qC91nfuQwJtQG6l3o/dGuvfxloRyC1FgAhWNb0cwn
BK0geqSMhObj5QZiw+Yt60gbJKTOWOAWru9x4IICKlRH9Odw7+BHkCfWaB2KU37P
ciu+sO71pjbe9Vy0PBY/mK2dFV8ADSommfQoXHCrHvlLTzMIMdKTlBSxifimg7C3
qjWreDlNR/hKEVQDXci4ZgzFCuN2dEA5emfVxOnLsIae8J1aKZiSqASxRlnakm9j
MqkVO2FHGEy7Uo2A+BWX9P9mzsfYJJa+1KkHaI9tNX4RstRRmDU=
=6jIb
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6728-3
April 23, 2024
squid vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Squid could be made to crash if it received specially crafted network
traffic.
Software Description:
- squid: Web proxy cache server
Details:
USN-6728-1 fixed vulnerabilities in Squid. The fix for CVE-2023-5824 caused
Squid to crash in certain environments on Ubuntu 20.04 LTS and was disabled
in USN-6728-2. The problematic fix for CVE-2023-5824 has now been corrected
and reinstated in this update.
We apologize for the inconvenience.
Original advisory details:
Joshua Rogers discovered that Squid incorrectly handled collapsed
forwarding. A remote attacker could possibly use this issue to cause Squid
to crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-49288)
Joshua Rogers discovered that Squid incorrectly handled certain structural
elements. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of service. (CVE-2023-5824)
Joshua Rogers discovered that Squid incorrectly handled Cache Manager error
responses. A remote trusted client can possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2024-23638)
Joshua Rogers discovered that Squid incorrectly handled the HTTP Chunked
decoder. A remote attacker could possibly use this issue to cause Squid to
stop responding, resulting in a denial of service. (CVE-2024-25111)
Joshua Rogers discovered that Squid incorrectly handled HTTP header
parsing. A remote trusted client can possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2024-25617)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS:
squid 4.10-1ubuntu1.12
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6728-3
https://ubuntu.com/security/notices/USN-6728-1
CVE-2023-49288, CVE-2023-5824, https://launchpad.net/bugs/2060880
Package Information:
https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.12
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmYnoXgACgkQZWnYVadE
vpOfjRAAtaSxKXT3Tyxk67aVXjWAUyGWFvLNm9OG642aXaWKjj1Qyei91WL/4bmD
ZW9SsHDM/gTGSMfP71aWF4hiIOb8rj8vSCy9gyJIkptzV3cKSZK1Q/1YlpVle2dw
eSfqr6ePGSFuV9pgii+TX045VuZ7WhF+gn7bUKvQquQrCLA44rMH7C7fhN84Mx2q
OrqSlzcnkElX2zDkaeTxCSzumPt9MAdDiPRp59jfWSGhIUzaKoHhClv9OUVr3sYn
7jCE8B7aFGGquiXPvJesUiJsjrdNteBsmNwiH/0VjszXnemczKoOG/mY/7pw1+Gb
nYMzgu8WezJYmhCzP600nS2JEnMMf6rzGNislacZrPuf068M4QBj2n866ZloaJCy
vWOCM5TIgksj/tJng8e5Nh+qC91nfuQwJtQG6l3o/dGuvfxloRyC1FgAhWNb0cwn
BK0geqSMhObj5QZiw+Yt60gbJKTOWOAWru9x4IICKlRH9Odw7+BHkCfWaB2KU37P
ciu+sO71pjbe9Vy0PBY/mK2dFV8ADSommfQoXHCrHvlLTzMIMdKTlBSxifimg7C3
qjWreDlNR/hKEVQDXci4ZgzFCuN2dEA5emfVxOnLsIae8J1aKZiSqASxRlnakm9j
MqkVO2FHGEy7Uo2A+BWX9P9mzsfYJJa+1KkHaI9tNX4RstRRmDU=
=6jIb
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6728-3
April 23, 2024
squid vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Squid could be made to crash if it received specially crafted network
traffic.
Software Description:
- squid: Web proxy cache server
Details:
USN-6728-1 fixed vulnerabilities in Squid. The fix for CVE-2023-5824 caused
Squid to crash in certain environments on Ubuntu 20.04 LTS and was disabled
in USN-6728-2. The problematic fix for CVE-2023-5824 has now been corrected
and reinstated in this update.
We apologize for the inconvenience.
Original advisory details:
Joshua Rogers discovered that Squid incorrectly handled collapsed
forwarding. A remote attacker could possibly use this issue to cause Squid
to crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-49288)
Joshua Rogers discovered that Squid incorrectly handled certain structural
elements. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of service. (CVE-2023-5824)
Joshua Rogers discovered that Squid incorrectly handled Cache Manager error
responses. A remote trusted client can possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2024-23638)
Joshua Rogers discovered that Squid incorrectly handled the HTTP Chunked
decoder. A remote attacker could possibly use this issue to cause Squid to
stop responding, resulting in a denial of service. (CVE-2024-25111)
Joshua Rogers discovered that Squid incorrectly handled HTTP header
parsing. A remote trusted client can possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2024-25617)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS:
squid 4.10-1ubuntu1.12
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6728-3
https://ubuntu.com/security/notices/USN-6728-1
CVE-2023-49288, CVE-2023-5824, https://launchpad.net/bugs/2060880
Package Information:
https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.12
Intent to start ARC investigation git-forge replacement
Hello, Fedora community,
Following on from the Fedora Council's decision to investigate Forgejo
and GitLab as potential replacements[1], the Community Platform
Engineering team will start an ARC[2] investigation to compare
proposed alternatives for current pagure use cases.
The council has defined some broad requirements for the team to
consider during this investigation. But we would like inputs from all
gitforge user groups in our community.
So, if you have a specific use case or workflow, share it with us in
the form of a user story in this ticket[6], or consider joining the
ARC team for this investigation.
High-level overview of investigation requirements by the council:
1. Suitability for dist-git and src.fedoraproject.org replacement
2. Suitability for replacement of Bugzilla for packaging issues and
review process
3. Suitability for replacement of Pagure and Bugzilla for release
issues (change process, blocker bugs, etc)
* https://fedoraproject.org/wiki/QA:SOP_blocker_bug_process
* https://fedoraproject.org/wiki/QA:SOP_freeze_exception_bug_process
4. Suitability for replacement of Pagure for SIG and Team ticket
tracking (e.g. FESCo tracker)
5. Cost of hosting and maintenance (hardware + time and resources
from CPE and wider infrastructure team)
6. Ease of migration from current Pagure, GitHub, and GitLab
7. Ease of extension and enhancement — can we improve things
ourselves to add missing features/features that are cool and useful
like CI integration?
8. New features like Asciidoc support, Online editor, and others to
make things easier for the Fedora teams and their workflows.
9. Estimate Future risk for Fedora project and Infrastructure team
1. Long-term project vision
2. Platform SMEs in the Fedora Infrastructure team and the wider community
These requirements do not represent feature sets, but rather a
high-level overview of our current use cases.
CPE has already done some initial mapping of how our current
applications interact with distgit[3] and if we have missed anything,
please let folks know in a thread on discussions.fp.o[4].
The aim of this investigation will not be to pick one solution or the other,
but instead, focus on providing the Fedora Council and decision
makers[5] with an extensive comparison of the two.
For discussion about the purpose of this investigation please use the
discussions.fp.o thread[7]
The ARC investigation will commence in early May.
[1] - https://communityblog.fedoraproject.org/2024-git-forge-evaluation/
[2] - https://fedora-arc.readthedocs.io/en/latest/index.html
[3] - https://fedora-arc.readthedocs.io/en/latest/dist-git-move/index.html#interactions
[4] - https://discussion.fedoraproject.org/t/dist-git-decoupling-investigation/93644/10
[5] - https://pagure.io/Fedora-Council/tickets/issue/488
[6] - https://pagure.io/fedora-infra/arc/issue/164
[7] - https://discussion.fedoraproject.org/t/arc-git-forge-investigation/114018
Tomas Hrcka
Cat herder at Community Platform Engineering team
fas: humaton
libera.CHAT: jednorozec
matrix: @humaton:fedora.im
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Following on from the Fedora Council's decision to investigate Forgejo
and GitLab as potential replacements[1], the Community Platform
Engineering team will start an ARC[2] investigation to compare
proposed alternatives for current pagure use cases.
The council has defined some broad requirements for the team to
consider during this investigation. But we would like inputs from all
gitforge user groups in our community.
So, if you have a specific use case or workflow, share it with us in
the form of a user story in this ticket[6], or consider joining the
ARC team for this investigation.
High-level overview of investigation requirements by the council:
1. Suitability for dist-git and src.fedoraproject.org replacement
2. Suitability for replacement of Bugzilla for packaging issues and
review process
3. Suitability for replacement of Pagure and Bugzilla for release
issues (change process, blocker bugs, etc)
* https://fedoraproject.org/wiki/QA:SOP_blocker_bug_process
* https://fedoraproject.org/wiki/QA:SOP_freeze_exception_bug_process
4. Suitability for replacement of Pagure for SIG and Team ticket
tracking (e.g. FESCo tracker)
5. Cost of hosting and maintenance (hardware + time and resources
from CPE and wider infrastructure team)
6. Ease of migration from current Pagure, GitHub, and GitLab
7. Ease of extension and enhancement — can we improve things
ourselves to add missing features/features that are cool and useful
like CI integration?
8. New features like Asciidoc support, Online editor, and others to
make things easier for the Fedora teams and their workflows.
9. Estimate Future risk for Fedora project and Infrastructure team
1. Long-term project vision
2. Platform SMEs in the Fedora Infrastructure team and the wider community
These requirements do not represent feature sets, but rather a
high-level overview of our current use cases.
CPE has already done some initial mapping of how our current
applications interact with distgit[3] and if we have missed anything,
please let folks know in a thread on discussions.fp.o[4].
The aim of this investigation will not be to pick one solution or the other,
but instead, focus on providing the Fedora Council and decision
makers[5] with an extensive comparison of the two.
For discussion about the purpose of this investigation please use the
discussions.fp.o thread[7]
The ARC investigation will commence in early May.
[1] - https://communityblog.fedoraproject.org/2024-git-forge-evaluation/
[2] - https://fedora-arc.readthedocs.io/en/latest/index.html
[3] - https://fedora-arc.readthedocs.io/en/latest/dist-git-move/index.html#interactions
[4] - https://discussion.fedoraproject.org/t/dist-git-decoupling-investigation/93644/10
[5] - https://pagure.io/Fedora-Council/tickets/issue/488
[6] - https://pagure.io/fedora-infra/arc/issue/164
[7] - https://discussion.fedoraproject.org/t/arc-git-forge-investigation/114018
Tomas Hrcka
Cat herder at Community Platform Engineering team
fas: humaton
libera.CHAT: jednorozec
matrix: @humaton:fedora.im
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Subscribe to:
Posts (Atom)