Debian Bug report logs - #692492
ITA: audit -- tools, library, plugin and bindings for security auditing

version graph

Package: wnpp; Maintainer for wnpp is wnpp@debian.org;

Reported by: Laurent Bigonville <bigon@debian.org>

Date: Tue, 6 Nov 2012 19:03:02 UTC

Owned by: Laurent Bigonville <bigon@debian.org>

Severity: normal

Fixed in version audit/1:2.3.4-1

Done: Laurent Bigonville <bigon@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, debian-qa@lists.debian.org, Philipp Matthias Hahn <pmhahn@debian.org>:
Bug#692492; Package auditd. (Tue, 06 Nov 2012 19:03:04 GMT) Full text and rfc822 format available.

Acknowledgement sent to Laurent Bigonville <bigon@debian.org>:
New Bug report received and forwarded. Copy sent to debian-qa@lists.debian.org, Philipp Matthias Hahn <pmhahn@debian.org>. (Tue, 06 Nov 2012 19:03:04 GMT) Full text and rfc822 format available.

Message #5 received at submit@bugs.debian.org (full text, mbox):

From: Laurent Bigonville <bigon@debian.org>
To: submit@bugs.debian.org
Subject: ITO: Orphaning audit package
Date: Tue, 6 Nov 2012 20:01:54 +0100
[Message part 1 (text/plain, inline)]
Package: auditd
Severity: serious
Version: 1:1.7.18-1.1

Hi,

I've tried to enter in contact with Philipp Matthias regarding the
status of the audit package. I've sent a first mail a bit more than a
month ago and a second one 15 days later. But I unfortunately didn't
get any answer so far.

The last maintainer upload for this package has been done a bit more
than a year ago. In the mean time, there was an attempt of NMU to
upgrade the package to a newer version (which has been reverted by a 3rd
party) and an other NMU (with maintainer approval) to experimental. This
version in experimental has currently a 'serious' bug (see #682251).

I've prepared an upload for experimental that would fix several issues
(including the serious bug) and cleaned up a bit the package. The git
repository can be found at:
http://git.bigon.be/?p=user/bigon/audit.git;a=summary

I'm planning to orphan (and upload my changes for experimental) "soon"
if nobody objects.

Cheers

Laurent Bigonville
[signature.asc (application/pgp-signature, attachment)]

Information forwarded to debian-bugs-dist@lists.debian.org, Philipp Matthias Hahn <pmhahn@debian.org>:
Bug#692492; Package auditd. (Tue, 06 Nov 2012 20:06:02 GMT) Full text and rfc822 format available.

Acknowledgement sent to Steve Langasek <vorlon@debian.org>:
Extra info received and forwarded to list. Copy sent to Philipp Matthias Hahn <pmhahn@debian.org>. (Tue, 06 Nov 2012 20:06:02 GMT) Full text and rfc822 format available.

Message #10 received at 692492@bugs.debian.org (full text, mbox):

From: Steve Langasek <vorlon@debian.org>
To: Laurent Bigonville <bigon@debian.org>, 692492@bugs.debian.org
Cc: debian-qa@lists.debian.org
Subject: Re: Bug#692492: ITO: Orphaning audit package
Date: Tue, 6 Nov 2012 12:02:33 -0800
[Message part 1 (text/plain, inline)]
severity 692492 normal
thanks

On Tue, Nov 06, 2012 at 08:01:54PM +0100, Laurent Bigonville wrote:
> Package: auditd
> Severity: serious
> Version: 1:1.7.18-1.1

"serious" severity refers to bugs that are blockers for a release.  A
missing maintainer is not a serious bug.  The other serious bug stands on
its own - but does not impact the release because it only applies to
experimental.  Please do not inflate the severity of bug reports, this
causes extra work for release tracking.

> I've tried to enter in contact with Philipp Matthias regarding the
> status of the audit package. I've sent a first mail a bit more than a
> month ago and a second one 15 days later. But I unfortunately didn't
> get any answer so far.

And where did you cc: this mail for a public record, to what address did you
send it, and what was written in this mail that should give the maintainer
reason to prioritize responding to it?

Private mails should not be a justification for expedited orphaning of
packages.  With this bug report you have *now* used a proper channel for
notifying the maintainer that you want to salvage the package; so the clock
starts now, not whenever your private mail was sent.


> I'm planning to orphan (and upload my changes for experimental) "soon"
> if nobody objects.

Are you deliberately ignoring the ongoing discussion on debian-devel about
why "nobody objects" is not an acceptable standard for orphaning packages?

According to LDAP, the maintainer has been active in the BTS as recently as
two days ago.  An NMU for a serious bug is obviously ok (including in
experimental), but you can consider this an objection to any such "soon"
orphaning.

-- 
Steve Langasek                   Give me a lever long enough and a Free OS
Debian Developer                   to set it on, and I can move the world.
Ubuntu Developer                                    http://www.debian.org/
slangasek@ubuntu.com                                     vorlon@debian.org
[signature.asc (application/pgp-signature, inline)]

Severity set to 'normal' from 'serious' Request was from Steve Langasek <vorlon@debian.org> to control@bugs.debian.org. (Tue, 06 Nov 2012 20:06:04 GMT) Full text and rfc822 format available.

Information forwarded to debian-bugs-dist@lists.debian.org, Philipp Matthias Hahn <pmhahn@debian.org>:
Bug#692492; Package auditd. (Tue, 06 Nov 2012 21:51:05 GMT) Full text and rfc822 format available.

Acknowledgement sent to Bart Martens <bartm@debian.org>:
Extra info received and forwarded to list. Copy sent to Philipp Matthias Hahn <pmhahn@debian.org>. (Tue, 06 Nov 2012 21:51:05 GMT) Full text and rfc822 format available.

Message #17 received at 692492@bugs.debian.org (full text, mbox):

From: Bart Martens <bartm@debian.org>
To: Laurent Bigonville <bigon@debian.org>, Philipp Matthias Hahn <pmhahn@debian.org>, Philipp Matthias Hahn <pmhahn@pmhahn.de>
Cc: 692492@bugs.debian.org
Subject: Re: Bug#692492: ITO: Orphaning audit package
Date: Tue, 6 Nov 2012 21:48:40 +0000
On Tue, Nov 06, 2012 at 08:01:54PM +0100, Laurent Bigonville wrote:
> I'm planning to orphan (and upload my changes for experimental) "soon"
> if nobody objects.

Hi Laurent, in this case I prefer to hear the maintainer.

Hi Philipp, is it OK that Laurent Bigonville updates the package in
experimental ? Do you agree that he takes over maintenance, or do you prefer
co-maintenance, or maybe an NMU (like Andrew Pollock did) ?

Regards,

Bart Martens



Information forwarded to debian-bugs-dist@lists.debian.org, Philipp Matthias Hahn <pmhahn@debian.org>:
Bug#692492; Package auditd. (Tue, 06 Nov 2012 22:21:03 GMT) Full text and rfc822 format available.

Acknowledgement sent to Laurent Bigonville <bigon@debian.org>:
Extra info received and forwarded to list. Copy sent to Philipp Matthias Hahn <pmhahn@debian.org>. (Tue, 06 Nov 2012 22:21:03 GMT) Full text and rfc822 format available.

Message #22 received at 692492@bugs.debian.org (full text, mbox):

From: Laurent Bigonville <bigon@debian.org>
To: Steve Langasek <vorlon@debian.org>
Cc: 692492@bugs.debian.org, debian-qa@lists.debian.org
Subject: Re: Bug#692492: ITO: Orphaning audit package
Date: Tue, 6 Nov 2012 23:17:22 +0100
[Message part 1 (text/plain, inline)]
Le Tue, 6 Nov 2012 12:02:33 -0800,
Steve Langasek <vorlon@debian.org> a écrit :

> On Tue, Nov 06, 2012 at 08:01:54PM +0100, Laurent Bigonville wrote:
> > I've tried to enter in contact with Philipp Matthias regarding the
> > status of the audit package. I've sent a first mail a bit more than
> > a month ago and a second one 15 days later. But I unfortunately
> > didn't get any answer so far.
> 
> And where did you cc: this mail for a public record, to what address
> did you send it, and what was written in this mail that should give
> the maintainer reason to prioritize responding to it?
> 
> Private mails should not be a justification for expedited orphaning of
> packages.  With this bug report you have *now* used a proper channel
> for notifying the maintainer that you want to salvage the package; so
> the clock starts now, not whenever your private mail was sent.

I've sent my first mail the 19th of September. The first mail about a
proposal is from the 28th and is I think the result of my questions on
#debian-qa as I was seeking for an ACK to orphan the package.

My 2nd mail from the 2nd of October was CC to the mia team. The mia
team is also aware of the situation.

> > I'm planning to orphan (and upload my changes for experimental)
> > "soon" if nobody objects.
> 
> Are you deliberately ignoring the ongoing discussion on debian-devel
> about why "nobody objects" is not an acceptable standard for
> orphaning packages?

I actually went on with what I started as I was seeing the discussions
on debian-devel about this continue for weeks. I already used similar
procedure in the past without any complains.

I've open this bug to only to conform to the proposal even if I find
that making public statements like "eh look that guy has disappeared
for the surface of the earth" is not a good idea nor desirable. But I
should probably have raised my concerns about this on debian-devel.

> According to LDAP, the maintainer has been active in the BTS as
> recently as two days ago.  An NMU for a serious bug is obviously ok
> (including in experimental), but you can consider this an objection
> to any such "soon" orphaning.

Then some MTA must be terribly broken. Let's hope that Bart's mail
will arrive at destination using the alternative email address.

The proper fix of the serious bug is requiring to split packages, I
feel that this is a bit too much for a NMU, isn't it?

If I had the time and the energy I would start again the discussion
about lowering strict ownership of the packages and making team
maintenance mandatory because I feel, especially in that kind of case,
that this is actually hurting the quality of some packages.

Laurent "that loves to justify himself" Bigonville
[signature.asc (application/pgp-signature, attachment)]

Information forwarded to debian-bugs-dist@lists.debian.org, Philipp Matthias Hahn <pmhahn@debian.org>:
Bug#692492; Package auditd. (Sun, 11 Nov 2012 18:24:11 GMT) Full text and rfc822 format available.

Acknowledgement sent to Philipp Matthias Hahn <pmhahn@pmhahn.de>:
Extra info received and forwarded to list. Copy sent to Philipp Matthias Hahn <pmhahn@debian.org>. (Sun, 11 Nov 2012 18:24:11 GMT) Full text and rfc822 format available.

Message #27 received at 692492@bugs.debian.org (full text, mbox):

From: Philipp Matthias Hahn <pmhahn@pmhahn.de>
To: Bart Martens <bartm@debian.org>, 692492@bugs.debian.org
Cc: Laurent Bigonville <bigon@debian.org>
Subject: Re: Bug#692492: ITO: Orphaning audit package
Date: Sun, 11 Nov 2012 19:03:39 +0100
Hello,

On Tue, Nov 06, 2012 at 09:48:40PM +0000, Bart Martens wrote:
> On Tue, Nov 06, 2012 at 08:01:54PM +0100, Laurent Bigonville wrote:
> > I'm planning to orphan (and upload my changes for experimental) "soon"
> > if nobody objects.
> 
> Hi Laurent, in this case I prefer to hear the maintainer.

Sorry for the late answer, but I'm still ill.

> Hi Philipp, is it OK that Laurent Bigonville updates the package in
> experimental ? Do you agree that he takes over maintenance, or do you prefer
> co-maintenance, or maybe an NMU (like Andrew Pollock did) ?

I'm fine with other taking over the audit package.

BYtE
Philipp
-- 
Philipp Matthias Hahn <pmhahn@debian.org>
 GPG/PGP: 9A540E39 @ keyrings.debian.org



Changed Bug title to 'O: audit -- tools, library, plugin and bindings for security auditing' from 'ITO: Orphaning audit package' Request was from Bart Martens <bartm@debian.org> to control@bugs.debian.org. (Sun, 11 Nov 2012 19:00:03 GMT) Full text and rfc822 format available.

Bug reassigned from package 'auditd' to 'wnpp'. Request was from Laurent Bigonville <bigon@debian.org> to control@bugs.debian.org. (Sun, 11 Nov 2012 22:30:03 GMT) Full text and rfc822 format available.

No longer marked as found in versions audit/1:1.7.18-1.1. Request was from Laurent Bigonville <bigon@debian.org> to control@bugs.debian.org. (Sun, 11 Nov 2012 22:30:04 GMT) Full text and rfc822 format available.

Owner recorded as Laurent Bigonville <bigon@debian.org>. Request was from Laurent Bigonville <bigon@debian.org> to control@bugs.debian.org. (Tue, 28 Jan 2014 16:39:08 GMT) Full text and rfc822 format available.

Changed Bug title to 'ITA: audit -- tools, library, plugin and bindings for security auditing' from 'O: audit -- tools, library, plugin and bindings for security auditing' Request was from Laurent Bigonville <bigon@debian.org> to control@bugs.debian.org. (Tue, 28 Jan 2014 16:39:09 GMT) Full text and rfc822 format available.

Reply sent to Laurent Bigonville <bigon@debian.org>:
You have taken responsibility. (Sat, 01 Mar 2014 18:06:05 GMT) Full text and rfc822 format available.

Notification sent to Laurent Bigonville <bigon@debian.org>:
Bug acknowledged by developer. (Sat, 01 Mar 2014 18:06:05 GMT) Full text and rfc822 format available.

Message #42 received at 692492-close@bugs.debian.org (full text, mbox):

From: Laurent Bigonville <bigon@debian.org>
To: 692492-close@bugs.debian.org
Subject: Bug#692492: fixed in audit 1:2.3.4-1
Date: Sat, 01 Mar 2014 18:03:41 +0000
Source: audit
Source-Version: 1:2.3.4-1

We believe that the bug you reported is fixed in the latest version of
audit, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 692492@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Laurent Bigonville <bigon@debian.org> (supplier of updated audit package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sat, 01 Mar 2014 18:52:55 +0100
Source: audit
Binary: auditd libauparse0 libauparse-dev libaudit1 libaudit-common libaudit-dev python-audit audispd-plugins
Architecture: source amd64 all
Version: 1:2.3.4-1
Distribution: unstable
Urgency: medium
Maintainer: Laurent Bigonville <bigon@debian.org>
Changed-By: Laurent Bigonville <bigon@debian.org>
Description: 
 audispd-plugins - Plugins for the audit event dispatcher
 auditd     - User space tools for security auditing
 libaudit-common - Dynamic library for security auditing - common files
 libaudit-dev - Header files and static library for security auditing
 libaudit1  - Dynamic library for security auditing
 libauparse-dev - Header files and static library for the libauparse0 library
 libauparse0 - Dynamic library for parsing security auditing
 python-audit - Python bindings for security auditing
Closes: 692492
Changes: 
 audit (1:2.3.4-1) unstable; urgency=medium
 .
   * New upstream release
     - Adjust debian/libauparse0.symbols: Add a new symbol
   * Adopt the audit package (Closes: #692492)
Checksums-Sha1: 
 440198d36d70462deba7763b4b1a6e47d832e2f1 1972 audit_2.3.4-1.dsc
 636373769904a2b2b945c21580d8f9187d97b379 921908 audit_2.3.4.orig.tar.gz
 d0f4c98cbe38d01832b706cfe0c895e60c78f9fa 15588 audit_2.3.4-1.debian.tar.xz
 f8f4ecc54057fa9244c9ff584270971eb6ef8f09 196640 auditd_2.3.4-1_amd64.deb
 117b6ff7ebf091871fee6f9e6817bc4f9b81e866 43994 libauparse0_2.3.4-1_amd64.deb
 b6b70ad5591e8d7277a96a9a88f86a1f29c004fb 70724 libauparse-dev_2.3.4-1_amd64.deb
 cb76564756970266fb6858a708bf6aca355a0e34 42504 libaudit1_2.3.4-1_amd64.deb
 3feb068cf3e7dae3f6496e3f436c90890f84e7a6 12412 libaudit-common_2.3.4-1_all.deb
 fb944b559755cdd8cb4ab089c68dfa6c11d2fed1 69790 libaudit-dev_2.3.4-1_amd64.deb
 eab9c5bdef91533de194f6f933f2edcc7d7506e6 57992 python-audit_2.3.4-1_amd64.deb
 fc324e2ef6ab819c82fa894bb5d6fd9281c2f9f3 61700 audispd-plugins_2.3.4-1_amd64.deb
Checksums-Sha256: 
 509431cc3940a354f99533595e8531feadd9aaa4958c0b82b98a77ba96d9d180 1972 audit_2.3.4-1.dsc
 6a529cdaca6b2dfafb92c2770f2e5b3ce16d44aa2dd646071fbec418bf4082a1 921908 audit_2.3.4.orig.tar.gz
 6099f432cc509de4c50a7c25eab808c6f928c81b11ca27f6eb5d4ed08d10d3d8 15588 audit_2.3.4-1.debian.tar.xz
 75096f8ea64cf148b0c4a00e9566ef2a6569c46d9c6106a1743d8f9c65cbf735 196640 auditd_2.3.4-1_amd64.deb
 f02a9a1291a2b100207efdb26f9aa53f5527d7de0ce41983276aef75ca47892c 43994 libauparse0_2.3.4-1_amd64.deb
 0fe1679b72816515eac16c2e28a2cdcf2e582317954981363c5e3f3b90247613 70724 libauparse-dev_2.3.4-1_amd64.deb
 9cbbc19efd504f815fd2b2ba9f02ab6fd1a39f9ded751cefa42cda74949942c9 42504 libaudit1_2.3.4-1_amd64.deb
 5b9126e8a208cee91a9ccd9cfdb6040bd8af98cbbbb4b5bbc61e8a5f96702893 12412 libaudit-common_2.3.4-1_all.deb
 a18554960aba5b185801b73cc99903f4cfd084e4515a9e671546dcadaf0b8a21 69790 libaudit-dev_2.3.4-1_amd64.deb
 f14f3003c3b9056f9902a4702282270a533b19bfe7ba931dec0c0b935cb30079 57992 python-audit_2.3.4-1_amd64.deb
 4db6705b8356290b2a7a5894724cabd27f1b656b74adf7713487b60829e70db5 61700 audispd-plugins_2.3.4-1_amd64.deb
Files: 
 0e9c4617f19439be744f9a4d981ebf86 1972 libs extra audit_2.3.4-1.dsc
 ababfa3a192d6acba8806c9dcb16a6c8 921908 libs extra audit_2.3.4.orig.tar.gz
 a4ab450f3a683658bdc76b191569d6f6 15588 libs extra audit_2.3.4-1.debian.tar.xz
 117eb25578d92b7e8815618a3278861d 196640 admin extra auditd_2.3.4-1_amd64.deb
 cfe90ba9315b14ea11eec9ca7aa3976a 43994 libs optional libauparse0_2.3.4-1_amd64.deb
 c499e9d8e5126765576e0d1ceece914f 70724 libdevel extra libauparse-dev_2.3.4-1_amd64.deb
 02515de65850eebdf0de8c2802e288ec 42504 libs optional libaudit1_2.3.4-1_amd64.deb
 a429a314b39a074bd99b8661cfa953ee 12412 libs optional libaudit-common_2.3.4-1_all.deb
 d6b00620a191efd0d10d47ea228c81a0 69790 libdevel extra libaudit-dev_2.3.4-1_amd64.deb
 c6a74ddbaefa17ad5995cb5ac2dcc9af 57992 python extra python-audit_2.3.4-1_amd64.deb
 2eed9870cae5a856ed89ad49fe97114c 61700 admin extra audispd-plugins_2.3.4-1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBCAAGBQJTEh+IAAoJEB/FiR66sEPVz04IAI9W/kferv+SMaY33dEw2/J+
5e67Zb1p6qLY7kk7Xp4KYd7HUv55LbHLa83HwkpU/mmUDTOVy7mvzaRYV60bY6nC
V352vVwp1/2QseFsFtY7RAEONbfxG0dVFQ38K8YhQ3J5bvFSQGuJj9AC9gIrDiYN
cVfC/NViJJJJOi+ZLDZMj+yNdJovzrrBIyds/kaGCXEamtwsTaSA41YL5iWReUtc
y+c6f+d2uEqmdaGM2iHVXUqiZDMIZuMHtrg5QJXVe2TlolMQW94nZh78Acdtsr3l
9TgMoUtanub4zQfuXqjkRfA6tUE85pB927khmmWPd406xMp6Mf+MzxIB+oJcqMc=
=ZIoG
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 30 Mar 2014 07:36:27 GMT) Full text and rfc822 format available.

Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Sat Apr 19 18:17:46 2014; Machine Name: buxtehude.debian.org

Debian Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.