Re: nginx-snippets_1.3~bpo13+1_amd64.changes REJECTED
Thomas Ward <[email protected]> Tue, 23 Jun 2026 22:11:23 -0400
| Newsgroups | gmane.linux.debian.backports.general |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--------------yJi3yfzw2SVNdiRTv9egEB1A
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Micha,
The attempt to get this into trixie-pu was rejected by the corresponding
teams that manage updates as "it does not meet the criterion for a pu
update".
Accordingly, the Security Team indicated it does not meet a Security
update threshold, leaving the only 'solution' to this being to provide
an update in Backports.
If the wider ftp team chooses to reject this upload consistently, they
are thus setting a precedent that "insecure configuration files shipped
by default".
The relevant trixie-pu bug where this is discussed is at
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138593 where this was
originally rejected by Adrian Bunk:
> Backports is the right place for giving users the option to pick a
specific package from the next stable release if they need some specific
newer functionality.
If this is rejected by Backports or ftp master team, and Security is
unwilling to touch this, then I require that someone *far up in the
chain* for managing packages - way beyond me as a DM, so either Security
or a higher level ftp team member - reply to the original bug of
#1138590 detailing the following:
(1) why this is not suitable for trixie-pu (already established in
1138593),
(2) why *backports* is not the proper place for this as the larger
consensus by the team who approves things for trixie-updates or such
with proposed update bugs was that Backports was in fact the proper
place for this to land, and
(3) how this fails to qualify as a backport as 'new functionality' of
the newer configurations is being applied.
Should this still be rejected, I may have no option but to open a larger
discussion on a mailing list because at this point Security told me to
go the trixie-pu route, and the people in charge of that route *and* the
Security team after the trixie-pu was rejected said to go the Backports
route.
I don't want to be the one to wontfix that 1138590 bug when the original
bug (filed via a security@ email and NOT as a bug in BTS) asked for this
to be updated. (And for this reason, security@ is cc'd on this email as
well).
Thomas
On 2026-06-23 15:01, Micha Lenk wrote:
> I've read through the discussion in bug #1138590 but I fail to understand how
> the backport is supposed to help in this case. Making it available in
> trixie-backports will not automatically install it, (due to NotAutomatic being
> set for all backport suites) not even on machines that already have the
> trixie-backports suite configured in APT. And people interested enough to find
> out about the situation can install nginx-snippets from forky directly (it's an
> arch:all package containing configuration files only).
>
>
>
> ===
>
> Please feel free to respond to this email if you don't understand why
> your files were rejected, or if you upload new files which address our
> concerns.
>
--------------yJi3yfzw2SVNdiRTv9egEB1A
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<font face="Calibri">Micha,<br>
<br>
The attempt to get this into trixie-pu was rejected by the
corresponding teams that manage updates as "it does not meet the
criterion for a pu update".<br>
<br>
Accordingly, the Security Team indicated it does not meet a
Security update threshold, leaving the only 'solution' to this
being to provide an update in Backports.<br>
<br>
If the wider ftp team chooses to reject this upload consistently,
they are thus setting a precedent that "insecure configuration
files shipped by default".<br>
<br>
The relevant trixie-pu bug where this is discussed is at
<a class="moz-txt-link-freetext" href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138593">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138593</a> where
this was originally rejected by Adrian Bunk:<br>
<br>
> </font>Backports is the right place for giving users the
option to pick a specific package from the next stable release if
they need some specific newer functionality.<br>
<br>
If this is rejected by Backports or ftp master team, and Security is
unwilling to touch this, then I require that someone *far up in the
chain* for managing packages - way beyond me as a DM, so either
Security or a higher level ftp team member - reply to the original
bug of #1138590 detailing the following:<br>
<br>
(1) why this is not suitable for trixie-pu (already established in
1138593), <br>
(2) why *backports* is not the proper place for this as the larger
consensus by the team who approves things for trixie-updates or such
with proposed update bugs was that Backports was in fact the proper
place for this to land, and<br>
(3) how this fails to qualify as a backport as 'new functionality'
of the newer configurations is being applied.<br>
<br>
Should this still be rejected, I may have no option but to open a
larger discussion on a mailing list because at this point Security
told me to go the trixie-pu route, and the people in charge of that
route *and* the Security team after the trixie-pu was rejected said
to go the Backports route.<br>
<br>
I don't want to be the one to wontfix that 1138590 bug when the
original bug (filed via a security@ email and NOT as a bug in BTS)
asked for this to be updated. (And for this reason, security@ is
cc'd on this email as well).<br>
<br>
<br>
Thomas<br>
<br>
<br>
<div class="moz-cite-prefix">On 2026-06-23 15:01, Micha Lenk wrote:<br>
</div>
<blockquote type="cite"
cite="mid:[email protected]">
<pre wrap="" class="moz-quote-pre">
I've read through the discussion in bug #1138590 but I fail to understand how
the backport is supposed to help in this case. Making it available in
trixie-backports will not automatically install it, (due to NotAutomatic being
set for all backport suites) not even on machines that already have the
trixie-backports suite configured in APT. And people interested enough to find
out about the situation can install nginx-snippets from forky directly (it's an
arch:all package containing configuration files only).
===
Please feel free to respond to this email if you don't understand why
your files were rejected, or if you upload new files which address our
concerns.
</pre>
</blockquote>
<br>
</body>
</html>
--------------yJi3yfzw2SVNdiRTv9egEB1A--