Bug#1124117: marked as done (Seeking advice on fixing openconnect despite multi-developer dispute)
"Debian Bug Tracking System" <[email protected]> Mon, 05 Jan 2026 14:59:02 +0000
| Newsgroups | gmane.linux.debian.devel.ctte |
|---|---|
| Message-ID | <handler.1124117.D1124117.17676250743009662.ackdone@bugs.debian.org> |
This is a multi-part message in MIME format... ------------=_1767625142-3011076-0 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Your message dated Mon, 5 Jan 2026 14:57:46 +0000 with message-id <[email protected]> and subject line Openconnect uploads done has caused the Debian Bug report #1124117, regarding Seeking advice on fixing openconnect despite multi-developer disp= ute to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) --=20 1124117: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1124117 Debian Bug Tracking System Contact [email protected] with problems ------------=_1767625142-3011076-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by bugs.debian.org; 28 Dec 2025 10:02:36 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-21.9 required=4.0 tests=BAYES_00, BODY_INCLUDES_PACKAGE,FOURLA,FROMDEVELOPER,FVGT_m_MULTI_ODD, HAS_PACKAGE,HEADER_FROM_DIFFERENT_DOMAINS,PGPSIGNATURE,SPF_HELO_NONE, SPF_PASS autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 102; hammy, 149; neutral, 383; spammy, 1. spammytokens:0.995-1--disagreements hammytokens:0.000-+--H*ct:pgp-sha256, 0.000-+--trixie, 0.000-+--H*ct:application, 0.000-+--H*ct:protocol, 0.000-+--H*ct:micalg Return-path: <[email protected]> Received: from mail.servers.dxld.at ([2001:678:4d8::1a57]:37622) by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1vZnbe-00Ecep-2C for [email protected]; Sun, 28 Dec 2025 10:02:36 +0000 Received: mail.servers.dxld.at; Sun, 28 Dec 2025 11:02:24 +0100 Date: Sun, 28 Dec 2025 11:02:15 +0100 From: Daniel =?utf-8?Q?Gr=C3=B6ber?= <[email protected]> To: [email protected] Subject: Seeking advice on fixing openconnect despite multi-developer dispute Message-ID: <qhkerhhkunqhkephcgakxs73777h72cu672ljynqe45yx3u3t3@lsvv5i4mtcfb> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="fx4yetv4zvhoc2hy" Content-Disposition: inline Delivered-To: [email protected] --fx4yetv4zvhoc2hy Content-Type: text/plain; protected-headers=v1; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Subject: Seeking advice on fixing openconnect despite multi-developer dispute MIME-Version: 1.0 Package: tech-ctte X-Debbugs-CC: Salvatore Bonaccorso <[email protected]>, [email protected] Control: block 1099497 by -1 Control: block 1119239 by -1 Control: block 1119300 by -1 Hi Debian Technical Comittee, Community Team (CT) has been advising two DDs regarding disagreements with = Luca Boccassi over the openconnect package over the last two months. One of the developers involved, Salvatore, would like to get tech-ctte's ad= vise on how to proceed; Luca has not been collaborating and so Salvatore as= ked CT to act as mediator to keep the discussion focused and constructive. For context the dispute on openconnect extends over three bugs: - Bug#1119239 - Lee's bug - Bug#1119300 - Lee's trixie p-u - Bug#1099497 - Salvatore's bug (and NMUdiff) =46rom CT's perspective the dispute history can be summarized like this: - Lee files bug+p-u and makes 0-day NMU in good faith assuming LowNMU decl= aration applies (Maintainer: Mike Miller's)=20 - Luca responds with inappropriate angry NACK citing himself actually be= ing maintainer (see extensive upload history) - CT issues a conduct warning and asks Luca to cooperate on a fix - Release Team puts Lee's p-u on hold - No response from Luca. - Lee's NMU fixed his bug in unstable as Luca has not reverted it (yet?)= , but stable is still affected. - Salvatore triages a distinct Bug#1099497 and pushes a cherry-picked fix = (MR !8) - Luca rejects MR as "not safe to do" citing concerns over "another Open= SSL random() debacle" - Salvatore later cites (msg#88) user impact and urgency, care in consid= ering upstream context and (unsuccessful) attempt at reaching upstream for = clarification - Salvatore sends intent to NMU (+diff) per CT advise to move things forwa= rd - Luca requests cancellation privately with a short message but does not= address any of the concerns raised previously - Salvatore has cancelled the NMU and informed Luca So it would appear things are stuck and we need a way forward. What does te= ch-ctte make of the situation? Please note Salvatore has expressed a desire not to miss the window for the= Jan 10th Trixie stable update (13.3). Please let us know if this is not en= ough time for tech-ctte to gague the situation. Since Luca cites avoiding another instance of the well-known Debian OpenSSL= bug as a reason for rejecting Salvatore's changes I would also like to bri= ng Russ Cox's "Lessons from the Debian/OpenSSL Fiasco" post to everyone's a= ttention before we start the discussion: https://research.swtch.com/openssl=20 I found the "Cascade of Failures" section especially enlightening: https://research.swtch.com/openssl#:~#text=3DCascade%20of%20Failures > Like any true fiasco, a cascade of bad decisions and mistakes all lined u= p to make this happen: > [...] > Reading various blogs you find various involved party's intelligence bein= g insulted, but this is really a failure of process, not of intelligence. T= he maintainer knew he wasn't an expert on the code in question, asked the e= xperts for help, and was given bad information.=20 Below you will find Salvatore's request for help/advice (only sent to CT so= far) on Luca's NMU cancellation request as further input for the discussio= n. --Daniel for the Debian Community Team -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Hi, On Sat, Dec 27, 2025 at 11:59:47AM +0000, Luca Boccassi wrote: > On Wed, 24 Dec 2025 06:57:40 +0100 Salvatore Bonaccorso <[email protected]= g> wrote: > > I've prepared an NMU for openconnect (versioned as 9.12-3.2) and > > uploaded it to DELAYED/5. Please feel free to tell me if I > > should cancel it. >=20 > Hi, please cancel this. Thank you, and merry christmas Okay I will cancel the upload. Though I have some questions or concerns, and I seek input on how we should handle this properly within Debian. I'm seeking advice from the technical committee, as they according to 6.1.5 can offer advice, and this is my aim here getting some additional input on the techical front/weight for the problems. I try to summarize the problem to the best of my knowledge. We have reports of users in Debian affected by the Debian bug #1099497. After updates of Cisco ASA gateways users reported not to be able to connect anymore to the coorproate an universities VPNs with openconnect. The issue does not affect all installations using Cisco ASA gateways but a set of reports exists. The issue is known upstream as well as https://gitlab.com/openconnect/openconnect/-/issues/659 An initial merge request for unstable was proposed via https://salsa.debian.org/debian/openconnect/-/merge_requests/8 One of the maintainers of openconnect (the currently main active one) Luca Boccassi declined back one month ago the update wtih the reply in https://salsa.debian.org/debian/openconnect/-/merge_requests/8#note_693990 =2E I'm not completely agreeing with this assessment, because it does not balance in the problems reported by users and the both upstream reports acknowledging that the applied fix upstream fixes the problem and as well those for Debian users. I do agree that one needs to carefully handle openconnect as it is used in security-critical context. Upstream has not cut yet another release and the questions to this in the upstream issue remained unanswered. This might indicate to either upstream does not consider the issue improtant enough, they have concerns yet about the stability, or something else. Unfortunately even a private reachout to clarify this to the main author of openconnect remained unanswered so far. The suggestion that affected users can compile the upstream branch =66rom source or use the upstream provided packages might is personally for me not a friendly option if we include openconnect in a Debian stable release. On the fix side, the patch is targetting specifically the upstream issue https://gitlab.com/openconnect/openconnect/-/issues/659 . The additional commit picked for the MR is to make the commit apply cleanly (and if desired can be skipped, as the hunk which otherwise would not apply cleanly is not compiled in Debian, the openssl.c code). Can someone help weigth in here and advise how we can balance bringing the fixes needed to users vs. handling the security-critical context use of openconnect and avoiding introducing potential Debian specific issues? The goal would be to see both #1099497 and #1119239 (cf. #1119300) be fixed in Debian trixie. Regards, Salvatore -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmlP+h1fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Sg1Q/+NiyKdJE/05P2QVZyPuQPbFJs8J66puIUGQ6KlLO254SR2f702xsoRqVM ieDD6X/RQu5hazBoL7e97oGkLf/63CV2DUj32XqYabrPimXHBwNMU4NZKWRRUVty 7gHVoW5DIMY6zRsS1Gg9e8/3wO0rrxczMnK8dR/hMT8d9c4MFKw2BSLU1fbE6DGQ ig8MfW8SZMnhcYr//ZiDK6jiXYKaLZLMVkz3luOnFF7mcc6sgB+ye0RAfR45QErz wUq7HW2FZ49xCIrt95995a72xAUAJQ1wfVkOOdF6JiLaJjKlhC0RyOESuZvJI49u HZKLBQjr/xFB3g1AOYhh5iOaw0Q+oUvFeeiflWHuyM7boliKNzpkVDsvXL3UCMOx ljl1iez0ZrK5DQKHdu5e8c5YbBm6LNS/0H+cUU2wnd6kKffufthomKr4SSlpe3Xb a7u7jMDg5IPyumJy+a2vDF4ItiO6Ux9lkCpEVWpEyvEjFh1/DgHQUjBAE+1Swanf 7tXD3HKWdgRqkiFALCwnNvlYiBUGI135odt67NBUv134fE2dpQTwXxpcDrWSC+OT LJAiCsoccjC38zDNV4yq8I/qL3ViivDV6XHQLfbtnEGXrJ9Es+AIC6nyJqc7FUZS mQZf7ZXXI5vrPpAgGwifDCexLggVK8nELycuHMNDnbhhBDf+xXg=3D =3Dn8ec -----END PGP SIGNATURE----- --fx4yetv4zvhoc2hy Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEV6G/FbT2+ZuJ7bKf05SBrh55rPcFAmlRACIACgkQ05SBrh55 rPeAJA//VoguB+r0TqrJb9rLtRev8eiTyQ1+R1OWbV1O3pnCiVU7CGDJYrtq/kjN v8JfZt8bOq0aXgu8jXl6ARLXyuH8uneK/uQwCvvWDXy2QoKkSPGsNkSS2z1XQ2la AVTTdWbCpwzUigFVEDRRu3INX3ijaBiWryS9sfOzjZq5ReatctUsjx1e4MXa3DUZ /DHs03+h3KYuiyjBWqoVM/fmKOq1/CNhFbRJP3fb6bpKAk85TcSXOMrf/PlpSZ3H jJJHbGCxIJty/sdSRnMOLEggERkdAeRd9EcfN7OV9FBB0H/3qtt3Xvk+4Re7Jgje h88frvjoP7wQjkWf4FQY2oF56Lfme5M2NLiXqiZHO1cd7S9hhBbOGV2lxMb21n2t WZ/xwMhnz9u+0QBbJLoHCG/CD8WtRzIdP4neO0tLj8ifJGRq1Dv/v5K9WGU0o6wo 4zvDqQ9tKMUf1YsiO+5wcWwxz9HHYTvTV7hXK636iU1fx6AEvq3+Bbcy+Lx1NvdO kcWiKtUGQ6ekl589EyYsrd6jpCn2lJpyvVXM4IzEv+aoiXccHhPtYU9tX9K/Pt7r GVibmQYWbe/5Mn5mjc+SoE3WM+tnLBRpvEBRoeFQ/zZqZ/7Snk5JxHSr62kuXprr IP1XUPlAHyT+Waz1/WAjfeyyQB2lYj19Rh+pPaOGmHGKLwKeDYI= =pDxR -----END PGP SIGNATURE----- --fx4yetv4zvhoc2hy-- ------------=_1767625142-3011076-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at 1124117-done) by bugs.debian.org; 5 Jan 2026 14:57:54 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-105.2 required=4.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FROMDEVELOPER, SPF_HELO_NONE,SPF_NONE,UNPARSEABLE_RELAY,USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 15; hammy, 85; neutral, 23; spammy, 0. spammytokens: hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin, 0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311, 0.000-+--H*RT:311, 0.000-+--H*RT:108 Return-path: <[email protected]> Received: from stravinsky.debian.org ([2001:41b8:202:deb::311:108]:42740) by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1vcm1q-00Ccwn-1B for [email protected]; Mon, 05 Jan 2026 14:57:54 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.stravinsky; h=X-Debian-User:Content-Transfer-Encoding:Content-Type :Subject:From:To:MIME-Version:Date:Message-ID:Reply-To:Cc:Content-ID: Content-Description:In-Reply-To:References; bh=yNSilUG153kNafdntydz1ErIHNKXHO1MxOI09/bajpw=; b=uIdU0QoWG9r1YwDCPEpWMySNBj mElAjTuOpMwqKBrDzmRrZg0SrEQrU49SMn0OZ9a3mkAUlMwZIgq/ybRdgz3C8lFDO7oHSfY3S/XZ7 QZAs+DpKSyjcfJ1zrW7SXqJ65EaJNvjnaAnbhp+ZHilaRhV7z/SSI6nkzZQ7dMb8t8w3Ps5eHrOy8 3kXurb/pHagc1MGIoQ2Re/oULkmJR8QvWK/RVyHPznF8OluKvbbFK8dMbocagHNkhpKgIrJgDFxxE FwMF0w8c+OTl3ZiFY02ikzVXZtD7X+Sposvg0K7w0BMAHzT8lLC3wgIurMhg2tNgAV4LiWE34lGbi SmiIZoEw==; Received: from authenticated user by stravinsky.debian.org with esmtpsa (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_128_GCM:128) (Exim 4.94.2) (envelope-from <[email protected]>) id 1vcm1o-00Gxry-KV; Mon, 05 Jan 2026 14:57:52 +0000 Message-ID: <[email protected]> Date: Mon, 5 Jan 2026 14:57:46 +0000 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Content-Language: en-GB To: [email protected], =?UTF-8?Q?Daniel_Gr=C3=B6ber?= <[email protected]> From: Matthew Vernon <[email protected]> Subject: Openconnect uploads done Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Debian-User: matthew Hi, I see that Openconnect now has these changes and the updates to trixie have been accepted. So I'm closing the TC bug; if you need anything else from the TC about this issue, do shout, though. Thanks, Matthew ------------=_1767625142-3011076-0--