Bug#1124117: marked as done (Seeking advice on fixing openconnect despite multi-developer dispute)

"Debian Bug Tracking System" <[email protected]> Mon, 05 Jan 2026 14:59:02 +0000
Newsgroups gmane.linux.debian.devel.ctte
Message-ID <handler.1124117.D1124117.17676250743009662.ackdone@bugs.debian.org>
This is a multi-part message in MIME format...

------------=_1767625142-3011076-0
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="utf-8"

Your message dated Mon, 5 Jan 2026 14:57:46 +0000
with message-id <[email protected]>
and subject line Openconnect uploads done
has caused the Debian Bug report #1124117,
regarding Seeking advice on fixing openconnect despite multi-developer disp=
ute
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


--=20
1124117: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1124117
Debian Bug Tracking System
Contact [email protected] with problems

------------=_1767625142-3011076-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at submit) by bugs.debian.org; 28 Dec 2025 10:02:36 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
	(2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-21.9 required=4.0 tests=BAYES_00,
	BODY_INCLUDES_PACKAGE,FOURLA,FROMDEVELOPER,FVGT_m_MULTI_ODD,
	HAS_PACKAGE,HEADER_FROM_DIFFERENT_DOMAINS,PGPSIGNATURE,SPF_HELO_NONE,
	SPF_PASS autolearn=ham autolearn_force=no
	version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 102; hammy, 149; neutral, 383; spammy,
	1. spammytokens:0.995-1--disagreements
	hammytokens:0.000-+--H*ct:pgp-sha256, 0.000-+--trixie,
	0.000-+--H*ct:application, 0.000-+--H*ct:protocol, 0.000-+--H*ct:micalg
Return-path: <[email protected]>
Received: from mail.servers.dxld.at ([2001:678:4d8::1a57]:37622)
	by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1vZnbe-00Ecep-2C
	for [email protected];
	Sun, 28 Dec 2025 10:02:36 +0000
Received: mail.servers.dxld.at;
	Sun, 28 Dec 2025 11:02:24 +0100
Date: Sun, 28 Dec 2025 11:02:15 +0100
From: Daniel =?utf-8?Q?Gr=C3=B6ber?= <[email protected]>
To: [email protected]
Subject: Seeking advice on fixing openconnect despite multi-developer dispute
Message-ID: <qhkerhhkunqhkephcgakxs73777h72cu672ljynqe45yx3u3t3@lsvv5i4mtcfb>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha256;
	protocol="application/pgp-signature"; boundary="fx4yetv4zvhoc2hy"
Content-Disposition: inline
Delivered-To: [email protected]


--fx4yetv4zvhoc2hy
Content-Type: text/plain; protected-headers=v1; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Subject: Seeking advice on fixing openconnect despite multi-developer dispute
MIME-Version: 1.0

Package: tech-ctte
X-Debbugs-CC: Salvatore Bonaccorso <[email protected]>, [email protected]
Control: block 1099497 by -1
Control: block 1119239 by -1
Control: block 1119300 by -1

Hi Debian Technical Comittee,

Community Team (CT) has been advising two DDs regarding disagreements with =
Luca Boccassi over the openconnect package over the last two months.

One of the developers involved, Salvatore, would like to get tech-ctte's ad=
vise on how to proceed; Luca has not been collaborating and so Salvatore as=
ked CT to act as mediator to keep the discussion focused and constructive.

For context the dispute on openconnect extends over three bugs:
 - Bug#1119239 - Lee's bug
 - Bug#1119300 - Lee's trixie p-u
 - Bug#1099497 - Salvatore's bug (and NMUdiff)

=46rom CT's perspective the dispute history can be summarized like this:
 - Lee files bug+p-u and makes 0-day NMU in good faith assuming LowNMU decl=
aration applies (Maintainer: Mike Miller's)=20
   - Luca responds with inappropriate angry NACK citing himself actually be=
ing maintainer (see extensive upload history)
   - CT issues a conduct warning and asks Luca to cooperate on a fix
   - Release Team puts Lee's p-u on hold
   - No response from Luca.
   - Lee's NMU fixed his bug in unstable as Luca has not reverted it (yet?)=
, but stable is still affected.
 - Salvatore triages a distinct Bug#1099497 and pushes a cherry-picked fix =
(MR !8)
   - Luca rejects MR as "not safe to do" citing concerns over "another Open=
SSL random() debacle"
   - Salvatore later cites (msg#88) user impact and urgency, care in consid=
ering upstream context and (unsuccessful) attempt at reaching upstream for =
clarification
 - Salvatore sends intent to NMU (+diff) per CT advise to move things forwa=
rd
   - Luca requests cancellation privately with a short message but does not=
 address any of the concerns raised previously
   - Salvatore has cancelled the NMU and informed Luca

So it would appear things are stuck and we need a way forward. What does te=
ch-ctte make of the situation?

Please note Salvatore has expressed a desire not to miss the window for the=
 Jan 10th Trixie stable update (13.3). Please let us know if this is not en=
ough time for tech-ctte to gague the situation.

Since Luca cites avoiding another instance of the well-known Debian OpenSSL=
 bug as a reason for rejecting Salvatore's changes I would also like to bri=
ng Russ Cox's "Lessons from the Debian/OpenSSL Fiasco" post to everyone's a=
ttention before we start the discussion:
  https://research.swtch.com/openssl=20

I found the "Cascade of Failures" section especially enlightening:
  https://research.swtch.com/openssl#:~#text=3DCascade%20of%20Failures

> Like any true fiasco, a cascade of bad decisions and mistakes all lined u=
p to make this happen:
>   [...]
> Reading various blogs you find various involved party's intelligence bein=
g insulted, but this is really a failure of process, not of intelligence. T=
he maintainer knew he wasn't an expert on the code in question, asked the e=
xperts for help, and was given bad information.=20

Below you will find Salvatore's request for help/advice (only sent to CT so=
 far) on Luca's NMU cancellation request as further input for the discussio=
n.

--Daniel
for the Debian Community Team

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi,

On Sat, Dec 27, 2025 at 11:59:47AM +0000, Luca Boccassi wrote:
> On Wed, 24 Dec 2025 06:57:40 +0100 Salvatore Bonaccorso <[email protected]=
g> wrote:
> > I've prepared an NMU for openconnect (versioned as 9.12-3.2) and
> > uploaded it to DELAYED/5. Please feel free to tell me if I
> > should cancel it.
>=20
> Hi, please cancel this. Thank you, and merry christmas

Okay I will cancel the upload. Though I have some questions or
concerns, and I seek input on how we should handle this properly within
Debian. I'm seeking advice from the technical committee, as they
according to 6.1.5 can offer advice, and this is my aim here getting
some additional input on the techical front/weight for the problems.

I try to summarize the problem to the best of my knowledge.

We have reports of users in Debian affected by the Debian bug
#1099497. After updates of Cisco ASA gateways users reported not to be
able to connect anymore to the coorproate an universities VPNs with
openconnect. The issue does not affect all installations using Cisco
ASA gateways but a set of reports exists.

The issue is known upstream as well as
https://gitlab.com/openconnect/openconnect/-/issues/659

An initial merge request for unstable was proposed via
https://salsa.debian.org/debian/openconnect/-/merge_requests/8

One of the maintainers of openconnect (the currently main active one)
Luca Boccassi declined back one month ago the update wtih the reply in
https://salsa.debian.org/debian/openconnect/-/merge_requests/8#note_693990
=2E

I'm not completely agreeing with this assessment, because it does not
balance in the problems reported by users and the both upstream
reports acknowledging that the applied fix upstream fixes the problem
and as well those for Debian users. I do agree that one needs to
carefully handle openconnect as it is used in security-critical
context.

Upstream has not cut yet another release and the questions to this in
the upstream issue remained unanswered. This might indicate to either
upstream does not consider the issue improtant enough, they have
concerns yet about the stability, or something else. Unfortunately
even a private reachout to clarify this to the main author of
openconnect remained unanswered so far.

The suggestion that affected users can compile the upstream branch
=66rom source or use the upstream provided packages might is personally
for me not a friendly option if we include openconnect in a Debian
stable release.

On the fix side, the patch is targetting specifically the upstream
issue https://gitlab.com/openconnect/openconnect/-/issues/659 . The
additional commit picked for the MR is to make the commit apply
cleanly (and if desired can be skipped, as the hunk which otherwise
would not apply cleanly is not compiled in Debian, the openssl.c
code).

Can someone help weigth in here and advise how we can balance bringing
the fixes needed to users vs. handling the security-critical context
use of openconnect and avoiding introducing potential Debian specific
issues?  The goal would be to see both #1099497 and #1119239 (cf.
#1119300) be fixed in Debian trixie.

Regards,
Salvatore
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmlP+h1fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0Sg1Q/+NiyKdJE/05P2QVZyPuQPbFJs8J66puIUGQ6KlLO254SR2f702xsoRqVM
ieDD6X/RQu5hazBoL7e97oGkLf/63CV2DUj32XqYabrPimXHBwNMU4NZKWRRUVty
7gHVoW5DIMY6zRsS1Gg9e8/3wO0rrxczMnK8dR/hMT8d9c4MFKw2BSLU1fbE6DGQ
ig8MfW8SZMnhcYr//ZiDK6jiXYKaLZLMVkz3luOnFF7mcc6sgB+ye0RAfR45QErz
wUq7HW2FZ49xCIrt95995a72xAUAJQ1wfVkOOdF6JiLaJjKlhC0RyOESuZvJI49u
HZKLBQjr/xFB3g1AOYhh5iOaw0Q+oUvFeeiflWHuyM7boliKNzpkVDsvXL3UCMOx
ljl1iez0ZrK5DQKHdu5e8c5YbBm6LNS/0H+cUU2wnd6kKffufthomKr4SSlpe3Xb
a7u7jMDg5IPyumJy+a2vDF4ItiO6Ux9lkCpEVWpEyvEjFh1/DgHQUjBAE+1Swanf
7tXD3HKWdgRqkiFALCwnNvlYiBUGI135odt67NBUv134fE2dpQTwXxpcDrWSC+OT
LJAiCsoccjC38zDNV4yq8I/qL3ViivDV6XHQLfbtnEGXrJ9Es+AIC6nyJqc7FUZS
mQZf7ZXXI5vrPpAgGwifDCexLggVK8nELycuHMNDnbhhBDf+xXg=3D
=3Dn8ec
-----END PGP SIGNATURE-----

--fx4yetv4zvhoc2hy
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEV6G/FbT2+ZuJ7bKf05SBrh55rPcFAmlRACIACgkQ05SBrh55
rPeAJA//VoguB+r0TqrJb9rLtRev8eiTyQ1+R1OWbV1O3pnCiVU7CGDJYrtq/kjN
v8JfZt8bOq0aXgu8jXl6ARLXyuH8uneK/uQwCvvWDXy2QoKkSPGsNkSS2z1XQ2la
AVTTdWbCpwzUigFVEDRRu3INX3ijaBiWryS9sfOzjZq5ReatctUsjx1e4MXa3DUZ
/DHs03+h3KYuiyjBWqoVM/fmKOq1/CNhFbRJP3fb6bpKAk85TcSXOMrf/PlpSZ3H
jJJHbGCxIJty/sdSRnMOLEggERkdAeRd9EcfN7OV9FBB0H/3qtt3Xvk+4Re7Jgje
h88frvjoP7wQjkWf4FQY2oF56Lfme5M2NLiXqiZHO1cd7S9hhBbOGV2lxMb21n2t
WZ/xwMhnz9u+0QBbJLoHCG/CD8WtRzIdP4neO0tLj8ifJGRq1Dv/v5K9WGU0o6wo
4zvDqQ9tKMUf1YsiO+5wcWwxz9HHYTvTV7hXK636iU1fx6AEvq3+Bbcy+Lx1NvdO
kcWiKtUGQ6ekl589EyYsrd6jpCn2lJpyvVXM4IzEv+aoiXccHhPtYU9tX9K/Pt7r
GVibmQYWbe/5Mn5mjc+SoE3WM+tnLBRpvEBRoeFQ/zZqZ/7Snk5JxHSr62kuXprr
IP1XUPlAHyT+Waz1/WAjfeyyQB2lYj19Rh+pPaOGmHGKLwKeDYI=
=pDxR
-----END PGP SIGNATURE-----

--fx4yetv4zvhoc2hy--

------------=_1767625142-3011076-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at 1124117-done) by bugs.debian.org; 5 Jan 2026 14:57:54 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
	(2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-105.2 required=4.0 tests=BAYES_00,DKIMWL_WL_HIGH,
	DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FROMDEVELOPER,
	SPF_HELO_NONE,SPF_NONE,UNPARSEABLE_RELAY,USER_IN_DKIM_WELCOMELIST
	autolearn=ham autolearn_force=no
	version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 15; hammy, 85; neutral, 23; spammy, 0.
	spammytokens: hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin,
	0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311,
	0.000-+--H*RT:311, 0.000-+--H*RT:108
Return-path: <[email protected]>
Received: from stravinsky.debian.org ([2001:41b8:202:deb::311:108]:42740)
	by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1vcm1q-00Ccwn-1B
	for [email protected];
	Mon, 05 Jan 2026 14:57:54 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org;
	s=smtpauto.stravinsky; h=X-Debian-User:Content-Transfer-Encoding:Content-Type
	:Subject:From:To:MIME-Version:Date:Message-ID:Reply-To:Cc:Content-ID:
	Content-Description:In-Reply-To:References;
	bh=yNSilUG153kNafdntydz1ErIHNKXHO1MxOI09/bajpw=; b=uIdU0QoWG9r1YwDCPEpWMySNBj
	mElAjTuOpMwqKBrDzmRrZg0SrEQrU49SMn0OZ9a3mkAUlMwZIgq/ybRdgz3C8lFDO7oHSfY3S/XZ7
	QZAs+DpKSyjcfJ1zrW7SXqJ65EaJNvjnaAnbhp+ZHilaRhV7z/SSI6nkzZQ7dMb8t8w3Ps5eHrOy8
	3kXurb/pHagc1MGIoQ2Re/oULkmJR8QvWK/RVyHPznF8OluKvbbFK8dMbocagHNkhpKgIrJgDFxxE
	FwMF0w8c+OTl3ZiFY02ikzVXZtD7X+Sposvg0K7w0BMAHzT8lLC3wgIurMhg2tNgAV4LiWE34lGbi
	SmiIZoEw==;
Received: from authenticated user
	by stravinsky.debian.org with esmtpsa (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_128_GCM:128)
	(Exim 4.94.2)
	(envelope-from <[email protected]>)
	id 1vcm1o-00Gxry-KV; Mon, 05 Jan 2026 14:57:52 +0000
Message-ID: <[email protected]>
Date: Mon, 5 Jan 2026 14:57:46 +0000
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: en-GB
To: [email protected], =?UTF-8?Q?Daniel_Gr=C3=B6ber?=
 <[email protected]>
From: Matthew Vernon <[email protected]>
Subject: Openconnect uploads done
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Debian-User: matthew

Hi,

I see that Openconnect now has these changes and the updates to trixie 
have been accepted.

So I'm closing the TC bug; if you need anything else from the TC about 
this issue, do shout, though.

Thanks,

Matthew
------------=_1767625142-3011076-0--