Bug#1144966: please add exception for llvm-toolchain-22 1:22.1.8-1~deb13u4 to allow security-buildds to use it

Adrian Bunk <[email protected]>
Newsgroups gmane.linux.debian.devel.release
Message-ID <ao6raHM7p1SwyB0M__43965.3667084471$1787735008$gmane$org@localhost>
On Wed, Aug 26, 2026 at 09:59:03AM +0200, Salvatore Bonaccorso wrote:
> Hi,
> 
> On Mon, Aug 24, 2026 at 01:46:45PM -0400, Andres Salomon wrote:
> > Hi,
> > 
> > Chromium has been carrying patches to make it work with llvm-toolchain-19,
> > and I've uploaded llvm-toolchain-22 to stable-proposed-updates (and pochu
> > already uploaded llvm-toolchain-22 to oldstable-pu and oldoldstable-pu) in
> > order to be able to drop those patches as well as use a newer rustc. I
> > didn't realize (mea culpa) that I needed to ask for an exception from the
> > wanna-build team in order to have security buildds use packages from s-pu.
> > Can we please have an exception for llvm-toolchain-22 in s-pu for the
> > security buildds? llvm-toolchain-22 only supports static linking, so
> > anything that builds against it shouldn't end up with any binary package
> > dependencies on libc++1(-19/-22) or anything like that.
> > 
> > Note that I have a pending security update (151.0.7922.173-1~deb13u1) that
> > was already uploading and build-deps on llvm-toolchain-22. The equivalent
> > bookworm-security (deb12u1) release already built, but the trixie-security
> > version is still being given back on the security buildds due to lack of
> > llvm-toolchain-22. So there is a bit of urgency in getting either an ACK or
> > NACK to this request.
> 
> We are not sure if that felt through the cracks, and excuse if the
> ping follows too shortly (I realize it is only two days passing).
> 
> I see two options, eithr stable-proposed-updates is enabled for
> security builds temporarily until chromium is done (I guess we should
> not have it longer, vs. as we discussed for -updates).
> 
> Or second option is to relese the llvm-toolchain-22 as needed via a
> SUA, would that be an option? I'm explicitly adding Adam here into CC.
> 
> I notice there would be another chromium update as there was a new
> batch of CVEs yesterday AFAICS.

A third option would be:

  llvm-toolchain-22 (1:22.1.8-1~deb13u5) trixie-security; urgency=medium

    * Rebuild for trixie-security.

This would be the most natural solution of uploading to security what is
needed in security.

Among the architectures where chromium is built, the slowest at building
llvm-toolchain-22 is ppc64el with 7-8 hours build time.

> Regards,
> Salvatore

cu
Adrian
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.