Re: [lfs-support] "Security Advisories" dead?

"Rainer Fiebig" ([email protected] via blfs-support Mailing List) <[email protected]> Thu, 15 May 2025 19:50:20 +0200
Newsgroups gmane.linux.lfs.beyond.support,gmane.linux.lfs.support
Message-ID <[email protected]>
Am 15.05.25 um 17:20 schrieb "Douglas R. Reno"
([email protected] via lfs-support Mailing List):
> On 5/15/25 3:38 AM, Rainer Fiebig ([email protected] via lfs-support
> Mailing List) wrote:
>> The last Security Advisory was as of 2025-03-14 for PHP.  The last SAs
>> for Firefox and Thunderbird recommended updating to -128.08.0esr.  Both
>> are at -128.10.0 already since a while.
>>
>> I consider the SAs a great service and hope that they have not been
>> abandoned or can no longer be maintained.  But if so the LFS/BLFS
>> community should be informed about it.  Thanks.
>>
>> Rainer
>>
> Hi Rainer!
> 
> The security advisories are alive and well. As Rahul alluded too I've
> had some other things going on, but that isn't the only reason.
> 
> Many of the new security updates have caused build bustages or
> regressions that I've had to deal with, and unfortunately several of
> them have been in large packages that take a long time to build. These
> include packages like QtWebEngine, Qt, libarchive, Expat, WebKitGTK,
> GhostScript, and Libreoffice, amongst some others. The security
> advisories are something I'm very passionate about, so anytime I receive
> a report of a build issue or regression I always take it seriously and
> investigate first. The current security landscape involving some
> packages has also made it extremely difficult to get the information
> needed to file an advisory, but Joe Locash got me the information for
> that package and mailed it to me privately so we have a comprehensive
> list of everything we need to cover in that advisory! Because of all of
> the regressions though many of the advisories will have additional text
> about things that need to be done to fix issues with them.
> 
> I currently have 8 security updates on my radar, and I'm going to start
> with finishing up OpenJDK. After that expect updates to screen, libsoup2
> (removal from BLFS, but patch available for BLFS <= 12.3 users),
> libsoup3, giflib, intel-microcode, node.js, OpenJDK, and another update
> to WebKitGTK (which hopefully will not cause more build issues!). I know
> OpenJDK is going to have issues with at least one package so I will need
> to resolve and test that at the same time.
> 
> In March I also got a new development system, and got it setup to
> replace my old machine (which was approaching 7 years old). The SSD
> failed in that system about two weeks later and I lost everything that I
> had worked on during that time, which included work on QtWebEngine
You know the rules, Doug: "No backup - no mercy." ;)

Even a simple but regular
   rsync -aq /important_stuff_on_fancy_ssd /good_old_harddisk
can be a real boon at times.

> regressions in particular, as well as the very recent GNOME update that
> I had put in. It took me a long time to get that caught back up, I think
> almost three weeks because I had to spend a lot of time building and
> dealing with more security update related regressions while trying to
> manage university stuff at the same time. I also had to deal with issues
> with packages like CMake-4 and libxml2-2.14 as well during the same
> time. That normally wouldn't be a big issue in late February/early March
> because I work hard to get ahead of everything in classes before release
> times, but late March/early April timing made it take longer, and I try
> to test everything new that comes in to make sure we're as regression
> free as we can be, though things happen! I have a handle on everything
> now and should be able to take care of these all soon. The machine has
> been very amazing to work with though and it's very fast, which should
> allow me to get to issues like we have today much faster.
> 
> I'm expecting to be filing advisories tomorrow or Saturday, and I will
> send an email about all of the updates afterwards as normal. I will also
> mention issues with a couple of other packages that should be taken
> seriously.
> 
> One more security related thing that I wanted to bring up here, that
> isn't security advisory related, is that I'll be probably adding fwupd
> to the book to assist users with firmware updates. Given the current
> landscape of firmware related vulnerabilities and minor hardware issues
> in new hardware, it might be useful for users to have the opportunity to
> get their BIOS updated through fwupd (since you'll get extra security
> fixes on Intel systems for the Management Engine for example). The
> caveat with fwupd though is that your hardware has to support it, but
> for users who can update it through there it will be extremely useful.
> Bruce has requested a writeup on how to build it and it's dependencies
> first for him to try so I'll give it to him first, and then we'll
> include it in the book probably in a week or two. I really need to take
> care of existing security issues, file advisories, and take care of some
> Texlive related problems first before I do that though.
Well, that's a lot of stuff you're juggling with.  But at least we don't
have to worry that you're suffering from boredom. ;)

Thanks a lot, Doug!  And please don't feel pressured by my inquiry - I
was just wondering, as two months without SAs was an unusually long time.

Rainer

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-support
Unsubscribe: See the above information page