Control: tags -1 + confirmed On Mon, 2016-05-23 at 15:28 +0200, Vincent Blut wrote: > Could you please accept chrony 1.30-2+deb8u2 in the next jessie point > release? It fixes three issues of different magnitudes. > > The most important one is the fix for CVE-2016-1567 though it didn’t > warrant a DSA. > > The next one might sound probably not important enough to be fixed in a > stable point release but it has some nasty consequences. We are > mistakenly deleting the content of /var/lib/chrony on package removal. > This directory contains the driftfile and the measurement history for > each time source. The former file has a particularly important role, it > stores the gain or loss rate of the system clock relative to the RTC > which could take some time to calculate depending of how crappy the RTC > is so it would be definitely better if we could avoid to delete it each > time chrony is upgraded or installed from Config-Files state. > > To conclude, the last fix revises the postrotate script from the > logrotate configuration file. It suffers from two issues, the first one > is that it assumes the commandkey directive from chrony.conf takes ID 1, > that’s not necessarily true!
Please go ahead. Regards, Adam