Public bug reported:

This is a MIR request for src:openssh-gssapi. It's a split from
src:openssh, which is already in main, triggered by debian[1]. The main
reasoning is to reduce the security exposure of src:openssh by removing
the kerberos/gssapi feature in src:openssh and moving it to src:openssh-
gssapi. It's basically a different set of build options of the same
source.

I'm invoking the Renamed or reorganized sources[6] part of the MIR
process.

The one thing Ubuntu is adding on top is the ccache patch[2], from
Fedora.

That patch has been requested for ubuntu since 2020[2], and has been
provided in a Server Team maintained PPA[3] for jammy, noble, and more
recently resolute. The PPA work is detailed in a Canonical-internal
SPEC[4]. The security team was made aware[7] (Canonical-only internal
link) of this PPA back then and agreed to help support it if needed, but
that was never necessary as the patch always applied cleanly and
introduced no regressions in all these years. Still, it's of course
feasible that a security vulnerability could only affect src:openssh-
gssapi due to this patch.

The other consequence of this new source package is that a non-
kerberos/gssapi vulnerability on openssh will likely need to be fixed in
both source packages.

Differently from the PPA, the approach here is a plain patch-and-build
one. The PPA for jammy, noble, resolute, still uses the alternatives
mechanism and two builds from the same source.

The package includes a new autopkgtest[5] which covers the patch
behavior, and runs the normal upstream regression test at both build-
time and as an autopkgtest. And still has the normal openssh
autopkgtests, like socket-activation, xinetd, and general
gssapi/kerberos login.

The canonical-server team will subscribe to this package.

1. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141274
2. https://bugs.launchpad.net/ubuntu/+source/openssh-gssapi/+bug/1889548
3. 
https://launchpad.net/~canonical-server/+archive/ubuntu/openssh-server-default-ccache
4. 
https://docs.google.com/document/d/1UJDtDNCbDxfaq10inp5nVlisbMh-zwxzpPR0Hp_UrnI/edit
5. 
https://git.launchpad.net/ubuntu/+source/openssh-gssapi/tree/debian/tests/ssh-gssapi-default-ccache
6. 
https://ubuntu.com/project/docs/MIR/mir-rereview/#renamed-or-reorganized-sources
7. 
https://docs.google.com/document/d/1-qadf8qTJyOF5CKVR5iFFYlKF5-XLB_qShDw5Ykp5pw/edit?tab=t.0

** Affects: openssh-gssapi (Ubuntu)
     Importance: Undecided
         Status: New

** Summary changed:

- MIR (source rename): openssh-gssapi + ccache patch (the new thing)
+ MIR (source fork): openssh-gssapi + ccache patch (the new thing)

** Description changed:

  This is a MIR request for src:openssh-gssapi. It's a split from
- src:openssh, which is already in main, triggered by debian[1].
+ src:openssh, which is already in main, triggered by debian[1]. The main
+ reasoning is to reduce the security exposure of src:openssh by removing
+ the kerberos/gssapi feature in src:openssh and moving it to src:openssh-
+ gssapi. It's basically a different set of build options of the same
+ source.
  
  I'm invoking the Renamed or reorganized sources[6] part of the MIR
  process.
  
  The one thing Ubuntu is adding on top is the ccache patch[2].
  
  That patch has been requested for ubuntu since 2020, and has been
  provided in a Server Team maintained PPA[3] for jammy, noble, and more
  recently resolute. The PPA work is detailed in a Canonical-internal
  SPEC[4]. The security team was made aware[7] (Canonical-only internal
  link) of this PPA and agreed to help support it if needed, but that was
  never necessary as the patch always applied cleanly and introduced no
  regressions in all these years. Still, it's of course feasible that a
  security vulnerability could only affect src:openssh-gssapi due to this
  patch.
  
  Differently from the PPA, the approach here is a plain patch-and-build
  one. The PPA for jammy, noble, resolute, still uses the alternatives
  mechanism and two builds from the same source.
  
  The package includes a new autopkgtest[5] which covers the patch
  behavior.
  
  The canonical-server team will subscribe to this package.
  
  1. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141274
  2. https://bugs.launchpad.net/ubuntu/+source/openssh-gssapi/+bug/1889548
  3. 
https://launchpad.net/~canonical-server/+archive/ubuntu/openssh-server-default-ccache
  4. 
https://docs.google.com/document/d/1UJDtDNCbDxfaq10inp5nVlisbMh-zwxzpPR0Hp_UrnI/edit
  5. 
https://git.launchpad.net/ubuntu/+source/openssh-gssapi/tree/debian/tests/ssh-gssapi-default-ccache
  6. 
https://ubuntu.com/project/docs/MIR/mir-rereview/#renamed-or-reorganized-sources
  7. 
https://docs.google.com/document/d/1-qadf8qTJyOF5CKVR5iFFYlKF5-XLB_qShDw5Ykp5pw/edit?tab=t.0

** Description changed:

  This is a MIR request for src:openssh-gssapi. It's a split from
  src:openssh, which is already in main, triggered by debian[1]. The main
  reasoning is to reduce the security exposure of src:openssh by removing
  the kerberos/gssapi feature in src:openssh and moving it to src:openssh-
  gssapi. It's basically a different set of build options of the same
  source.
  
  I'm invoking the Renamed or reorganized sources[6] part of the MIR
  process.
  
  The one thing Ubuntu is adding on top is the ccache patch[2].
  
  That patch has been requested for ubuntu since 2020, and has been
  provided in a Server Team maintained PPA[3] for jammy, noble, and more
  recently resolute. The PPA work is detailed in a Canonical-internal
  SPEC[4]. The security team was made aware[7] (Canonical-only internal
- link) of this PPA and agreed to help support it if needed, but that was
- never necessary as the patch always applied cleanly and introduced no
- regressions in all these years. Still, it's of course feasible that a
- security vulnerability could only affect src:openssh-gssapi due to this
- patch.
+ link) of this PPA back then and agreed to help support it if needed, but
+ that was never necessary as the patch always applied cleanly and
+ introduced no regressions in all these years. Still, it's of course
+ feasible that a security vulnerability could only affect src:openssh-
+ gssapi due to this patch.
  
  Differently from the PPA, the approach here is a plain patch-and-build
  one. The PPA for jammy, noble, resolute, still uses the alternatives
  mechanism and two builds from the same source.
  
  The package includes a new autopkgtest[5] which covers the patch
  behavior.
  
  The canonical-server team will subscribe to this package.
  
  1. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141274
  2. https://bugs.launchpad.net/ubuntu/+source/openssh-gssapi/+bug/1889548
  3. 
https://launchpad.net/~canonical-server/+archive/ubuntu/openssh-server-default-ccache
  4. 
https://docs.google.com/document/d/1UJDtDNCbDxfaq10inp5nVlisbMh-zwxzpPR0Hp_UrnI/edit
  5. 
https://git.launchpad.net/ubuntu/+source/openssh-gssapi/tree/debian/tests/ssh-gssapi-default-ccache
  6. 
https://ubuntu.com/project/docs/MIR/mir-rereview/#renamed-or-reorganized-sources
  7. 
https://docs.google.com/document/d/1-qadf8qTJyOF5CKVR5iFFYlKF5-XLB_qShDw5Ykp5pw/edit?tab=t.0

** Description changed:

  This is a MIR request for src:openssh-gssapi. It's a split from
  src:openssh, which is already in main, triggered by debian[1]. The main
  reasoning is to reduce the security exposure of src:openssh by removing
  the kerberos/gssapi feature in src:openssh and moving it to src:openssh-
  gssapi. It's basically a different set of build options of the same
  source.
  
  I'm invoking the Renamed or reorganized sources[6] part of the MIR
  process.
  
  The one thing Ubuntu is adding on top is the ccache patch[2].
  
  That patch has been requested for ubuntu since 2020, and has been
  provided in a Server Team maintained PPA[3] for jammy, noble, and more
  recently resolute. The PPA work is detailed in a Canonical-internal
  SPEC[4]. The security team was made aware[7] (Canonical-only internal
  link) of this PPA back then and agreed to help support it if needed, but
  that was never necessary as the patch always applied cleanly and
  introduced no regressions in all these years. Still, it's of course
  feasible that a security vulnerability could only affect src:openssh-
  gssapi due to this patch.
  
  Differently from the PPA, the approach here is a plain patch-and-build
  one. The PPA for jammy, noble, resolute, still uses the alternatives
  mechanism and two builds from the same source.
  
  The package includes a new autopkgtest[5] which covers the patch
- behavior.
+ behavior, and runs the normal upstream regression test at both build-
+ time and as an autopkgtest. And still has the normal openssh
+ autopkgtests, like socket-activation, xinetd, and general
+ gssapi/kerberos login.
  
  The canonical-server team will subscribe to this package.
  
  1. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141274
  2. https://bugs.launchpad.net/ubuntu/+source/openssh-gssapi/+bug/1889548
  3. 
https://launchpad.net/~canonical-server/+archive/ubuntu/openssh-server-default-ccache
  4. 
https://docs.google.com/document/d/1UJDtDNCbDxfaq10inp5nVlisbMh-zwxzpPR0Hp_UrnI/edit
  5. 
https://git.launchpad.net/ubuntu/+source/openssh-gssapi/tree/debian/tests/ssh-gssapi-default-ccache
  6. 
https://ubuntu.com/project/docs/MIR/mir-rereview/#renamed-or-reorganized-sources
  7. 
https://docs.google.com/document/d/1-qadf8qTJyOF5CKVR5iFFYlKF5-XLB_qShDw5Ykp5pw/edit?tab=t.0

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167624

Title:
  MIR (source fork): openssh-gssapi + ccache patch (the new thing)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssh-gssapi/+bug/2167624/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to