From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by finch.gentoo.org (Postfix) with ESMTPS id 7C8B51396D0 for ; Sat, 23 Sep 2017 20:04:26 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id D1B5C1FC1D5; Sat, 23 Sep 2017 20:04:20 +0000 (UTC) Received: from smtp.gentoo.org (smtp.gentoo.org [140.211.166.183]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id 8A3CC1FC185 for ; Sat, 23 Sep 2017 20:04:19 +0000 (UTC) Received: from sf (host86-155-195-219.range86-155.btcentralplus.com [86.155.195.219]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: slyfox) by smtp.gentoo.org (Postfix) with ESMTPSA id 6012A33BE95; Sat, 23 Sep 2017 20:04:14 +0000 (UTC) Date: Sat, 23 Sep 2017 21:04:07 +0100 From: Sergei Trofimovich To: Yury German Cc: gentoo-dev@lists.gentoo.org, Gentoo Security Subject: Re: [gentoo-dev] Re: On dropping sparc@ from CC on bugs Message-ID: <20170923210407.20af72d1@sf> In-Reply-To: <20170914082823.5afacd75@sf> References: <20170911084313.2cf9f40e@sf> <4481473.IXDqc1jNCF@localhost.localdomain> <22968.55158.799187.902608@a1i15.kph.uni-mainz.de> <20170913090344.0adcbede@sf> <3363B1E2-10B2-4ADF-B47B-6B6A8846EA4C@gentoo.org> <20170914082823.5afacd75@sf> X-Mailer: Claws Mail 3.15.1-dirty (GTK+ 2.24.31; x86_64-pc-linux-gnu) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-dev@lists.gentoo.org Reply-to: gentoo-dev@lists.gentoo.org MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; boundary="Sig_/7fkL5jOAgeB8qayrDXDkmpE"; protocol="application/pgp-signature" X-Archives-Salt: 54f7195a-1a81-49c1-9bb9-bfe1f21c69ad X-Archives-Hash: 5dc136bf01de633085f1fbb94f1f9fe8 --Sig_/7fkL5jOAgeB8qayrDXDkmpE Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: quoted-printable On Thu, 14 Sep 2017 08:28:23 +0100 Sergei Trofimovich wrote: > On Wed, 13 Sep 2017 22:44:23 -0400 > Yury German wrote: >=20 > Thank you! That's very helpful. A few clarifying questions below > to be absolutely clear. >=20 > > OK so let me repeat the comments that were made on @dev (and expand a = bit further) and close the issue. > >=20 > > 1. Maintainers are free to cc the non-stable and experimental arches as= part of their call for stabilization. It is up to the maintainer of the pa= ckage to decide. > >=20 > > 2. This is providing that there is no problems caused by stableboy or e= xtra dependencies raised > > Note: as a follow up change was made: 07:47 <@kensington> leio: b-man: = good point, dropped sparc from stable_arches > >=20 > > 3. Clean up is required as part of the security bug process, and if an = arch is holding it up (example hppa before Slyfox took it over) an issue wo= uld have to be raised with the QA team for action. [1] =20 >=20 > 'Cleanup' is only vulnerabe ebuild removal, not CC removal from the bug, = right? >=20 > > 4. Bugs will be closed without waiting for any non-security supported a= rches, once the security process is complete. =20 >=20 > CC for exp lagging arches are not removed from the bug, right? >=20 > > 5. Security bugs are not re-assigned since they are assigned as a vulne= rability in bugzilla. If you need to continue work on the bug, please feel = free to open another bug for the particular arch for stabilization, fix, et= c. > >=20 > > If you have any questions please let me know. > >=20 > >=20 > > [1] - https://wiki.gentoo.org/wiki/Project:Security/GLSA_Coordinator_Gu= ide#Bugs_in_.5Bcleanup.5D_status =20 Ping. --=20 Sergei --Sig_/7fkL5jOAgeB8qayrDXDkmpE Content-Type: application/pgp-signature Content-Description: Цифровая подпись OpenPGP -----BEGIN PGP SIGNATURE----- iF0EARECAB0WIQSZKa0VG5avZRlY01hxoe52YR/zqgUCWca+NwAKCRBxoe52YR/z qtDDAJ9W0WANy6K1UiYsLQkCCbyjELNHTwCeMn6U5uFEnNhTBaH5uYZ4byZYhIA= =qoZ0 -----END PGP SIGNATURE----- --Sig_/7fkL5jOAgeB8qayrDXDkmpE--