MRE revoked [Was: Re: MRE request for Bind9]

Steve Langasek steve.langasek at ubuntu.com
Fri Apr 14 19:45:41 UTC 2023


On Fri, Apr 14, 2023 at 08:39:59PM +0100, Robie Basak wrote:
> On Fri, Apr 14, 2023 at 11:23:22AM -0700, Steve Langasek wrote:
> > It is the nature of MRE exceptions that we declare that *such scrutiny is
> > not required*, because we trust that upstream has a microrelease policy in
> > place that makes this unnecessary.

> > While upstream has legitimate reasons for wishing to flag these
> > configurations as broken, and they did document it prominently on their
> > website, the fact that it was included in a microrelease means that their
> > policy is not consistent with what our MRE policy requires; and therefore we
> > cannot, under the present circumstances, delegate to upstream in this
> > matter.

> I agree with this principle. This kind of change should be considered on
> a case-by-case basis by the SRU team and/or TB as appropriate[1] before
> landing an Ubuntu stable release. So we cannot just delegate this to
> upstream in this case.

> However, given that they did document it prominently, I wonder if we
> could find some middle ground, such as a requirement that somebody[2]
> inspect upstream documentation for any such notices, document that
> search, and then if none are found, trust the upstream microrelease to
> be in line with our policies.

I'm happy to have that discussion - I just didn't want to leave the MRE in
its current state as a foot-gun to other SRU team members given the
information we currently have.

> Robie

> [1] The current SRU policy on this matter was decided and delegated by
> the TB and says: "In other cases where such upstream automatic testing
> is not available, exceptions must still be approved by at least one
> member of the Ubuntu Technical Board."

> [2] Who exactly is an important matter for discussion.


-- 
Steve Langasek                   Give me a lever long enough and a Free OS
Debian Developer                   to set it on, and I can move the world.
Ubuntu Developer                                   https://www.debian.org/
slangasek at ubuntu.com                                     vorlon at debian.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/ubuntu-release/attachments/20230414/fa515791/attachment.sig>


More information about the Ubuntu-release mailing list