Archive Admin, please promote src:frr and these binary packages to main:
frr
frr-pythontools (pulled in by frr via Recommends)

Note libyang2 will be pulled in as well, and its MIR (#1958293) was
completed and ACKed.

Leave in universe:
frr-snmp
frr-rpki-rtrlib (uses a library that is still in universe)
frr-doc (or not, whatever happens automatically)

frr-snmp I decided to not promote:
- there are quite a large number of bugs filed in the upstream tracker with 
"snmp" in them that are still open 
(https://github.com/FRRouting/frr/issues?page=2&q=is%3Aissue+is%3Aopen+snmp)
- the upstream documentation warns that it can be a firehose and lead to 
crashes and hangs[1] if abused
- snmp is usually hard to troubleshoot, and can be a security nightmare
- it's easier to promote it to main later if deemed necessary, than to demote 
it after it has been in main in a release

frr was given a special consideration by the security team (see comment
#10) and didn't go through the usual security review process. This plus
all the above made me decide to keep frr-snmp in universe for now.


1. http://docs.frrouting.org/en/latest/snmp.html

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1951834

Title:
  [MIR]: frr

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/frr/+bug/1951834/+subscriptions


-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to