** Description changed:

  [Availability]
  - The source package jitterentropy-library is published in Ubuntu (universe).
  - Current Launchpad builds pass on: amd64, amd64v3, arm64, armhf, i386, 
ppc64el, riscv64, s390x.
  - Source package: https://launchpad.net/ubuntu/+source/jitterentropy-library
  
  [Rationale]
  - The package src:jitterentropy-library is required in Ubuntu main for
  
-   The package libssl-dev in Ubuntu main ships a static library libcrypto.a. 
The static library comes with a pkg-config configuration that declares a 
dependency on libjitterentropy.a which is packaged in the libjitterentropy3-dev.
-   See more details 
https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/2158026.
+   The package libssl-dev in Ubuntu main ships a static library libcrypto.a. 
The static library comes with a pkg-config configuration that declares a 
dependency on libjitterentropy.a which is packaged in the libjitterentropy3-dev.
+   See more details 
https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/2158026.
  
  - The package src:jitterentropy-library serves a narrower but important 
Ubuntu use case.
  - The narrower use case is important because There is not better supported 
alternative. Each package static linking with libcrypto.a will have to declare 
delcare dependency on libjitterentropy3-dev package which is not ideal.
  - The Ubuntu user benefit and enabled use cases are Developers static linking 
with libcrypto.a will be able to build their applications.
  - There is no other/better way already in main; alternatives considered: I 
considered explicitly asking users to declare dependency on 
libjitterentropy3-dev in their builds. I rejected it becasue it is reasonalbe 
to expect the static library dependency to be being present on the system.
  - Specific binary packages built by src:jitterentropy-library, listed below, 
need to be in main.
-   The specific binary packages needing promotion are libjitterentropy3-dev
+   The specific binary packages needing promotion are libjitterentropy3-dev
  - The package src:jitterentropy-library is required in Ubuntu main by no 
later than 18 August, 2026
  
  [Security]
  - No package-associated CVEs were found in the queried trackers.
  - No setuid/setgid files, sbin executables, systemd units, or cron jobs were 
found.
  - No AppArmor profiles, desktop files, translations, or plugin candidates 
were found.
  - Security exposure and proportional mitigation assessment: Assess 
security-sensitive behavior, exposed endpoints, privileged operation, 
cryptography, and whether mitigations are proportional.
  - Deprecated cryptographic algorithm concerns: No
  
  [Quality assurance - function/usage]
  - Package function after installation and required configuration: The package 
works after installation.
  
  [Quality assurance - maintenance]
  - No critical Ubuntu or release-critical Debian bugs were found.
  - The package does not depend on exotic hardware we cannot support.
  - The package maintenance health is: The package maintenance health is: Good. 
The package is new, one version behind the latest upstream. There are no open 
old bugs in Debian or Ubuntu.
  
  [Quality assurance - testing]
  - The package does not run a test at build time.
-   #TODO
+   #TODO - I need to add these before promotion to main.
  - No autopkgtest results were found for this source package.
-   #TODO
+   #TODO - I need to add these before promotion to main.
  - Testing gaps and the owning team test plan are: There are no build time 
tests or autopkgtest.
  - Overall automated and end-to-end test adequacy: Low
  
  [Quality assurance - packaging]
  - A debian/watch upstream-release mechanism is present.
  - Lintian reported 0 error(s) and 0 warning(s).
  - Maintainer: Eric Berry <[email protected]>; source format: 3.0 
(quilt); debconf templates: 0; debian/rules overrides: dh_auto_install.
  - Packaging complexity and maintainability assessment: Packaging complexity 
and maintainability assessment: Simple
  
-   Maintainer field needs an update. Somebody from
- https://launchpad.net/~canonical-security-certification
+   Maintainer field needs an update. Somebody from
+ https://launchpad.net/~canonical-security-certification (canonical-
+ security-certification: 0)
  
  - No Python 2, GTK 2, or other catalogued obsolete runtime dependency
  was found.
  
  [UI standards]
  - Evidence-based UI applicability assessment: There are not desktop files.
  
  [Dependencies]
  - No in-scope runtime dependencies outside main require a separate MIR.
  
  [Standards compliance]
  - This package correctly follows FHS and Debian Policy.
  - No license expiry, time-bound terms, entity/contract coupling, withdrawable 
branches, patents, or other encumbrances were identified; the license is 
expected to remain compatible with Ubuntu main throughout the full support 
lifetime.
  
  [Maintenance/Owner]
  - A different owning team will subscribe to this package, named below.
- - The new owning team will be 
https://launchpad.net/~canonical-security-certification and has acknowledged 
the commitment.
+ - The new owning team will be 
https://launchpad.net/~canonical-security-certification 
(canonical-security-certification: 0)  and has acknowledged the commitment.
  - No owning-team package bug subscription was found.
-   (A team must subscribe before promotion.)
+   (A team must subscribe before promotion.)
  - No shipped vendored directories were detected.
  - No Launchpad build within the last three months was confirmed.
-   #TODO
+   #TODO - There should be a new build before promotion to main.
  - This change affects other Ubuntu teams and the required coordination is 
still in progress.
  
  [Background information]
  - The package description and additional background explain the package: 
Jitter Entropy library enables fips based containers to run on non-fips host 
Ubuntu systems. the library has been compiled into OpenSSL.
  - Upstream project: https://github.com/smuellerDD/jitterentropy-library
- 
  
  Original report is below
  
================================================================================
  openssl 4.0.1-1ubuntu2 in stonking proposed requires a MIR for 
jitterentropy-library
  
  As a result of 4.0.1-1ubuntu2 lp: #2158026
  
  update_excuses shows:
  
  libssl-dev/amd64 in main cannot depend on libjitterentropy3-dev in universe
  libssl-dev/amd64v3 in main cannot depend on libjitterentropy3-dev in universe
  libssl-dev/arm64 in main cannot depend on libjitterentropy3-dev in universe
  libssl-dev/armhf in main cannot depend on libjitterentropy3-dev in universe
  libssl-dev/i386 in main cannot depend on libjitterentropy3-dev in universe
  libssl-dev/ppc64el in main cannot depend on libjitterentropy3-dev in universe
  libssl-dev/riscv64 in main cannot depend on libjitterentropy3-dev in universe
  libssl-dev/s390x in main cannot depend on libjitterentropy3-dev in universe
  
  confirmed in component mismatches:
  
  https://ubuntu-archive-team.ubuntu.com/component-mismatches-proposed.svg

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2162943

Title:
  [MIR] jitterentropy-library

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/jitterentropy-library/+bug/2162943/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to