[go: up one dir, main page]

Debian Bug report logs - #763148
Prevent migration to jessie

Package: ffmpeg; Maintainer for ffmpeg is Debian Multimedia Maintainers <debian-multimedia@lists.debian.org>; Source for ffmpeg is src:ffmpeg (PTS, buildd, popcon).

Reported by: Moritz Muehlenhoff <jmm@debian.org>

Date: Sun, 28 Sep 2014 08:27:02 UTC

Severity: serious

Tags: jessie, moreinfo

Done: Andreas Cadhalpun <andreas.cadhalpun@googlemail.com>

Bug is archived. No further changes may be made.

Full log


Message #49 received at 763148@bugs.debian.org (full text, mbox, reply):

Received: (at 763148) by bugs.debian.org; 2 Oct 2014 16:44:11 +0000
From jmm@inutil.org Thu Oct 02 16:44:11 2014
X-Spam-Checker-Version: SpamAssassin 3.3.2-bugs.debian.org_2005_01_02
	(2011-06-06) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-6.9 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER,
	RCVD_IN_DNSWL_MED,T_RP_MATCHES_RCVD autolearn=ham
	version=3.3.2-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 10; hammy, 151; neutral, 50; spammy,
	0. spammytokens: hammytokens:0.000-+--H*u:2014-03-12,
	0.000-+--H*UA:2014-03-12, 0.000-+--H*u:1.5.23, 0.000-+--H*UA:1.5.23,
	0.000-+--H*r:jmm
Return-path: <jmm@inutil.org>
Received: from inutil.org ([83.151.30.8])
	by buxtehude.debian.org with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:256)
	(Exim 4.80)
	(envelope-from <jmm@inutil.org>)
	id 1XZjUB-0007eM-G7
	for 763148@bugs.debian.org; Thu, 02 Oct 2014 16:44:11 +0000
Received: from p5dccca18.dip0.t-ipconnect.de ([93.204.202.24] helo=pisco.westfalen.local)
	by inutil.org with esmtpsa (TLS1.0:RSA_AES_128_CBC_SHA1:16)
	(Exim 4.69)
	(envelope-from <jmm@inutil.org>)
	id 1XZjDu-0002rY-Va; Thu, 02 Oct 2014 18:27:23 +0200
Received: from jmm by pisco.westfalen.local with local (Exim 4.84)
	(envelope-from <jmm@pisco.westfalen.local>)
	id 1XZjTp-0001HP-DC; Thu, 02 Oct 2014 18:43:49 +0200
Date: Thu, 2 Oct 2014 18:43:49 +0200
To: Andreas Cadhalpun <andreas.cadhalpun@googlemail.com>
Cc: Andreas Barth <aba@ayous.org>,
	Debian Security Team <team@security.debian.org>,
	Debian Release Team <debian-release@lists.debian.org>,
	Niv Sardi <xaiki@debian.org>, Alexander Strasser <eclipse7@gmx.net>,
	Michael Niedermayer <michael@niedermayer.cc>,
	763148@bugs.debian.org
Subject: Re: Bug#763148: Prevent migration to jessie
Message-ID: <20141002164349.GA4870@pisco.westfalen.local>
References: <20140928082411.3642.2324.reportbug@pisco.westfalen.local>
 <5427D467.4070207@googlemail.com>
 <20140928104705.GN20713@mails.so.argh.org>
 <542800C8.7040701@googlemail.com>
 <20140928124440.GT3278@mails.so.argh.org>
 <542C1078.7020402@googlemail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <542C1078.7020402@googlemail.com>
User-Agent: Mutt/1.5.23 (2014-03-12)
From: Moritz Mühlenhoff <jmm@inutil.org>
X-SA-Exim-Connect-IP: 93.204.202.24
X-SA-Exim-Mail-From: jmm@inutil.org
X-SA-Exim-Scanned: No (on inutil.org); SAEximRunCond expanded to false
On Wed, Oct 01, 2014 at 04:32:24PM +0200, Andreas Cadhalpun wrote:
> >However, I can understand why one embedded
> >code copy is better than one embedded code copy plus a library in
> >addition to it.
> 
> This would be understandable, yes.
> 
> There are now two options:
> a) Let FFmpeg migrate to testing and make chromium use it.
> b) Don't let FFmpeg migrate and let chromium continue to use the
>    embedded copy, in spite of the policy violation.
>    If this really would be preferred, then the FFmpeg libraries and
>    tools could be build from the chromium source package, because that
>    can't increase the security workload, as the source is already in
>    wheezy.

Chromium is actually a special case. It's a huge monster package which is 
very difficult to integrate and maintain. 
You seem to have missed that for Chromium we rebuild the current upstream 
releases in stable. Since there're not guarantees for any kind of API stability in
the local ffmpeg copy that is obviously not a good idea.

Cheers,
        Moritz



Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Mon Nov 3 08:57:28 2025; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU General Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.