Permanent Updates Policy exception for llhttp #3115

Closed
opened 2023-11-27 20:57:45 +00:00 by music · 10 comments

This ticket asks FESCo to consider whether the llhttp package should be granted a permanent exception under the Updates Policy.

The llhttp package is a C library (transpiled from TypeScript) that provides the low-level HTTP support for NodeJS (which currently bundles it, although the maintainers have discussed unbundling it), for python-aiohttp, and for uxplay.

It has twice been necessary (https://pagure.io/fesco/issue/3106, https://pagure.io/fesco/issue/3049) to request an Updates Policy Exception because a security problem in llhttp was fixed in a release that also broke ABI and/or API compatibility. In both cases, the corresponding python-aiohttp update was API-compatible, and there was no disruption to recursively-dependent packages.

Prompted by a suggestion by @gotmax23, and considering llhttp’s status as a low-level dependency with high security relevance (as its purpose is to parse potentially-untrusted HTTP), this ticket asks FESCo whether llhttp should be granted a categorical exception for such updates.

Good practice would still imply that such updates should avoid unnecessary incompatibilities, and should avoid breaking dependent packages (e.g. by updating or rebuilding them in the same side tag and Bodhi update).

It’s not possible to predict how many—if any—such updates might be required in the future. If this exception is not granted, then any similar updates that might be required in the future would be handled via case-by-case exception requests; this means more things that FESCo might need to consider and vote on, but would be perfectly feasible. I’m not personally strongly invested in a particular outcome to this ticket.

This ticket asks FESCo to consider whether the [`llhttp`](https://src.fedoraproject.org/rpms/llhttp) package should be granted a [permanent exception under the Updates Policy](https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/#_exceptions). The [`llhttp`](https://src.fedoraproject.org/rpms/llhttp) package is a C library (transpiled from TypeScript) that provides the low-level HTTP support for NodeJS (which [currently bundles it](https://src.fedoraproject.org/rpms/nodejs20/blob/9b2e0bcd7141401b2331c55d95eef1a6da09cc7c/f/nodejs20.spec#_212), although the maintainers have discussed unbundling it), for [`python-aiohttp`](https://src.fedoraproject.org/rpms/python-aiohttp), and for [`uxplay`](https://src.fedoraproject.org/rpms/uxplay). It has twice been necessary (https://pagure.io/fesco/issue/3106, https://pagure.io/fesco/issue/3049) to request an Updates Policy Exception because a security problem in `llhttp` was fixed in a release that also broke ABI and/or API compatibility. In both cases, the corresponding `python-aiohttp` update was API-compatible, and there was no disruption to recursively-dependent packages. Prompted by a [suggestion](https://pagure.io/fesco/issue/3106#comment-885162) by @gotmax23, and considering `llhttp`’s status as a low-level dependency with high security relevance (as its purpose is to parse potentially-untrusted HTTP), this ticket asks FESCo whether `llhttp` should be granted a [categorical exception](https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/#_other_packages) for such updates. Good practice would still imply that such updates should avoid *unnecessary* incompatibilities, and should avoid breaking dependent packages (e.g. by updating or rebuilding them in the same side tag and Bodhi update). It’s not possible to predict how many—if any—such updates might be required in the future. If this exception is not granted, then any similar updates that might be required in the future would be handled via case-by-case exception requests; this means more things that FESCo might need to consider and vote on, but would be perfectly feasible. I’m not *personally* strongly invested in a particular outcome to this ticket.
Owner

+1

+1
Owner

+1

+1
Owner

+1

+1
Owner

+1

+1
Owner

Metadata Update from @ngompa:

  • Issue tagged with: updates policy exception
**Metadata Update from @ngompa**: - Issue tagged with: updates policy exception

+1

+1
Owner

+1

+1
Author

It looks like this will be approved, so here’s a PR to update documentation once voting has ended.

https://pagure.io/fesco/fesco-docs/pull-request/82

It looks like this will be approved, so here’s a PR to update documentation once voting has ended. https://pagure.io/fesco/fesco-docs/pull-request/82
Owner

After a week: APPROVED (+6, 0, 0)

I'll add the announcement to today's agenda.

After a week: APPROVED (+6, 0, 0) I'll add the announcement to today's agenda.
Owner

Metadata Update from @zbyszek:

  • Issue close_status updated to: Accepted
  • Issue status updated to: Closed (was: Open)
**Metadata Update from @zbyszek**: - Issue close_status updated to: Accepted - Issue status updated to: Closed (was: Open)
Sign in to join this conversation.
No milestone
No project
No assignees
7 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
fesco/tickets#3115
No description provided.