Especially because the fix is so tiny and can easily be applied to any affected apt version, and I only know three distributions shipping a self-built apt (Debian, Ubuntu, Tanglu), I'd like to get this rolled out in the next 34 hours basically (until Wed 23:59 CET). I'd be happy extending that to Thu 23:59 CET if that gets a few more distros on board that for whatever reasons ship a self-built apt. But I would not want to hold a fix for Debian and Ubuntu back for longer than that to give 1% or so the time to fix up things, as that would be irresponsible.
Release procedure:
For yakkety, the fix will be a new 1.3.2 "upstream" micro release containing just that fix, so I'll just provide a debdiff for that.
For xenial, there will be a new 1.2.18 upstream micro release, but as 1.2.17 is stuck in the queue for proposed, I can also provide a 1.2.15ubuntu0.1 (did I get that right?) debdiff for security. Once the security upload has been done, I'll replace 1.2.17 with 1.2.18 in the proposed queue.
For trusty, I will provide a debdiff for 1.0.1ubuntu2.16.
Especially because the fix is so tiny and can easily be applied to any affected apt version, and I only know three distributions shipping a self-built apt (Debian, Ubuntu, Tanglu), I'd like to get this rolled out in the next 34 hours basically (until Wed 23:59 CET). I'd be happy extending that to Thu 23:59 CET if that gets a few more distros on board that for whatever reasons ship a self-built apt. But I would not want to hold a fix for Debian and Ubuntu back for longer than that to give 1% or so the time to fix up things, as that would be irresponsible.
Release procedure:
For yakkety, the fix will be a new 1.3.2 "upstream" micro release containing just that fix, so I'll just provide a debdiff for that.
For xenial, there will be a new 1.2.18 upstream micro release, but as 1.2.17 is stuck in the queue for proposed, I can also provide a 1.2.15ubuntu0.1 (did I get that right?) debdiff for security. Once the security upload has been done, I'll replace 1.2.17 with 1.2.18 in the proposed queue.
For trusty, I will provide a debdiff for 1.0.1ubuntu2.16.