Re: KDE Security/Packaging fails us again

Rob Kaper <[email protected]> Wed, 14 Jan 2004 17:39:26 +0100
Newsgroups gmane.comp.kde.cafe
Message-ID <[email protected]>
On Wed, Jan 14, 2004 at 10:26:50AM -0600, Andreas Pour wrote:
> KDE is not responsible for them, as they are provided by third parties, but KDE
> does *coordinate* with the packagers.

Then perhaps we should be less submissive.

> They don't affect the cycle but do (somewhat) affect the release *date*.  E.g.,
> standard practice is to permit the distributors one week to package a release
> (hence the standard practice is to announce a release 1 week after the source
> tarball is ready).  In fact it often turns out that the packaging process
> reveals bugs and compile problems and so this ends up also being a 1-week
> bug-testing period.

Four weeks isn't one week. Last time, five weeks, after a vulnerability had
been dormant at SuSE for half a year, wasn't one week either.

> The packagers are not "ours" but work for the major distributors (and not just
> the commercial ones; Debian and Fedora, e.g., are included).  In this case quite
> a few of them were too busy w/ other pre-year-end work and they requested an
> extension to complete the packaging (and actually the timeline you quoted is
> incomplete, while the original tarballs were ready on Dec. 18 there was a
> packaging bug in it - only a few translations were included and then although
> this was fixed by Dec. 22 there were some additional compile issues with the
> tarballs - and the final tarball was not uploaded by the RC for the packagers
> until Jan. 7 (you can see also from ftp://ftp.kde.org/pub/kde/stable/3.1.5/src/
> that kdebase is dated Jan. 2 and the other packages Dec. 28).
> 
> Perhaps you might update your blog entry to reflect these facts :-).

I'll be glad to do so, as they in fact illustrate the problem. It's just
another list of unnecessary delays. I know that Debian tends to release
security updates by patching their existing releases, so the entire
translation/packaging hoopla can be removed from the process.

I don't care if it takes a week to package an entire KDE release, I just
don't think it's necessary to package an entire KDE release for a security
fix, precisely *because*, as you've elaborated, it introduces errors and
delays all over.

Rob
-- 
Rob Kaper     | Fate fell short this time, your smile fades in the summer
[email protected] | Place your hand in mine, I'll leave when I wanna
www.capsi.com |   -- "Feeling This", Blink 182
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQFABXC+tppIl2G1SjcRArnqAJ9u81s9tZixCDca/DHGVwLrS74atgCgpZxD
VAVkL6HYEObntfIUZ+FSvEU=
=Lwhv
-----END PGP SIGNATURE-----