Re: KDE Security/Packaging fails us again
Rob Kaper <[email protected]> Wed, 14 Jan 2004 17:39:26 +0100
| Newsgroups | gmane.comp.kde.cafe |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Jan 14, 2004 at 10:26:50AM -0600, Andreas Pour wrote: > KDE is not responsible for them, as they are provided by third parties, but KDE > does *coordinate* with the packagers. Then perhaps we should be less submissive. > They don't affect the cycle but do (somewhat) affect the release *date*. E.g., > standard practice is to permit the distributors one week to package a release > (hence the standard practice is to announce a release 1 week after the source > tarball is ready). In fact it often turns out that the packaging process > reveals bugs and compile problems and so this ends up also being a 1-week > bug-testing period. Four weeks isn't one week. Last time, five weeks, after a vulnerability had been dormant at SuSE for half a year, wasn't one week either. > The packagers are not "ours" but work for the major distributors (and not just > the commercial ones; Debian and Fedora, e.g., are included). In this case quite > a few of them were too busy w/ other pre-year-end work and they requested an > extension to complete the packaging (and actually the timeline you quoted is > incomplete, while the original tarballs were ready on Dec. 18 there was a > packaging bug in it - only a few translations were included and then although > this was fixed by Dec. 22 there were some additional compile issues with the > tarballs - and the final tarball was not uploaded by the RC for the packagers > until Jan. 7 (you can see also from ftp://ftp.kde.org/pub/kde/stable/3.1.5/src/ > that kdebase is dated Jan. 2 and the other packages Dec. 28). > > Perhaps you might update your blog entry to reflect these facts :-). I'll be glad to do so, as they in fact illustrate the problem. It's just another list of unnecessary delays. I know that Debian tends to release security updates by patching their existing releases, so the entire translation/packaging hoopla can be removed from the process. I don't care if it takes a week to package an entire KDE release, I just don't think it's necessary to package an entire KDE release for a security fix, precisely *because*, as you've elaborated, it introduces errors and delays all over. Rob -- Rob Kaper | Fate fell short this time, your smile fades in the summer [email protected] | Place your hand in mine, I'll leave when I wanna www.capsi.com | -- "Feeling This", Blink 182
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQFABXC+tppIl2G1SjcRArnqAJ9u81s9tZixCDca/DHGVwLrS74atgCgpZxD VAVkL6HYEObntfIUZ+FSvEU= =Lwhv -----END PGP SIGNATURE-----