Re: [blfs-support] protobuf-33.0

"Rainer Fiebig" ([email protected] via blfs-dev Mailing List) <[email protected]> Sun, 19 Oct 2025 14:26:31 +0200
Newsgroups gmane.linux.lfs.beyond.devel
Message-ID <[email protected]>
Am 18.10.25 um 18:11 schrieb Bruce Dubbs ([email protected] via
blfs-dev Mailing List):
> On 10/18/25 4:31 AM, Rainer Fiebig ([email protected] via blfs-dev Mailing
> List) wrote:
>> Am 17.10.25 um 21:44 schrieb Rahul Chandra ([email protected] via
>> blfs-support Mailing List):
>>> On Fri, Oct 17, 2025 at 9:00 AM Bruce Dubbs
>>> <[email protected]> wrote:
>>>>
>>>> I updated to protobuf-33.0 yesterday, but checking md5sums today I
>>>> found that
>>>> upstream made a 'stealth' update.  That is, they changed the tarball
>>>> without changing
>>>> the version number.
>>>>
>>>> One file was changed.
>>>>
>>>> I've updated the book, but it will not render until early tomorrow
>>>> morning.
>>>>
>>>> The updated md5sum is 936b48fdf816b0341c74ba73a42348c0.  Nothing
>>>> else changed.
>>>
>>>
>>> I can't seem to find the original file but if you still have it can
>>> you extract and diff -Naur them, might just be my paranoia talking but
>>> we don't want to end up with another xz scenario. If that's what you
>>> meant by nothing else changed then ignore this message.
>> Paranoia is not always bad.  Andy Grove once put it this way: "Only the
>> paranoid survive."  Intel should have heeded that.
>>
>> Anyway - I share your qualms about this incident and I'm a bit appalled
>> how something like this seems to be just shrugged off in this thread.
> 
> It wasn't just shrugged off in this thread.  I found the problem a day
> after I updated the book to version 33.0. It is a part of our QA process.
That's good and you deserve credit for it.  But I still find the
reaction to this serious incident rather lame and more like "So what?"
instead of "Unacceptable!".  And "unacceptable" it was, because issuing
a release and then _stealthily_ modifying its content stinks and borders
on willful deceit, at least in my view.

> 
> I checked it out and found it not harmful.  I then updated the book for
> the change and made an announcement here.
Right, but those were only internal measures to sort of
counterbalance/mitigate seriously bad behaviour of others.  And thus
unlikely to have any bearing on future behaviour.

But  what the protobuf-project did is unacceptable, harmful or not.
It's not a pettiness.  And IIRC this is not the first incident of this
kind ("stealth update").  Thus I would have appreciated a much tougher
reaction to this and similar incidents:
- make the project aware that this has not gone unnoticed and is deemed
serious and unacceptable for obvious reasons
- that they did a disservice to opensource in general
- that in case of recurrence the project will be expelled from LFS/BLFS
with users being notified about the reason for it

BTW: I took a look at protobuf's "Code of Conduct" [1]:

"Examples of unacceptable behavior include:"

    [...]
    Other conduct which could reasonably be considered inappropriate in
a professional setting"

But maybe they have their own idea of "unacceptable" or "inappropriate".

Thanks.

Rainer


[1]
https://github.com/protocolbuffers/.github/blob/main/profile/CODE_OF_CONDUCT.md

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-dev
Unsubscribe: See the above information page