Re: [blfs-support] protobuf-33.0
"Rainer Fiebig" ([email protected] via blfs-dev Mailing List) <[email protected]> Sun, 19 Oct 2025 14:26:31 +0200
| Newsgroups | gmane.linux.lfs.beyond.devel |
|---|---|
| Message-ID | <[email protected]> |
Am 18.10.25 um 18:11 schrieb Bruce Dubbs ([email protected] via blfs-dev Mailing List): > On 10/18/25 4:31 AM, Rainer Fiebig ([email protected] via blfs-dev Mailing > List) wrote: >> Am 17.10.25 um 21:44 schrieb Rahul Chandra ([email protected] via >> blfs-support Mailing List): >>> On Fri, Oct 17, 2025 at 9:00 AM Bruce Dubbs >>> <[email protected]> wrote: >>>> >>>> I updated to protobuf-33.0 yesterday, but checking md5sums today I >>>> found that >>>> upstream made a 'stealth' update. That is, they changed the tarball >>>> without changing >>>> the version number. >>>> >>>> One file was changed. >>>> >>>> I've updated the book, but it will not render until early tomorrow >>>> morning. >>>> >>>> The updated md5sum is 936b48fdf816b0341c74ba73a42348c0. Nothing >>>> else changed. >>> >>> >>> I can't seem to find the original file but if you still have it can >>> you extract and diff -Naur them, might just be my paranoia talking but >>> we don't want to end up with another xz scenario. If that's what you >>> meant by nothing else changed then ignore this message. >> Paranoia is not always bad. Andy Grove once put it this way: "Only the >> paranoid survive." Intel should have heeded that. >> >> Anyway - I share your qualms about this incident and I'm a bit appalled >> how something like this seems to be just shrugged off in this thread. > > It wasn't just shrugged off in this thread. I found the problem a day > after I updated the book to version 33.0. It is a part of our QA process. That's good and you deserve credit for it. But I still find the reaction to this serious incident rather lame and more like "So what?" instead of "Unacceptable!". And "unacceptable" it was, because issuing a release and then _stealthily_ modifying its content stinks and borders on willful deceit, at least in my view. > > I checked it out and found it not harmful. I then updated the book for > the change and made an announcement here. Right, but those were only internal measures to sort of counterbalance/mitigate seriously bad behaviour of others. And thus unlikely to have any bearing on future behaviour. But what the protobuf-project did is unacceptable, harmful or not. It's not a pettiness. And IIRC this is not the first incident of this kind ("stealth update"). Thus I would have appreciated a much tougher reaction to this and similar incidents: - make the project aware that this has not gone unnoticed and is deemed serious and unacceptable for obvious reasons - that they did a disservice to opensource in general - that in case of recurrence the project will be expelled from LFS/BLFS with users being notified about the reason for it BTW: I took a look at protobuf's "Code of Conduct" [1]: "Examples of unacceptable behavior include:" [...] Other conduct which could reasonably be considered inappropriate in a professional setting" But maybe they have their own idea of "unacceptable" or "inappropriate". Thanks. Rainer [1] https://github.com/protocolbuffers/.github/blob/main/profile/CODE_OF_CONDUCT.md -- http://lists.linuxfromscratch.org/sympa/info/blfs-dev Unsubscribe: See the above information page