Re: [Security-Discuss] Firefox Backport Request to 10.1
Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On 16-May-05, at 2:49 PM, Joe Baker wrote:
>> The updates for this are exists
>> http://www.mandriva.com/security/advisories?name=MDKSA-2005:088
>>
>> Are you not in the mailing list for security updates ?
>>
>>
>>
> I did see the security update email message. And I noticed that
> Firefox was not listed in the Mandrake 10.1 stanza. I'll be happy
> to add the macro that was mentioned in an earlier thread and try
> recompiling the source for the 10.2 version in my 10.1
> environment. I had found a Firefox package for 10.1 on
> rpm.pbone.net that had been packaged by H.J. Heines of the NL
> Mandrakeclub.
>
> Our organization is persuing a migration strategy from Windows
> desktops to the LTSP approach on Linux. Our Terminal server is
> presently running Mandrake 10.1. Mozilla Firefox has been chosen
> as our company's preferred web browser for at least 8 months now.
> This standard browser makes one less application users need to
> learn when switching from Windows to Linux.
>
> My concern with purchasing Mandrake's Corporate Desktop server is
> that Mandriva's adoption of new programs and upgrades of existing
> programs might not keep up with the pace of the developers.
It doesn't. That's what new releases are for.
> In other words, Firefox is an awesome web browser and Mandriva
> should be releasing new versions of it for old versions of the
> Mandrake operating system that are still supported.
No. Firefox was in contribs prior to LE2005... contribs is not
supported. Mozilla is what was used, so that is what got updated.
> Open Office is another example.
>
> I saw the Open Office.org security release about Mandrake's updated
> packages for OOo. The security patch was backported to 1.1.3! Why
> didn't you simply bring forward 1.1.4 into the Mandrake 10.1 and
> 10.0 environments?
Because there could potentially be conflicts and other regressions
for things that require specific versions of OpenOffice.org. It's
been policy for years to backport patches whereever possible... the
exception to the rule being applications where the backporting is far
too intrusive.
> Is there any work going on that would streamline the update
> download process to using diff files? Consider the recent Open
> Office upgrade was basically the changing of a single file If I
> read OOo's security announcement correctly.
Yup, you're right. Work is going on for a binary delta format for
rpms (IIRC, but I'm not a developer). I'm hoping to see something in
place for the 2006 version. Trust, me I don't like uploading these
GB of data.
You'd have to ask on cooker for more details about this. I heard
about it, but largely ignored it until it affects me.
> Well I hope to upgrade to Mandriva 2005 LE on our Terminal Server
> soon anyway, but you can imagine the precautions I take, backing up
> the drives, then testing the resulting system to make sure
> everything from Samba to KDM to VMWare to nfs, to X font servers
> are running properly after the upgrade. Determining if the system
> is workable and then rolling back to the backup if it isn't fixable.
>
> The enterprise version of Mandriva must also integrate Gnome 2.10.1
> also before we will buy it.
Looks like it has GNOME 2.4. I can almost guarantee you that
Corporate Desktop will never have GNOME 2.10.1 (except for a newer
version). The current version won't get that update (it would cause
probably half the distro requiring to be rebuilt).
> Forgive my at length discussion, but you have my attention, and we
> are seriously considering your business offerings, I hope you will
> seriously consider our feedback.
I'm sorry I can't give you a more positive response on this.
--
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig
(application/pgp-signature, 186 B) - not displayed