Re: [Security-Discuss] spamassassin

Michael Scherer <[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On Wednesday 18 May 2005 21:08, Dieter Schütze wrote:
> Am Dienstag, den 17.05.2005, 19:33 -0400 schrieb Stew Benedict:
> > On Tue, 17 May 2005, Dieter [ISO-8859-1] Schtze wrote:
> > > Hi,
> > > the next question.
> > > Whats about spamassassin ?
> > > there is the 3.0.3 since 28th of April out with bug fixes.
> > > http://spamassassin.apache.org/full/3.0.x/dist/Changes
> > >
> > > LE2005 main tree 3.0.2-2  no updates
> >
> > If your intent is to troll, you're just wasting everyone's time.
> > All software has bugs. We don't update every package for a given
> > release just because something newer came out. When we do release
> > updates, they are generally backported fixes (there are
> > exceptions), and whether updates are released is gauged against the
> > severity of the issue at hand.
> >
> > This is the update policy as has already been explained to you by
> > Vincent.
>
> It is very interesting how you treated the people here.

I think stew was polite, and I can perfectly understand that answering 
the same question over and over, especially for a policy that is here 
since the beginning is annoying.

> I don't think that this is good for mandriva because the list is open
> and everyone can read.

Almost everyone know that main doesn't get new version updated.
This is a basic of distribution building and quality assurance.

Even a simple rebuild can change a lot of thing, see :
http://qa.mandriva.com/show_bug.cgi?id=9167
http://qa.mandriva.com/show_bug.cgi?id=9101

The only thing I did was to rebuild apache, it took 2 months to find the 
bugs, to reproduce, to understand, and to correct it. 
And the package was heavily tested by the QA before being uploaded, as 
we were in freeze. Of course, it worked fine on the various test 
machines, as one of the bug was triggered by by a special combination 
of cpu/kernel ( ie a old kernel ).

So no, simply rebuilding can introduce bugs, and require a fair amount 
of testing. 

Since the distribution is tested by the whole community for 6 months, 
especially during the last month, I fail to see how you can achieve the 
same result with a much smaller team, in a more limited period of time.

Unless there is a good reason ( critical bug fix, security fix ), 
package are not be rebuild ( or not in a official way ).

Since you failed to prove there is a critical bug fix or a security 
problem ( security from the distribution point of view, as explained in 
another mail ), there is no official updates. 

The issue of security update vs version update was already discussed by 
the past, either here on on other lists, even for other distribution, 
and I am pretty sure you can find if you seek.

Having rebuild and test made by the community, in a unofficial way 
( like backport.zarb.org ) could be acceptable, since 

1) no one will blame mandriva about problem
2) people will be able to revert to the old rpm in case of problem


> The only who have send me good information on a simple question was
> Michael a person without a mandriva.com address.

Not posting with a mandriva.com address doesn't mean you do not have one 
( I no longer have one in .com, but in .org ) or you are not involved 
in the developement.

> So, what can i think about this ?

That I have more time than stew and vincent to answer mail, because I do 
this after my work hours.

> I don't no what your intention is.
>
> Regards
>
> Dieter Schütze

-- 
Michaël Scherer

On the importance to respond to proposal email :
http://www.nntp.perl.org/group/perl.bootstrap/1127
message.footer (text/plain, 239 B)
____________________________________________________
Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.