Re: Security Updates in Slackware64-14.2

Robby Workman via slackware <[email protected]> Tue, 7 Nov 2017 19:50:56 -0600
Newsgroups gmane.linux.slackware
Organization Generally OCD
Message-ID <[email protected]>
On Tue, 7 Nov 2017 21:35:19 -0400
Ed Fletcher via slackware <[email protected]> wrote:

> On 11/07/2017 08:03 PM, Robby Workman via slackware wrote:
> > On Tue, 7 Nov 2017 19:42:23 -0400
> > Ed Fletcher via slackware <[email protected]> wrote:
> >   
> >> I just did an install of Slackware 64 14.2 on a spare box.  I'd
> >> looked at slackware64-14.2/FILELIST.TXT
> >> on my local mirror and saw
> >> mozilla-firefox-52.4.0esr-x86_64-1_slack14.2.txz
> >> as one of the listed files.  So I checked a couple of other
> >> security updates and they were included too.  This led me to
> >> believe that I would have an up-to-date and secure install.
> >>
> >> However, when I finished and fired up Firefox, I found that I had
> >> 45.2.0 instead of the newer version.  So I checked
> >> slackware64-14.2/source/FILE_LIST
> >> and, sure enough, it lists
> >> mozilla-firefox/firefox-45.2.0esr.source.tar.xz.
> >> And
> >> slackware64-14.2/slackware64/FILE_LIST
> >> says v45 also.
> >>
> >> A bit more checking confirmed that none of the security updates are
> >> installed.
> >>
> >> So what is the FILELIST.TXT in the main directory telling me?  And
> >> do I have to install 16 or 17 months worth of security updates?
> >> Because I'd rather switch to Slackware64-current and save myself
> >> the work.  
> > 
> > 
> > Unless you've taken some sort of explicit action to install the
> > post-release packages, then they're not installed. The installer
> > doesn't install those when the OS is first installed, even though
> > one could perhaps argue that it should (at least offer the option
> > to) do so.
> > 
> > In short, your next move is up to you. I don't think a migration
> > to -current is the best one at this time, but that's of course
> > your call.
> > 
> > I personally use slackpkg to keep the systems for which I'm
> > responsible up to date, but there are other options as well.
> > 
> > -RW
> >   
> 
> Yep, slackpkg did the trick.  I'd looked at that before but never got 
> around to trying it.  It's pretty slick.  Thanks!


Well, there's a newer version in -current, and while it's not 
normally recommended to put -current packages on a 14.2 system,
it would be fine in this case. 

On a related note, I've sorta-assumed maintenance of slackpkg
since PiterPUNK has been largely absent for a long time now,
and I've tried to keep the releases on slackpkg.org in sync
with the Slackware -current tree [1].  More importantly, I've
set up a git repo [2] for slackpkg and just pushed a 2.82.3beta1 
release [3] - the only notable change since 2.82.2 is the 
ability to use vimdiff for comparison of changes in .new files.

[1] https://slackpkg.org/stable/
[2] https://git.rlworkman.net/slackpkg/
[3] https://slackpkg.org/beta/slackpkg-2.82.3beta1-noarch-1_rlw.txz

-RW

-- 
slackware mailing list
[email protected]
https://mailman.lug.org.uk/mailman/listinfo/slackware