Re: DHCP server bug (miscompiled by GCC compiler)

Milan Keršláger <[email protected]> Sun, 11 Sep 2005 08:08:57 +0200
Newsgroups gmane.linux.tao.general
Message-ID <[email protected]>
On Fri, Sep 09, 2005 at 10:30:07AM -0500, Ed Wilts wrote:
> > Sure, it's right there in the bug report:
> > The dhcp-3.0.1-12_EL package was built on Nov 17th 2004,
> > with compiler 3.4.3-2.EL4 and that is the version that 
> > was tested, when no such problems were found .
> > 
> > That compiler isn't available anywhere I can find, though it might have
> > been in RHEL4 beta1 (RHEL4 b2 had gcc-3.4.3-9, which has the bug).
> 
> Interesting.  I've heard claims before that a rebuild of the sources
> doesn't necessarily get you the equivalent of the binaries because you
> can't guarantee the build order but I didn't realize that Red Hat used
> compilers that weren't publicly available.  I thought it was FUD before
> but I guess it really is true that the rebuilds aren't bug for bug
> compatible.
> 
> Not that it bothers me much but I like to have all the facts in hand if
> I can.  

RH did not guarantee the system is self-hosting (read: is able to build
itself) because they needs reasonable QA and once a package passed QA,
should not be rebuild as if it is, new QA cycle is needed.

This mean that every bugfix and subsequental rebuild of all packages
mean new full QA cycle. This is not possible so some packages are pretty
old (if they are not updated they did not become rebuilded since last
change as passed QA in their "old" state).

RH has a build farm and this is possible (especially before the new
release) that some of the building machines has "hot fixes" to be able
to build packages without bugs... and when official GCC fix hit the
public, this is possible that some of the fixes may introduce new
[hidden] bugs).

-- 
                        Milan Kerslager
                        E-mail: [email protected]
                        WWW:    http://www.pslib.cz/ke/