removing support for interop with unison before 2.52.0
Greg Troxel <[email protected]> Sun, 01 Mar 2026 07:57:09 -0500
| Newsgroups | gmane.network.unison.general |
|---|---|
| Message-ID | <[email protected]> |
It's time for (meteorological) spring cleaning. There has been very recently ocaml security advisories about the builtin marshaling code -- used by the old protocol. That's not a unison bug, and everyone using ocaml should be updating to a fixed version. https://urldefense.com/v3/__https://seclists.org/oss-sec/2026/q1/231__;!!IBzWLUs!Ud_l9CHqCYEHsM8pDw0i7Xda2cBVGzrNN8lXiubRH91tVVX2lIvPfqnyWxP8nF6KrcRsSrqoC61IyU3V8A$ 2.52.0 was released on March 11, 2022, which will shortly be 4 years ago: https://urldefense.com/v3/__https://github.com/bcpierce00/unison/releases/tag/v2.52.0__;!!IBzWLUs!Ud_l9CHqCYEHsM8pDw0i7Xda2cBVGzrNN8lXiubRH91tVVX2lIvPfqnyWxP8nF6KrcRsSrqoC621r13H8g$ That brought a new wire protocol, and compat to use the old protocol when interoperating with pre-2.52.0 unison (which needs compatible ocaml versions). Now, everyone should have updated, so I believe there is no usefulness to having the compat code operational. Thus, I am thinking of a new unison release with it disabled. Is anyone using the compat code? If so, are there reasons other than "I could update but I haven't" or "my distribution/packaging-system has super old unison and I could update or switch distributions but I haven't"? To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].