Re: Why back-porting patches to stable instead of releasing a new package.
On Sat, Aug 16, 2003 at 12:38:00PM -0400, Matt Zimmerman wrote:
> So if maintainers prepare thoughtful updates for stable, with clear and
> documented changes which fix real bugs and nothing more, then we should
> accept them into stable?
> 
> That is what proposed-updates is.  Most maintainers don't use it.
Probably because most users don't use it.  Seriously, maybe better
use of proposed-updates is all I'm asking for.  If there is a good
policy for proposed-updates (and your wording looks fine) and it is
publicized, then users can decide which to use, and we can learn by
experience which tends to work better for whom.
> For almost every bug we have fixed in woody, even if we had somehow pushed
> every upstream change into stable since it was released, we would still have
> been vulnerable.  Security researchers, of all kinds, can and do find new
> bugs all the time.
That's partly because security researchers generally look for new
bugs, and most security advisories come from the proactive work of
researchers (as opposed to reaction to exploits).
If I'm a bad guy, I think I'd first try the publicized holes.  If
the target machine applies his patches, the next thing I'd try is
"overlooked" bugs, the ones I'm talking about.  Only if that failed
would I try to find a new hole.
This is all very hypothetical, I grant, but my gut tells me it's a
problem.
> The urgency of a bug does not, in general, bear any direct relationship to
> its age.  Consider the local root vulnerabilities in the kernel which
> existed from 2.2 through 2.4.  If the bug is significant enough to warrant a
> fix in stable, please send a note to team@security.debian.org with the
> details.
Done.
Andrew
Reply to: