Re: Do we need to hide packages in NEW queue
- To: debian-devel@lists.debian.org
- Subject: Re: Do we need to hide packages in NEW queue
- From: Russ Allbery <rra@debian.org>
- Date: Mon, 31 Jan 2022 19:46:37 -0800
- Message-id: <[🔎] 87k0efi6zm.fsf@hope.eyrie.org>
- In-reply-to: <[🔎] 61F8A7B9.9080207@fastmail.fm> (The Wanderer's message of "Mon, 31 Jan 2022 22:23:37 -0500")
- References: <YeqL7XiE1Q9PCzWm@an3as.eu> <ae00554c41106cb34b2e5caf0d7468a8d5bffec8.camel@debian.org> <m3bkzzh7py.fsf@debian.org> <164314389064.312615.9222305474885608025@auryn.jones.dk> <87k0enij6g.fsf@hope.eyrie.org> <YfDsUuoNpxK+5WT6@an3as.eu> <20220130192552.7672bc28292279ba3de5b234@paranoici.org> <87a6fdnhk1.fsf@hope.eyrie.org> <CAKZYK4-xjsbQg6O-gd_RbG-cCpSVi8YD1QxpG0gs3kfocPNqtw@mail.gmail.com> <E1nEUUt-008AF8-PW@drop.zugschlus.de> <87r18ndd5p.fsf@hope.eyrie.org> <[🔎] 61F8A7B9.9080207@fastmail.fm>
The Wanderer <wanderer@fastmail.fm> writes:
> I am not on the inside of these things, certainly, but I have kept my
> eyes open from the outside, and I am not aware of there being any
> mechanism for removing something root-and-branch - across all affected
> versions, however far back those may stretch - from these repositories
> and archive locations once it's made it in. In order to avoid continuing
> to distribute something which we once accepted but which has since been
> deemed legally undistributable (and thus exposing ourselves to
> copyright-infringement lawsuits), we would need to have such a
> mechanism.
The thing is, we need this anyway for something we would legally need to
stop distributing, since otherwise we would be expecting ftp-master review
to be perfect *and* to never introduce unredistributable content in a
package update that doesn't go through NEW. I don't think either of those
are realistic (or fair) expectations.
Now, we could defer creating such a thing until we actually need it and
then try to come up with something under emergency circumstances, and
maybe we'd get lucky and never need it. But I think that's also true in
either scenario. I'm not sure that the ftp-master review reduces the
likelihood so much as to change the risk analysis that much. (But that
could well be a point of disagreement.)
--
Russ Allbery (rra@debian.org) <https://www.eyrie.org/~eagle/>
Reply to: