[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Fwd: [Announce] Samba 4.6.1, 4.5.7 and 4.4.12 Security Releases Available for Download



On Tue, Mar 28, 2017 at 10:18:07PM +0200, Mathieu Parent wrote:
> 2017-03-28 21:07 GMT+02:00 Ola Lundqvist <ola@inguza.com>:
> > Hi Mathieu and Roberto
> 
> Hi,
> 
> > Mathieu, do you mean that they patches should apply cleanly and if they do
> > not, then we have missed some other important patch, or do you just mean
> > that they should generally apply cleanly?
> 
> I don't know for sure, but I think that if a hunk doesn't apply it is
> an indication of
> a change that may be a requirement.
> 
> For Roberto question on patch not applicable can be explained by:
> https://git.samba.org/?p=samba.git;a=commitdiff;h=8234c6a3c7
> 
> This doesn't look to be a requirement (not related to path traversal).
> 
I agree that it does not appear related.

> > I'm asking as it is rather expected that patches do not apply cleanly when
> > we are dealing with these old versions in wheezy. I do not want to give a
> > precise estimate but something between 20 and 60% of the patches that I have
> > applied to the packages I have done updates to in wheezy have not applied
> > cleanly. Usually it is just minor things, but in some cases quite a lot of
> > work have to be put in understanding the problem and finding out a new fix.
> >
> > We should not be afraid to do that kind of work.
> >
> > We do have the possibility to update to the latest software also in wheezy
> > but that should really be done as a last resort, or only for packages that
> > have a very good reputation on backwards compatibility. At least that is how
> > I have understood the current practices. I mean we do not want to introduce
> > unnecessary regressions.
> 
> The 3.6 branch was in maintenance mode since 2012-12-11, i.e after 3.6.10.
> So it is probably better to only cherry-pick the fixes and continue
> like Roberto did.
> 
OK.  I will continue working on integrating the patch from upstream.

> I can help the testing.
> 
I will announce when I have packages available for testing.

Regards,

-Roberto

-- 
Roberto C. Sánchez
http://people.connexer.com/~roberto
http://www.connexer.com


Reply to: