[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#220486: Acknowledgement (perl-suid: suidperl security)



Dear Matt,

>> Who/what is "upstream": perl5-porters, or the Debian maintainer? I still
>> hope to get somewhere with perl5-porters; the patches I submitted to
>> #203426 and #220486 are "proper" (so maybe permanent).
> 
> I'm not familiar with perl5-porters, but if they are the folks who decide
> what goes into the version of Perl that is the source for Debian and other
> vendors' perl packages, then yes, they are upstream.

That is right: perl5-porters is upstream from Debian. I find it puzzling
that Debian has used "known broken" patches (over and above the "upstream"
code), instead of the "proper" ones.

Cheers,

Paul Szabo - psz@maths.usyd.edu.au  http://www.maths.usyd.edu.au:8000/u/psz/
School of Mathematics and Statistics  University of Sydney   2006  Australia



Reply to: