5 ms·
It's OK to have your own definition of what 'stable' software is. For some folks, its what's on the master branch of the repo, for others its software that's be
by click170 11y ago
It's OK to have your own definition of what 'stable' software is. For some folks, its what's on the master branch of the repo, for others its software that's been tested for years by a large community already.
Debian has a specific documented process of how their stable releases are produced, and though that can cause problems for some developers because they get bug reports for old versions, that specific documented process is part of what makes Debian special to me.
I sympathize with devs for having to put up with those bug reports, but putting messages into the software to specifically goad the OS package maintainers is just poor form. Surely there's a better way to have handled that.
- rossy 11y agoI feel like it's possible to be wrong about your definition of stable software though. Software is not like wine. It doesn't become better just from leaving it alone for a few years. In fact, all software has bugs and developers are constantly struggling to fix them. In the case of a screen-locker like XScreenSaver, it's also security-critical software, so the developer(s) are constantly in a race against people who want to exploit the bugs. Using a version from 2014 instead of the latest stable version is not just a opinion/preference, it's a bad idea, and I think jwz is totally right in saying that it's better Debian don't package it at all than package an old version.
- caf 11y agoThe Debian maintainers do backport security fixes to the older version they're shipping, though. Eg. for the package in question here we have: xscreensaver (5.30-1+deb8u1) jessie-security; urgency=medium * Add upstream patch for "xscreensaver aborts when unplugging second monitor" security issue (closes: #802914) http://www.openwall.com/lists/oss-security/2015/10/24/2 -- Tormod Volden <debian.tormod@gmail.com> Sun, 25 Oct 2015 11:35:52 +0100 Keeping the old version isn't supposed to imply "it has no bugs" - instead, it's based on the idea that "if if works for you now, it will continue to work for you". In other words, you can be reasonably sure distribution point updates won't break anything that you're relying on.
- vacri 11y agoGiven that this is a saga that's been going on for years, I wonder why debian hasn't just put it into stable-backports?
- ashitlerferad 10y agoYou might want to read the response, there were no changes worth backporting.
- ashitlerferad 10y agoIf you actually look at the changes to xscreensaver upstream (as the Debian xscreensaver maintainer did), you will see that most of the changes only mattered for iOS users so there was little point updating to the latest version, apart from the security fix, which was backported quickly.
- drewcrawford 11y agoSuppose for a minute that it is legitimately impossible to have a secure screensaver older than 6 months. Like, we live in a universe where either we can have secure screensavers, or we can have Debian stable, but not both. What we have in this situation is an engineer–as far as I can tell, an engineer on the short list of "world experts in lockscreen security"–who earnestly believes that our universe operates in exactly this way. What is a reasonable thing to do–short of warning end users, which apparently is immature in your mind–to prevent what he believes, as a subject matter expert, to be a major and ongoing security vulnerability waiting to happen? Should he have released under a non-DFSG license so as to prevent Debian from packaging the software at all? Or should he have politely written to the Debian maintainer asking for its removal from Debian? Should he have gotten into the Debian politics and lobbied for the "special exceptions" that iceweasel etc. enjoy to get frequent updates? Should he have taken it upon himself to backport security fixes to Debian, RHEL, etc? I sympathize with the OS package maintainers, but I sympathize more with someone who found himself trapped between his commitment to software freedom and his commitment to keeping his users secure.
- vacri 11y ago> found himself trapped between his commitment to software freedom and his commitment to keeping his users secure. It's more about the spam for already-fixed features than the love of keeping users secure. jwz also isn't exactly fair in his characterisations in the article. Things like "taking advantage of a creator's work, ignoring their wishes, and giving nothing back in return." when the explicit problem is that they're giving back, just not in the right manner. That's just the way jwz rolls, though... It would be wrong for debian to remove the warning, though, since it's there specifically for debian users; they're not 'collateral damage' from an unrelated change or similar.
- drewcrawford 11y ago> It's more about the spam for already-fixed features than the love of keeping users secure. I realize this is the reason presented in the comment, but after I dug into his statements elsewhere, I developed a different picture. Anyway, there's no law that says a comment must present every argument why the code exists. To step back a minute, I seem to be seeing the same facts very differently. Where some see an immature attempt to annoy users, I see a demonstration that Debian is unable to spot a bug when it has a 50-line comment above it complaining that Debian doesn't fix bugs. To me, the very existence of this situation itself is a powerful argument against Debian stable as a working concept. Most of the time a bug is introduced it does not announce itself with a preamble. How the hell did this make it all the way to stable?