3 ms·
The real bug here is not having a test for this, or not running the tests as part of the packaging process. We should not have situations where packages are so
by ris 5y ago
The real bug here is not having a test for this, or not running the tests as part of the packaging process. We should not have situations where packages are so sensitive that a small change to them should be considered unsafe. Open Source is pointless if your source is regarded as immutable. If there is a subtle detail like this (and sometimes it's unavoidable), it should be covered by a test so that ensuring the end result is "ok" is nothing more than seeing the tests pass.
I'm not going to weigh in on which party should be responsible for that test.
- Jasper_ 5y agoUnfortunately, Debian will sometimes also patch the package to remove failing tests, not understanding that it is a security issue. This is not the first time this has happened.
- ris 5y agoThis is also sometimes unavoidable because not all test suites are built very robustly. One often comes across projects with test suites that the author only intended for their own use and doesn't care if it fails on other peoples systems.