5 ms·
Maybe this is the kick in the ass Debian needs to upgrade the embarrassingly ancient dnsmasq in "stable" because while I can't think of any new features, the la
by washingupliquid 5mo ago
Maybe this is the kick in the ass Debian needs to upgrade the embarrassingly ancient dnsmasq in "stable" because while I can't think of any new features, the latest versions contain many non-CVE bug fixes.
But I doubt it, they will lazily backport these patches to create some frankenstein one-off version and be done with it.
Before anyone says "tHaT's wHaT sTaBlE iS fOr": they have literally shipped straight-up broken packages before, because fixing it would somehow make it not "stable". They would rather ship useless, broken code than something too new. It's crazy.
- zrm 5mo agoThey're not going to put a newer version in stable. The way stable gets newer versions of things is that you get the newer version into testing and then every two years testing becomes stable and stable becomes oldstable, at which point the newer version from testing becomes the version in stable. The thing to complain about is if the version in testing is ancient.
- wolttam 5mo agoLooks like the version in stable is 2.91, which was released within a couple months of trixie. It's not 'ancient' by any stretch. FWIW the fixes referenced here are already fixed in trixie: https://security-tracker.debian.org/tracker/source-package/dnsmasq https://security-tracker.debian.org/tracker/source-package/d...
- braiamp 5mo agoYeah was about to comment, parent says "if it is ancient", it is not. So the root comment is nothing burger. Stable has 1 release cycle old, and depending on how things play out, testing may have 2.93 or later anyways.
- PunchyHamster 5mo ago2.92 currently
- koverstreet 5mo agoNo, that's exactly the thing to complain about. That whole model dates to before automated testing was even really a thing, and no one knew how to do QA; your QA was all the people willing to run your code and report bugs, and that took time. Not to mention, you think the C of today is bad? Have you looked at old C? And the disadvantage is that backporting is manual, resource intensive, and prone to error - and the projects that are the most heavily invested in that model are also the projects that are investing the least in writing tests and automated test infrastructure - because engineering time is a finite resource. On top of that, the backport model heavily discourages the kinds of refactorings and architectural cleanups that would address bugs systemically and encourage a whack-a-mole approach - because in the backport model, people want fixes they can backport. And then things just get worse and worse. We'd all be a lot better off if certain projects took some of the enthusiasm with which they throw outrageous engineering time at backports, and spent at least some of that on automated testing and converting to Rust.
- jeroenhd 5mo agoIf you want that, you don't want Debian. Other people do. Some people will even run Debian on the desktop. I would never, but some people get real upset when anything changes. Debian does regularly bring newer versions of software: they release about every two years. If you want the latest and greatest Debian experience, upgrade Debian on week one. From your description, you seem to want Arch but made by Debian?
- koverstreet 5mo agoWell, my workstation runs Debian sid, and all the newer stuff runs NixOS... But that does nothing for people who write and support code Debian wants to ship - packaging code badly can create a real mess for upstream.
- jampekka 5mo ago> From your description, you seem to want Arch but made by Debian? Isn't that essentially Debian unstable (with potentially experimental enabled)? I've been running Debian unstable on my desktops for something like 20 years.
- fulafel 5mo agoClose: New versions go in unstable where development happens, testing is where things go to marinate for a while.
- afarviral 5mo agoWhat if the new release which contains the fixes has new dependencies and those also have new dependencies? I assume they have to Frankenstein packages sometimes to maintain the borders of the target app while still having major vulns patched right in stable.
- wolttam 5mo agoI dunno, 2.92 seems to bring in some new features and changes that would not typically be brought into a stable release: https://thekelleys.org.uk/dnsmasq/CHANGELOG https://thekelleys.org.uk/dnsmasq/CHANGELOG
- lutoma 5mo agoFor what it's worth, Debian had a security update for dnsmasq yesterday, presumably to address this.
- rlpb 5mo ago> ...they have literally shipped straight-up broken packages before, because fixing it would somehow make it not "stable" Irrelevant strawman, since you're not accusing the dnsmasq package in Debian stable of being straight-up broken.
- asveikau 5mo agoYou can always ask the Debian project for your money back.
- deleted 5mo ago[deleted]
- ploxiln 5mo agoYou don't have to use Debian stable, if you'd prefer Ubuntu every 6 months, or Fedora (6 months? 9 months?), or even Arch Linux updated daily ... I use Arch on my laptop, when I got it 2 years ago the amd gpu was a bit new so it was prudent to get the latest kernel, mesa, everything. Since I use it daily it's not bad to update weekly and keep on top of occasional config migrations. I use Debian stable on my home server, it's been in-place upgraded 4-ish times over 10 years. I can install weekly updates without worrying about config updates and such. I set up most stuff I wanted many years ago, and haven't really wanted new features since, though I have installed tailscale and jellyfin from their separate debian package repos so they are very current. It does the same jobs I wanted it to do 8 years ago, with super low maintenance. But if you don't want Debian stable, that's fine. Just let others enjoy it.
- lmm 5mo agoThat's what stable is for though. Like, sure, stable's policy is ludicrous and you would have to be insane to run stable. But the remedy for that isn't to try to change Debian policy, it's to get people to stop running stable. Maybe once no-one uses it Debian will see sense.
- LtWorf 5mo agoYep, let's all use libraries that change API every day instead. That will be more productive.
- lmm 5mo agoThe only thing worse than changing APIs is never changing APIs. Having to use APIs from 5 years ago sucks.
- LtWorf 5mo agoHaving to modify a software every few months when it could be left untouched for 5 years and keep running sucks way more :) Not every software needs updates, and if it doesn't, just using the new name for the API all the time is useless churn. I'm starting to appreciate java, where all my software written for java5 still works fine without a single change.
- TacticalCoder 5mo agohttps://security-tracker.debian.org/tracker/CVE-2026-2291 https://security-tracker.debian.org/tracker/CVE-2026-4890 https://security-tracker.debian.org/tracker/CVE-2026-4891 https://security-tracker.debian.org/tracker/CVE-2026-4892 https://security-tracker.debian.org/tracker/CVE-2026-4893 https://security-tracker.debian.org/tracker/CVE-2026-5172 fixed, fixed, fixed, fixed, fixed and fixed
- ExoticPearTree 5mo agoAbout a decade ago I switched to Ubuntu LTS because of Debian’s “policy?” of having pretty old packages in “stable” and a long release cycles. Nowadays, even with Ubuntu’s two year or so release cycle I have to use 3rd party packages to have up to date software (PHP being one) and not some version from three years ago. We no longer live in a world (with few exceptions) where running a 3-5 year old distribution (still supported) makes sense.
- LtWorf 5mo agoI am running debian oldstable on two rpi-based appliances i built at home. They have been working fine for several years. I'll have to update them because eventually security updates will stop. That means that the python code on them no longer works on current python versions, C++ needs some tweaks because some library changed API. Better to do these things every few years than every 6 months for no reason whatsoever.
- ExoticPearTree 5mo ago> That means that the python code on them no longer works on current python versions, C++ needs some tweaks because some library changed API. And this is why you update often, to keep up with the programming language ecosystem too. I have seen way too many times software unmaintained for years and then when it was actually time to upgrade it would take much more time to bring it to current framework versions than it would have taken if it was updated regularly throughout the years. And I was not referring to hobby projects you do at home.
- LtWorf 5mo ago> And this is why you update often Updating often would mean waste time every year rather than every 6 years. Do we agree that 6 > 1? At work they pay me so I'm there no matter what, but it's still a cost for the company to have me do that rather than something useful.
- PunchyHamster 5mo agowhatever you're on, stop, it's not making your brain any better
- BrandoElFollito 5mo agoIt depends on how you look at it. I use Debian stable in the smallet possible configuration because it is, well, stable. A rock on which I put docker to run actually useful services, which are upaded the way I want. If I was to run dnsmasq on Debian, it would be in a container. Since I run Pihole (in a container), it kinda is.
- LtWorf 5mo ago> they have literally shipped straight-up broken packages before And did you open a high severity bug or you just kept it to yourself until you came here to complain years after the fact?
- LtWorf 5mo agoNice troll fake account :) And no "good faith" assumption here, since you literally claim debian stable ships broken kernels, according to you nobody should be able to even boot a computer.