This is the mail archive of the libc-alpha@sourceware.org mailing list for the glibc project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

Re: Requesting CVEs for glibc security issues


On Mon, 19 May 2014, Siddhesh Poyarekar wrote:

> > It would also be useful to do the backports to stable branches of the
> > security fix, but at the moment it seems every vendor has their own
> > stable branch.
> 
> Yes, nobody is using the point releases right now, so there is no real
> incentive in maintaining those branches.  This is true for bug fixes
> in general, not just security fixes.

Given the risk of mistakes in backports, I'd think that having a standard 
version of the backport on the glibc release branch, with all the 
distribution maintainers reviewing it carefully, would be better than each 
distribution having its own, even if the distributions then select only 
certain patches from the release branches rather than actually using the 
branches or point releases from them.

-- 
Joseph S. Myers
joseph@codesourcery.com


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]