Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 11 Apr 2001 11:16:29 PST
From:      Jason DiCioccio <geniusj@bluenugget.net>
To:        bmah@FreeBSD.ORG
Cc:        sjohn@airlinksys.com, freebsd-security@FreeBSD.ORG, Jason.DiCioccio@Epylon.com
Subject:   Re: Security Announcements
Message-ID:  <20010411191629.27C3213642@bluenugget.net>

next in thread | raw e-mail | index | archive | help
On Wed, 11 Apr 2001 12:06:53 -0700 bmah@FreeBSD.ORG wrote:

> If memory serves me right, Jason DiCioccio wrote:
> 
> > And how would I know which day/time was considered reasonably
> bug-free.   
> > I do not know of any webpages or anything that tell you this, 
> 
> Read -stable (you are doing that right?).  I care more about how
> machines work in my own environment that what some Web page says.
> 

Yes.  But of course the -STABLE/CURRENT branches change by the second.
However you clear this up below.

> You mentioned the hypothetical case of someone running -STABLE on boxes
> that needed to be "up at all times".  Tell me that this someone would be
> willing to drop a new version of *any* operating system on
> mission-critical machines without testing on their own scratch machines
> first.

~20 lines of code (for example) in a patch is a lot easier to go through
(and to trust as a result) than the many more lines involved in a diff
between 2 snapshots (moving targets) of a branch that are, say, 1 month apart.

> 
> > nor does
> > any given time in the -STABLE branch get as much testing as a -RELEASE..
> 
> For people who need version of FreeBSD that's been though testing
> (and there is nothing whatsoever wrong with that), well, they should be
> running -RELEASE.  There's been a lot of discussion as to how to deal
> with the issue of security updates to -RELEASEs, and the message that
> rwatson recently posted outlines the result of that discussion.  I 
> think this is going to solve a lot of problems, even though it's going 
> to create more work for those who make advisories and patches.

Yes, I definitely like the new branch tag idea in 4.3. :-)  It definitely 
clears up a lot of my concerns..

Cheers,
-JD-



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20010411191629.27C3213642>