From owner-freebsd-ports@freebsd.org Fri Jun 23 21:36:49 2017 Return-Path: Delivered-To: freebsd-ports@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id C3B11D8A6F6 for ; Fri, 23 Jun 2017 21:36:49 +0000 (UTC) (envelope-from michelle@sorbs.net) Received: from hades.sorbs.net (hades.sorbs.net [72.12.213.40]) by mx1.freebsd.org (Postfix) with ESMTP id A7A3E75A27; Fri, 23 Jun 2017 21:36:49 +0000 (UTC) (envelope-from michelle@sorbs.net) MIME-version: 1.0 Content-transfer-encoding: 7BIT Content-type: text/plain; CHARSET=US-ASCII; format=flowed Received: from isux.com (firewall.isux.com [213.165.190.213]) by hades.sorbs.net (Oracle Communications Messaging Server 7.0.5.29.0 64bit (built Jul 9 2013)) with ESMTPSA id <0OS000CA4SE4ER00@hades.sorbs.net>; Fri, 23 Jun 2017 14:44:29 -0700 (PDT) Subject: Re: [RFC] Why FreeBSD ports should have branches by OS version To: Julian Elischer , freebsd-ports@freebsd.org References: <20170622121856.haikphjpvr6ofxn3@ivaldir.net> <20170622141644.yadxdubynuhzygcy@ivaldir.net> <4jrnkcpurfmojfdnglqg5f97sohcuv56sv@4ax.com> <20170622211126.GA6878@lonesome.com> <594C4663.5080209@quip.cz> <09384577-ed7e-d142-43f3-0a08f5d21056@freebsd.org> From: Michelle Sullivan Message-id: <5f1a71bb-abd4-6e89-f6c9-37527eba3239@sorbs.net> Date: Fri, 23 Jun 2017 23:36:46 +0200 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:49.0) Gecko/20100101 Firefox/49.0 SeaMonkey/2.46 In-reply-to: <09384577-ed7e-d142-43f3-0a08f5d21056@freebsd.org> X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 23 Jun 2017 21:36:49 -0000 Julian Elischer wrote: > > (*) From my experience, the best way to cope with openssl is to have > everything link with > the system openssl and issue security upgrades to the base OS that > upgrades that when there is a need. > (this may change, but it's been my experience so far). Agree on previous parts of your message but have to say 'no' here... Ports OpenSSL is the way to go.. because of the FreeBSD policy "we won't change the ABI" one of the reasons for no having 9.4 was OpenSSL 0.9.8 was EoLd and there were/are bugs unpatched.... Thing is its a perfect example of why OpenSSL should not be bundled into the OS... but then you can't rely on the ports system because of the drive to change it. Rock and a hard place comes to mind... Problem is you have @freebsd.org email holder saying, "we don't get paid for this so we'll do it our way... pay us to do it your way or do it yourself" vs the users, that are shouting, "come on guys we can't keep up, we need stability, we're not using this as a desktop here".... And both sides are diametrically opposed and steadfast to the point of zealous-ism... -- Michelle Sullivan http://www.mhix.org/