Regression identified in Service Provider library, new version pushed

Cantor, Scott cantor.2 at osu.edu
Tue Nov 21 09:32:34 EST 2017


> I'd be interested to hear what sorts of support requests arrive from
> Debian users, especially if something makes these Debian-specific.

My point isn't that there are a lot of those issues, it's that I'd risk being stuck supporting versions of the code I've already replaced. This same issue would be true with Red Hat if they shipped packages, and in fact they did ship Xerces and refuse to support it (and they broke curl, etc.). These are major problems for me and it would be worse if they'd shipped more libraries than just those two. Imagine this latest issue, going unfixed for years like the Xerces vulnerabilities have.
 
> Supporting a particular packaging is a concept different from supporting
> the packaged software itself (just like user support differs from
> security support).

I think it goes hand in hand.
 
> I can imagine the elderly versions being a giveaway; always feel free to
> refer such requests to the pkg-shibboleth-devel mailing list or the
> Debian bug tracker.  We'll help determine if the issue is present in the
> latest supported version and if so, proxy it.

Well, that's certainly a possibility but it's the thing we'd have to work out on some level. That's all I was saying.

> What I mean: upstreams aren't expected to actively backport security fixes or
> otherwise support the versions frozen into Debian releases.  That's the
> responsibility of the package maintainer and the security team.  Of
> course timely and correct security updates are really only possible with
> upstream cooperation, which you've always been more than open to.

I guess that's all I was really trying to say. If that's made clear to people, and our support extends to the current version in some particularly packaging, that's very likely to be a non-issue for us.

> On the other hand, the Debian LTS team was very quick to backport the
> latest security fixes to the oldoldstable release (that is: to 2.4.3).

Security fixes don't concern me all that much because I know they're being handled. It's the bugs and other problems that people ask about and then don't like being told that the fix is to get a version their OS doesn't give them.

-- Scott



More information about the users mailing list