OpenSSH 5.0 released
Posted Apr 7, 2008 10:07 UTC (Mon) by
dwmw2 (subscriber, #2063)
In reply to:
OpenSSH 5.0 released by madscientist
Parent article:
OpenSSH 5.0 released
madscientist writes:
You're right about all these errors, but you left out the one specific error I called out as the most egregious one:
x) Red Hat does not report the bug and its fix upstream to OpenSSH back in 2005, when they found it.
This is fairly unfortunate, and definitely not Fedora policy. For both selfish and altruistic reasons, we really do try to merge patches upstream as promptly as possible.
OpenSSH is a bit special here, since it seems so hard to get patches merged. It's very unfortunate that we carry so many patches, but after my own experience with bugs/RFEs #1328, #1329 and #1330, for which I've been building my own packages for years and occasionally trying to merge the patches but getting nowhere, I can't really criticise our OpenSSH package maintainer for that.
Looking through the (unfortunately private) bug report in RHEL bugzilla, it seems that it was originally reported to us with the text "Grrr. This is a *known* sshd bug...", which probably made it seem even less necessary for the package maintainer to chase it to the recalcitrant upstream.
Still, maybe this is a good time for us to improve matters by trying to flush all our pending patches to upstream, and for upstream to start being a little more receptive to them.
(
Log in to post comments)