Bugs in Debian stable
Posted May 7, 2003 18:23 UTC (Wed) by
hazelsct (guest, #3659)
Parent article:
Debian Weekly News - May 6th, 2003
As a Debian maintainer, I have to strongly agree with Remy Perrot that Debian's policy preventing bug fixes from entering stable does a real disservice to users. As a result, the "stable" mozilla (1.0.0) and samba (2.2.3a) packages are in a horrible state of disrepair, with numerous confirmed security problems in the former and numerous potential ones in the latter. The mozilla security fixes are being kept out of stable because nobody has spent the man-weeks required to disentangle them from the non-security bug fixes in 1.0.1 and 1.0.2. How this can be construed to be beneficial to users is beyond me, and that this state can persist for months with no end in sight is a real disgrace to a project which prides itself on reliability and security.
I can name numerous other packages with non-security bugs which have known fixes, but are also refused from stable because the bugs are not security-related. Again, how is this a service to our users?
The band-aid of alternative apt repositories on apt-get.org is nice, but with no mechanism for users to learn about bugfix availability, and no BTS representation for any of these unofficial sources, it is of very limited utility to most stable users.
[Yes, I've expressed these sentiments in Debian mailing lists, and they are mostly ignored, just as Remy's post has been greeted with the usual party line of "This is the way it is. It will never change. Sorry."]
(
Log in to post comments)