LWN.net Logo

Bugs in Debian stable

Bugs in Debian stable

Posted May 7, 2003 18:23 UTC (Wed) by hazelsct (guest, #3659)
Parent article: Debian Weekly News - May 6th, 2003

As a Debian maintainer, I have to strongly agree with Remy Perrot that Debian's policy preventing bug fixes from entering stable does a real disservice to users. As a result, the "stable" mozilla (1.0.0) and samba (2.2.3a) packages are in a horrible state of disrepair, with numerous confirmed security problems in the former and numerous potential ones in the latter. The mozilla security fixes are being kept out of stable because nobody has spent the man-weeks required to disentangle them from the non-security bug fixes in 1.0.1 and 1.0.2. How this can be construed to be beneficial to users is beyond me, and that this state can persist for months with no end in sight is a real disgrace to a project which prides itself on reliability and security.

I can name numerous other packages with non-security bugs which have known fixes, but are also refused from stable because the bugs are not security-related. Again, how is this a service to our users?

The band-aid of alternative apt repositories on apt-get.org is nice, but with no mechanism for users to learn about bugfix availability, and no BTS representation for any of these unofficial sources, it is of very limited utility to most stable users.

[Yes, I've expressed these sentiments in Debian mailing lists, and they are mostly ignored, just as Remy's post has been greeted with the usual party line of "This is the way it is. It will never change. Sorry."]


(Log in to post comments)

Bugs in Debian stable

Posted May 10, 2003 22:12 UTC (Sat) by wolfrider (guest, #3105) [Link]

> [Yes, I've expressed these sentiments in Debian mailing lists, and they are mostly ignored, just as Remy's post has been greeted with the usual party line of "This is the way it is. It will never change. Sorry."]

--Then that means that Debian stable is too complacent, and needs a wake-up call like XFree86 got.

--Seriously, I'd kind of like Klaus Knopper to integrate more tightly with Debian main, but with attitudes like that it won't happen. Most people I know are running unstable/testing because of Knoppix anyway, including me. I couldn't get stable working the way I wanted to *at all* so I abandoned it and went to Knoppix.

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds