qmail doesn't *need* any patches
qmail doesn't *need* any patches
Posted Nov 4, 2007 5:52 UTC (Sun) by njs (subscriber, #40338)In reply to: qmail doesn't *need* any patches by xanni
Parent article: Daniel Bernstein: ten years of qmail security
FWIW, I didn't mean 'built on Apache' as in 'runs as part of an Apache HTTPD'; Apache is in part a very nice framework for writing generic server apps these days. (Maybe this is technically part of APR, I haven't followed where exactly they're drawing that boundary.) On a further look, though, I see that you're right, when qpsmtpd is not running under httpd, it uses a different home-brew network framework rather than APR. I was misled by looking at the first anti-malware plugin linked on their homepage: http://svn.perl.org/qpsmtpd/trunk/plugins/check_earlytalker which contains a bunch of code using APR -- but it turns out that's because there are two copies of all that code, one that works when being run under Apache and one that works with the home-brew. I don't know how typical this is of qpsmtpd's codebase, but it doesn't strike me as The DJB Way either. (If I were them, I'd consider just using Apache in all cases, even if it is a big hunk of scary C that makes baby DJB cry, but I don't actually know what I'm talking about so *shrug*.)
