|
|
Log in / Subscribe / Register

Re: Glibc stable release process (Glibc 2.26.1)

From:  Arjan van de Ven <arjan-AT-linux.intel.com>
To:  Zack Weinberg <zackw-AT-panix.com>, "Yann E. MORIN" <yann.morin.1998-AT-free.fr>
Subject:  Re: Glibc stable release process (Glibc 2.26.1)
Date:  Sat, 30 Sep 2017 07:27:19 -0700
Message-ID:  <6295418b-5420-8285-1cce-c783ed788fc9@linux.intel.com>
Cc:  Tulio Magno Quites Machado Filho <tuliom-AT-linux.vnet.ibm.com>, Romain Naour <romain.naour-AT-gmail.com>, "libc-alpha-AT-sourceware.org" <libc-alpha-AT-sourceware.org>, Joseph Myers <joseph-AT-codesourcery.com>, "Gabriel F. T. Gomes" <gabriel-AT-inconstante.eti.br>, Siddhesh Poyarekar <siddhesh-AT-sourceware.org>, Paul Eggert <eggert-AT-cs.ucla.edu>

On 9/30/2017 4:57 AM, Zack Weinberg wrote:
> 
> I'm a little underslept and I'm not sure I fully understand the issue
> here, but would it help if we literally just tagged point releases and
> pushed tarballs to ftp.gnu.org from a cron job?  Once a month if there
> have been any patches since the previous tag, perhaps?  With the
> official line being that all patches on the release branches are
> carefully vetted and we recommend tracking the git branch if you can,
> but this is easier for some downstream organizations so we offer this
> as well.

with my distro hat on, yes I would appreciate this already a lot.
I'll consume these (and likely other distros will as well) as very
good anchor points.

It also leads to, say, a CVE be able to list "fixed in 2.26.5"
and everyone (and all more importantly, all tools that we all use
to cross reference our distros to CVE databases) will know if things
are already fixed, or if someone needs to take a look for a fix
to backport outside of the releases






to post comments


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds