|
|
Log in / Subscribe / Register

Conill: The long-term consequences of maintainers’ actions

Conill: The long-term consequences of maintainers’ actions

Posted Sep 17, 2021 19:52 UTC (Fri) by josh (subscriber, #17465)
In reply to: Conill: The long-term consequences of maintainers’ actions by ariadne
Parent article: Conill: The long-term consequences of maintainers’ actions

> Other distributions begrudgingly upgrade rust in already released branches when needed, but only because they have to in order to support the security updates of other software. Firefox is an example here.

This seems like a fundamental incompatibility between Firefox's security model and the distribution security model. Upgrading to a new major version of something can mean upgrading to new versions of its dependencies. That's true for any piece of software.

Perhaps it would make sense to have a version of Rust in the distribution used as a dependency of Firefox (and anything else that uses the "you must upgrade to a new major version" security model), and a version of Rust used for everything else that follows the distribution security model (maintain the same major version, incorporate minimal security/bugfix patches).


The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:

Note: you can avoid this step in the future by logging into your LWN account.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds