Re: New Google Group for discussion and notices on Arch security.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On Fri, Jun 18, 2010 at 2:33 PM, Andres P <aepd87@xxxxxxxxx> wrote:
> On Fri, Jun 18, 2010 at 1:18 AM, Jeffrey 'jf' Lim <jfs.world@xxxxxxxxx> wrote:
>>
>> ah yes, SSL! sorry :)
>>
>
> On 2006-05-01 22:34:12, Ulf Möller, openssl developer [1], responded
> [2] to openssl packager Kurt Roeckx [3] saying that he was for
> applying the patch just to keep valgrind quiet.
>

cool. I wasnt aware of that. I was aware that there was some form of
silence regarding what to do. But as for actually saying ok... hm.
Agree with the point about making sense to defer to upstream for the
final word.

-jf


> But openssl doesn't like to talk about that, and neither does slashdot
> for that matter.
>
> For a distro packager, the maximum authority regarding what to do with
> a given piece of software is upstream and common sense.
>
> If upstream says it's a ok, then common sense takes a backseat during
> technical discussions.
>
> Not to mention that initializing variables like that is undefined and
> bound to *always* cause confusion.
>
> Andres P
>
> [1] http://openssl.org/about
> [2] http://marc.info/?l=openssl-dev&m=114652287210110&w=2
> [3] http://qa.debian.org/developer.php?login=kurt@xxxxxxxxx
>


[Index of Archives]     [Linux Wireless]     [Linux Kernel]     [ATH6KL]     [Linux Bluetooth]     [Linux Netdev]     [Kernel Newbies]     [Share Photos]     [IDE]     [Security]     [Git]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux ATA RAID]     [Samba]     [Device Mapper]
  Powered by Linux