From owner-freebsd-questions@FreeBSD.ORG Wed Apr 12 11:00:05 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B61D616A400 for ; Wed, 12 Apr 2006 11:00:05 +0000 (UTC) (envelope-from nospam@mgedv.net) Received: from mgedv.at (mail.mgedv.at [195.3.87.103]) by mx1.FreeBSD.org (Postfix) with ESMTP id 35A2B43D46 for ; Wed, 12 Apr 2006 11:00:04 +0000 (GMT) (envelope-from nospam@mgedv.net) Received: from metis (localhost [127.0.0.1]) by mgedv.at (SMTPServer) with ESMTP id 10942186864 for ; Wed, 12 Apr 2006 13:00:03 +0200 (MEST) From: "No@SPAM@mgEDV.net" To: Date: Wed, 12 Apr 2006 13:00:08 +0200 Message-ID: <003f01c65e20$43368a10$dededede@avalon.lan> MIME-Version: 1.0 Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: 7bit X-Mailer: Microsoft Office Outlook 11 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180 In-Reply-To: <443CC5D0.7020404@dial.pipex.com> thread-index: AcZeEpk9HLChNCDtTZuRWz5LrEqzfgADB84w Subject: RE: upcoming release 6.1: old version of some core components X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: nospam@mgedv.net List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 12 Apr 2006 11:00:05 -0000 did i ever mention "i love communities!" ;-) well, 1st of all, thx 2 all the people who gave it a whirl and went deeper into cvs as i would ever do (i'm definitely not a dev ;-), btw. that was my reason for asking this on the list ) 2nd, the thing alex brought up is very confusing, because it seems, that security fixes which are related to zlib 1.2.3 have been applied to 1.2.2#FREEBSD-VERSION and the rest (?whatever it is?) of the changes have not been applied (if the're any). from my point of view (compatibility and transparence come to my mind) shouldn't be the code as close as possible to the original developed code for any library? ok, we could discuss libjpeg here, but zlib should be a standard, and it seems for some guys it's easier to implement the fixes instead of upgrading to the new version. i'm again sure, that the maintainer of fbsd-zlib knows why, but to an "not-so-deep-in-c" guy like me, it's still confusing. with openssl even i had problems replacing one version with another, but looking at the security, i try to stay with some more or less current version. finally, for the userland stuff (goes into jails anyway, so no interference with the os at all) i'll compile/get packages with newer versions, and the os (hell, if someone is possible to insert malicious compressed streams on my os, he can have the box at all ;-) ) stay's with the standards being delivered with the release/stable versions. does this sound smart for you? ps: i had to stop writing this 3 times because of some odd customer, please forgive some stupid wording in here ;-)