Ah, interesting. We are not trying to solve the same problem, which
might explain why it's so hard to converge to a single solution.
The problem I am interested in solving is:
It is currently difficult for people not involved in Debian
development (upstream, other distros, users) to know which patches we
applied, the reason for the patch, and whether they should be
interested in that patch or not.
C'est "marrant". Parce que le problème, même s'il est recentré, n'est pas principalement ici (même si le problème décrit n'est pas à négliger). Le problème est de remonter les patchs upstream. Les développeurs upstream ne vont pas regarder les patchs de Gentoo, de Mandriva, de Red Hat, de Novell, Fedora, Ubuntu, Mepis, etc.
[^] # Re: Mesures qui seront prises ?
Posté par IsNotGood . En réponse à la dépêche Découverte d'une faille de sécurité critique dans OpenSSL de Debian. Évalué à 2.
Un message après un très long thread :
http://lists.debian.org/debian-devel/2008/05/msg00681.html
Ah, interesting. We are not trying to solve the same problem, which
might explain why it's so hard to converge to a single solution.
The problem I am interested in solving is:
It is currently difficult for people not involved in Debian
development (upstream, other distros, users) to know which patches we
applied, the reason for the patch, and whether they should be
interested in that patch or not.
C'est "marrant". Parce que le problème, même s'il est recentré, n'est pas principalement ici (même si le problème décrit n'est pas à négliger). Le problème est de remonter les patchs upstream. Les développeurs upstream ne vont pas regarder les patchs de Gentoo, de Mandriva, de Red Hat, de Novell, Fedora, Ubuntu, Mepis, etc.
Ils ne l'ont pas fait pour cette faille...