Bug#490688: gnus: Old alpha version shouldn't be included in lenny
Package: gnus Version: 5.11+v0.5.dfsg-3 Severity: serious This package should be orphaned, currently it has a two year old version of the gnus development series (No Gnus). If the package goes to lenny it should atleast have the latest No Gnus version. I have not had any problems with No Gnus, but they are still declared alpha versions, and maybe should be completely kept out of stable. Both emacs and xemacs have the latest stable Gnus already included. -- System Information: Debian Release: lenny/sid APT prefers unstable APT policy: (500, 'unstable') Architecture: amd64 (x86_64) Kernel: Linux 2.6.25.9 (SMP w/2 CPU cores) Locale: LANG=fi_FI.UTF-8, LC_CTYPE=fi_FI.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Versions of packages gnus depends on: ii make 3.81-5 The GNU version of the "make" util ii ucf 3.007 Update Configuration File: preserv ii xemacs21 21.4.21-3 highly customizable text editor ii xemacs21-mule [xemacs21] 21.4.21-3 highly customizable text editor -- gnus recommends no packages. -- debconf-show failed -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]
Re: Bug#490688: gnus: Old alpha version shouldn't be included in lenny
On 13 Jul 2008, Russ Allbery wrote: > Mika Tiainen <[EMAIL PROTECTED]> writes: > >> I have not had any problems with No Gnus, but they are still >> declared alpha versions, and maybe should be completely kept out of >> stable. Both emacs and xemacs have the latest stable Gnus already >> included. > > This package is useful for emacs21 users, as it's considerably newer > than what was included in emacs21. I agree that it's not useful for > emacs22 users (and indeed isn't installable if you only have emacs22 > installed) since the version that is included in emacs22 is newer. Emacs 22 doesn't have a newer version, it has version based on the latest stable Gnus (Oort) released in 2003, there is no stable version of No Gnus. Xemacs 21 also has Oort Gnus. Gnus versioning has been explained on another bug: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=432143#42 I would also like to keep the separate No Gnus package, atleast in unstable, but if it stays it should have an active maintainer. It's not very useful to report bugs against a two year old development snapshot. -- Mika TiainenAlways be wary of any helpful item that [EMAIL PROTECTED] weighs less than its operating manual. http://mikat.iki.fi -- (Terry Pratchett, Jingo) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]
Re: Bug#490688: gnus: Old alpha version shouldn't be included in lenny
On 14 Jul 2008, Steve Langasek wrote: > severity 490688 wishlist > thanks > > On Sun, Jul 13, 2008 at 08:25:30PM +0300, Mika Tiainen wrote: >> Package: gnus >> Version: 5.11+v0.5.dfsg-3 >> Severity: serious > >> This package should be orphaned, currently it has a two year old >> version of the gnus development series (No Gnus). If the package >> goes to lenny it should atleast have the latest No Gnus version. > > - Since the package has not been orphaned, you don't have the > authority to declare it to be unsuitable for release "in the > maintainer's opinion". OK > - You don't mention any other technical problems with the package that make > it unsuitable for release, just that it's old. Well not just that it is old, but that it is a old alpha release not recommended for casual users: ,[ http://gnus.org/manual/gnus_324.html ] | This phase is called the alpha phase, since the Gnusae released in | this phase are alpha releases, or (perhaps more commonly in other | circles) snapshots. During this phase, Gnus is assumed to be unstable | and should not be used by casual users. ` Maybe there should just be a warning in the package description then. Looking at the bug reports there's mention of a possible security problem in http://bugs.debian.org/415562. Someone should atleast look into that, I think it might refer to this: http://article.gmane.org/gmane.emacs.gnus.general/63627 -- Mika TiainenAlways be wary of any helpful item that [EMAIL PROTECTED] weighs less than its operating manual. http://mikat.iki.fi -- (Terry Pratchett, Jingo) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]
Possible gnus security bug (#415562) (was: Bug#490688: gnus: Old alpha version shouldn't be included in lenny))
On 14 Jul 2008, Steve Langasek wrote: > On Mon, Jul 14, 2008 at 02:09:12PM +0300, Mika Tiainen wrote: > >> Looking at the bug reports there's mention of a possible security >> problem in http://bugs.debian.org/415562. Someone should atleast >> look into that, I think it might refer to this: >> http://article.gmane.org/gmane.emacs.gnus.general/63627 > > Given that you've expressed interest in gnus, I think you would be > the ideal person to investigate this bug and discuss with the > security team what the correct severity of this bug should be. In > general, the severity definitions at > <http://www.debian.org/Bugs/Developer#severities> apply. Thijs Kinkhorst has just asked the submitter for more information. It doesn't appear to be the issue mentioned in the gmane URL, that seems to have only concerned the stable branch. -- Mika TiainenAlways be wary of any helpful item that [EMAIL PROTECTED] weighs less than its operating manual. http://mikat.iki.fi -- (Terry Pratchett, Jingo) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]