Re: Security lessons from liblzma

From: Bruce Momjian <bruce(at)momjian(dot)us>
To: Joe Conway <mail(at)joeconway(dot)com>
Cc: Andres Freund <andres(at)anarazel(dot)de>, Robert Haas <robertmhaas(at)gmail(dot)com>, PostgreSQL-development <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Security lessons from liblzma
Date: 2024-03-31 01:52:47
Message-ID: ZgjB7-Kvvj4xYluH@momjian.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On Sat, Mar 30, 2024 at 07:54:00PM -0400, Joe Conway wrote:
> Virtually every RPM source, including ours, contains out of tree patches
> that get applied on top of the release tarball. At least for the PGDG
> packages, it would be nice to integrate them into our git repo as build
> options or whatever so that the packages could be built without any patches
> applied to it. Add a tarball that is signed and traceable back to the git
> tag, and we would be in a much better place than we are now.

How would someone access the out-of-tree patches? I think Debian
includes the patches in its source tarball.

--
Bruce Momjian <bruce(at)momjian(dot)us> https://momjian.us
EDB https://enterprisedb.com

Only you can decide what is important to you.

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Thomas Munro 2024-03-31 01:56:06 Re: pg_combinebackup --copy-file-range
Previous Message Thomas Munro 2024-03-31 01:03:25 Re: pg_combinebackup --copy-file-range