On Wednesday, October 9, 2002, at 08:04 PM, Oden Eriksson wrote:

[...]
>> The point is I don't like to do this.  It's fine to patch things for
>> fixes, proper language translations, etc.  But adding features like
>> this causes other problems... it will bring a lot of bad publicity for
>> MandrakeSoft because of Theo; he's made many threats in the past and
>> he's neurotic enough to follow through.  For instance, if we do
>> something Theo really doesn't like, or that Markus doesn't like, any
>> questions regarding openssh that even faintly mention Mandrake
>> somewhere in the equation, will get blasted by the openssh developers,
>> and they'll be referred here with none too kind words.
>>
>> I'd rather avoid that sort of thing.
>
> Ahh, I didn't think that far, are they really such a*holes? May I ask 
> what
> those threats were?

Let's call them protective.  And the threats were basically bad 
publicity amongst many other Linux/BSD vendors and communities, big 
anti-MandrakeSoft sentiments on the openssh website, that sort of 
thing.  I don't recall the particulars, but it was enough for me to 
remove the offending patches.

If you look at the openssh spec, you'll see a note in there about 
"authorized patches"...  I stick with that 100% (and I put it there).  
openssh is one of the things I (we) don't really want or need to fsck 
with.

>> This is something that can be done with an optional build switch so
>> someone can easily rebuild the srpm for themself with the patch
>> applied.  It's not something I want to make mainstream unless I know
>> that the openssh authors aren't going to be pricks about it.  I prefer
>> to have as few headaches as possible.
>
> Ok. I will fix an conditional switch for this. It would be interesting 
> to hear
> what they have to say about this as it's a pretty new feature. As I
> understand it it's as new as of this month. They might not even know 
> about
> it?

I just posted to the dev list about it, so we'll see what comes of it.  
Pending the inevitable discussion about it, we'll see what we do with 
it.

--
MandrakeSoft Security; http://www.mandrakesecure.net/
"lynx - source http://linsec.ca/vdanen.asc | gpg --import"
{FE6F2AFD: 88D8 0D23 8D4B 3407 5BD7 66F9 2043 D0E5 FE6F 2AFD}

Attachment: PGP.sig
Description: PGP signature

Reply via email to