Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #245115 > unrolled thread

let me understand this - packages delay

Started byMaurizio Caloro <maurizio@caloro.ch>
First post2022-02-08 22:20 +0100
Last post2022-02-09 00:50 +0100
Articles 3 — 3 participants

Back to article view | Back to linux.debian.user


Contents

  let me understand this - packages delay Maurizio Caloro <maurizio@caloro.ch> - 2022-02-08 22:20 +0100
    Re: let me understand this - packages delay Greg Wooledge <greg@wooledge.org> - 2022-02-08 22:40 +0100
    Re: let me understand this - packages delay "Andrew M.A. Cater" <amacater@einval.com> - 2022-02-09 00:50 +0100

#245115 — let me understand this - packages delay

FromMaurizio Caloro <maurizio@caloro.ch>
Date2022-02-08 22:20 +0100
Subjectlet me understand this - packages delay
Message-ID<DOG41-tQF-1@gated-at.bofh.it>
Hello, please this is a friendly request and a discussion starter

keep asking myself why there are such big version differences
between the publisher and the packages.

-Buster 10.11-
ii  postfix 3.4.14-0+deb10u1, was announced June 27, 2020
ii  dovecot-core 1:2.3.4.1-5+deb10u6, was announced Feb 5, 2019
ii  spamassassin 3.4.2-1+deb10u3, was announced Sep 16, 2018
ii  openssl 1.1.1d-0+deb10u7, was announced Sep 11, 2018

I see that Bullseye would have newer releases (sorry, i'dont check this now)
but can this really only be renewed with Package mechanismus, so i need
to run a global upgrade of the OS?

every system that i run will be installed with Debian, and iam happy 
with it!
i would appreciate it if packages were kept reasonably up-to-date. certainly
not extreme that you should follow up on every patch or release, but would
still be a bit more up-to-date without having to upgrade an entire OS.

please this should be a friendly discussion/review, thanks

--

if your tires profile expire, you have also put the hole car to trash?

[toc] | [next] | [standalone]


#245118

FromGreg Wooledge <greg@wooledge.org>
Date2022-02-08 22:40 +0100
Message-ID<DOGnn-tWR-7@gated-at.bofh.it>
In reply to#245115
On Tue, Feb 08, 2022 at 10:17:48PM +0100, Maurizio Caloro wrote:
> keep asking myself why there are such big version differences
> between the publisher and the packages.

You mean, between upstream and Debian?

> -Buster 10.11-
> ii  postfix 3.4.14-0+deb10u1, was announced June 27, 2020
> ii  dovecot-core 1:2.3.4.1-5+deb10u6, was announced Feb 5, 2019
> ii  spamassassin 3.4.2-1+deb10u3, was announced Sep 16, 2018
> ii  openssl 1.1.1d-0+deb10u7, was announced Sep 11, 2018

Buster is a stable release.  It's not even the *current* stable release.
It's one iteration behind.

A stable Debian release is a snapshot of a set of packages at a moment
in time.  The versions of the packages that are included in the release
are fixed.  They do not change once the release has occurred.  This is
what the word "stable" means in Debian's nomenclature.

This is a *beneficial feature* for those of us who like systems that
are known to work.  Using postfix as an example, when you installed
Debian buster, you got postfix version 3.4.14 with some known set of
patches applied by Debian.  This version was tested for some number of
months or years, and no critical bugs were found in it during that
period (or if there were, they got fixed).  So now, there is some
measure of trust.  You know that this version is unlikely to fail in
some spectacular way.

If a security bug is found, then a new patch will be applied, and you'll
be running postfix version 3.4.14-0+deb10u2 and so on.  There won't be
any incompatible changes, one hopes.  Everything will just continue
working.

Let's speculate for the sake of argument that a later version of postfix
(say, postfix 4.0.0) comes out.  This version introduces a lot of changes.
Some of the lines in the system-wide configuration file no longer have
the same meaning that they used to have under version 3.4.14.  In order
to use the new version of postfix, you would have to edit your config
files.

That's precisely the sort of change that you *don't* want to have to deal
with, and which would be unwelcome on a stable release.

When you upgrade to a newer stable release, there could be incompatible
changes like this.  They'll be mentioned in the release notes, most
likely.  The upgrade procedure will also notify you of such packages,
by displaying a few paragraphs of text in a pager.  You'll have to deal
with these packages as part of your upgrade.

> I see that Bullseye would have newer releases (sorry, i'dont check this now)
> but can this really only be renewed with Package mechanismus, so i need
> to run a global upgrade of the OS?

That's how Debian's releases work.  Each one is a snapshot at a given
point in time.

[toc] | [prev] | [next] | [standalone]


#245119

From"Andrew M.A. Cater" <amacater@einval.com>
Date2022-02-09 00:50 +0100
Message-ID<DOIpb-v7v-1@gated-at.bofh.it>
In reply to#245115
On Tue, Feb 08, 2022 at 10:17:48PM +0100, Maurizio Caloro wrote:
> 
> Hello, please this is a friendly request and a discussion starter
> 
> keep asking myself why there are such big version differences
> between the publisher and the packages.
> 
> -Buster 10.11-
> ii  postfix 3.4.14-0+deb10u1, was announced June 27, 2020
> ii  dovecot-core 1:2.3.4.1-5+deb10u6, was announced Feb 5, 2019
> ii  spamassassin 3.4.2-1+deb10u3, was announced Sep 16, 2018
> ii  openssl 1.1.1d-0+deb10u7, was announced Sep 11, 2018
> 
> I see that Bullseye would have newer releases (sorry, i'dont check this now)
> but can this really only be renewed with Package mechanismus, so i need
> to run a global upgrade of the OS?
> 

Timescale of building support and testing is something like this:

Debian 10 Buster is released July 6th 2019. At that time, the next release
is forked as testing to eventually become Debian 11 - Bullseye.
After two years of test and development, it's released.

Debian 11 is released July 14th 2021 and Bookworm is forked ...
Debian 10 Buster is supported until July 14th 2022 by the main Debian team.

So every release releases with packages that have been tested for about 
two years prior to release, are patched, are stable and are supported
for a further year after the next release. [And then maybe some LTS/ELTS
support thereafter].

If you don't run a "global update" of the system fairly regularly, you don't
get security fixes. That's an apt update ; apt upgrade or equivalent.

For a very few packages, they are updated very regularly becuse old versions
have no support upstream - especially web browsers like Firefox/Chromium.
At any given point, if a package becomes impossible to support, it may
be removed from the package archive. This can happen with point releases, 
especially if the package no longer functions For a very few packages, they are updated very regularly becuse old versions
have no support upstream - especially web browsers like Firefox/Chromium.
At any given point, if a package becomes impossible to support, it may
be removed from the package archive. This can happen with point releases, 
especially if the package no longer functions or is dependent on a service
that no longer exists, for example. 

> every system that i run will be installed with Debian, and iam happy with
> it!
> i would appreciate it if packages were kept reasonably up-to-date. certainly
> not extreme that you should follow up on every patch or release, but would
> still be a bit more up-to-date without having to upgrade an entire OS.
> 

When it does come time to upgrade a Debian system to the next major version
this is supported and is well explained in release notes. This doesn't always
follow with other Linux distributions.

> please this should be a friendly discussion/review, thanks
> 
> --
> 
> if your tires profile expire, you have also put the hole car to trash?
>

With every good wish, as ever,

Andy Cater 

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web