Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.devel > #111736

Re: De-vendoring gnulib in Debian packages

From Russ Allbery <rra@debian.org>
Newsgroups linux.debian.devel
Subject Re: De-vendoring gnulib in Debian packages
Date 2024-05-12 17:50 +0200
Message-ID <IDjCx-cRGs-7@gated-at.bofh.it> (permalink)
References <ICVAd-cCO8-5@gated-at.bofh.it> <IDgbD-cPNk-5@gated-at.bofh.it>
Organization The Eyrie

Show all headers | View raw


"Theodore Ts'o" <tytso@mit.edu> writes:

> The best solution to this is to try to promote people to put those
> autoconf macros that they are manually maintaining that can't be
> supplied in acinclude.m4, which is now included by default by autoconf
> in addition to aclocal.m4.

Or use a subdirectory named something like m4, so that you can put each
conceptually separate macro in a separate file and not mush everything
together, and use:

    AC_CONFIG_MACRO_DIR([m4])

(and set ACLOCAL_AMFLAGS = -I m4 in Makefile.am if you're also using
Automake).

> Note that how we treat gnulib is a bit differently from how we treat
> other C shared libraries, where we claim that *all* libraries must be
> dynamically linked, and that include source code by reference is against
> Debian Policy, precisely because of the toil needed to update all of the
> binary packages should some security vulnerability gets discovered in
> the library which is either linked statically or included by code
> duplication.

> And yet, we seem to have given a pass for gnulib, probably because it
> would be too awkward to enforce that rule *everywhere*, so apparently
> we've turned a blind eye.

No, there's an explicit exception for cases like gnulib.  Policy 4.13:

    Some software packages include in their distribution convenience
    copies of code from other software packages, generally so that users
    compiling from source don’t have to download multiple packages. Debian
    packages should not make use of these convenience copies unless the
    included package is explicitly intended to be used in this way.

-- 
Russ Allbery (rra@debian.org)              <https://www.eyrie.org/~eagle/>

Back to linux.debian.devel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

De-vendoring gnulib in Debian packages Simon Josefsson <simon@josefsson.org> - 2024-05-11 16:10 +0200
  Re: De-vendoring gnulib in Debian packages Bruno Haible <bruno@clisp.org> - 2024-05-11 18:00 +0200
    Re: De-vendoring gnulib in Debian packages Simon Josefsson <simon@josefsson.org> - 2024-05-11 18:40 +0200
  Re: De-vendoring gnulib in Debian packages Paul Eggert <eggert@cs.ucla.edu> - 2024-05-11 18:50 +0200
  Re: De-vendoring gnulib in Debian packages "Theodore Ts'o" <tytso@mit.edu> - 2024-05-12 14:10 +0200
    Re: De-vendoring gnulib in Debian packages Simon Josefsson <simon@josefsson.org> - 2024-05-12 16:30 +0200
      Re: De-vendoring gnulib in Debian packages "Theodore Ts'o" <tytso@mit.edu> - 2024-05-12 21:00 +0200
        gzip --rsyncable (was: Re: De-vendoring gnulib in Debian packages) Simon Josefsson <simon@josefsson.org> - 2024-05-20 10:30 +0200
    Re: De-vendoring gnulib in Debian packages Russ Allbery <rra@debian.org> - 2024-05-12 17:50 +0200
      Re: De-vendoring gnulib in Debian packages Ansgar πŸ™€ <ansgar@43-1.org> - 2024-05-12 18:30 +0200
        Re: De-vendoring gnulib in Debian packages Russ Allbery <rra@debian.org> - 2024-05-12 19:50 +0200

csiph-web