emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Why wasn't the 25.3 release based on the then-head of the emacs-25 b


From: Paul Eggert
Subject: Re: Why wasn't the 25.3 release based on the then-head of the emacs-25 branch?
Date: Thu, 14 Sep 2017 20:24:18 -0700
User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.3.0

Glenn Morris wrote:
There were very few
changes in the emacs-25 branch post 25.2, and I don't see why they were
omitted.

Eli decided on a very thin 25.3 release, with just a patch for the newly-discovered serious bug, along with minimal other changes such as renumbering 25.2 to 25.3.

In particular, it's disappointing that 94a6c96 isn't included. This
(security) issue was reported to emacs-devel three years ago.

Although I also argued privately for releasing based on the emacs-25 branch instead of just a thin release, Eli worried that the other changes in emacs-25 (including the change you mention) might have caused problems in 25.3's hasty release. As I recall, the security issue that you mention is not as serious as the one fixed in 25.3, since it occurs only in an unlikely installation nowadays (no gnutls library or binaries available) whereas the 25.3 issue is an easy way to break into anyone using Gnus to read email.



reply via email to

[Prev in Thread] Current Thread [Next in Thread]