From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Glenn Morris Newsgroups: gmane.emacs.devel Subject: Re: proposal: require GnuTLS 3.1.x (previous stable) Date: Sat, 29 Nov 2014 15:02:53 -0500 Message-ID: References: <87389762xj.fsf_-_@lifelogs.com> <87h9xnqfdl.fsf@violet.siamics.net> <87mw7eaz2w.fsf@lifelogs.com> <87oartaoq7.fsf@lifelogs.com> <87egsp8xul.fsf@lifelogs.com> <87bnnr40qo.fsf@lifelogs.com> NNTP-Posting-Host: plane.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Trace: ger.gmane.org 1417291415 7397 80.91.229.3 (29 Nov 2014 20:03:35 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Sat, 29 Nov 2014 20:03:35 +0000 (UTC) To: emacs-devel@gnu.org Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Sat Nov 29 21:03:31 2014 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1XuoEo-00036I-MM for ged-emacs-devel@m.gmane.org; Sat, 29 Nov 2014 21:03:26 +0100 Original-Received: from localhost ([::1]:48709 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1XuoEo-000696-9s for ged-emacs-devel@m.gmane.org; Sat, 29 Nov 2014 15:03:26 -0500 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:48311) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1XuoEJ-0005k6-VA for emacs-devel@gnu.org; Sat, 29 Nov 2014 15:02:56 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1XuoEI-0006j8-5L for emacs-devel@gnu.org; Sat, 29 Nov 2014 15:02:55 -0500 Original-Received: from fencepost.gnu.org ([2001:4830:134:3::e]:46144) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1XuoEI-0006ix-3M for emacs-devel@gnu.org; Sat, 29 Nov 2014 15:02:54 -0500 Original-Received: from rgm by fencepost.gnu.org with local (Exim 4.71) (envelope-from ) id 1XuoEH-0003Zn-4l; Sat, 29 Nov 2014 15:02:53 -0500 X-Spook: AVN Roswell Steve Case president COSCO underground X-Ran: AL&c6+3rAv>tacrVqV|rxSJY&G|ZqK#x%lj6]n1qzXWXQ0&IX-u(,Z@Rg5>ipC#"#}OL|v X-Hue: white X-Attribution: GM User-Agent: Gnus (www.gnus.org), GNU Emacs (www.gnu.org/software/emacs/) X-detected-operating-system: by eggs.gnu.org: Error: Malformed IPv6 address (bad octet value). X-Received-From: 2001:4830:134:3::e X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:178484 Archived-At: Ted Zlatanov wrote: > "Whether you need to support gnutls 2.12.x is up to you. However, I note > that this version is totally unsupported, if it is broken or has a > critical bug you are on your own." Unsupported by _upstream_ gnutls. However, it is part of the function of LTS distributions to backport security patches to the versions that they include (or if that is impossible to update to newer versions). Eg I can assure you that this is what Red Hat will do for RHEL6 (it was in the context of RHEL6 that this issue first came up). Debian security, Ubuntu LTS, they all do the same kind of thing. It's not Emacs's problem, and not your problem, to worry about these things. Emacs should just (generally speaking) support whatever library versions the commonly used distributions support, and let the distributions worry about security issues in those libraries.