From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp0 ([2001:41d0:2:c151::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms11 with LMTPS id kPwxBfZzUmBVYgAA0tVLHw (envelope-from ) for ; Wed, 17 Mar 2021 21:26:14 +0000 Received: from aspmx2.migadu.com ([2001:41d0:2:c151::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp0 with LMTPS id iFDbAPZzUmAlZgAA1q6Kng (envelope-from ) for ; Wed, 17 Mar 2021 21:26:14 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx2.migadu.com (Postfix) with ESMTPS id B420623451 for ; Wed, 17 Mar 2021 22:26:13 +0100 (CET) Received: from localhost ([::1]:38864 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1lMdgC-00012c-Og for larch@yhetil.org; Wed, 17 Mar 2021 17:26:12 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:51436) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lMdff-00011r-K4 for guix-devel@gnu.org; Wed, 17 Mar 2021 17:25:39 -0400 Received: from mail-wm1-x32a.google.com ([2a00:1450:4864:20::32a]:37433) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1lMdfa-0001Nq-5i for guix-devel@gnu.org; Wed, 17 Mar 2021 17:25:38 -0400 Received: by mail-wm1-x32a.google.com with SMTP id f22-20020a7bc8d60000b029010c024a1407so4214055wml.2 for ; Wed, 17 Mar 2021 14:25:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:in-reply-to:references:date:message-id :mime-version:content-transfer-encoding; bh=tghk2uF1eZExw6xI9CrUHwFqLg/1nNEzy5iYPmaUyiA=; b=QJ4/ijxB6dFxRFq6Xq+zGF9WgKoxxSiK1ELhONNoWy4M8oZKk2TkFXLfU5+MMGM+sa jb7vEaw078SKEcpMQr2zYiRwMZz2lPFQkPvTenLRzggsI0JaTnv6QZL1GObX23oRiHiw pibiw6d10QbhCZRHQfYcEZKzxYPXJ751vv+ebDWh/VaNaFnm19s60lLc8wOID91lnH8x Tunqs0K0a1VSGfu5ZrjAn2NbzdWv1dGAKCzj1TH95LFCcoSxXy/E1Zdg4wh/TMqNoiBs GtpExxGd0BJO1bdmKnrC6jkWS3lNVhW6Yzz1VMKYqAduFi8u78AiE7pp2j25wZs+pRq/ xfZg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:in-reply-to:references:date :message-id:mime-version:content-transfer-encoding; bh=tghk2uF1eZExw6xI9CrUHwFqLg/1nNEzy5iYPmaUyiA=; b=YcZ2axaIQcO2xb5OgwBPzc1Se8nFz4MZoBqAvGi+Mdbf/dirvhM0ZHwK/GVyU6UMGn Gkdfa2gneBPwFZMW2X4MJdTMH4/mNvSZmy4kaL53xwQVpfj8everLx9QFNmY35DzBwdu Il/jVmQElIbfpc6cqBsYkxQHyzpH2SgEdZXMK7hrF4445g8UviiH9f7RB3WhqdcYKI4c L2WfeLXtM+gQxNtCMpVLKWxX1pLmZrwd/WNx2H3vZVex9YO25qN6FVV5lyNkFfJYG6Jq sYjAwC6cb0H+sR5OFHZSlTTuW4+g7ZKpINi5ltSob9ddRLOATph4S1wGtIxMcSwfVe+0 VDJw== X-Gm-Message-State: AOAM531rKbDI1w4ovUEciA1zuH3+w5UMDB/yhgiXNT+rAbiPvngpWzLW MCjR93cZQHzRfKGKrzKXAyC89qrK1R0= X-Google-Smtp-Source: ABdhPJyEtRDZAGoUBFcVLlioDWY3sEL9DQqd0jt84ceoRACYtK9U7BGK6YP42mwiELbp2Of8u2tVBQ== X-Received: by 2002:a1c:448a:: with SMTP id r132mr627420wma.157.1616016332289; Wed, 17 Mar 2021 14:25:32 -0700 (PDT) Received: from lili ([2a01:e0a:59b:9120:65d2:2476:f637:db1e]) by smtp.gmail.com with ESMTPSA id f22sm109027wmc.33.2021.03.17.14.25.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 17 Mar 2021 14:25:32 -0700 (PDT) From: zimoun To: =?utf-8?Q?L=C3=A9o?= Le Bouter Subject: Re: Why [bug#47081] Remove mongodb? In-Reply-To: References: <20210312005632.13690-1-lle-bout@zaclys.net> <86ft0twwg8.fsf@gmail.com> <86a6r1wtnz.fsf@gmail.com> <61252a58340e1491b950bd619e73103e93515877.camel@zaclys.net> <86zgz1vcjx.fsf@gmail.com> Date: Wed, 17 Mar 2021 22:24:09 +0100 Message-ID: <86lfalv5hi.fsf@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Received-SPF: pass client-ip=2a00:1450:4864:20::32a; envelope-from=zimon.toutoune@gmail.com; helo=mail-wm1-x32a.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: guix-devel@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: guix-devel@gnu.org Errors-To: guix-devel-bounces+larch=yhetil.org@gnu.org Sender: "Guix-devel" X-Migadu-Flow: FLOW_IN ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1616016373; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:list-id:list-help: list-unsubscribe:list-subscribe:list-post:dkim-signature; bh=tghk2uF1eZExw6xI9CrUHwFqLg/1nNEzy5iYPmaUyiA=; b=aVT/bhrwSEO2se30AOp7HFQscSIns3a3V563NblOpCZdUSfHzPe0q+Xu6Jw4hTzGgxgGwE B4FtuzpWC1pOijROpkct52tkyG6ZPu66mtv2IZ4v5KQG3g9615idl6UWYVhrw+2KLcIHee uZ33dWPcyrUpTXovxkKcUfKytmMEQhas5TJTmhz1HUkL2duNucovdUk9N39SKLV0XFDo/r yGHyyAR6mDNFQX2tecZEY58XlGXozYATpvYMiZJmKS+9yEXTzvnU6QSCbba9JAWAzRgVKU +oW2S0+Bj6gXW1g9UKIuAOBJVjhe96cAPDEF1ODl0Uh6M8lWv0oSbdPTZ/xWcQ== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1616016373; a=rsa-sha256; cv=none; b=bIaPehO/AeNIV6DhVJmXY7JSUP67T8LntQ7t8mX/Ji+nvqnKqtJu0YY8n7sdiFg4nh88lx 0k/fq0yjYL4F3zfQq4n6XY5LO0Avv1SoJQKy688P3oJElSmqgNpyi0R+jTKxl5O4tyVBYS 873aF9xdsBebPOkvUyHkVAVyUtbPdBjlrg8b+leFHwNPJIPRGJzCEUTEbOc1ph57/EAzBr W7LWbILs9xtWy4vSsCEAy2Ddsd6RfsyshfN3WW9XamCjLi+2KMLfD7xl61dNpA7EKKHVkf Lrlv3XB1u1wrCN45iwO5Xm+vMHhRXU8lwN8neXvzxNvePvG2t6NF3Ew7aTW1hw== ARC-Authentication-Results: i=1; aspmx2.migadu.com; dkim=pass header.d=gmail.com header.s=20161025 header.b="QJ4/ijxB"; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (aspmx2.migadu.com: domain of guix-devel-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=guix-devel-bounces@gnu.org X-Migadu-Spam-Score: -2.10 Authentication-Results: aspmx2.migadu.com; dkim=pass header.d=gmail.com header.s=20161025 header.b="QJ4/ijxB"; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (aspmx2.migadu.com: domain of guix-devel-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=guix-devel-bounces@gnu.org X-Migadu-Queue-Id: B420623451 X-Spam-Score: -2.10 X-Migadu-Scanner: scn0.migadu.com X-TUID: 0Prv7g+vqetw On Wed, 17 Mar 2021 at 20:11, L=C3=A9o Le Bouter wrot= e: > On Wed, 2021-03-17 at 19:51 +0100, zimoun wrote: >> It shows exactly my point. The correct and polite way of doing the >> thing is first to examine the issue at hand (3.4.10 is old with >> security >> vulnerabilities), then propose a fix (e.g., the removal), wait >> feedback, >> and complete. > > Actually we did not know pushing a security fix with 3.4.24 was not > fine, from quick auditing I have made 3.4.24 would still be under AGPL > so it would be fine to upgrade, turns out not since some files inside > are under SSPL but that was discovered way later, even when Efraim had Later means here only hours. > doubt and reverted my commit we had a debate and Efraim bought my > arguing even though I was wrong and they were right, if for every > security issue I have to ask feedback I may not ship them in a timely > manner, so that's also why they tend to be pushed faster than usual.. Haste is not speed. > we may want to establish a clear process here. I usually create issues > for things I need help on, if I can do it myself and feel confident, I > just push, I can be wrong of course and always sorry for issues, I fix > them shortly in next commits if any. I really appreciate your valuable work. I have the impression you think that you have to push as fast as you can, whatever if it is the right fix. If I might, first please avoid to burn out and second do not worry, the world will not explode because of a security vulnerability in Guix. Maybe one day when Guix will dominate the world, soon! :-) I am not convinced that the regular Guix user is upgrading their package set twice a day; maybe once a week at best and more probably time to time. Guix is rooted in The Right Thing=E2=84=A2 and sometimes it means de= lay to think what the right thing really is. Therefore, the process is already clear: go via guix-patch for non-trivial changes and wait feedback. At the end, I cannot express better what Tobias wrote: or Leo: =20=20=20 All the best, simon