1 |
On 07/11/2017 04:21 PM, Michael Palimaka wrote: |
2 |
> On 07/12/2017 12:15 AM, Kristian Fiskerstrand wrote: |
3 |
>> On 07/11/2017 04:13 PM, Kristian Fiskerstrand wrote: |
4 |
>>> On 07/11/2017 03:47 PM, Michael Palimaka wrote: |
5 |
>>>> The main risk of breakage of a package moving from testing to |
6 |
>>>> stable is always at build time anyway. |
7 |
>>> |
8 |
>>> citation needed |
9 |
>>> |
10 |
>> |
11 |
>> Anecdotal evidence against, currently gnupg 2.1.21 scdaemon bug will |
12 |
>> happily sign a third party public keyblock's UID using signature subkey |
13 |
>> on smartcard, which results in useless signature that doesn't have any |
14 |
>> effect, but the application builds fine. |
15 |
>> |
16 |
>> This means gnupg 2.1.21 is not a candidate for stabilization, but it |
17 |
>> certainly builds fine. |
18 |
>> |
19 |
> |
20 |
> Stop trolling - you know perfectly well that this sort of issue would |
21 |
> never ever be caught during arch testing. Nor should it be - it's called |
22 |
> *arch* testing for a reason. |
23 |
|
24 |
That presumes that the maintainer is the one calling for the |
25 |
stabilization, and it is not an automated procedure simply due to 30 |
26 |
days in ~arch. In this particular case, look for the number of bug |
27 |
reports filed in Gentoo for the issue. |
28 |
|
29 |
But the main risk is certainly not built testing, it is breaking |
30 |
operational live stable systems. Nowhere was it claimed that the arch |
31 |
testers are responsible for it, but it certainly doesn't coincide, at |
32 |
any point, with "The main risk of breakage of a package moving from |
33 |
testing to stable is always at build time anyway." |
34 |
|
35 |
-- |
36 |
Kristian Fiskerstrand |
37 |
OpenPGP keyblock reachable at hkp://pool.sks-keyservers.net |
38 |
fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3 |