Re: Security lessons from liblzma - Mailing list pgsql-hackers

From Bruce Momjian
Subject Re: Security lessons from liblzma
Date
Msg-id ZgjB7-Kvvj4xYluH@momjian.us
Whole thread Raw
In response to Re: Security lessons from liblzma  (Joe Conway <mail@joeconway.com>)
Responses Re: Security lessons from liblzma
Re: Security lessons from liblzma
Re: Security lessons from liblzma
List pgsql-hackers
On Sat, Mar 30, 2024 at 07:54:00PM -0400, Joe Conway wrote:
> Virtually every RPM source, including ours, contains out of tree patches
> that get applied on top of the release tarball. At least for the PGDG
> packages, it would be nice to integrate them into our git repo as build
> options or whatever so that the packages could be built without any patches
> applied to it. Add a tarball that is signed and traceable back to the git
> tag, and we would be in a much better place than we are now.

How would someone access the out-of-tree patches?  I think Debian
includes the patches in its source tarball.

-- 
  Bruce Momjian  <bruce@momjian.us>        https://momjian.us
  EDB                                      https://enterprisedb.com

  Only you can decide what is important to you.



pgsql-hackers by date:

Previous
From: Thomas Munro
Date:
Subject: Re: pg_combinebackup --copy-file-range
Next
From: Thomas Munro
Date:
Subject: Re: pg_combinebackup --copy-file-range