RE: [PATCH v3 02/15] xdiff: introduce rust
- From
rsbecker@nexbridge.com <rsbecker@nexbridge.com>
- Date
- Sep 8, 2025, 15:41 UTC
- Message-ID
- <049501dc20d7$0bb08ed0$2311ac70$@nexbridge.com>
- In-Reply-To
- <CAH=ZcbAjpgAVjVK6iYEr2150a+WgFfxrWuJUoR1pa08JqM4BDw@mail.gmail.com>
On September 8, 2025 11:10 AM, Ezekiel Newren wrote:
Show 43 quoted lines
>On Sun, Sep 7, 2025 at 10:10 AM <rsbecker@nexbridge.com> wrote: >> >> On September 7, 2025 12:10 AM, Elijah Newren wrote: >> >Sorry for the delay; life outside of work is challenging at the moment... >> > >> >> I am going to address the critical point mentioned below and snip the rest for >brevity. >> >> >I still don't see why distributors _must_ ship the latest version of >> >Git and why folks on some platforms are considered broken if they are using a >slightly older version. >> >Let me ask again: has anyone answered why this is considered >> >mandatory? If they have, I've missed it, but I've asked multiple >> >times. Even if you want to lump "distributors cannot build a newer >> >version" under the umbrella of "breaking changes", I argue it's a >> >much different kind of break and one which merits different timelines for >handling than e.g. lumping it in with 3.0. >> >> I do not see that distributors _must_ ship the latest version. Suppose >> we are on >> 2.51.0 and a CVE comes out that prohibits its use in an organization >> that does not allow any medium-high to high CVEs. This represents >> hundreds of thousands of impacted users in my community alone. How >> does the CVE get applied if the latest cannot be built and the git >> team does not apply the CVE fixes to old versions. Personally, I do >> not care if git versions are different between work and home, or even >> between CI/CD and other platforms. I don't even care ... > >Ok, that answers the question for NonStop, but that doesn't answer the question >for the plethora of other distributions. Most distributions don't ship the latest >version of Git in their package manager, and if an organization deems it critical to >have the latest they can build it themselves and ignore the Git version in the >package manager. So why does Windows, Mac, Linux, etc... _need_ the latest >version of Git in the package manager? > >If security updates are backported to NonStop, until that platform supports Rust, >then I don't see why using an older version of Git in Windows, Mac, Linux, etc... is a >catastrophe. Most existing distributions _can_ package the latest version of Git, but >they _don't_. > >I reiterate Elijah's question "Why _must_ distributors ship the latest version of >Git?".
My emphatic answer is that they do not. There is no requirement from me or anyone I know to ship the latest version. What is crucial is that there be fixes for medium-high and above CVEs that are delivered in 30 days from initial fix availability (that would be in Rust, for this conversation and applied to C). If that were supported, I could live with as would my customers and their auditors for LTS releases. Please see my expectation of LTS defined elsewhere in this thread - essentially 5 years. Perhaps 3 at a bare minimum.