Do you think equally-bad bugs haven’t made it into upstream projects directly? Hell, many downstream patches exist to fix security bugs.
It was a predictable result of Debian policy, which Debian did not see fit to change. Debian still patches upstream sources including security-critical software, still does not have any dedicated security review of those patches, still leaves it up to individual maintainers to decide whether and how to clear these things with upstream, and still thinks all of this is fine.
> Do you think equally-bad bugs haven’t made it into upstream projects directly?
Honestly, I can't think of a single equally-bad bug in "normal" code, only in medical devices / industrial controllers / etc.. Cloudbleed wasn't this bad. Bumblebee deleting /usr wasn't this bad. It really was a uniquely awful bug.
It's not fine, but when the upstream authors do not regard or consider requirements of downstream projects, what can you do? like with the example of phonehome features?
arch and other distros are only possible, because for a long time, debian and other distros kept nagging the upstream authors for missing features or "nonfeatures". if debian wouldn't exist, i bet, arch had to patch much more itself.
Well, as one of those upstream authors whose code was patched: I was never contacted about it, so I never knew there was a requirement to be met, and so they carried around a bad patch for years, about which I knew nothing. Once a user pointed this out to me, the next release fixed the underlying issue in a better way. After years in which the Debian folks didn't file an issue or report the problem in any way that I could tell.
Mind you, Debian is not alone in this, it happens with other distros, too.
And to be fair, I think this rather depends a lot on the downstream package maintainer; I've witnessed this with other projects where they were quite good in interacting with upstream to get something sorted out. I am not really sure if any policy Debian/Fedora/... could enact would really help with it; people can (accidentally or intentionally) ignore them.
In my experience it's rather uncommon for a DD not to contact upstream. Would you mind sharing the package name and vulnerability so I and others can learn what happened?
Upstream was contacted about it: https://marc.info/?t=114651088900003&r=1&w=2
the maintainer made an error there. did you open a bugreport that you fixed it so the patch is not necessary?
> And to be fair, I think this rather depends a lot on the downstream package maintainer; I've witnessed this with other projects where they were quite good in interacting with upstream to get something sorted out. I am not really sure if any policy Debian/Fedora/... could enact would really help with it; people can (accidentally or intentionally) ignore them.
yeah and that's the point. people in this thread (not you as far as i see) say they do not trust debian because of this, but other distributors and packagers? do they have technical or organisatorial fences for avoiding such mishaps? if not, then other distributions are as problematic as debian, even arch.
debian did a whole lotta good for Free software and i really start to dislike how people shit on the project (again not you).
Many distributions have a dedicated security team that has to sign off any patches to security-critical software. Debian's position is that they do not have the resources for such a team, which is fair enough, but IMO the conclusion should be that they don't have the resources to be applying their own patches to security-critical software.
More subjectively I get the sense that Debian packagers patch more aggressively and generally think the Debian way of things is better. This isn't completely groundless: there's a lot of very high quality engineering in Debian, and for a long time their package management was head and shoulders above others, especially if we're talking about C programs/libraries where upstream dependency management is very weak. But it's also made for a culture where packagers think they know better than upstream maintainers, and an approach that ends up conflicting quite a bit with newer languages where there is high-quality dependency management in the upstream builds.
Which are some of those distros? (I'd consider using myself in the future)
This is false. Debian has a security team and it's way more active than most distributions.
> But it's also made for a culture where packagers think they know better than upstream maintainers
Yes and for good reasons.
On the flip side of the coin, there are plenty of open source authors who release their work into the wild and refuse to support or even engage with downstream packagers because they see any other distribution or use of their work as Not Their Problem. And they're not really wrong, building a supportive community around a useful project is totally optional after all.
Between the constant stream of version bumps, security updates, patching, bug triaging, and user support, distribution maintenance seems to be the most thankless job in the open source world.
It was interesting because the cause was a patch crafted to satisfy a static analysis tool they insisted on applying to every package, which demonstrated their want to go above and beyond with respect to quality. Kudos to Debian in that regard. But a blindly applied policy, and bad judgement in disabling some cryptographic initialization code, caused a terrible bug.
I wonder if this is less of an issue today because of well defined kernel interfaces for getting "good" random numbers (i.e. cryptographically suitable). I'm sure the devil is in the details, and OpenSSH's support for unpopular systems means intentional use of uninitialized variables is still in the code base. It's all very impressive to an outsider who knows enough not to tell cryptographers how to do their job.
More than a decade ago a programmer friend got Ubuntu running on a second hand desktop for a rather computer illiterate arts & letters student. He was able to navigate the GUI like any other system, and it had Firefox, OpenOffice, and mplayer. I knew then that Linux is a perfectly fine desktop OS. And now we're back to using Debian of a sort. ;-)
I stopped using Debian when its ridiculous "free" purely ideological approach to software actually caused me issues.
I needed to install Debian on a relatively old laptop a few years ago. It had all "mainstream" hardware. It's WiFi adapter was an Intel one (and a very common/popular one at the time), but it was one that wasn't open source.
How did Debian approach this? It's installer gave me a not very subtle passive aggressive message telling me that although they have the drivers for the device, it was not going to install them... because the ISO did not include them. With no working WiFi, it of course could not connect to the internet to download them! Worse still, turns out that even if it had connected to the internet it wouldn't have downloaded and installed them anyway. I found this out because I managed to use an Ethernet connection.
Completely stupid and frustrating and it felt like I was being blamed as if it was my fault.
Installed Ubuntu, included the drivers, connected to WiFi during the installation.
I have not used Debian on anything since.
I like it that that try to focus on a completely free version, as that is what they stand for and why a lot of people respect them, while at the same time being realistic about the real world problems that people face.
And Debian is great. We might take it for granted now, but 2 decades ago while everyone else was fiddling with their own package dependencies with RPM (pre-Yum) Debian had amazing package management with builds for all sorts of amazing architectures. They were leaders both in thought and execution.
I tried (but failed) to influence an employer to invest more in Debian; instead they went with SuSe which eventually caused a few small problems. Now Debian & Ubuntu are booming.
They do provide "nonfree" install media which include firmware blobs that many people need to get their wifi up - https://cdimage.debian.org/cdimage/unofficial/non-free/cd-in.... But it's not easy to get there (I google "Debian nonfree") and it has "unofficial" in the URL which I imagine doesn't help things either.
I understand that Ubuntu is meant to be the user-friendly Debian-based distro and that Debian is meant to be Free Software first and foremost. I just wish that this nonfree install image was a bit more official and easier for users to discover.
edit: oops, I should refresh before hitting "reply" I didn't see the other answer
So the "firmware" I required for my Thinkpad's wifi to work (and which was included in that Debian nonfree image) is this: https://wiki.debian.org/iwlwifi
update: actually on that Debian wiki there's a page called "Firmware" which explains things well https://wiki.debian.org/Firmware
It validates their hobby-like approach to their OS.
Most run Ubuntu or Debian, and a few run Arch. And every few weeks someone mentions again how something broke, and they need to spend some time fixing it. I think the last one was VMWare not working on a kernel yet.
Arch requires more time to maintain, and more manual maintenance. So in order to justify that extra spent time a lot of times they will bring up minor stuff that happens in Debian/Ubuntu, like this bug from 12 years ago, in order to justify running Arch, which is more of a "learn Linux" hobby.
That being said, running Arch on a computer that you need to be working at all time, might not be a good idea for professional reasons. However, I think you are essensially making a similiar argument for Arch, as they are making for the Debian bug.
I learned my lesson. From now on it is boring LTS distros only, and guix for things in userland where I want up to date things.
This is the feeling I get, and it's why I never bothered with Arch, or Gentoo before that. I started on Slackware, and while it was a great learning experience, I feel that's not a lesson I need to repeat.
Same reason for my move from RedHat (after an RPM dependency breakage) to Debian: Debian just works. It GTFO of my way and let's me focus on my code and my projects. Yes, there have been issues, no, Debian isn't "perfect", but like my preferred MUA "it sucks less than all the alternatives."
I've used Arch for the last six+ months and I don't want this to happen.
I switched as I couldn't get VFIO to work with Debian (presumably due to outdated kernel/qemu/libs). In my time with Arch I have had no problems. It has just worked and stayed out of my way. My experience with Debian is that it mostly works, but often uses much older software than one wants. Arch, in my limited experience, is an excellent distribution.
This is only personal observation, not direct remark to your case. I've just seen similar scenarios too many times.
On the other hand - I've played with Arch since early beginnings, but last time more than 10 years ago. Although minimal, simple and straightforward, I have never been able to grope that rolling-release core philosophy.
TL;DR: To silence a valgrind warning, Debian maintainers added a local patch to OpenSSL that commented out the entropy pool, making all SSL keys predictable.