But a lot of programmers who have never done anything more difficult than mylamesocialstartup.com in PHP have no idea what it's like to build and test something as complex as an OS. No, recompiling your Linux kernel ain't the same thing.
It's now been 5 days PLUS however long they sat on this for ios.
Again, this isn't some little web site. This is a piece of software that thousands of programmers have worked on for more than a decade, millions of lines of code with a tremendously complex build, testing, release, and approval system.
And finally, Apple's primary concern isn't that a handful of customers might be exposed to risk for a couple of extra days. It's that they botch the rollout of a major security patch and have to re-release, or customers are victimized by new bugs as part of the patch. That sort of thing can cost them billions in market punishment.
You don't spend a week holding the fix hostage so you can fine tune a new os release with "improvements to autofill forms" in safari while script kiddies are running wild with mitmproxy.
Also I would think that a full ios+appletv OS release is much more complicated than an OSX release due to the way the mobile OSes are packaged (probably 10+ unique/model restore images plus delta downloads)
If their build process is so broken that it takes days to take the 10.9.1 tag, apply a one-line patch, and release it, then they're doing it severely wrong. Security problems happen, and you need to be ready to move fast.
Personally, if I was on that team and it came down to taking days to recompile and retest everything, I'd be seriously considering a binary patch as an interim fix. Take the actual built binaries, apply this one patch, and you know nothing else got somehow miscompiled or mislinked in the process.
You're right. It's not at all like Red Hat compiling and releasing a new RPM which they would push out in hours, max. It's actually much easier. Apple retains absolute control over their source code.
The manager who is holding the SSL fix hostage to 10.9.2's shitty feature-adds should be terminated out of a cannon. It's hilarious that we don't know who that person is -- who is the head of software security at Apple? From what I've heard there are at least two separate teams, and the relevant team is closely tied to Federighi, but no one outside Apple (generally) knows sub-SVP people at Apple.
There should be 10.9.1.1 with just the SSL fix. If that means delaying 10.9.2 another month, so be it.