Advice needed: update-manager in wheezy considered dangerous

Julian Andres Klode jak at debian.org
Wed Mar 13 23:01:30 UTC 2013


On Tue, Mar 12, 2013 at 08:21:52PM +0100, Julien Cristau wrote:
> On Tue, Mar 12, 2013 at 00:42:45 +0100, Julian Andres Klode wrote:
> 
> > Dear release team, I report this problem as we have switched our
> > package management stack in wheezy from update-manager and other
> > components to PackageKit. Those old components are still in wheezy
> > however, and especially update-manager can be considered to be
> > horribly dangerous: It might break systems or contain extreme security
> > issues as it has not seen someone really care about it since 2 years.
> > 
> You're going to need more convincing arguments than "might have issues"
> to argue for removal at this stage.  As in specific ones, preferrably
> with bug numbers attached.

Issues with bug numbers:
  * It might downgrade packages without any notice (#599523)
  * It often crashes (#607105, #671468, and about 10 others)

Issues without bug numbers:
  * Nobody knows how it works or has looked at this code since
    December 2010 (apart from two uploads; fixing only
    bugs with a new Python version and a build issue; but no
    fundamental bug fixes as nobody really knows this code)
  * It is installed on every default desktop squeeze installation,
    and thus on upgraded systems as well (wide exposure)

-- 
Julian Andres Klode  - Debian Developer, Ubuntu Member

See http://wiki.debian.org/JulianAndresKlode and http://jak-linux.org/.



More information about the pkg-gnome-maintainers mailing list