From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-oa1-x32.google.com (mail-oa1-x32.google.com [IPv6:2001:4860:4864:20::32]) by sourceware.org (Postfix) with ESMTPS id 8BB513858C5E for ; Thu, 12 Oct 2023 18:22:06 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 8BB513858C5E Authentication-Results: sourceware.org; dmarc=pass (p=none dis=none) header.from=dinwoodie.org Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=dinwoodie.org Received: by mail-oa1-x32.google.com with SMTP id 586e51a60fabf-1dd2e4f744dso173025fac.0 for ; Thu, 12 Oct 2023 11:22:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dinwoodie.org; s=google; t=1697134926; x=1697739726; darn=cygwin.com; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=zBXAouw0MAHsdqBLCAwk3iKAOqaTdLagt8/CcGTu9pg=; b=LGdWjjCSbB5mo/7BAGF9ektlJtgYENz9vALLH7WCbmC1mUAxgQSAs2nTtP6STLVxrw f/tBfScRWX0DiQHFfpMSBJdq+qnQ6AQEgy9T9reuI3fwFauRVK7r3R9FAXAzz7weRsPF gvN21RkqeYLtV6UMz3CITg8qoVnrT5ZzGwZt8E5PmaZYQ3PEULRXfqBwaFFF8QafZs3N O/MS3vGxhcYHJgOQsukteRnCOxDcOC2gTqTJJ0fGf94WfiHVZXdJoG37X8YnU7vK3Fs2 IOJXxPqByvIdZqVurFFZCun05mLxq7lGHo3Wwal4D3650N45iZQEaS7bwO/Zy2Hfy9JQ PAmQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1697134926; x=1697739726; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=zBXAouw0MAHsdqBLCAwk3iKAOqaTdLagt8/CcGTu9pg=; b=Qhvha1JH/aFCTZHZBtx4qTfoNpCulI4fwLBkXeUvWZAdbcw4Xuccg65YQPJ/trsPb3 8Qad4SLmHMz4E4QQZaB1iiLUe9nkS3yjgvfDW8AGN4+NauQbVwpGz5I3PqbwYvcT9Tcp 0MIBKTYoYxyWwS64kNsJznesKQQ/6KOmOxigWQJVpMiI8m/t6OTkmmRQc6ZACMyFdXyD 5YSIsC3FDICj6mcxakoUPEtVkfxAVrwMWuohcH2yIO8h1mRZWI9Cal5DeiDfpRt2ql+/ nBRxZvkvpDfuSOKmtuSBVdlADIiXOAUEjC6ooBozUXEmuIbMX9vuKpZI+HjZsEswFXc9 pMrw== X-Gm-Message-State: AOJu0YwRSsjzOTL7mR7CaDx7TghZiqyC6ISZZgNdn+4HzAiyM2lDhVMK bnQwpXOZ3FjINrAZ+c76u0hmBB9tRcHkT0MOgRdTBQ== X-Google-Smtp-Source: AGHT+IGoHkMKiW+11EF8lNbfjtkE/VkFHlhXIuqoQ2NlGM2wi34FSJtFPydL22aPjKZsEfSiYhBSZ6YDNNWWoCdJBms= X-Received: by 2002:a05:6870:a111:b0:1e9:bbfe:6458 with SMTP id m17-20020a056870a11100b001e9bbfe6458mr2656448oae.1.1697134925621; Thu, 12 Oct 2023 11:22:05 -0700 (PDT) MIME-Version: 1.0 References: <8cae1a30-cc92-cbea-4599-d7d550850ac5@cs.umass.edu> In-Reply-To: From: Adam Dinwoodie Date: Thu, 12 Oct 2023 19:21:39 +0100 Message-ID: Subject: Re: Ruby EOL in Cygwin 3.4.9? To: Eric D Hendrickson Cc: gs-cygwin.com@gluelogic.com, "Hendrickson, Eric D" , "cygwin@cygwin.com" Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Spam-Status: No, score=-0.4 required=5.0 tests=BAYES_00,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS,TXREP autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org List-Id: Picking up a few threads that I think others might have missed, and which I think are worthy of acknowledgement=E2=80=A6 On Thu, 12 Oct 2023 at 05:16, Eric D Hendrickson via Cygwin wrote: > How does Cygwin being an all volunteer effort have any bearing on this > question, other than the time and interest of the volunteers? The fact that this is a volunteer effort doesn't have much direct bearing. But the fact that we're volunteers means that time and interest are very finite quantities. There are really not many folk involved in actually making Cygwin, and I think everyone actively involved in the project already has a wishlist of things they'd do if they had the time. > Perhaps the volunteer team should consider adopting a process of evaluati= ng > the support status of every package it redistributes, even at the expense > of slowing down the rate of releases. Or dropping packages when no one h= as > the time or interest in creating a package from a supported version of th= e > tool in question. Packages do get dropped from the distribution occasionally when they're no longer being updated and no longer viable. I don't believe there's any comprehensive package-by-package review, because that's a lot of work, and it's not even very interesting work. But if someone provides a reason a specific package should be dropped, it can happen. The mere fact that a package no longer has upstream support is probably not enough, though; I expect we'd need no upstream support and either a genuine significant vulnerability in the package, or availability of a viable replacement. > Again for the benefit of Cygwin as a whole - distributing EOL packages > could put Cygwin as a whole at risk, which I'm sure you would agree is mu= ch > worse than dropping a package from the suite. I don't agree. If Cygwin mandated that packages be kept rapidly up-to-date or be dropped, I expect Cygwin would rapidly become unusable. A lot of our package maintainers =E2=80=93 myself included =E2=80= =93 are only able to work on Cygwin as and when they have the time. If the project required maintainers to spend a regular amount of time on their packages, which a reliable update schedule would require, I expect a lot of us would just stop contributing. When there are vulnerabilities identified, we can and do move quickly to mitigate them. The fact that there's some EOL products available through Cygwin is at least in part because there aren't any significant security vulnerabilities that we're aware of. It would, of course, be nice if the cutting edge were available for everything, but that has its own disadvantages: rapid release cycles have more chance of introducing new bugs. There's a reason plenty of people use Debian Stable; there's lots of critical infrastructure still running on Python 2. (But, of course, the package in question here is actually reasonably up-to-date: as Yasuhiro Kimura noted, the Cygwin mirrors are distributing ruby 3.2.2-2, which has an advertised upstream EOL date of March 2026. So a possibly more useful question is why *you* are deploying an EOL version when more up-to-date versions are available! To investigate that, I think we'd need a useful bug report explaining what you're doing to get an install with such an old version.) I also think it's worth remembering the use case for Cygwin. Cygwin is designed to provide a *nix-like environment for Windows users, with relatively little effort required to port software that was originally written for *nix systems. The sorts of use cases where you really care about most zero-day vulnerabilities aren't ones where I'd expect Cygwin to be in use; if you have a public-facing web server, for example, using Cygwin is a bad idea, not just because of the security concerns, but also because Cygwin makes a lot of compromises around performance, and you're likely to have a vastly better experience using a Windows-native or Linux-native web server. > This goes back to my other question - > > Is there an Issues log or backlog a la GitHub where bugs / enhancement > requests / feature suggestions like this can be logged for future > consideration / evaluation, instead of one off discussions in this > ephemeral medium of email? Email isn't ephemeral: everything sent to this mailing list is archived indefinitely. You can browse and search the archives at https://cygwin.com/lists.html. That said, there is a reason folk use bug trackers. There's no central bug tracker for Cygwin; individual maintainers may have their own systems for tracking problems (I use GitHub), but there's no mandate about what to use or how to use it. Even if we had someone willing to set one up and maintain one, migrating to a central bug tracker is a very significant amount of work, and it's not work that many people would find fun or interesting. If you want to help, there's a list of packages that don't have maintainers at http://www.cygwin.com/packages/reports/unmaintained.html =E2=80=93 if you'd be willing to adopt one of those and keep it a bit more up-to-date, that's likely to be very well received. If there are packages not on that list but which you think need updating, you could offer to help the maintainer with getting them up-to-date, or =E2=80=93 if = the maintainer is unresponsive for any reason =E2=80=93 offer to produce an upd= ate to be packaged as a non-maintainer-upload. The general guidance on how to manage Cygwin packages as a maintainer is at https://cygwin.com/packages.html. More general advice on contributing to Cygwin is at https://cygwin.com/contrib.html. Conversely, asking people to do more work, for free, tends not to go down well. You did offer to help =E2=80=93 thank you! =E2=80=93 but asking = for folk to tell you how to help is itself asking other people to do work for you. All the links in the previous paragraph are ones that can be found in one or two clicks from the Cygwin home page, and while http://www.cygwin.com/packages/summary/ruby.html is a little harder to find, it clearly shows that one of your key assumptions =E2=80=93 that Cygw= in is distributing a version of ruby with no upstream support =E2=80=93 is onl= y true if you include cases where someone is deliberately choosing to use an old version. This is a community that tends to be much more supportive when people show they've done at least some initial investigations themselves. We do want and need more people contributing to Cygwin; new volunteers are genuinely great. Hopefully all the above is useful for you and for the archives about how to usefully contribute.