WOW! The developers came alive!

Discussion of general topics related to the new version and its place in the world. Don't discuss new features, report bugs, ask for support, et cetera. Don't use this to spam for other boards or attack those boards!
Forum rules
Discussion of general topics related to the new release and its place in the world. Don't discuss new features, report bugs, ask for support, et cetera. Don't use this to spam for other boards or attack those boards!
Martin Blank
Registered User
Posts: 687
Joined: Sun May 11, 2003 11:17 am

Re: WOW! The developers came alive!

Post by Martin Blank »

CVS updates to 2.0.x have occasionally been made in the past outside of official releases, though I don't think they've had much or anything to do with security. This is a break in the common tradition, but not unheard of.
You can never go home again... but I guess you can shop there.

NeoThermic
Registered User
Posts: 198
Joined: Fri Jan 02, 2004 3:44 pm
Location: United Kingdom
Contact:

Re: WOW! The developers came alive!

Post by NeoThermic »

Security fixes are not committed to the CVS until after the release of the next phpBB version for the reason that 'code reader' mentioned (i.e. we don't want anyone reversing the fix and working an exploit from it). This has been policy for as long as I can remember, and that’s about from 2.0.4 onwards.

This doesn't make phpBB "closed source". To be 'open source', that means you'll be able to download the code of a release. It would be nearly impossible for phpBB to become closed source (since its PHP files, and they are a matter of text).

What you're seeing from the CVS in relation to commits to the 2.0.x line is Graham going through the bugtracker and fixing the bugs reported. If you feel like helping, grab a CVS of phpBB, read the bug you want to check, and see if the fix does indeed fix it. If it doesn't, reply back into the bug.

Finally, one must note that bugfixes committed to the CVS for the 2.0.x line isn't unusual; it just wasn't done for a while due to many factors (no bugtracker, priority on security updates, etc)


NeoThermic
phpBB release date pool!
The NeoThermic.com... a well of information. Ask me for the bit bucket so you can drink its goodness. ||新熱です

APTX
Registered User
Posts: 680
Joined: Thu Apr 24, 2003 12:07 pm

Re: WOW! The developers came alive!

Post by APTX »

But as long as phpBB is "open source" the fixes will be found. So... the only reason I see for adding all fixes at once is to make it harder to find the fixes which is very close to "doesn't make sense" for me. :|
Don't give me my freedom out of pity!

code reader
Registered User
Posts: 653
Joined: Wed Sep 21, 2005 3:01 pm

Re: WOW! The developers came alive!

Post by code reader »

ok, i'll try one last time.
the vast majority of phpbb users (ie, people who operate phpbb sites) do not have (and do not want) access to the cvs repository. they rely on the "official realease" to update their site.
otoh, its a fair assumption that the hacker "community" do actually look at the cvs repository.
committing a security fix to the cvs will highlight (no pun intended) a vulnerability, without actually giving the main user-body any solution.
so, with the security-related fixes, it makes perfect sense for the cvs repository to trail the official release. such a rationale does not exist for non-security related bug fixes.

APTX
Registered User
Posts: 680
Joined: Thu Apr 24, 2003 12:07 pm

Re: WOW! The developers came alive!

Post by APTX »

I think I get it :) .
2 things:
me != most of the users
and cvs != the official version
The first time I undestood it as something like "not commiting the fix becouse it might not really work" and I wondered why commit something like that...
Don't give me my freedom out of pity!

User avatar
Acyd Burn
Posts: 1838
Joined: Tue Oct 08, 2002 5:18 pm
Location: Behind You
Contact:

Re: WOW! The developers came alive!

Post by Acyd Burn »

We are not committing security fixes before the package has been released, else users would instantly check the changed code and write scripts to attack phpBB boards. People tend to do this, yes. After the release we are checking in the changes of course.

Bug fixes to the codebase are checked in normally. This is also useful for those using the latest 2.0.x CVS and those wanting to help bug hunting and test the fixes (sometimes a fix introduces another bug or behave "strange").

BTW, open source does not mean open development. ;)

Image

User avatar
Vigacmoe
Registered User
Posts: 27
Joined: Mon Jul 19, 2004 7:01 am

Re: WOW! The developers came alive!

Post by Vigacmoe »

trenzterra wrote: anyway i found something weird today: http://sourceforge.net/mailarchive/foru ... um_id=2657" target="_blank
It's Japanese, seems like some kind of advertisement.
Does anyone happen to know Japanese?
http://sourceforge.net/mailarchive/forum.php?thread_id=8313748&forum_id=2657 wrote: 若い女性とのSEXも楽しいけど、一度知ると「熟女」とのSEXはとてもはまるらしいモノらしい。
*url deleted*

最近は、SEXへの認識・結婚への意識もずいぶん変わってきていて、「ばれなければ」何でもやる主婦も結構多いので、熟女とSEXするチャンスは大幅に増えています。
主婦が若い男を捜しているのが、最近の出会い系のコミュニケーションの主流です。
*url deleted*

男が女性を援助するから・・・とエッチしてしまうとあっとゆうまに大変なことになってしまうけど、逆バージョンは全く問題がない、というのも不思議ですが。

とにかく主婦は若い男性にお小遣いをあげながら自分の性処理を手伝わせています。
SEXとお小遣い、一度にゲットできる機会を試してみてはいかがですか?
*url deleted*

NeoThermic
Registered User
Posts: 198
Joined: Fri Jan 02, 2004 3:44 pm
Location: United Kingdom
Contact:

Re: WOW! The developers came alive!

Post by NeoThermic »

Its porn spam. For the saftey of everyone here, I will not translate that out.

NeoThermic
phpBB release date pool!
The NeoThermic.com... a well of information. Ask me for the bit bucket so you can drink its goodness. ||新熱です

APTX
Registered User
Posts: 680
Joined: Thu Apr 24, 2003 12:07 pm

Re: WOW! The developers came alive!

Post by APTX »

I never knew the sex is spelled exactly the same in Japanese... ;)
Don't give me my freedom out of pity!

who_cares
Registered User
Posts: 218
Joined: Mon Feb 07, 2005 1:20 pm
Contact:

Re: WOW! The developers came alive!

Post by who_cares »

NeoThermic wrote: Its porn spam. For the saftey of everyone here, I will not translate that out.

NeoThermic
you speak Japanese?

Post Reply