Suspecting GOLD Very Soon...

Discussion of general topics related to the new version and its place in the world. Don't discuss new features, report bugs, ask for support, et cetera. Don't use this to spam for other boards or attack those boards!
Forum rules
Discussion of general topics related to the new release and its place in the world. Don't discuss new features, report bugs, ask for support, et cetera. Don't use this to spam for other boards or attack those boards!
Post Reply
code reader
Registered User
Posts: 653
Joined: Wed Sep 21, 2005 3:01 pm

Re: Suspecting GOLD Very Soon...

Post by code reader »

you all seem to be missing the point, imo.
asking "how long will it take?" only makes sense if you know the answer to the question "when will it start?".
i mean, who cares if it takes "only 3 weeks" if it starts, let's say, mid april 2011?
i am not saying this is the case, all i say is that the question "how long will it take" seems to be almost meaningless at this point.

User avatar
John Hjorth
Registered User
Posts: 235
Joined: Tue May 09, 2006 3:32 pm
Location: Odense, Denmark, EU
Contact:

Re: Suspecting GOLD Very Soon...

Post by John Hjorth »

code reader,

You certainly have a point here. Furthermore, it is also about what does such a security audit really imply, and what is it's scope and contents defined, and how is it performed. I would not be surprised later to read some information about it actually going on right now - There is quite calme the last days regards commits.

User avatar
Dog Cow
Registered User
Posts: 271
Joined: Wed May 25, 2005 2:14 pm

Re: Suspecting GOLD Very Soon...

Post by Dog Cow »

I think we ought to see Gold before the end of this year, I really hope so, anyway. :)

User avatar
John Hjorth
Registered User
Posts: 235
Joined: Tue May 09, 2006 3:32 pm
Location: Odense, Denmark, EU
Contact:

Re: Suspecting GOLD Very Soon...

Post by John Hjorth »

From "Bug is less" :
Kevin Clark wrote:In case you guys missed it
http://www.phpbb.com/community/viewtopi ... 2#p3204042

User avatar
Stallyon
Registered User
Posts: 73
Joined: Mon May 31, 2004 1:30 pm
Location: BNE
Contact:

Re: Suspecting GOLD Very Soon...

Post by Stallyon »

RC6 = It's always to be better safe than sorry. The group wants it to be as secure and bug free as possible. We have to remember this is a major version, and even if it has taken 6 years to develop, there are some huge new features to work through. Like I said back in July, they don't want to have to release 3.0.1 a few weeks after ;)

User avatar
Nicholas the Italian
Registered User
Posts: 659
Joined: Mon Nov 20, 2006 11:19 pm
Location: 46°8' N, 12°13' E
Contact:

Re: Suspecting GOLD Very Soon...

Post by Nicholas the Italian »

Stallyon wrote:they don't want to have to release 3.0.1 a few weeks after ;)
Don't you think it will eventually happen?

User avatar
Stallyon
Registered User
Posts: 73
Joined: Mon May 31, 2004 1:30 pm
Location: BNE
Contact:

Re: Suspecting GOLD Very Soon...

Post by Stallyon »

Not necessarily right away, but eventually it's inevitable a bug or exploit will be somewhere.

code reader
Registered User
Posts: 653
Joined: Wed Sep 21, 2005 3:01 pm

Re: Suspecting GOLD Very Soon...

Post by code reader »

looking at al the recent commits, especially those with #iXXX marking, it seems as if the security audit is going strong (even though it was never actually announced...), and security-related stuff is getting fixed as soon as it's reported.
some changes seem to be proactive: for instance the new "form stamping" mechanism, and changes that make the install process itself more secure.
kudos to the team. it seems that phpbb3 will be more secure straight out of the box than phpbb2 ever was (or ever will be...). in today's environment i think this was a very good decision.
from what it seems, i think we will see rc6 within days, and i do believe that this rc6 will become "gold" not too long after that.

the idea that some people on this board and on this thread have expressed, namely that the bug-count in the tracker must hit 0 before gold is, of course, complete nonsense.

so the picture as it is now looks roughly so: rc6 within less than a week, most probably before the end of the coming weekend, and gold, (surprise! surprise!) pretty much in-line with the prediction rivaldo have been making for some 18 odd months now, sometime in november 2007. (see viewtopic.php?p=138104#p138104 and on and on and on and on and on)

User avatar
John Hjorth
Registered User
Posts: 235
Joined: Tue May 09, 2006 3:32 pm
Location: Odense, Denmark, EU
Contact:

Re: Suspecting GOLD Very Soon...

Post by John Hjorth »

Hi code reader,

Yes, a lot is going on now in the CVS commits, but actually, nobody but people with access to the "internal/private tracker" know what is standing open there right now. We will - as always - just have to wait and see, see and wait. ;)

code reader
Registered User
Posts: 653
Joined: Wed Sep 21, 2005 3:01 pm

Re: Suspecting GOLD Very Soon...

Post by code reader »

john,
i'll try to explain my reasoning and show you why i call my prediction "educated guess".
you are right in that we can't see the reports, but we can see the commits.
at least all the actual changes i looked at seem to be security related. i am talking about the #iXXX commits. there are a few "regular bugs" related commits, but most of the "mysterious" ones seems to be security oriented.
since acyd mentioned having an audit done by a "real security company", and being paid for, and since the funds available for this audit have to be pretty limited, i can't imagine that the audit itself will be (or was?) much more than one week, two tops, just because of the old equation time === money.
the first "#iXXX" commit appeared on 9/21 (or 21/9/2007 for you european guys), roughly 3 weeks ago.
i guess that the audit itself is either finished or will be finished within days.
since bugs are much more difficult to find than to fix, my guess is that the fixes will all be in very shortly after the end of the audit.

so my conclusion, which is completely unfounded and based on pure speculation, is that all the security-audit related fixes should be in within days, surely less than a week from now, and probably some time over the coming weekend.

if you look at the time line, you'll see that until now, most RC stages took a month or less (RC1 took 35 days, but after that every single one was less than a month).
RC5 is more than 40 days old now, and counting. extrapolating from previous RC stages, i conclude that very shortly after the security-audit related fixes are all in, RC6 will be released.

this brings me to the final conclusion: rc6 will most likely happen some time this weekend, or earlier.
everybody expects rc6 to be the last RC, and keeping in line with the "one month per RC stage" rule, you get the final "rivaldo was right all along" final deduction.

so you see, although my guesses are not founded, they are no pulled out of thin air, either.

Post Reply