On Tue, Sep 22, 2026 at 01:23 AM, Paul Barker wrote:
On Mon, 2026-09-21 at 15:56 +0530, Vijay Anusuri wrote:
Hi Yoann, Paul,

I checked with the rsync upstream maintainers regarding the security patch
branches and the possibility of an archive/tarball.

They confirmed that v3.4.1-sec-patches3 and v3.2.7-sec-patches3 are
official rsync security-maintenance branches. They have now also published:

- v3.4.1-sec-patches4
- v3.2.7-sec-patches4

These branches contain the security and compatibility fixes applicable to
the respective older release lines after *-sec-patches3. Both branches have
been tested against the refreshed stable testsuite.

Regarding the archive/tarball, the maintainer clarified that they do not
plan to provide release tarballs for these security branches. The branches
are intended to be used as reviewable Git sources from which downstream
maintainers can cherry-pick commits or construct their own patch series.

Based on this, can we switch the rsync recipe to Git and use the
v3.4.1-sec-patches4 & v3.2.7-sec-patches4 branches for Wrynose/Scarthgap?

This would allow us to consume the upstream security and compatibility
fixes directly from the maintained security branch instead of carrying the
large 34KLOC patch series.


The discussion with the rsync maintainers is here:
https://github.com/RsyncProject/rsync/discussions/1095
Hi Vijay,

Thanks for checking with upstream. It seems a bit of a strange way of
doing things to me - I am surprised these aren't further releases in the
3.4.x and 3.2.x series. Or at least they could be 3.4.1.x and 3.2.7.x
releases. But if this is the way upstream want to handle things then
that's their call.

We do need to discuss how this fits in with our policies on LTS
maintenance. We will get back to you soon.

Best regards,

--
Paul Barker

Hi Paul, Yoann,
Could you please share if there are any updates on this?

Regards,
Hetvi Thakar