From: Mikko Rapeli <mikko.rapeli@linaro.org>
To: Alexander Kanavin <alex.kanavin@gmail.com>
Cc: nicolas.wirth@speedgoat.ch, yocto@lists.yoctoproject.org
Subject: Re: [yocto] How to switch between package version ?
Date: Thu, 17 Aug 2023 10:47:41 +0300 [thread overview]
Message-ID: <ZN3Qnbg+DLPeOTwa@nuoska> (raw)
In-Reply-To: <CANNYZj9iCmC5_HHhv9jvQGsohh-whcn=+J2hVRDrgH+Jjd23bw@mail.gmail.com> <177BD8C48AE805D0.8497@lists.yoctoproject.org>
Hi,
On Thu, Aug 17, 2023 at 09:37:51AM +0200, Alexander Kanavin wrote:
> On Thu, 17 Aug 2023 at 06:41, Mikko Rapeli <mikko.rapeli@linaro.org> wrote:
> > One of the major problems with yocto major updates is that it becomes a big bang,
> > everything must be updated at once. This can be split down and individual layers updated
> > one at a time while keeping poky on the old version. This requires working around
> > layer compatibility, which in many cases is quite artificial and just indiciates that layer
> > is not tested with the other poky versions but it might still just work.
> >
> > I've done this so many times now that I don't see any reason to hide it,
> > also because many non-core layers are simply not maintaining other than master branch
> > exposing users to obsole and insecure SW if they stick to the branch name.
>
> Getting around LAYERSERIES_COMPAT or using BBMASK in order to update
> layers one at a time is not the problem here. The problem here is that
> a newcomer wants to have an older boost (which is in poky) with a
> newer everything else (which is also in poky). What I'm trying to say,
> nobody stopped and asked, what are they actually trying to do? What
> made them think they need an older boost? Why isn't a newer boost
> suitable? Maybe it is, with a bit of work?
Yes:
On Wed, Aug 16, 2023 at 02:13:39PM +0300, Mikko Rapeli via lists.yoctoproject.org wrote:
> First, I would seriously question and fight back on requirements which dictate using
> old, possibly unmaintained SW versions with a lot of known CVE security vulnerabilities.
> Updating to a new boost version is straight forward work and almost all of the compile
> etc issues can be resolved using Internet search engines since most open source projects
> have also done the same.
We agree on this.
Cheers,
-Mikko
next prev parent reply other threads:[~2023-08-17 7:47 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-08-16 10:54 How to switch between package version ? Nicolas Wirth
2023-08-16 11:13 ` [yocto] " Mikko Rapeli
2023-08-16 11:55 ` Nicolas Wirth
2023-08-16 12:05 ` [yocto] " Mikko Rapeli
2023-08-16 14:45 ` Nicolas Wirth
2023-08-16 15:02 ` [yocto] " Alex Kiernan
2023-08-16 15:30 ` Alexander Kanavin
2023-08-16 15:32 ` Alexander Kanavin
2023-08-17 4:41 ` Mikko Rapeli
2023-08-17 7:37 ` Alexander Kanavin
[not found] ` <177BD8C48AE805D0.8497@lists.yoctoproject.org>
2023-08-17 7:47 ` Mikko Rapeli [this message]
2023-08-17 10:51 ` Nicolas Wirth
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ZN3Qnbg+DLPeOTwa@nuoska \
--to=mikko.rapeli@linaro.org \
--cc=alex.kanavin@gmail.com \
--cc=nicolas.wirth@speedgoat.ch \
--cc=yocto@lists.yoctoproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox