Hi,

We rely on nsd and unbound from base for our DNS infrastructure, so I'd like to 
understand how updates to them are handled for -stable.

Errata 022 for 7.9 updates nsd to 4.15.2, from 4.14.2 as shipped with 7.9, if I 
read it correctly. 
Upstream, in the meantime, there were:

- NSD 4.14.3 *security release* (Jun 25)
- NSD 4.15.0 release (Jul 7)
- NSD 4.15.1 *security release* (Aug 26)
- NSD 4.15.2 release (Sep 2)

I'm asking because OpenBSD usually gets security fixes out very quickly, so the 
gap here surprised me.

I'm not complaining or demanding anything, I'd just like to understand the 
process: how does the project decide when nsd/unbound security releases become 
an errata, and what led to doing it now rather than with 4.14.3 or 4.15.1?
Or was it something in 4.15.2, rather than the earlier CVEs, that triggered it?

Knowing this would help us plan (e.g. whether to track upstream ourselves for 
these daemons).

regards,

Giannis

ps: Stuart, none of this is aimed at you. My question is about the process, not 
the people doing the work. Much respect for everything you do for OpenBSD, not 
only nsd and unbound.


Reply via email to