Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread liviuslivius
On Thu, Mar 14, 2013 at 01:07:15PM -0300, Adriano dos Santos Fernandes wrote: > Everything would be easier if we were using versions numbers in a more > sane way. > > We do use two slots (say, 2.5) to actually represent major versions. > > If we were using only one: > 1.0.0 = 1.0.0 > 1.5.0 = 2.0.0

[Firebird-devel] Odp: Firebird should listen on localhost only (secure by default)

2013-03-14 Thread liviusliv...@poczta.onet.pl
Hi, I suppose that isolating computer and some ports is work for firewall and router not for FB. You say locslhost, someone can say localnetwork, other som mask, others mayby some groups of masks... If you need to block port go to firewall and block incomming traffic to port 3050. Regards, Ka

Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread Michal Kubecek
On Thu, Mar 14, 2013 at 01:07:15PM -0300, Adriano dos Santos Fernandes wrote: > Everything would be easier if we were using versions numbers in a more > sane way. > > We do use two slots (say, 2.5) to actually represent major versions. > > If we were using only one: > 1.0.0 = 1.0.0 > 1.5.0 = 2.0.

Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread Michal Kubecek
On Thu, Mar 14, 2013 at 05:13:42PM +0100, Stefan Heymann wrote: > > Then let's skip 2.5.3 and name the new thing 2.5.4. Everyone will > understand that "fixed in 2.5.3" also means that it's still fixed in > later versions. This would still mean such 2.5.4 would miss a lot of fixes and improvement

Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread Leyne, Sean
> > There are customers out there who are very concerned about security > > and for them there should also be a note in the release notes. > > The trouble of this solution is that many people use snapshot builds, already > named 2.5.3. And it has a number of other bugs fixed. Anyone using snaps

Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread Nick Upson
some other packages use 2.5.3-1 On 14 March 2013 15:55, Alex Peshkoff wrote: > On 03/14/13 18:51, Stefan Heymann wrote: > >>> What I do not understand - what number will get that release? It's > >>> definitely not 2.5.3. May be Firebird-2.5.2.26540-1? (We had > >>> Firebird-2.5.2.26539-0). >

[Firebird-devel] [FB-Tracker] Created: (CORE-4064) bulk_insert fails with boolean values - Invalid boolean value

2013-03-14 Thread Treeve Jelbert (JIRA)
bulk_insert fails with boolean values - Invalid boolean value - Key: CORE-4064 URL: http://tracker.firebirdsql.org/browse/CORE-4064 Project: Firebird Core Issue Type: Bug

Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread Adriano dos Santos Fernandes
On 14/03/2013 13:19, Paul Reeves wrote: > That seems like a recipe for version number hyper-inflation to me. In no time > at all we will be into double figures for version numbers - perhaps even > triple before the end of the decade! It can't be allowed - if nothing else > firebird stands for pr

Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread Paul Reeves
On Thursday 14 March 2013 17:07:15 Adriano dos Santos Fernandes wrote: > On 14/03/2013 12:55, Alex Peshkoff wrote: > > The trouble of this solution is that many people use snapshot builds, > > already named 2.5.3. And it has a number of other bugs fixed. > > Everything would be easier if we were us

Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread Stefan Heymann
>> So the most honest and straightforward thing would be to call this >> 2.5.3 and everything that comes later will then be 2.5.4 and so on. >> > You make a good point. The only problem is that 2.5.3 has been available as a > rolling snapshot release for a while now and a lot of fixes in the track

Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread Adriano dos Santos Fernandes
On 14/03/2013 12:55, Alex Peshkoff wrote: > The trouble of this solution is that many people use snapshot builds, > already named 2.5.3. And it has a number of other bugs fixed. > > Everything would be easier if we were using versions numbers in a more sane way. We do use two slots (say, 2.5) to

Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread Alex Peshkoff
On 03/14/13 18:51, Stefan Heymann wrote: >>> What I do not understand - what number will get that release? It's >>> definitely not 2.5.3. May be Firebird-2.5.2.26540-1? (We had >>> Firebird-2.5.2.26539-0). >> This may cause confusion with Firebird-2.5.3.26540 which does not have >> the bug fixed. B

Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread Mark Rotteveel
On Thu, 14 Mar 2013 16:47:24 +0100, Paul Reeves wrote: > On Thursday 14 March 2013 15:51:40 Stefan Heymann wrote: >> >> I don't know how your versions are organized. But for us users out >> there it would be difficult to distinguish Firebird by build numbers >> or, even worse, sub-build numbers. >

Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread Paul Reeves
On Thursday 14 March 2013 15:51:40 Stefan Heymann wrote: > > I don't know how your versions are organized. But for us users out > there it would be difficult to distinguish Firebird by build numbers > or, even worse, sub-build numbers. > > So the most honest and straightforward thing would be to ca

Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread Stefan Heymann
>> What I do not understand - what number will get that release? It's >> definitely not 2.5.3. May be Firebird-2.5.2.26540-1? (We had >> Firebird-2.5.2.26539-0). > This may cause confusion with Firebird-2.5.3.26540 which does not have > the bug fixed. But I'm out of better ideas. I don't know how

Re: [Firebird-devel] Firebird should listen on localhost only (secure by default)

2013-03-14 Thread Alex Peshkoff
On 03/14/13 17:36, marius adrian popa wrote: > I have better ideas for securing firebird in the future chroot , > seccomp filter ... > > http://scarybeastsecurity.blogspot.ro/2012/04/vsftpd-300-and-seccomp-filter.html > Looks like good thing. A bit not happy that it requires kernel >=3.5. But for

Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread Dmitry Yemanov
14.03.2013 11:48, Alex Peshkoff wrote: > I see no problems building packages with this patch. It's really > trivial, and if packages are based on previous tags (2.1.5/2.5.2), not > branches, they do not require QA and release notes, they can be released > with just single note: "Fixed severe secur

Re: [Firebird-devel] Firebird should listen on localhost only (secure by default)

2013-03-14 Thread marius adrian popa
I have better ideas for securing firebird in the future chroot , seccomp filter ... http://scarybeastsecurity.blogspot.ro/2012/04/vsftpd-300-and-seccomp-filter.html On Thu, Mar 14, 2013 at 1:18 PM, Michal Kubecek wrote: > On Wed, Mar 13, 2013 at 07:37:28PM +0400, Dmitry Yemanov wrote: >> Persona

Re: [Firebird-devel] Firebird should listen on localhost only (secure by default)

2013-03-14 Thread Philippe Makowski
I think this is more something for packagers for example under Fedora and derivative, Firebird service is not started by default at install, so it let the system administrator to make the changes he want before starting Firebird. --

Re: [Firebird-devel] Firebird should listen on localhost only (secure by default)

2013-03-14 Thread Michal Kubecek
On Wed, Mar 13, 2013 at 07:37:28PM +0400, Dmitry Yemanov wrote: > Personally, I think that it would be a mistake to change the default > network interface in point releases. > > As for v3.0, I don't mind, but only if the installer will be changed to > ask the user to configure this setting durin

Re: [Firebird-devel] Firebird should listen on localhost only (secure by default)

2013-03-14 Thread Michal Kubecek
On Wed, Mar 13, 2013 at 04:53:32PM +0100, Mark Rotteveel wrote: > > Initial security by disallowing external connections. If and when you want > your server available to the outside world you can configure it so, and it > will be a conscious choice instead of a (potentially) insecure default. Wel

[Firebird-devel] [FB-Tracker] Created: (CORE-4063) WOW64 folder missed in zip installer for 64-bit windows

2013-03-14 Thread Anton B. Gusev (JIRA)
WOW64 folder missed in zip installer for 64-bit windows --- Key: CORE-4063 URL: http://tracker.firebirdsql.org/browse/CORE-4063 Project: Firebird Core Issue Type: Bug Components:

Re: [Firebird-devel] Firebird should listen on localhost only (secure by default)

2013-03-14 Thread Alex Peshkoff
On 03/13/13 19:37, Dmitry Yemanov wrote: > Personally, I think that it would be a mistake to change the default > network interface in point releases. Agreed. > As for v3.0, I don't mind, but only if the installer will be changed to > ask the user to configure this setting during setup. Except

Re: [Firebird-devel] Firebird new release is needed

2013-03-14 Thread Alex Peshkoff
On 03/13/13 12:45, marius adrian popa wrote: > I agre Patch seems to be trivial and is one of thouse cases like a new > kit is needed > I see no problems building packages with this patch. It's really trivial, and if packages are based on previous tags (2.1.5/2.5.2), not branches, they do not req