severity 481469 minor
thanks

Hi Fabio,

Thanks for bringing this to our attention.

> I see that the upgrade which deprecates mail_extra_groups is regarded as
> having been fixed.   However, I don't think the fix is optimal for most of
> us.  I opted to use my old config file when upgrading as there was no clear
> warning not to do this,

There /is/ a clear warning not to do that, and it is in the advisory text. 
This is the place were updates to stable security and their consequences are 
announced.

Besides, in general in Debian users not accepting config file changes on 
upgrade are considered themselves responsible for fixing it up, and this is 
especially so in the case of a security upgrade when you as a user can expect 
that that change has not been made lightly.

It's a pity that the error warnings are not very clear, but that is a minor 
issue and not something appropriate to be changing in a security update. It 
also doesn't render the package unusable.

I'm marking the bug as minor. You can ask the stable release team if they're 
willing to accept an update for this, but it's out of the scope of the 
security team.


cheers,
Thijs

Attachment: pgppthnPbHOR3.pgp
Description: PGP signature

Reply via email to