[pca] New Sun policy on security/recommended patch versions
Craig Bell
Craig.Bell at standard.com
Fri Jun 18 01:35:39 CEST 2010
Martin Paul wrote:
> I've spent quite some time thinking about how to integrate the new kind of information about the minimum recommended patch revision into pca's command line options, but still haven't come to a conclusion.
Martin, this is a tough one! Sites with rigorous change controls likely wish to steer close to Oracle's intention, so IMHO it's reasonable to suggest minimal R becomes the default, and R promotion requires an option.
I tend to see "missingr" as a modifier to "missing", which gets the current revision. If the "r" suffix becomes minimal, then "missingr" seems ambiguous. Now what about "s", which always promotes? Xref is yet more inconsistent...
Incidentally, could the S flag get the minimal treatment? Patchfinder already differentiates between new and accumulated security patches. Maybe this is left over from Sun's previous "only new security fixes are free" policy.
For clarity's sake, it may indeed be worth overhauling the group operands to reflect the new assumptions. I haven't thought of a clever way to extend the existing syntax, without confusing either new or old pca users. =-/
In any case, I'm happy to update my syntax, if it keeps things clear and simple. -cheers, CSB
P.S. In practice, minimal R patching does little for me, as I still need to apply the same total number of patches. So long as I am confident about patch release quality, then I don't mind the additional fixes in the current rev.
If Oracle challenges my patches during a service request, I'll bet it's because I'm behind, not ahead. =-) It's quite rare that we are burned by a released patch, and the next bad one could still sport a new R or S flag. -c
More information about the pca
mailing list