2024.04.19 08:34 "[Tiff] Call for discussion: RFC 2: Restoring needed libtiff tools", by Sulau

2024.04.19 08:34 "[Tiff] Call for discussion: RFC 2: Restoring needed libtiff tools", by Sulau

Hi,

I've drafted a proposal for request for comment (RFC) at https://gitlab.com/libtiff/libtiff/-/merge_requests/581.

Please provide feedback either within the merge request or via e-mail reply.

Guidelines for the response to RFCs can be found at: https://libtiff.gitlab.io/libtiff/rfcs/rfc1_psc.html

Summary:

The purpose of this RFC is to clarify if and which tools that were moved to the archive in libtiff 4.6.0 should be reactivated.

Prehistory:

The very old and unmaintained tools in libtiff caused many vulnerabilities and CVEs that were attributed to the libtiff library itself. Trying to fix the security holes in the tools turned out to be a Sisyphean task (can never be done).

Therefore, most of the tools in libtiff 4.6.0 were moved to the archive and the existing problems were closed with "wontfix-unmaintained".

It was later understood that some users depend on some of these archived tools.

Some problems with the tools have now been fixed (see e.g. https://gitlab.com/libtiff/libtiff/-/merge_requests/569).

Proposed Procedure:

References to previous contributions to the discussion:

Regards

Su