OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: upgrade path from immunix 7

From: Seth Arnold (sarnoldwirex.com)
Date: Fri Jun 06 2003 - 12:54:59 CDT


On Fri, Jun 06, 2003 at 07:31:55PM +0800, Leon Harris wrote:
> Do people have any experiences/gotchas on upgrading between 7.0 and 7+ ?

Internally, we only have experience upgrading through the anaconda
upgrade path on the bootable CD. Upgrading the packages through rpm
is theoretically possible, but the openssl and zlib upgrades introduce
significant version churn which really isn't friendly to command-line
upgrades with rpm.

Users have reported mixed success with tools such as auto_rpm to assist
upgrades.

> I have a number of customised packages (sendmail the most important
> amongst them) and a number of subdomain profiles on a very "live"
> server. Is it straight forward enough to get the upgrade scripts to
> leave these alone?

The 7+ CD shipped with only rpm-ized profiles for glibc (ld and ldd,
to help implement some further policies required to make 2.4-based
SubDomain as tightly constrained as it should be), which will likely
replace files named /etc/subdomain.d/{usr.bin.ldd,lib.ld-2.2.so}.

> Are there any tools for upgrading the subdomain profiles, or is it
> a question of regenerating them by hand (pull them all out, update
> the md5sums, then introduce them one by one and stand by with the
> extinguisher )?

You're in luck. We've removed the md5sum requirement from SubDomain
profiles. We found it to be too brittle to long-term maintainence of
profiles. The parser included with 7+ does not require md5sums, and it
will happily ignore (with warning) any md5sums in the profiles.

This leaves you only with changed dependencies in programs as a result
of the upgrade. I don't expect more than a handful of problems; sendmail
comes to mind as likely to change -- files that used to be found in /etc
are now more likely to be found in /etc/mail.

> Any other things I need to plan around ?

Not that I know of, which is a little less helpful than I think you were
looking for. :) We tried to keep 7+ to a minimum of code changes from 7.0,
but this goal is a little more difficult to attain than one would hope.

But I will make a gentle reminder to back up whatever you think is
important, in the event something goes less than smoothly..

Thanks

--
"Dependence on computers is apparently making a significant fraction
of the population incurably stupid." -- Fritz Whittington

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iEYEARECAAYFAj7g1XMACgkQ+9nuM9mwoJl6ZwCdEmZbvDpg9jZImzqs8XerQbCe
76kAnR+CJYOLQwPJH5M8+Tv9aiUqPpY4
=npu5
-----END PGP SIGNATURE-----

_______________________________________________
Immunix-users mailing list
Immunix-usersmail.wirex.com
http://mail.wirex.com/mailman/listinfo/immunix-users