SUMMARY: Security Patch 760 (IGMP) ? (fwd)

From: David Komanek (xdavid@lib-eth.natur.cuni.cz)
Date: Fri Nov 29 2002 - 02:10:44 EST


Dear managers,

I asked about problems regarding installing patches over existing CSP
("C") patches (see the original message bellow).

Thanks go to Olle Eriksson who is the only one who responded to me. The
advice is to remove all patches, which name starts with "C" and then
reinstall PK3. I read dupatch log to find all these patches. After
removing them, everything goes well.

But I am a bit disappointed from the way dupatch handles "C" patches.
First of all, removing every single patch forces me to reboot regardless
if it constructs new kernel or not. It makes the patch removal real
nightmare.
Second, if the kernel build is started after patch removal, me was given
no choice what components of kernel I want and all components were used
together. In addition, I had no opportunity to edit the configuration
file. What about having i.e. AFS which needs it ?
Third, I suppose many "C" patches are the same as the newer ones from
consolidated patch kit, except they only have other numbers, so the patch
dependency is broken if the older ones are not removed. Well, it would be
nice to have patch numbering in more consistent manner.

Hope, these are only my specific problems, not general :-)

Sincerely,

  David Komanek

---------- Original message ----------

> Dear managers,
>
> in a while ago, I got an allert about the security patch 00760.00 for
> Tru64 Unix 5.1A PK3, which resolves some security issue with IGMP ( Patch
> C 00760.00 - Fix for SSRT2266, IGMP). Since my network cards are
> configured with the MULTICAST switch, I think I need this patch. Is it
> rigth ?
>
> The patch installation failed on patch 00846.00 not installed. But when I
> try to install patches from PK3, I got only the response that all patches
> from this patchkit are already installed.
>
> According to the documentation to the PK3, the patch 846 should be
> included.
>
> Well, I have no idea how to install the patch 00846.00 from PK3. In the
> dupatch log is the following information:
>
> -------------------------------------------------------------------------
>
> Problem installing:
>
> - Tru64_UNIX_V5.1A / Security Related Patches:
> Patch 00846.00 - Security (SSRT1-40U, SSRT1-41U, SSRT1-42U, SSRT1-45U)
> ./sys/BINARY/advfs.mod:
> is installed by Customer Specific Patch (CSP):
>
>
> - Tru64_UNIX_V5.1A:
> Patch C 00308.00
>
> and can not be replaced by this patch. To install this patch,
> you must first remove the CSP using dupatch. Before performing
> this action, you should contact your Compaq Service
> Representative to determine if this patch kit contains the
> CSP. If it does not, you may need to obtain a new CSP from
> Compaq in order to install the patch kit and retain the CSP fix.
>
> This patch will not be installed.
>
> -------------------------------------------------------------------------
>
>
> Do you think, it has some meaning to remove all patches after the previous
> patchkit (PK2) in this case before installing the new one (PK3). I thought
> that all single patches which were officialy released are later in time
> included in the next patchkit.
>
> In this concrete issue, is it safe to remove the patch for advfs.mod and
> re-run PK3 installation ? Will this have some effect in the way dupatch
> allows me to reinstall some parts of PK3 after this or have I go back to
> PK2 with no subsequent patches first ?
>
> Thanks in advance,
>
> David Komanek
>
>
>
>
>



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:49:00 EDT