Re: Informix patches?
Posted in 2007
Topics: Installation, Setup & Upgrades, Server Administration, Clustering, Grid & MACH11
M.J.R. said: > I'm a dba in both an Informix and Oracle shop. I have > a question about patches. Four times a year (October, > January, April, and July), Oracle releases what they > call a Critical Patch Update, or CPU. Oracle > "strongly recommends applying the patches as soon as > possible," I believe because of security concerns. To > apply the patches, you must shut the databases > (instances) down, apply the patch, correct any and all > errors that occur (and it seems there's always at > least one, normally more), and then restart the > databases. To my knowledge, Informix doesn't release > such patches. Maybe I'm asking the wrong group, but > my question is how does Oracle know that every four > months a critical patch will be necessary? Why They don't. They're just "managing" security concerns. > doesn't Informix release such patches? I don't mean Because Informix isn't as prone to being hacked as Oracle is. (Note that I have chosen my words very carefully, here. :o) > to start another flame war, although they are fun to > read, but this has been on my mind for some time now > and I never read any mention of patches in this group. > Upgrades to new versions, yes, but not of any > patches, per se. IBM does release patches quite often, and these address a range of bugs. But they aren't marketed as "critical patches" because quite often they aren't critical across the board. Informix versions look like N.MM.Axy, and the x and y are the patch level, effectively. So in 10.0.FC7, the patch level is C7. Interesting about correcting the errors that occur, I can't say I've ever had an error occur as the result of a patch or any other upgrade. -- Bye now, Obnoxio "I'm astonished anyone pays real money for this crap." -- Cosmo "Cluster in my trousers" -- Guy Bowerman -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean.
Obnoxio The Clown wrote: > >> doesn't Informix release such patches? I don't mean > > Because Informix isn't as prone to being hacked as Oracle is. (Note that I > have chosen my words very carefully, here. :o) > Very well chosen words. Oracle also has patches (one offs), and every 9 months or so bundles them into a patchset, which when applied increments the release number (i.e. 10.2.0.3 becomes 10.2.0.4 when the latest patchset for 10.2 is applied). Generally customers will look at what is fixed in a given patchset, and decide if they will apply it or not (if you have 8000 installations, patching them all to the same level is expensive). However, some problems are security problems. And this causes a Catch 22. If Oracle sends out a patch or a patchset that describes and fixes a security problem, then everyone that reads the patchset notes now knows what that security problem is. And if they don't then apply the patch or patchset, then Oracle has now made the problem worse- a previously unknown vulnerability is now widely known, and could potentially be taken advantage of. So a CPU is a special patchset, that comes out regulary, that just fixes known security vulnerabilities. It comes out on all platforms at the same time so that no one platform is favored (or disadvantaged over another). And they come out at regular times so that customers can plan on at least applying this set of fixes, even if they apply nothing else.