# Development Process

## Background
- The first phase of the development process (work done in "testing") is handled properly.
- The last phase of the development process, official releases, are handled by James, but the process/requirements for a release are not documented.
- Right now, "testing" is effectively a fork of James' "stable" SVN tree.
- There is no roadmap for the next 2.x release.

## Which Tree to Base Releases On?

### Option 1: Basing Releases on James' "Stable" Tree
- There's no process to move code from "testing" (git) to "stable" (svn).
- The release process is not documented.

### Option 2: Basing Releases on David's "Testing" Tree
- Currently, James makes his modifications to his SVN tree and David pulls his changes to "testing". In this regard, James' SVN tree is no different from any other external tree.
- Only David's "allmerged" branch contains all code (James', external trees, etc.).
- The "testing" tree should get the widest testing, especially after we start releasing testing snapshots and linking to them from openvpn.net.

## How to Verify Stability of the "Testing" Code (for Moving to "Stable" or Prior to a Release?)
- Publishing or linking to "testing" releases on openvpn.net is essential to get wider use for "testing".

# Other

## Bridging Issues
- From [OpenVPN FAQ on Bridging](http://openvpn.net/index.php/open-source/faq.html#bridge1): "Another bridge disadvantage should be that layer2 is insecure by design, opening your layer2 exposes to ARP poisoning and the like."
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9