Gentoo Archives: gentoo-dev

From: Aaron Bauman <bman@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] why is the security team running around p.masking packages
Date: Wed, 06 Jul 2016 11:25:00
Message-Id: a5a88b0d-1867-40df-9de8-48126db4f05e@gentoo.org
In Reply to: Re: [gentoo-dev] why is the security team running around p.masking packages by "Anthony G. Basile"
1 On Wednesday, July 6, 2016 8:15:24 PM JST, Anthony G. Basile wrote:
2 > On 7/6/16 6:54 AM, Aaron Bauman wrote:
3 >> On Wednesday, July 6, 2016 5:10:25 PM JST, Anthony G. Basile wrote: ...
4 >
5 > Except that I state such facts BEFORE the p.mask and you ignored it.
6 > Referring to bug #473770:
7 >
8 > <Comment #2>
9 >
10 > (In reply to Anthony Basile from comment #1)
11 >> The CVE for this has gone nowhere. See
12 >>
13 >> http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2013-2183
14 >>
15 >> There are no references and I can't get at the upstream bug report anymore
16 >> since they moved to github.
17 >
18 > Actually, I found it. Its fixed:
19 >
20 > https://github.com/monkey/monkey/issues/93
21 >
22 > </Comment #2>
23 >
24 > <Comment #3>
25 >
26 > Aaron Bauman gentoo-dev Security 2016-07-01 01:39:40 UTC
27 >
28 > # Aaron Bauman <bman@g.o> (1 Jul 2016)
29 > # Unpatched security vulnerabilities and dead upstream
30 > # per bugs #459274 and #473770 Removal in 30 days
31 > www-servers/monkeyd
32 >
33 > </Comment #3>
34 >
35 >
36 > People reading following this can clearly see the problem here.
37 >
38 > I'm also disappointed that no one else in the security team has
39 > recommended any internal policing in response to this. I maintain that
40 > forced p.masking and version bumping should not be done by the security
41 > team but passed to QA for review. Only QA is mandated with such powers
42 > by GLEP 48.
43 >
44
45 What kind of policing would you like to see councilman? Would you like to
46 see me removed from the project, because your precious package was
47 p.masked? You have ignored every thing I have said regarding your
48 inability to work with the security team. Even after an apology from me
49 and a request to work with us you continue on with the rhetoric of powers.
50 It displays a lot about your inability to work with others.
51
52 No other developer is complaining... it is *literally* only you.
53 NP-Hardass's case was not even a security bug nor handled by the security
54 team. One of the bugs for monkeyd led to additional discovery of
55 insecurities regarding log files, but it took a p.mask to get your
56 attention. Quit pushing an agenda and work with others to make Gentoo more
57 secure. Everyone else is.
58
59 >

Replies