Gentoo Archives: gentoo-osx

From: Grobian <grobian@g.o>
To: gentoo-osx@l.g.o
Subject: [gentoo-osx] Ruby issue
Date: Thu, 06 Oct 2005 20:30:48
Message-Id: 43458967.5040408@gentoo.org
1 Some of you might have noticed the Ruby (security) issue. I'd like to
2 have a quick round on it.
3
4 A short situation sketch:
5 - ruby 1.8.2 compiles with some patches made by usata on Panther
6 - ruby 1.8.2 collides on Tiger with system installed ruby
7 - ruby 1.8.2 contains security vulnerability and stuff
8 - ruby 1.8.3 is safe(r)
9 - ruby 1.8.3 doesn't compile on Panther due to autoconf 2.59 requirement
10 - ruby 1.8.3 of course also collides on Tiger
11 - ruby 1.8.2 is marked ppc-macos stable
12 - ruby 1.8.3 is marked ~ppc-macos unstable
13
14 ruby is for Tiger in p.mask, since the sec. bug I added the mask in the
15 Panther profile too, however, that's not really a solution, and the sec.
16 guys want more action from us, basically.
17
18 I can think of three 'solutions':
19 1. drop ppc-macos keyword for all ruby keywords.
20 This is drastical, but since ruby won't have a nice mariage with OSX
21 using oldstyle Gentoo/OSX it solves the problem for good.
22 2. drop ppc-macos keyword in 1.8.2 and replace it with 1.8.3
23 This is bad because we basically drop the keyword, but it leaves us
24 with the 'desired' state of having only ~ppc-macos.
25 3. stable 1.8.3
26 This feels bad to me, but it's what the sec. guys want to see. It
27 makes sense for progressive users (although I don't know of any real
28 ones). We would stable a package without testing that is masked.
29
30 So, a quick round of input on any one of the three (or a solution I
31 haven't thought of) solutions would be nice, in order to 'fix' the ruby
32 bug instead of letting it slide. It's wrong anyway.
33
34
35 --
36 Fabian Groffen
37 Gentoo for Mac OS X Project -- Interim Lead
38 --
39 gentoo-osx@g.o mailing list

Replies

Subject Author
Re: [gentoo-osx] Ruby issue Finn Thain <fthain@××××××××××××××××.au>
Re: [gentoo-osx] Ruby issue Grobian <grobian@g.o>