Gentoo Archives: gentoo-osx

From: Grobian <grobian@g.o>
To: gentoo-osx@l.g.o
Subject: Re: [gentoo-osx] Ruby issue
Date: Sat, 08 Oct 2005 15:01:48
Message-Id: 4347DF51.8080409@gentoo.org
In Reply to: [gentoo-osx] Ruby issue by Grobian
1 I decided to go for option 2, consider it done.
2
3 Grobian wrote:
4 > Some of you might have noticed the Ruby (security) issue. I'd like to
5 > have a quick round on it.
6 >
7 > A short situation sketch:
8 > - ruby 1.8.2 compiles with some patches made by usata on Panther
9 > - ruby 1.8.2 collides on Tiger with system installed ruby
10 > - ruby 1.8.2 contains security vulnerability and stuff
11 > - ruby 1.8.3 is safe(r)
12 > - ruby 1.8.3 doesn't compile on Panther due to autoconf 2.59 requirement
13 > - ruby 1.8.3 of course also collides on Tiger
14 > - ruby 1.8.2 is marked ppc-macos stable
15 > - ruby 1.8.3 is marked ~ppc-macos unstable
16 >
17 > ruby is for Tiger in p.mask, since the sec. bug I added the mask in the
18 > Panther profile too, however, that's not really a solution, and the sec.
19 > guys want more action from us, basically.
20 >
21 > I can think of three 'solutions':
22 > 1. drop ppc-macos keyword for all ruby keywords.
23 > This is drastical, but since ruby won't have a nice mariage with OSX
24 > using oldstyle Gentoo/OSX it solves the problem for good.
25 > 2. drop ppc-macos keyword in 1.8.2 and replace it with 1.8.3
26 > This is bad because we basically drop the keyword, but it leaves us
27 > with the 'desired' state of having only ~ppc-macos.
28 > 3. stable 1.8.3
29 > This feels bad to me, but it's what the sec. guys want to see. It
30 > makes sense for progressive users (although I don't know of any real
31 > ones). We would stable a package without testing that is masked.
32 >
33 > So, a quick round of input on any one of the three (or a solution I
34 > haven't thought of) solutions would be nice, in order to 'fix' the ruby
35 > bug instead of letting it slide. It's wrong anyway.
36 >
37 >
38
39 --
40 Fabian Groffen
41 Gentoo for Mac OS X Project -- Interim Lead
42 --
43 gentoo-osx@g.o mailing list