Gentoo Archives: gentoo-security

From: Calum <caluml@×××××.com>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Days of yore
Date: Mon, 16 Apr 2007 17:19:25
Message-Id: 635498b70704161009saa1f181r7665e339bc4dce2f@mail.gmail.com
In Reply to: Re: [gentoo-security] Days of yore by Marius Mauch
1 On 4/16/07, Marius Mauch <genone@g.o> wrote:
2 >
3 > Not directly related, but you might be interested in the "affected"
4 > target or the --mail option of glsa-check.
5
6 I am interested in that - but I don't think those options were there
7 when I started putting those cronjobs on my servers many moons ago.
8 Thanks though - I'll investigate.
9
10
11 Sune:
12
13 > emerge gentoo-sources won't magically fix your
14 > machine and besides not everyone want to upgrade their kernel for every
15 > small issue.
16
17 Nope, of course. But those of us that used the GLSAs as a one-stop
18 package security report were hung out to dry.
19 (Talk about cold sweat when I found out....)
20
21 >That's why plasmaroo wrote KISS, sadly he left before it went
22 > public and now we waiting for another tool for kernel issues. It's not even on
23 > the horizon yet (at least not to my knowledge).
24
25 Yep, It sounds like it might have been promising. However, who on
26 earth thought it would be a good idea to remove the functioning kernel
27 security alert system **before** the replacement was written, working,
28 heavily tested, and all the users given 12 months of notice?
29 (The obvious method of notification would have been to create a fake
30 GLSA for glsa-check.)
31
32
33 > This started out as a small
34 > problem that we thought would be temporary but has sadly turned kind of
35 > permanent without us informing users properly.
36
37 This is why, when people ask me if they can "temporarily" do things in
38 my lab, I say no.
39 Temporarily often has a habit of not being.
40
41
42 Could we just get GLSAs going again for some of the most common
43 sources for now then? Say gentoo, and hardened? x86, and AMD?
44 Or some virtual ebuild that requires certain versions of kernels to be
45 installed, that can be updated via Portage from time to time.
46 Then you could script emerge -pv sys-kernel/secure-kernel-source, and
47 when it said it would need to install hardened-sources 2.6.26, you'd
48 know that there must have been a bug in <2.4.26.
49
50 --
51 http://linuxvps.org/
52 --
53 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] Days of yore Sune Kloppenborg Jeppesen <jaervosz@g.o>