1 |
On Sat, Aug 19, 2017 at 6:34 AM, Francisco Blas Izquierdo Riera |
2 |
(klondike) <klondike@g.o> wrote: |
3 |
> El 19/08/17 a las 13:18, Aaron W. Swenson escribió: |
4 |
>> On 2017-08-19 13:01, Francisco Blas Izquierdo Riera (klondike) wrote: |
5 |
>>> El 19/08/17 a las 12:37, Aaron W. Swenson escribió: |
6 |
>>>> On 2017-08-15 17:01, Francisco Blas Izquierdo Riera (klondike) wrote: |
7 |
>>>>> Hi! |
8 |
>>>>> |
9 |
>>>>> I'd like to get this one up by Saturday so that we can proceed with |
10 |
>>>>> masking and removing of the hardened-sources after upstream stopped |
11 |
>>>>> releasing new patches. |
12 |
>>>> I hope I’m not too late. |
13 |
>>>> |
14 |
>>>>> We'd like to note that all the userspace hardening and MAC support |
15 |
>>>>> for SELinux provided by Gentoo Hardened will still remain there and |
16 |
>>>>> is unaffected by this removal. |
17 |
>>>> Where is there? I think you’re talking about the packages, but the news |
18 |
>>>> item is about the kernels. It would help to be more specific here. |
19 |
>>>> |
20 |
>>>> That’s all I had that the others hadn’t touched on. |
21 |
>>> Do you think something like that is better then? |
22 |
>>> |
23 |
>>> We'd like to note that all the userspace hardening and MAC support |
24 |
>>> for SELinux provided by Gentoo Hardened will still remain available |
25 |
>>> on the portage. Keep in mind though that the security provided by |
26 |
>>> these features will be weakened a bit when using |
27 |
>>> sys-kernel/gentoo-sources. Also, all PaX related packages other than |
28 |
>>> the hardened-sources will remain available for the time being. |
29 |
>>> |
30 |
>>> |
31 |
>> Much better. We should mention that we’re specifically discussing |
32 |
>> packages and not portage itself. At least, that’s my understanding from |
33 |
>> your edit. |
34 |
>> |
35 |
>> Here’s my take on it: |
36 |
>> |
37 |
>> We'd like to note that all the userspace hardening and MAC support for |
38 |
>> SELinux provided by Gentoo Hardened will still remain in the packages |
39 |
>> found in portage. Keep in mind, though, that the security provided by |
40 |
>> these features will be weakened a bit when using |
41 |
>> sys-kernel/gentoo-sources. Also, all PaX related packages, except |
42 |
>> sys-kernel/hardened-sources, will remain available for the time being. |
43 |
> |
44 |
> I updated the news item with your propossal. Thanks a lot :) |
45 |
> |
46 |
|
47 |
The discussion is nice but no one has actually touched on the |
48 |
technical merits of removing the packages besides "they are old." |
49 |
There's plenty of old software in portage. Why not remove it first? |
50 |
|
51 |
I had a similar issue with the GCC developer who removed GCJ support. |
52 |
I asked him for any justification at all for the removal and he had |
53 |
none but some vague statements about it creating work. I would have |
54 |
taken any more specific example he gave at face value, but he didn't |
55 |
want to give one. I was left to conclude he didn't have one to give. |
56 |
|
57 |
So I ask again: On what basis are the hardened sources being removed |
58 |
from the tree? |
59 |
|
60 |
At this point I am far less interested in making sure the sources stay |
61 |
in the tree than I am in forcing you to justify your actions, because |
62 |
I suspect your attempt to do so will be entertaining. |
63 |
|
64 |
R0b0t1. |