Gentoo Archives: gentoo-dev

From: R0b0t1 <r030t1@×××××.com>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] New item for sys-kernel/hardened-sources removal
Date: Sun, 20 Aug 2017 05:40:05
Message-Id: CAAD4mYiw-78zx+VpCXhCtE0rDK-ibS7QYm5ESipy-PvR1Rt=7Q@mail.gmail.com
In Reply to: Re: [gentoo-dev] New item for sys-kernel/hardened-sources removal by "Francisco Blas Izquierdo Riera (klondike)"
1 On Sat, Aug 19, 2017 at 6:34 AM, Francisco Blas Izquierdo Riera
2 (klondike) <klondike@g.o> wrote:
3 > El 19/08/17 a las 13:18, Aaron W. Swenson escribió:
4 >> On 2017-08-19 13:01, Francisco Blas Izquierdo Riera (klondike) wrote:
5 >>> El 19/08/17 a las 12:37, Aaron W. Swenson escribió:
6 >>>> On 2017-08-15 17:01, Francisco Blas Izquierdo Riera (klondike) wrote:
7 >>>>> Hi!
8 >>>>>
9 >>>>> I'd like to get this one up by Saturday so that we can proceed with
10 >>>>> masking and removing of the hardened-sources after upstream stopped
11 >>>>> releasing new patches.
12 >>>> I hope I’m not too late.
13 >>>>
14 >>>>> We'd like to note that all the userspace hardening and MAC support
15 >>>>> for SELinux provided by Gentoo Hardened will still remain there and
16 >>>>> is unaffected by this removal.
17 >>>> Where is there? I think you’re talking about the packages, but the news
18 >>>> item is about the kernels. It would help to be more specific here.
19 >>>>
20 >>>> That’s all I had that the others hadn’t touched on.
21 >>> Do you think something like that is better then?
22 >>>
23 >>> We'd like to note that all the userspace hardening and MAC support
24 >>> for SELinux provided by Gentoo Hardened will still remain available
25 >>> on the portage. Keep in mind though that the security provided by
26 >>> these features will be weakened a bit when using
27 >>> sys-kernel/gentoo-sources. Also, all PaX related packages other than
28 >>> the hardened-sources will remain available for the time being.
29 >>>
30 >>>
31 >> Much better. We should mention that we’re specifically discussing
32 >> packages and not portage itself. At least, that’s my understanding from
33 >> your edit.
34 >>
35 >> Here’s my take on it:
36 >>
37 >> We'd like to note that all the userspace hardening and MAC support for
38 >> SELinux provided by Gentoo Hardened will still remain in the packages
39 >> found in portage. Keep in mind, though, that the security provided by
40 >> these features will be weakened a bit when using
41 >> sys-kernel/gentoo-sources. Also, all PaX related packages, except
42 >> sys-kernel/hardened-sources, will remain available for the time being.
43 >
44 > I updated the news item with your propossal. Thanks a lot :)
45 >
46
47 The discussion is nice but no one has actually touched on the
48 technical merits of removing the packages besides "they are old."
49 There's plenty of old software in portage. Why not remove it first?
50
51 I had a similar issue with the GCC developer who removed GCJ support.
52 I asked him for any justification at all for the removal and he had
53 none but some vague statements about it creating work. I would have
54 taken any more specific example he gave at face value, but he didn't
55 want to give one. I was left to conclude he didn't have one to give.
56
57 So I ask again: On what basis are the hardened sources being removed
58 from the tree?
59
60 At this point I am far less interested in making sure the sources stay
61 in the tree than I am in forcing you to justify your actions, because
62 I suspect your attempt to do so will be entertaining.
63
64 R0b0t1.

Replies