Gentoo Archives: gentoo-dev

From: "Michał Górny" <mgorny@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] New item for sys-kernel/hardened-sources removal
Date: Sun, 20 Aug 2017 07:54:08
Message-Id: 1503215634.2055.1.camel@gentoo.org
In Reply to: Re: [gentoo-dev] New item for sys-kernel/hardened-sources removal by R0b0t1
1 W dniu nie, 20.08.2017 o godzinie 00∶39 -0500, użytkownik R0b0t1
2 napisał:
3 > On Sat, Aug 19, 2017 at 6:34 AM, Francisco Blas Izquierdo Riera
4 > (klondike) <klondike@g.o> wrote:
5 > > El 19/08/17 a las 13:18, Aaron W. Swenson escribió:
6 > > > On 2017-08-19 13:01, Francisco Blas Izquierdo Riera (klondike) wrote:
7 > > > > El 19/08/17 a las 12:37, Aaron W. Swenson escribió:
8 > > > > > On 2017-08-15 17:01, Francisco Blas Izquierdo Riera (klondike) wrote:
9 > > > > > > Hi!
10 > > > > > >
11 > > > > > > I'd like to get this one up by Saturday so that we can proceed with
12 > > > > > > masking and removing of the hardened-sources after upstream stopped
13 > > > > > > releasing new patches.
14 > > > > >
15 > > > > > I hope I’m not too late.
16 > > > > >
17 > > > > > > We'd like to note that all the userspace hardening and MAC support
18 > > > > > > for SELinux provided by Gentoo Hardened will still remain there and
19 > > > > > > is unaffected by this removal.
20 > > > > >
21 > > > > > Where is there? I think you’re talking about the packages, but the news
22 > > > > > item is about the kernels. It would help to be more specific here.
23 > > > > >
24 > > > > > That’s all I had that the others hadn’t touched on.
25 > > > >
26 > > > > Do you think something like that is better then?
27 > > > >
28 > > > > We'd like to note that all the userspace hardening and MAC support
29 > > > > for SELinux provided by Gentoo Hardened will still remain available
30 > > > > on the portage. Keep in mind though that the security provided by
31 > > > > these features will be weakened a bit when using
32 > > > > sys-kernel/gentoo-sources. Also, all PaX related packages other than
33 > > > > the hardened-sources will remain available for the time being.
34 > > > >
35 > > > >
36 > > >
37 > > > Much better. We should mention that we’re specifically discussing
38 > > > packages and not portage itself. At least, that’s my understanding from
39 > > > your edit.
40 > > >
41 > > > Here’s my take on it:
42 > > >
43 > > > We'd like to note that all the userspace hardening and MAC support for
44 > > > SELinux provided by Gentoo Hardened will still remain in the packages
45 > > > found in portage. Keep in mind, though, that the security provided by
46 > > > these features will be weakened a bit when using
47 > > > sys-kernel/gentoo-sources. Also, all PaX related packages, except
48 > > > sys-kernel/hardened-sources, will remain available for the time being.
49 > >
50 > > I updated the news item with your propossal. Thanks a lot :)
51 > >
52 >
53 > The discussion is nice but no one has actually touched on the
54 > technical merits of removing the packages besides "they are old."
55 > There's plenty of old software in portage. Why not remove it first?
56
57 Please select some, and I'll be happy to treeclean it ASAP.
58
59 > I had a similar issue with the GCC developer who removed GCJ support.
60 > I asked him for any justification at all for the removal and he had
61 > none but some vague statements about it creating work. I would have
62 > taken any more specific example he gave at face value, but he didn't
63 > want to give one. I was left to conclude he didn't have one to give.
64 >
65 > So I ask again: On what basis are the hardened sources being removed
66 > from the tree?
67
68 Old kernel versions are a natural vulnerability targets. Even if they
69 are not vulnerable at the moment, they surely will be soon enough.
70
71 > At this point I am far less interested in making sure the sources stay
72 > in the tree than I am in forcing you to justify your actions, because
73 > I suspect your attempt to do so will be entertaining.
74 >
75
76 This is called inappropriate behavior and in a civilized distribution it
77 should result in disciplinary action. However, that's just my opinion
78 and I'm free to express it just as you are free to express yours.
79
80 --
81 Best regards,
82 Michał Górny

Replies

Subject Author
[gentoo-dev] Re: New item for sys-kernel/hardened-sources removal Duncan <1i5t5.duncan@×××.net>