Gentoo Archives: gentoo-dev

From: "Stephen P. Becker" <geoman@g.o>
To: John Richard Moser <nigelenki@×××××××.net>
Cc: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Stack smash protected daemons
Date: Sun, 26 Sep 2004 15:51:46
Message-Id: 4156E5C3.1010102@gentoo.org
In Reply to: Re: [gentoo-dev] Stack smash protected daemons by John Richard Moser
1 > As someone who is passively absorbing this information, I find your
2 > ignorance combined with your claim of being a security expert to
3 > indicate that you're full of shit.
4 >
5 > You've repetedly referred to the issue of cross-platform portability
6 > with SSP in here, for example; and I've pointed out once a link that
7 > shows that SSP is OS and CPU independent. Do your research, read what's
8 > out there.
9 >
10
11 So are you then going to test it for us on mips then? "I read it on the
12 internet so it must be true" is a *horrible* way to do QA. Mozilla is
13 also supposed to be arch neutral. Guess what...it doesn't work on mips.
14 Oops! We're a small arch in terms of both devs and users. To my
15 knowledge, a full SSP userland has *never* been tested on mips. We are
16 spread way to thin currently for such an endeavor.
17
18 So then, are you volunteering to build mips stages with SSP to prove
19 that it works for certain? We really don't have the manpower to do that
20 currently. Are you going to answer to any bug reports we would get if
21 this is implemented?
22
23 Also, in terms of "researching" this problem, do you realize you just
24 told the Gentoo/sparc strategic manager that he doesn't know anything
25 about his own arch? "No! you're wrong! SSP does work on your arch!"
26 Reminds me of arguments I've had with people that tried to tell me (I'm
27 a geologist) the Earth is only 7000 years old because the bible says so.
28 I suggest you pull your head out of the collective x86 ass. The
29 non-x86 arch teams have enough breakage to deal with without introducing
30 another layer of potential brokenness.
31
32 I still don't understand why we can't simply place a blurb in the
33 install handbook as I suggested before. It is always much easier to add
34 something than take it away in this circumstance. If a user *really*
35 wants that functionality, they'll add it in. If a user *really* doesn't
36 want it, but it is on by default, they will have to rebuild their whole
37 userland, which on machines such a those supported by the mips port
38 would be *extremely* painful.
39
40 Steve
41
42
43 --
44 gentoo-dev@g.o mailing list

Replies

Subject Author
Re: [gentoo-dev] Stack smash protected daemons John Richard Moser <nigelenki@×××××××.net>