Gentoo Archives: gentoo-dev

From: "Anthony G. Basile" <blueness@g.o>
To: Gentoo Development <gentoo-dev@l.g.o>
Subject: [gentoo-dev] why is the security team running around p.masking packages
Date: Fri, 01 Jul 2016 02:52:05
Message-Id: 4c319530-3c7c-e8e3-300d-c80c84cf6674@gentoo.org
1 I'm going to ask the security team to please stop running around
2 p.masking packages without acknowledgement from the maintainers. I'm
3 referring in particular to commit
4 135b94c85950254f559f290f4865bce8b349a917 regarding monkeyd. Both of the
5 cited "security bugs" were long fixed, and even if the were not, they do
6 not merit masking because they were at best some information leakage
7 with minor impact. I have reverted that commit and would ask that
8 security stop this practice.
9
10 --
11 Anthony G. Basile, Ph.D.
12 Gentoo Linux Developer [Hardened]
13 E-Mail : blueness@g.o
14 GnuPG FP : 1FED FAD9 D82C 52A5 3BAB DC79 9384 FA6E F52D 4BBA
15 GnuPG ID : F52D4BBA

Replies