Gentoo Archives: gentoo-dev

From: Aaron Bauman <bman@g.o>
To: gentoo-dev@l.g.o
Cc: pr@g.o, Thomas Deutschmann <whissi@g.o>
Subject: Re: [gentoo-dev] [PATCH] 2021-07-09-systemd-tmpfiles: re-add news item
Date: Wed, 14 Jul 2021 00:28:56
Message-Id: YO4vvol6/tPycQYS@Aaron-Baumans-MacBook-Pro.local
In Reply to: Re: [gentoo-dev] [PATCH] 2021-07-09-systemd-tmpfiles: re-add news item by "Andreas K. Huettel"
1 On Wed, Jul 14, 2021 at 12:04:34AM +0200, Andreas K. Huettel wrote:
2 > <snip>
3 > > The package was masked due to a miscommunication with the Gentoo
4 > > Security project.
5 > >
6 > > While it is true that the way opentmpfiles is currently implemented
7 > > allows for certain races, from the security point of view, you always
8 > > have to classify the vulnerability in context of your threat model
9 > > because security depends on multiple layers (onion model).
10 > <snip>
11 >
12 > I would like to respectfully point out that this makes
13 >
14 > 1) either the severity assignment of this bug by the Security project as B1 wrong (i.e. it should have been classified "harmless")
15 >
16
17 The Gentoo model is not perfect and should be overhauled. However, it
18 works for most things and sometimes bugs fall between the cracks.
19
20 The package shouldn't have been masked either based on a bug that was
21 purposely ignored for many years simply because they want to disband the
22 package now and found a "security reason" to add to the mask.
23
24 > 2) or the entire classification of severity levels according to the Security project pointless (i.e. you can't base any actions on them because a mystery onion needs to be taken into account).
25 >
26
27 I am not sure if this is sarcasm, but every bug must be considered
28 through the correct aperture. That is, based on your environment,
29 protections in place, defense in depth, and other buzzwords... hence the
30 onion analogy.
31
32 -Aaron

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] [PATCH] 2021-07-09-systemd-tmpfiles: re-add news item "Andreas K. Huettel" <dilfridge@g.o>