Gentoo Archives: gentoo-dev

From: Duncan <1i5t5.duncan@×××.net>
To: gentoo-dev@l.g.o
Subject: [gentoo-dev] Re: Portage 2.0.51 comments/questions
Date: Mon, 27 Sep 2004 20:33:48
Message-Id: pan.2004.09.27.20.33.41.871367@cox.net
In Reply to: Re: [gentoo-dev] Portage 2.0.51 comments/questions by Nicholas Jones
1 Nicholas Jones posted <20040927083145.GA27459@××××××.net>, excerpted
2 below, on Mon, 27 Sep 2004 04:31:46 -0400:
3
4 >> 1) The new "spinner" is /very/ cool!
5 >
6 > It's been moved to FEATURES="candy"
7
8 Hmm. Good choice since some don't like it. I'm turning it on right now!
9 Some candy I like, especially when I don't have to worry about calories!
10 <g>
11
12 >> 2) Documentation is coming alone nicely.
13 > ...
14 >> /etc/portage/profiles/ [or] /etc/portage/profile/
15 >
16 > It's singular. I've updated all the references otherwise. They'll be in
17 > CVS before I post this. They are only in the ebuild as the plural
18 > version.
19
20 Noted. Thanks.
21
22 >> 3) What about the QA Notices?
23 >> enough of them it'd just be unnecessary noise?
24 >
25 > It get fixed faster if everyone is yelling for it to stop. Fixes by
26 > annoyance. Cheap, Easy, and Quick.
27
28 <g> From Paul's reply, looks like patches are needed. I'm better at
29 filing bugs than patching, so won't worry about it ATM. However, if I
30 have time, I'll look into it a bit and see if those sorts of things are
31 within my definitely limited abilities.
32
33 >> What about that security notice I've seen pop up a few times? Example:
34 >>
35 >> QA Notice: Security risk /usr/bin/crontab. Please consider relinking
36 >> with 'append-ldflags -Wl,-z,now' to fix.
37 >
38 > For the full implications you should talk to the security hardened/
39 > security guys. Solar is the one that put that patch up for me to add.
40 > Basically, there is the potential to use a glibc exploit to induce a
41 > race that could allow you to do weird things with libraries and files.
42
43 Thanks. Hopin' someone from hardened will take a swing at this then and
44 enlighten me a bit more. If not, maybe I'll have to subscribe to that
45 list and ask there, if google-linux isn't any help. At least I've a bit
46 to start a search on now, more than I had b4.
47
48 --
49 Duncan - List replies preferred. No HTML msgs.
50 "They that can give up essential liberty to obtain a little
51 temporary safety, deserve neither liberty nor safety." --
52 Benjamin Franklin
53
54
55
56 --
57 gentoo-dev@g.o mailing list