1 |
On Fri, Jan 3, 2020 at 11:28 AM Aaron Bauman <bman@g.o> wrote: |
2 |
> On January 3, 2020 9:55:31 AM EST, Michael Orlitzky <mjo@g.o> wrote: |
3 |
> >On 1/3/20 9:52 AM, Michael Orlitzky wrote: |
4 |
> >> |
5 |
> >> But here we are. Do we make OpenRC Linux-only and steal the fix from |
6 |
> >> systemd? Or pretend to support other operating systems, but leave |
7 |
> >them |
8 |
> >> insecure? |
9 |
> >> |
10 |
> > |
11 |
> >Or the gripping hand: rewrite opentmpfiles in C, so that it's only as |
12 |
> >insecure as checkpath. |
13 |
> > |
14 |
> >Every option sucks. I was only trying to point out that vanilla-sources |
15 |
> >gets no security support -- security@ has stated this, but it's on a |
16 |
> >private bug, so I won't quote it -- and the risk is more than academic. |
17 |
> |
18 |
> This should be known. Security does not support vanilla-sources. This is one reason vanilla-sources are not stabilized. |
19 |
> |
20 |
|
21 |
Packages without security support should be masked. Really I don't |
22 |
see the point of even having this in the repo. |
23 |
|
24 |
I run vanilla sources personally but I just get them from upstream. |
25 |
Makes way more sense than worrying about whether the version in the |
26 |
repo is up to date for the longterm kernel I'm following. People |
27 |
running vanilla sources are probably using out-of-tree modules (like |
28 |
me) and as such are going to have particular requirements around how |
29 |
they're updated. So, Gentoo is adding fairly little value. |
30 |
|
31 |
All they do is download sources anyway, which is trivially done from |
32 |
git more efficiently (or tarballs that are probably easy to obtain |
33 |
just as efficiently). I can see more of the point in the new |
34 |
distribution kernel project which will be turnkey. I can see some of |
35 |
the value in gentoo-sources (particularly as the upstream for the |
36 |
distribution kernels) especially if they're tied to Gentoo-specific |
37 |
bugs. For more general bugs that apply to all distros I really don't |
38 |
see the point in trying to compete with the upstream stable branches |
39 |
(if they're taking forever to merge a patch, chances are there is a |
40 |
reason for it, and I'm skeptical that Gentoo users are special in some |
41 |
way). |
42 |
|
43 |
Is there some reason that we should keep vanilla sources despite not |
44 |
getting security handling? |
45 |
|
46 |
-- |
47 |
Rich |