Gentoo Archives: gentoo-dev

From: Rich Freeman <rich0@g.o>
To: gentoo-dev <gentoo-dev@l.g.o>
Subject: Re: [gentoo-dev] Vanilla sources
Date: Sat, 04 Jan 2020 11:01:48
Message-Id: CAGfcS_=KzxrAWDasd-h4w+dXsUshtTCgNtEJsybaP1WKHz_yLA@mail.gmail.com
In Reply to: Re: [gentoo-dev] Vanilla sources by Aaron Bauman
1 On Fri, Jan 3, 2020 at 11:28 AM Aaron Bauman <bman@g.o> wrote:
2 > On January 3, 2020 9:55:31 AM EST, Michael Orlitzky <mjo@g.o> wrote:
3 > >On 1/3/20 9:52 AM, Michael Orlitzky wrote:
4 > >>
5 > >> But here we are. Do we make OpenRC Linux-only and steal the fix from
6 > >> systemd? Or pretend to support other operating systems, but leave
7 > >them
8 > >> insecure?
9 > >>
10 > >
11 > >Or the gripping hand: rewrite opentmpfiles in C, so that it's only as
12 > >insecure as checkpath.
13 > >
14 > >Every option sucks. I was only trying to point out that vanilla-sources
15 > >gets no security support -- security@ has stated this, but it's on a
16 > >private bug, so I won't quote it -- and the risk is more than academic.
17 >
18 > This should be known. Security does not support vanilla-sources. This is one reason vanilla-sources are not stabilized.
19 >
20
21 Packages without security support should be masked. Really I don't
22 see the point of even having this in the repo.
23
24 I run vanilla sources personally but I just get them from upstream.
25 Makes way more sense than worrying about whether the version in the
26 repo is up to date for the longterm kernel I'm following. People
27 running vanilla sources are probably using out-of-tree modules (like
28 me) and as such are going to have particular requirements around how
29 they're updated. So, Gentoo is adding fairly little value.
30
31 All they do is download sources anyway, which is trivially done from
32 git more efficiently (or tarballs that are probably easy to obtain
33 just as efficiently). I can see more of the point in the new
34 distribution kernel project which will be turnkey. I can see some of
35 the value in gentoo-sources (particularly as the upstream for the
36 distribution kernels) especially if they're tied to Gentoo-specific
37 bugs. For more general bugs that apply to all distros I really don't
38 see the point in trying to compete with the upstream stable branches
39 (if they're taking forever to merge a patch, chances are there is a
40 reason for it, and I'm skeptical that Gentoo users are special in some
41 way).
42
43 Is there some reason that we should keep vanilla sources despite not
44 getting security handling?
45
46 --
47 Rich

Replies

Subject Author
Re: [gentoo-dev] Vanilla sources Roy Bamford <neddyseagoon@g.o>
Re: [gentoo-dev] Vanilla sources Thomas Deutschmann <whissi@g.o>