Gentoo Archives: gentoo-dev

From: Kevyn Shortell <trance@g.o>
To: Jan Krueger <jk@×××××××××××.net>
Cc: azarah@g.o, Troy Dack <tad@g.o>, Gentoo-Dev <gentoo-dev@g.o>
Subject: Re: [gentoo-dev] Some suggestions
Date: Sun, 07 Sep 2003 20:14:18
Message-Id: 1062965649.6804.13.camel@localhost
In Reply to: Re: [gentoo-dev] Some suggestions by Jan Krueger
1 Don't you think the ebuilds get tested before they're pushed out to the
2 tree? If an ebuild was going to delete the contents of the hard drive, a
3 dev would be the first person to find out.
4
5 And any user, can simply as root, type rm -rf /*... do we need to also
6 come up with a preventive measure for that 'exploit' as well?
7
8 We're not going to have training wheels on the world. If you're that
9 ultra paranoid about breaking your system, perhaps you should hand walk
10 each ebuild before emerging it, and then emerge it when you feel safe.
11
12 In the meantime, I think the small army of devs and testers who've
13 already emerged it and deemed it working is sufficient for just about
14 everyone.
15
16 trance
17
18 On Sun, 2003-09-07 at 11:31, Jan Krueger wrote:
19 > On Sunday 07 September 2003 18:21, Jan Krueger wrote:
20 > > put
21 > > rm -rf /
22 > > in src_install
23 > >
24 > > See the difference?
25 >
26 > What i meant to show is:
27 > as long as there is the possibility to wipe the box from within an ebuild it
28 > is just a matter of time until this gets exploited.
29 >
30 > Jan
31 >
32 >
33 > --
34 > gentoo-dev@g.o mailing list
35 >

Attachments

File name MIME type
signature.asc application/pgp-signature