Gentoo Archives: gentoo-hardened

From: Gordon Malm <gengor@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] hardened glibc downgrade
Date: Fri, 13 Feb 2009 16:18:04
Message-Id: 200902130818.00827.gengor@gentoo.org
In Reply to: Re: [gentoo-hardened] hardened glibc downgrade by Thomas Sachau
1 On Friday, February 13, 2009 07:27:04 Thomas Sachau wrote:
2 > Guillaume Castagnino schrieb:
3 > > Hi,
4 > >
5 > > I noticed this in hardened profile :
6 > > # Mask off anything greater than glibc-2.6.x for now.
7 > > # 2009-02-11 gengor
8 > >
9 > >> =sys-libs/glibc-2.7
10 > >
11 > > Is there any good (means "critical") reason for this downgrade ?
12 > > Because it causes problem with some packages that needs higher glibc
13 > > version. For example :
14 > > - iproute2 needs >=glibc-2.7
15 > >
16 > >
17 > >
18 > > ('installed', '/', 'sys-libs/glibc-2.9_p20081201-r1', 'nomerge') pulled
19 > > in by
20 > >
21 > > >=sys-libs/glibc-2.7 required by ('installed', '/', 'sys-
22 > >
23 > > apps/iproute2-2.6.28', 'nomerge')
24 > > (and 12 more)
25 > >
26 > >
27 > > Thanks for your feedback
28 > >
29 > > Regards,
30 > > Guillaume
31 >
32 > I talked to gengor yesterday, so i just copy some lines from IRC:
33 >
34 > Feb 12 21:34:28 <gengor> Tommy[D]: because I haven't tested it against
35 > stable + stable kernel. Feb 12 21:37:57 <gengor> its safe because stable
36 > glibc (2.6.1) doesn't take advantage of any new API's between 2.6.{25,26}
37 > -> 2.6.27. I don't know about the newer glibc though, hence the mask. Feb
38 > 12 21:38:54 <gengor> it was fine to leave it that way when glibc was
39 > unstable (because those who run unstable should know what they are doing
40 > and be running unstable kernel too). But they're moving on glibc-2.8
41 > stabilization right now.
42 > Feb 12 21:40:33 <gengor> and there are still some minor lingering issues w/
43 > 2.6.27 and 2.6.28 so I don't want to mark it stable yet. Although we're
44 > getting to the point 2.6.26 is becoming out of date, not getting updates
45 > from mainline and I don't have time for a bunch of backports this time
46 > around - so my hand may be forced at some point.
47
48 In the future please refrain from cutting and pasting select bits of
49 conversation from IRC out of context. Or any IRC conversation for that
50 matter. You don't even realize that the bits you selected for cut/paste
51 don't even make sense w/o the other parts of the conversation. This is very
52 fscking rude.
53
54 To OP: If you've already upgraded your glibc then you've package.keyworded
55 it, so why not just package.unmask it as well? You're not forced to
56 downgrade.

Replies

Subject Author
Re: [gentoo-hardened] hardened glibc downgrade Guillaume Castagnino <casta@×××××.info>