Gentoo Archives: gentoo-hardened

From: Shinkan <shinkan@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Towards better profiles for hardened.
Date: Thu, 14 Jan 2010 14:00:47
Message-Id: 166af1cf1001140416r64b2be4cva66f512ae80da350@mail.gmail.com
In Reply to: [gentoo-hardened] Towards better profiles for hardened. by basile
1 2010/1/13 basile <basile@××××××××××××××.edu>
2
3 > Hi guys,
4 >
5 > I'm emailing because the profile issue came up again in IRC. I'd like
6 > to continue the discussion here. Let me try to get it started.
7 >
8 > Here's some general issues with the current profile stucture:
9 >
10 > 1) It is horribly complex and difficult to read the inheritance
11 > strucutre. Its not clear the inheritance even works. As a result, the
12 > user is not sure what is going on. This ambiguity makes it difficult
13 > to even start a coherent criticism!
14 >
15 > 2) There doesn't appear to be a good structure for seperation of various
16 > features. In OO language, I can't choose what to inherit. I wind up
17 > getting stuff from other profiles which I don't want and can't control
18 > this, so I'm tempted to just USE="-*" and start from scratch, which is
19 > not a good thing.
20 >
21 > 3) There is a clear bias towards the desktop. If you go that route, you
22 > get what you need/want. When you deviate, you start to get more things
23 > that you don't want/need and have to struggle against points 1 and 2.
24 >
25 > This effects hardened and hardened+server most. Comments?
26 >
27
28 I don't really get the productive side of this message, but I do agree with
29 all that points.
30
31
32 --
33 Pierre.
34 "Sometimes when I'm talking, my words can't keep up with my thoughts. I
35 wonder why we think faster than we speak. Probably so we can think twice." -
36 Bill Watterson

Replies

Subject Author
Re: [gentoo-hardened] Towards better profiles for hardened. Ed W <lists@××××××××××.com>