Gentoo Archives: gentoo-portage-dev

From: Duncan <1i5t5.duncan@×××.net>
To: gentoo-portage-dev@l.g.o
Subject: [gentoo-portage-dev] Re: New preserve-libs feature
Date: Sat, 24 Feb 2007 06:52:38
Message-Id: pan.2007.02.24.06.51.30@cox.net
In Reply to: Re: [gentoo-portage-dev] Re: New preserve-libs feature by Carsten Lohrke
1 Carsten Lohrke <carlo@g.o> posted
2 200702231422.05809.carlo@g.o, excerpted below, on Fri, 23 Feb 2007
3 14:22:05 +0100:
4
5 > I consider the preserve-libs functionality one of the biggest
6 > security threats for Gentoo users. You may dismiss this, saying the
7 > problem sits in front of the keyboard, but I'm telling you this is
8 > careless and that we can do better:
9 >
10 > echo "/path/to/preserved.so" >> /var/lib/portage/preserved_libs
11 >
12 > stores the libraries, and Portage can each time emerge is run look up,
13 > if the file lists libraries, check, if those exist, if not remove the
14 > lines or otherwise warn the user about the possibly vulnerable libraries
15 > and tell him what to do.
16
17 +1 here! During my own sysadmin-ings, I've wondered why there wasn't
18 such a list on several occasions. It would make things /so/ much
19 simpler, at least from the sysadmin perspective. (Of course, I realize
20 that's /not/ the same thing as simpler from a portage perspective, but
21 anyway, that's what's being discussed here. =8^)
22
23 If this is added, I think it's big enough to have it mentioned in the
24 handbook as well. Having that handy list all nicely centralized to one
25 location would be a /big/ boon to security conscious Gentoo sysadmins
26 everywhere, so it's easily worth mentioning in the handbook as one of the
27 valuable tools portage provides.
28
29 --
30 Duncan - List replies preferred. No HTML msgs.
31 "Every nonfree program has a lord, a master --
32 and if you use the program, he is your master." Richard Stallman
33
34 --
35 gentoo-portage-dev@g.o mailing list