Gentoo Archives: gentoo-project

From: "Michał Górny" <mgorny@g.o>
To: Andrew Savchenko <bircoph@×××××.com>
Cc: gentoo-project@l.g.o, Alexander Berntsen <bernalex@g.o>
Subject: Re: [gentoo-project] Call for agenda items - Council meeting 2014-08-12
Date: Wed, 30 Jul 2014 13:48:40
Message-Id: 20140730154852.11186366@pomiot.lan
In Reply to: Re: [gentoo-project] Call for agenda items - Council meeting 2014-08-12 by Andrew Savchenko
1 Dnia 2014-07-30, o godz. 15:44:28
2 Andrew Savchenko <bircoph@×××××.com> napisał(a):
3
4 > On Wed, 30 Jul 2014 12:28:32 +0200 Alexander Berntsen wrote:
5 > > On 30/07/14 09:26, Michał Górny wrote:
6 > > > 3. the use of group 'games' to control access to games can be
7 > > > deprecated and needs not to be enforced,
8 > > I would like the council to consider removing this group altogether,
9 > > and fixing all ebuilds to not use it.
10 >
11 > Please carefully consider this matter. Having a dedicated group is
12 > quite convenient to limit users from using games on workstations
13 > and is also handy as a parental control feature.
14
15 Please tell me, how many uses of games on workstations were actually
16 prevented thanks to it? How often do you happen to have a station that
17 has multiple users, games installed and you want to limit *all*
18 portage-installed games to subset of those users?
19
20 This a misguided attempt of fixing a social issue via technical means,
21 and it backfires a lot. In some cases it's an overkill, in some cases
22 it's incomplete. Following this logic, we ought to also limit access to
23 all ECMAScript-capable web browsers and scripting languages, including
24 the shell... oh wait, we just bricked the machine.
25
26 The only correct reason to limit access to games is when those involve
27 proprietary games for which only one of the users has license. But
28 then, it's a very big sledgehammer and a very small nut -- think of
29 the casualties.
30
31 > > Maybe we could finally get rid
32 > > of this[0] 8 year old bug in the process.
33 > >
34 > > [0] <https://bugs.gentoo.org/show_bug.cgi?id=125902>
35 >
36 > If application doesn't validate its input, this is an application's
37 > bug.
38
39 If users are allowed to edit files they were not supposed to edit, then
40 it's a distribution bug. Failure to validate input is orthogonal to
41 this, and should be fixed independently of it.
42
43 --
44 Best regards,
45 Michał Górny

Attachments

File name MIME type
signature.asc application/pgp-signature