Gentoo Archives: gentoo-security

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Days of yore
Date: Mon, 16 Apr 2007 18:38:57
Message-Id: 200704162031.32362.jaervosz@gentoo.org
In Reply to: Re: [gentoo-security] Days of yore by Calum
1 Hi Calum,
2
3 On Monday 16 April 2007 19:09, Calum wrote:
4 > Yep, It sounds like it might have been promising. However, who on
5 > earth thought it would be a good idea to remove the functioning kernel
6 > security alert system **before** the replacement was written, working,
7 > heavily tested, and all the users given 12 months of notice?
8 > (The obvious method of notification would have been to create a fake
9 > GLSA for glsa-check.)
10 I'm not proud of the situation either, but it's not going to magically give me
11 the time/skills to actually do this stuff. I agree that it has been
12 mishandled, but given my timerestraints I simply can only wait for a good
13 recruit to appear.
14
15 I agree that policy should be updated to reflect this but that got bogged down
16 by other issues last I tried. I'll try again.
17
18 > > This started out as a small
19 > > problem that we thought would be temporary but has sadly turned kind of
20 > > permanent without us informing users properly.
21 >
22 > This is why, when people ask me if they can "temporarily" do things in
23 > my lab, I say no.
24 > Temporarily often has a habit of not being.
25 Volunteer projects unfortunately doesn't work the way normal paid work does.
26 If someone is willing to actually sponsor kernel GLSAs I'm sure someone will
27 step up:-)
28
29 > Could we just get GLSAs going again for some of the most common
30 > sources for now then? Say gentoo, and hardened? x86, and AMD?
31 > Or some virtual ebuild that requires certain versions of kernels to be
32 > installed, that can be updated via Portage from time to time.
33 > Then you could script emerge -pv sys-kernel/secure-kernel-source, and
34 > when it said it would need to install hardened-sources 2.6.26, you'd
35 > know that there must have been a bug in <2.4.26.
36 I would gladly see that happen, but I guess you have to talk to hlieberman
37 from security or some of the kernel maintainers (which are understaffed as
38 well as far as I undestand it). Or wait for others to reply.
39
40 If someone is willing to take the time to actually draft the GLSAs I'd be
41 happy to send/review.
42
43 --
44 Sune Kloppenborg Jeppesen
45 Gentoo Linux Security Team

Replies

Subject Author
Re: [gentoo-security] Days of yore "C. Bergström" <cbergstrom@×××××××××.com>
Re: [gentoo-security] Days of yore Sune Kloppenborg Jeppesen <jaervosz@g.o>