1 |
Hi Calum, |
2 |
|
3 |
On Monday 16 April 2007 19:09, Calum wrote: |
4 |
> Yep, It sounds like it might have been promising. However, who on |
5 |
> earth thought it would be a good idea to remove the functioning kernel |
6 |
> security alert system **before** the replacement was written, working, |
7 |
> heavily tested, and all the users given 12 months of notice? |
8 |
> (The obvious method of notification would have been to create a fake |
9 |
> GLSA for glsa-check.) |
10 |
I'm not proud of the situation either, but it's not going to magically give me |
11 |
the time/skills to actually do this stuff. I agree that it has been |
12 |
mishandled, but given my timerestraints I simply can only wait for a good |
13 |
recruit to appear. |
14 |
|
15 |
I agree that policy should be updated to reflect this but that got bogged down |
16 |
by other issues last I tried. I'll try again. |
17 |
|
18 |
> > This started out as a small |
19 |
> > problem that we thought would be temporary but has sadly turned kind of |
20 |
> > permanent without us informing users properly. |
21 |
> |
22 |
> This is why, when people ask me if they can "temporarily" do things in |
23 |
> my lab, I say no. |
24 |
> Temporarily often has a habit of not being. |
25 |
Volunteer projects unfortunately doesn't work the way normal paid work does. |
26 |
If someone is willing to actually sponsor kernel GLSAs I'm sure someone will |
27 |
step up:-) |
28 |
|
29 |
> Could we just get GLSAs going again for some of the most common |
30 |
> sources for now then? Say gentoo, and hardened? x86, and AMD? |
31 |
> Or some virtual ebuild that requires certain versions of kernels to be |
32 |
> installed, that can be updated via Portage from time to time. |
33 |
> Then you could script emerge -pv sys-kernel/secure-kernel-source, and |
34 |
> when it said it would need to install hardened-sources 2.6.26, you'd |
35 |
> know that there must have been a bug in <2.4.26. |
36 |
I would gladly see that happen, but I guess you have to talk to hlieberman |
37 |
from security or some of the kernel maintainers (which are understaffed as |
38 |
well as far as I undestand it). Or wait for others to reply. |
39 |
|
40 |
If someone is willing to take the time to actually draft the GLSAs I'd be |
41 |
happy to send/review. |
42 |
|
43 |
-- |
44 |
Sune Kloppenborg Jeppesen |
45 |
Gentoo Linux Security Team |