Gentoo Archives: gentoo-user

From: Dale <rdalek1967@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Heads up: Your system might be broken and/or insecure due to serious patch-2.6 bug
Date: Sat, 05 Dec 2009 06:48:34
Message-Id: 4B1A01EC.60402@gmail.com
In Reply to: Re: [gentoo-user] Re: Heads up: Your system might be broken and/or insecure due to serious patch-2.6 bug by Philip Webb
1 Philip Webb wrote:
2 > The defective version of 'patch' had got into 'testing',
3 > where the only remaining problems are supposed to be in the ebuild;
4 > in fact in this case, there was still a serious problem upstream
5 > & that version of 'patch' has been re-masked (I believe).
6 >
7 > Anyway, don't do testing on the machine you use for everyday computing.
8 > If you want to get into testing, use a dedicated machine for it.
9 >
10 > It's late Friday, so let me stick my neck out again
11 > (grins, sighs & gets another beer out of the fridge).
12 >
13 > At least once/month, if not once/week, someone reports on Gentoo User:
14 > "I did an emerge sync, installed the latest blahblah-1.2.3,
15 > did 'emerge world' & something dreadful has happened to my system".
16 >
17 > I've been using Gentoo for more than 6 years & it's never happened to me.
18 > I believe the reason is that I follow my own advice as above:
19 > I do install 'testing' versions of non-vital pkgs (eg 'eix')
20 > & items which are well-supported upstream (eg KDE, kernel),
21 > but I am very cautious about installing testing versions of system pkgs
22 > whose collapse would do real damage to my everyday activities.
23 > Even when stuff is well-supported upstream, I give it a few weeks
24 > to see if there are reports anywhere of bad things happening.
25 >
26 > Eg I have not moved upto the testing 'eix-0.18.3',
27 > because it requires that I replace 'lzma-utils' with 'xz-utils':
28 > it's not worth the risk of doing real damage elsewhere
29 > simply to get the latest version of 'eix', which is useful but non-essential.
30 > When 'xz-utils' reaches 'stable' (and has a less frightening version number),
31 > I will happily make the upgrade.
32 >
33 > Also, I never do a bald 'emerge world'. I look thro' the output of 'eix-sync',
34 > write -- with a pencil+paper -- a list of installed pkgs which have changed,
35 > run 'emerge -Dup world' to see what order of emerging is recommended,
36 > then individually 'emerge -pv <pkg>' & -- if all looks well -- 'emerge <pkg>'.
37 > Yes, it takes a bit longer for my weekly update session (tomorrow Sat),
38 > but I don't risk the nightmare of reducing my system to chaos
39 > with all the extra frantic labor which would result.
40 >
41 > Again, I've been doing this for 6 years with Gentoo on 2 machines
42 > & haven't run into any major setbacks.
43 >
44 > By all means, ignore my advice & do it your own ways (smile).
45 >
46 >
47
48 I do somewhat similar to you. I just use the -a option instead and I
49 don't write things down. I just do a emerge -uvDNa world and give it
50 all a once over, USE flags, what gets updated and if I want it etc etc.
51
52 I also run latest on eix, portage and some of its utils. I try to stay
53 away from unstable system packages as it seems you do as well. I'm
54 still on baselayout 1 and not planning on the openrc thingy yet either.
55 May want to get ready tho, it is coming.
56
57 I did my first install from a Gentoo 1.4 CD. That was quite a while ago.
58
59 Dale
60
61 :-) :-)