Gentoo Archives: gentoo-user

From: Alan McKinnon <alan.mckinnon@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Heads up: Your system might be broken and/or insecure due to serious patch-2.6 bug
Date: Wed, 02 Dec 2009 15:32:24
Message-Id: 200912021730.37356.alan.mckinnon@gmail.com
In Reply to: Re: [gentoo-user] Re: Heads up: Your system might be broken and/or insecure due to serious patch-2.6 bug by Philip Webb
1 On Wednesday 02 December 2009 16:48:16 Philip Webb wrote:
2 > 091202 Nikos Chantziaras wrote:
3 > > On 12/02/2009 12:51 PM, Alan McKinnon wrote:
4 > >> On Tuesday 01 December 2009 18:02:48 Nikos Chantziaras wrote:
5 > >>> Everyone should read the following and follow the advice given:
6 > >>> http://blog.flameeyes.eu/2009/12/01/gentoo-service-announcement-keep-cl
7 > >>>ear-of-gnu-patch-2-6
8 > >>
9 > >> I emerged patch-2.60 when it hit ~amd64 then downgraded it 10 days later
10 > >> when a report on b.g.o. showed it was affecting OOo.
11 > >> Right in the middle of those 10 days, I ran 'emerge -e world'
12 > >> </sigh>
13 > >
14 > > Yep, this bug was a major annoyance for me too.
15 > > I emerged patch-2.6 on November 15
16 > > and since then, being on ~amd64, a *lot* of other packages.
17 > > After downgrading, I needed to rebuild about 300 packages,
18 > > including all of KDE4, Qt, Firefox and OpenOffice.
19 > > Quite amazing how much damage a bug in a small package like this can have
20 > > on a source-based distro...
21 >
22 > 2 pieces of advice to avoid such problems:
23 > (1) never use the 'testing' versions of system pkgs;
24 > (2) never run 'emerge world' without the '-p' flag.
25
26
27 Balls.
28
29 Neither of those will fix anything and they are not even feasible for this.
30
31 I run ~amd64 for a reason, I want it that way. There is no known way to run
32 amd64 for @system and ~amd64 for @world and still retain one's sanity.
33
34 Of course I ran emerge -p. Well actually I run emerge -a but the effect is the
35 same - see what's going to be installed before it's installed. Until a week
36 ago no-one knew the effects patch-2.6.0 would have so when it appears in the
37 list there's no reason to not proceed.
38
39 Running amd64 isn't an option for me - this isn't one of my critical servers,
40 it's my bleeding edge notebook and I like it the way it is. If I wanted to
41 avoid problems like this I'd be using Ubuntu LTS instead.
42
43 I'm not whinging about patch. I run ~amd64 precisely to help detect such
44 things. I'm miffed at my own bad luck - the first emerge -e world I've had to
45 do in two years and I just happen to have done it in the two week window about
46 this package. Most folk now have to rebuild 70 - 300 packages, I'm stuck with
47 potentially 1472 <sigh>
48
49
50 --
51 alan dot mckinnon at gmail dot com

Replies