public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
From: Andrew Savchenko <bircoph@gentoo.org>
To: gentoo-dev@lists.gentoo.org
Subject: Re: [gentoo-dev] why is the security team running around p.masking packages
Date: Mon, 4 Jul 2016 23:40:30 +0300	[thread overview]
Message-ID: <20160704234030.32bad9b5b2fb31f9a7d2ce73@gentoo.org> (raw)
In-Reply-To: <4c319530-3c7c-e8e3-300d-c80c84cf6674@gentoo.org>

[-- Attachment #1: Type: text/plain, Size: 1390 bytes --]

On Thu, 30 Jun 2016 22:51:51 -0400 Anthony G. Basile wrote:
> I'm going to ask the security team to please stop running around
> p.masking packages without acknowledgement from the maintainers.  I'm
> referring in particular to commit
> 135b94c85950254f559f290f4865bce8b349a917 regarding monkeyd.  Both of the
> cited "security bugs" were long fixed, and even if the were not, they do
> not merit masking because they were at best some information leakage
> with minor impact.  I have reverted that commit and would ask that
> security stop this practice.

Seconded here, the same applies to commit
61de68f69fdf7dd0aaa53303517c0e59738034c3, since security issues
doesn't affect most popular use cases, and at least first security
bug is fixed in [1]. Haven't tested the other bug, though.

The same applies for the tree-cleaners team. While their job is
very important, sometimes they are too hasty, like in commit
34181a1045d13142d959b9c894a46ddcebf3c512. If package builds and
works fine, have no critical bugs opened, the sheer fact that
upstream as inactive and package has no maintainer is no valid to
remove package. The reason "are still sitting in ~arch" is even
less valid, since it is absolutely fine that package never mades it
into stable (some people do not use stable at all).

[1] https://github.com/Mr-Dave/motion

Best regards,
Andrew Savchenko

[-- Attachment #2: Type: application/pgp-signature, Size: 819 bytes --]

  reply	other threads:[~2016-07-04 20:40 UTC|newest]

Thread overview: 42+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-07-01  2:51 [gentoo-dev] why is the security team running around p.masking packages Anthony G. Basile
2016-07-04 20:40 ` Andrew Savchenko [this message]
2016-07-04 21:09   ` Rich Freeman
2016-07-05  3:26     ` Aaron Bauman
2016-07-05 11:25       ` Rich Freeman
2016-07-05 13:07         ` james
2016-07-05 12:58           ` Alan McKinnon
2016-07-05 13:05             ` Rich Freeman
2016-07-05 16:53               ` james
2016-07-05 17:55                 ` Rich Freeman
2016-07-05 18:19                   ` Peter Stuge
2016-07-06 21:35                 ` OrangeFS support in Gentoo (Was: Re: [gentoo-dev] why is the security team running around p.masking packages) Andrew Savchenko
2016-07-06 21:08               ` [gentoo-dev] why is the security team running around p.masking packages Andrew Savchenko
2016-07-05 18:17           ` NP-Hardass
2016-07-05 19:53             ` james
2016-07-05 21:28               ` Alan McKinnon
2016-07-06  0:00       ` Anthony G. Basile
2016-07-06  2:43         ` Aaron Bauman
2016-07-06  2:52           ` NP-Hardass
2016-07-06  8:10             ` Anthony G. Basile
2016-07-06 10:54               ` Aaron Bauman
2016-07-06 11:15                 ` Anthony G. Basile
2016-07-06 11:23                   ` Aaron Bauman
2016-07-06 11:48                     ` Anthony G. Basile
2016-07-06 12:11                       ` Rich Freeman
2016-07-06 12:19                         ` Kristian Fiskerstrand
2016-07-06 13:49                           ` Rich Freeman
2016-07-06 14:02                             ` Kristian Fiskerstrand
2016-07-06 15:11                               ` Rich Freeman
2016-07-06 15:39                                 ` Paul Varner
2016-07-06 14:49                         ` Anthony G. Basile
2016-07-06 20:13                     ` Andrew Savchenko
2016-07-07  6:52                       ` J. Roeleveld
2016-07-08 16:02                       ` Andrew Savchenko
2016-07-08 17:17                         ` Alec Warner
2016-07-06 11:30                   ` Kristian Fiskerstrand
2016-07-06 11:50                     ` Anthony G. Basile
2016-07-06 11:00             ` Aaron Bauman
2016-07-06  8:04           ` Anthony G. Basile
2016-07-06  8:25             ` Kristian Fiskerstrand
2016-07-06  8:37               ` Anthony G. Basile
2016-07-06  8:49                 ` Kristian Fiskerstrand

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20160704234030.32bad9b5b2fb31f9a7d2ce73@gentoo.org \
    --to=bircoph@gentoo.org \
    --cc=gentoo-dev@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox