public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
From: "Kévin GASPARD DE RENEFORT" <kevingaspard@koshie.fr>
To: gentoo-dev@lists.gentoo.org
Subject: Re: [gentoo-dev] Re: Current unavoidable use of xz utils in Gentoo
Date: Wed, 3 Apr 2024 14:22:18 +0200	[thread overview]
Message-ID: <e8959706-decf-4547-9bc2-4b20b8c62748@koshie.fr> (raw)
In-Reply-To: <pan$36f07$72e9414d$17cd16a3$85bffcbd@cox.net>


> Helping with any of these three would certainly be reasonable.  But
> demanding a *LOT* of work to alternative-force an already attack-reverted
> package, when we actually KNOW about that one, it's reverted to pre-attack
> and there's likely to be no more mischief there /because/ everybody's
> looking at it now, when it could have been any of a number of packages,
> some of which might already be compromised and we just didn't happen to
> find it, IMO really doesn't make much sense.

Hello,

After so much reading and seeing almost a dead-end to this talk and from 
this citation above I had an idea for OP.

1/ OP is sure that Gentoo and others distro *should* avoid using 
xz-utils, at all cost.

(IMHO that is a respectable choice, *IF* it's possible without adding 
tremendous of works while Gentoo's dev could works on something else… 
Like being sure xz-utils is now safe to use…)

2/ Gentoo's dev stating that it's:

     a) Non-required, to not say useless.

     b) Would ask a lot of money to extend the infrastructure of Gentoo 
(two times the compressed file and the new non-xz would take like +30% 
in size…) and some works in addition for the systems administrators. As 
someone that had this job for some years, that is not always easy as it 
looks like and having more works is never fun while you already have 
some cooking… specially when you are not paid for this.

     c) Would ask a *LOT* of works for Gentoo's devs, ebuild mainteneurs…

     d) For, from Gentoos's dev opinion, something that only a very few 
users will actually use, without speaking about adding a layer of 
complexity in every process, from installing Gentoo or maintaining the 
packages. Looks like an awful jobs to be honest.

If OP is really that sure that Gentoo's dev are having a cavalier 
attitude, non-thinking enough about security in this subject, while 
(sorry but that's true) not paying much respect to the works into the 
community (Gentoo and free software in general)… Well:

Fork Gentoo, or any other distros, start a LFS…

I mean, this is *free software* (as in freedom), what makes you not 
starting your own project with peoples sharing your point-of-view ?

Some debian's user didn't liked the coming of SystemD, some made Devian 
(not even know if it's still around, but that is a simple example). 
Don't some *BSD distribution were borne for technical different 
point-of-view ? Yes, some did and are still here, since decades.

I think, IMHO, you should try to see if peoples around are having the 
same philosophy as you, if you find a bunch of peoples having times and 
willing to do it.

I suppose you have some knowledge, but I can only assume, maybe you 
don't have enough, could take years even if you have already these. Even 
more if you start from 0.

If you are alone, you have two choices:

1/ Do like Slackware, create as a lone-wolf your own distribution.

2/ Accept the idea that your idea is maybe not true, or good.

When a lot of peoples state that you are wrong, it doesn't means you are 
all the time. But at the same time, you were explained more than once 
that it's not a good idea, a really better way or they (Gentoo's dev) 
have other matter to take care of. Maybe Gentoo's dev are wrong. But in 
my case, I'll keep my side for the peoples that has proven theirs skills 
by their works. For more than 20 years, now.

That is just my opinion. You don't like it ? Fork it, find an 
alternative OR accept your faith. Or change for a distribution sharing 
your opinion about that.

PS : Sorry for my English.

Regards,
GASPARD DE RENEFORT Kévin



  parent reply	other threads:[~2024-04-03 12:22 UTC|newest]

Thread overview: 63+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-03-30  3:07 [gentoo-dev] Current unavoidable use of xz utils in Gentoo Eddie Chapman
2024-03-30  3:43 ` orbea
2024-03-30  7:06   ` Dale
2024-03-30 10:47     ` [gentoo-dev] " Duncan
2024-03-30 11:32     ` [gentoo-dev] " Rich Freeman
2024-03-30 14:57       ` Eddie Chapman
2024-03-30 15:02         ` Michał Górny
2024-03-30 15:17           ` Eddie Chapman
2024-03-30 15:29             ` Michał Górny
2024-03-30 15:59               ` Eddie Chapman
2024-03-30 16:07             ` Dale
2024-03-30 17:13             ` Re[2]: " Stefan Schmiedl
2024-03-30 17:36               ` Eddie Chapman
2024-03-31  1:41                 ` Thomas Gall
2024-03-30 23:49             ` Eddie Chapman
2024-03-31  1:36             ` Eli Schwartz
2024-03-30 15:23           ` orbea
2024-03-30 15:14         ` Rich Freeman
2024-03-30 17:19           ` Eddie Chapman
2024-03-31  1:25 ` Sam James
2024-03-31  1:33 ` Eli Schwartz
2024-03-31 11:13   ` Eddie Chapman
2024-03-31 11:59     ` Matt Jolly
2024-04-01  7:57       ` Eddie Chapman
2024-04-01 14:50         ` Eli Schwartz
2024-04-02  8:43           ` Eddie Chapman
2024-04-02 19:46             ` Eli Schwartz
2024-04-02 20:19               ` Eddie Chapman
2024-04-01 14:55         ` Michał Górny
2024-04-02  9:02           ` Eddie Chapman
2024-04-01 15:14     ` Kenton Groombridge
2024-04-01 15:40       ` orbea
2024-04-01 16:01         ` Kenton Groombridge
2024-04-01 16:21           ` orbea
2024-04-01 18:51             ` Kévin GASPARD DE RENEFORT
2024-04-01 20:07               ` James Le Cuirot
2024-04-02  6:32                 ` Joonas Niilola
2024-03-31 11:32   ` stefan11111
2024-04-01 14:56 ` Azamat Hackimov
2024-04-02 19:32   ` Eddie Chapman
2024-04-03 11:47     ` [gentoo-dev] " Duncan
2024-04-03 12:14       ` Sam James
2024-04-03 15:30         ` [gentoo-dev] " Eddie Chapman
2024-04-03 16:40           ` Michael Orlitzky
2024-04-04  3:20             ` [gentoo-dev] " Duncan
2024-04-04  3:49           ` [gentoo-dev] " Eli Schwartz
2024-04-04  8:32             ` Sam James
2024-04-04  8:34               ` Kévin GASPARD DE RENEFORT
2024-04-04 14:38               ` Eddie Chapman
2024-04-04 14:24             ` Eddie Chapman
2024-04-06 11:57               ` Eddie Chapman
2024-04-06 12:15                 ` Ulrich Mueller
2024-04-06 12:34                 ` Roy Bamford
2024-04-06 14:04                 ` Fabian Groffen
2024-04-07  6:44                   ` Eddie Chapman
2024-04-06 16:15                 ` Sam James
2024-04-07 11:24                   ` Eddie Chapman
2024-04-11  5:21                 ` Joonas Niilola
2024-04-12  7:18                   ` [gentoo-dev] " Duncan
2024-04-13  7:10                   ` [gentoo-dev] " Eddie Chapman
2024-04-03 12:22       ` Kévin GASPARD DE RENEFORT [this message]
2024-04-03 12:26         ` [gentoo-dev] " Kévin GASPARD DE RENEFORT
2024-04-04  1:41         ` Duncan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=e8959706-decf-4547-9bc2-4b20b8c62748@koshie.fr \
    --to=kevingaspard@koshie.fr \
    --cc=gentoo-dev@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox