From: Duncan <1i5t5.duncan@cox.net>
To: gentoo-dev@lists.gentoo.org
Subject: [gentoo-dev] Re: Revisions for USE flag changes
Date: Sun, 13 Aug 2017 02:32:20 +0000 (UTC) [thread overview]
Message-ID: <pan$a949d$db7c5bf4$6c108345$93010625@cox.net> (raw)
In-Reply-To: 265b4480-8425-4c52-df23-0cf423e1c7f4@gentoo.org
Michael Orlitzky posted on Sat, 12 Aug 2017 10:14:18 -0400 as excerpted:
> On 08/12/2017 06:29 AM, Rich Freeman wrote:
>>
>> My gut feeling is that the change you want is probably a good thing,
>> but it will never happen if you can't provide a single example of
>> something bad happening due to the lack of a revbump.
>
> There's an unfixed security vulnerability with USE=foo, so we drop the
> flag temporarily. Users who had USE=foo enabled will keep the vulnerable
> code installed until they update with --changed-use or --newuse.
>
> Even with the devmanual improvements, the advice we give is conflicting:
>
> * If you fix an important runtime issue, do a revbump.
>
> * If you drop a USE flag, don't do a revbump.
>
> What if you fix a runtime issue by dropping a flag? It's more confusing
> than it has to be: the USE flag exception interacts weirdly with all the
> other rules.
Bad example as it's a security vuln, which requires masking/removing
vulnerable versions, which will require a version bump in ordered to
prevent downgrades if it was the latest visible for a (stable or ~arch)
keyword.
So the version bump is effectively mandatory due to security overrides in
any case, and that it was fixed by a temporary USE flag drop doesn't
change things at all. If that security-override isn't explicit in
current documentation, that'd be the bug, not the fact that use-flag
drops don't on their own require a version-bump.
--
Duncan - List replies preferred. No HTML msgs.
"Every nonfree program has a lord, a master --
and if you use the program, he is your master." Richard Stallman
next prev parent reply other threads:[~2017-08-13 2:32 UTC|newest]
Thread overview: 39+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-08-11 23:50 [gentoo-dev] Revisions for USE flag changes Michael Orlitzky
2017-08-12 0:45 ` Brian Evans
2017-08-12 0:59 ` Michael Orlitzky
2017-08-12 1:04 ` Michael Orlitzky
2017-08-12 1:11 ` Brian Evans
2017-08-12 8:39 ` Paweł Hajdan, Jr.
2017-08-12 9:58 ` Michael Orlitzky
2017-08-13 2:52 ` [gentoo-dev] " Duncan
2017-08-13 10:11 ` Michael Orlitzky
2017-08-13 10:18 ` M. J. Everitt
2017-08-14 1:34 ` Duncan
2017-08-16 20:12 ` Daniel Campbell
2017-08-18 14:50 ` Duncan
2017-08-13 5:01 ` [gentoo-dev] " Hans de Graaff
2017-08-13 10:38 ` Michael Orlitzky
[not found] ` <CAJ0EP42EaW8=dm0c26Gaij9gEAmTVHxiyp5+Hc_CYGzEypudsA@mail.gmail.com>
[not found] ` <CAJ0EP40yVVpLqHL5qVixxgvMmJc7ezRsn42qLoe621wS0KF-VA@mail.gmail.com>
[not found] ` <CAJ0EP43YbX-vA5cWcFm_Etin4H31Nq2s_xYsrTwuOK6LVyW+9A@mail.gmail.com>
[not found] ` <CAJ0EP42HkoYEkL1vt=Lyt-Dw-1XkdAXed8DrBp4oYB9j01+PKQ@mail.gmail.com>
2017-08-13 17:28 ` Mike Gilbert
2017-08-12 4:22 ` [gentoo-dev] " Michael Palimaka
2017-08-12 10:16 ` Michael Orlitzky
2017-08-12 10:58 ` Michael Palimaka
2017-08-12 10:32 ` Rich Freeman
2017-08-12 5:02 ` [gentoo-dev] " Hans de Graaff
2017-08-12 7:03 ` Michał Górny
2017-08-12 9:57 ` Michael Orlitzky
2017-08-12 10:04 ` Toralf Förster
2017-08-12 10:29 ` Rich Freeman
2017-08-12 11:05 ` [gentoo-dev] " Michael Palimaka
2017-08-12 11:18 ` Rich Freeman
2017-08-14 12:01 ` Jason Zaman
2017-08-16 3:22 ` Michael Orlitzky
2017-08-16 15:56 ` Duncan
2017-08-16 16:09 ` Rich Freeman
2017-08-17 4:27 ` Jason Zaman
2017-08-12 14:14 ` [gentoo-dev] " Michael Orlitzky
2017-08-13 2:32 ` Duncan [this message]
2017-08-13 10:08 ` [gentoo-dev] " Michael Orlitzky
2017-08-13 16:06 ` [gentoo-dev] " William Hubbs
2017-08-13 16:12 ` Michael Orlitzky
2017-08-14 16:29 ` William L. Thomson Jr.
2017-08-14 16:21 ` William L. Thomson Jr.
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='pan$a949d$db7c5bf4$6c108345$93010625@cox.net' \
--to=1i5t5.duncan@cox.net \
--cc=gentoo-dev@lists.gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox